An account an agent runs as (novox/hq ADR 0266) is read on every look for a uid of 0, a group that grants root, any sudo rule and a mesh secret it can read; any way found is unhealthy and said, a read that fails is unknown.
27 lines
823 B
Go
27 lines
823 B
Go
package declaration
|
|
|
|
import (
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
// A user's root (novox/hq ADR 0266): "never" or absent, and nothing else.
|
|
func TestAUsersRootIsNeverOrAbsent(t *testing.T) {
|
|
for _, c := range []struct {
|
|
root string
|
|
ok bool
|
|
}{{`,"root":"never"`, true}, {``, true}, {`,"root":"always"`, false}, {`,"root":"no"`, false}} {
|
|
d, err := Parse([]byte(`{"declaration":1,"resources":[{"id":"claude-code.agent","type":"user","name":"agent"` +
|
|
c.root + `}]}`))
|
|
if c.ok != (err == nil) {
|
|
t.Errorf("%s: err %v", c.root, err)
|
|
}
|
|
if err != nil && !strings.Contains(err.Error(), `"never"`) {
|
|
t.Errorf("%s: the refusal does not name the allowed value: %v", c.root, err)
|
|
}
|
|
if c.ok && c.root != "" && d.Resources[0].(*User).Root != RootNever {
|
|
t.Errorf("%s: read as %+v", c.root, d.Resources[0])
|
|
}
|
|
}
|
|
}
|