Files
mesh-host/internal/declaration/root_test.go
T
jochen 8390fab5cb
mesh/merge-gate pass: builds mesh-host → ace, g14, novox, shanks; no bus step; every machine composes with the change as it did without (4 of 4 compose)
mesh/repo-check pass: its merge-check.sh passed
mesh/delivery superseded: a newer head of the same pull request
Judge whether an account declared never to become root can, so a machine's agents are known confined
An account an agent runs as (novox/hq ADR 0266) is read on every look for a
uid of 0, a group that grants root, any sudo rule and a mesh secret it can
read; any way found is unhealthy and said, a read that fails is unknown.
2026-10-08 18:30:10 +02:00

27 lines
823 B
Go

package declaration
import (
"strings"
"testing"
)
// A user's root (novox/hq ADR 0266): "never" or absent, and nothing else.
func TestAUsersRootIsNeverOrAbsent(t *testing.T) {
for _, c := range []struct {
root string
ok bool
}{{`,"root":"never"`, true}, {``, true}, {`,"root":"always"`, false}, {`,"root":"no"`, false}} {
d, err := Parse([]byte(`{"declaration":1,"resources":[{"id":"claude-code.agent","type":"user","name":"agent"` +
c.root + `}]}`))
if c.ok != (err == nil) {
t.Errorf("%s: err %v", c.root, err)
}
if err != nil && !strings.Contains(err.Error(), `"never"`) {
t.Errorf("%s: the refusal does not name the allowed value: %v", c.root, err)
}
if c.ok && c.root != "" && d.Resources[0].(*User).Root != RootNever {
t.Errorf("%s: read as %+v", c.root, d.Resources[0])
}
}
}