Luigit
repositories / bugabinga.net

bugabinga.net

personal infrastructure for bugabinga!

owned by admin

services/luci/internal/runner/mounts_test.go

Raw
package runner

import (
	"context"
	"os"
	"path/filepath"
	"testing"

	"bugabinga.net/luci/internal/ciconfig"
)

func TestAuthMountRequiresOwnerOnlySource(t *testing.T) {
	dataDir := t.TempDir()
	source := filepath.Join(dataDir, "mounts", "auth", "repo", "job", "credentials")
	if err := os.MkdirAll(source, 0o700); err != nil {
		t.Fatal(err)
	}
	declaration := ciconfig.Mount{Type: "auth", Name: "credentials", Target: "/auth"}
	mounts, cleanup, err := durableMounts(context.Background(), dataDir, "repo", "job", []ciconfig.Mount{declaration})
	if err != nil || len(mounts) != 1 {
		t.Fatalf("owner-only mount err=%v mounts=%v", err, mounts)
	}
	cleanup()
	if err := os.Chmod(source, 0o755); err != nil {
		t.Fatal(err)
	}
	if _, cleanup, err := durableMounts(context.Background(), dataDir, "repo", "job", []ciconfig.Mount{declaration}); err == nil {
		cleanup()
		t.Fatal("group-readable auth mount accepted")
	}
}