package runner import ( "context" "os" "path/filepath" "testing" "bugabinga.net/luci/internal/ciconfig" ) func TestAuthMountRequiresOwnerOnlySource(t *testing.T) { dataDir := t.TempDir() source := filepath.Join(dataDir, "mounts", "auth", "repo", "job", "credentials") if err := os.MkdirAll(source, 0o700); err != nil { t.Fatal(err) } declaration := ciconfig.Mount{Type: "auth", Name: "credentials", Target: "/auth"} mounts, cleanup, err := durableMounts(context.Background(), dataDir, "repo", "job", []ciconfig.Mount{declaration}) if err != nil || len(mounts) != 1 { t.Fatalf("owner-only mount err=%v mounts=%v", err, mounts) } cleanup() if err := os.Chmod(source, 0o755); err != nil { t.Fatal(err) } if _, cleanup, err := durableMounts(context.Background(), dataDir, "repo", "job", []ciconfig.Mount{declaration}); err == nil { cleanup() t.Fatal("group-readable auth mount accepted") } }