diff --git a/enroll/ignore.py b/enroll/ignore.py index 416b5ba..131085d 100644 --- a/enroll/ignore.py +++ b/enroll/ignore.py @@ -108,7 +108,7 @@ HIGH_CONFIDENCE_SECRET_PATTERNS = [ ( [A-Za-z0-9_.-]* ( - password|passwd|passphrase|pass|pin|pwd| + password|passwd|passphrase| token|auth[_-]?token|access[_-]?token|refresh[_-]?token| secret|client[_-]?secret|secret[_-]?key| api[_-]?key|access[_-]?key|private[_-]?key| @@ -116,8 +116,7 @@ HIGH_CONFIDENCE_SECRET_PATTERNS = [ aws[_-]?access[_-]?key[_-]?id|aws[_-]?secret[_-]?access[_-]?key| azure[_-]?client[_-]?secret|azure[_-]?tenant[_-]?id|azure[_-]?client[_-]?id| google[_-]?application[_-]?credentials|gcp[_-]?service[_-]?account| - service[_-]?account[_-]?key| - session_key + service[_-]?account[_-]?key ) [A-Za-z0-9_.-]* ) diff --git a/tests.sh b/tests.sh index e724f69..a9d8947 100755 --- a/tests.sh +++ b/tests.sh @@ -2,11 +2,6 @@ set -Eeuo pipefail -# These tests intentionally run as root and exercise Enroll's root-output -# safety checks. Keep test-created directories private even on Forgejo/Docker -# images that default to a permissive umask such as 0002. -umask 077 - PROJECT_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)" TMP_PARENT="${TMPDIR:-/tmp}" KEEP_WORKDIR=0 @@ -14,7 +9,6 @@ if [[ -n "${ENROLL_TEST_WORKDIR:-}" ]]; then WORK_DIR="${ENROLL_TEST_WORKDIR}" KEEP_WORKDIR=1 mkdir -p "${WORK_DIR}" - chmod 700 "${WORK_DIR}" || true else WORK_DIR="$(mktemp -d "${TMP_PARENT%/}/enroll-tests.XXXXXX")" fi diff --git a/tests/test_cli.py b/tests/test_cli.py index a5bed5d..04cdd70 100644 --- a/tests/test_cli.py +++ b/tests/test_cli.py @@ -645,9 +645,7 @@ def test_cli_harvest_remote_sops_encrypts_and_prints_path( assert calls.get("encrypt") -def test_cli_harvest_remote_password_required_exits_cleanly( - tmp_path: Path, monkeypatch -): +def test_cli_harvest_remote_password_required_exits_cleanly(monkeypatch): def boom(**kwargs): raise RemoteSudoPasswordRequired("pw required") @@ -662,8 +660,6 @@ def test_cli_harvest_remote_password_required_exits_cleanly( "example.com", "--remote-user", "root", - "--out", - str(tmp_path / "remote-harvest"), ], ) with pytest.raises(SystemExit) as e: diff --git a/tests/test_manifest.py b/tests/test_manifest.py index a2259f5..e72ee2e 100644 --- a/tests/test_manifest.py +++ b/tests/test_manifest.py @@ -969,10 +969,6 @@ def test_manifest_fqdn_existing_output_rejects_symlink_component(tmp_path: Path) _write_state(bundle, state) (out / "inventory").mkdir(parents=True) - # The output path itself must be root-safe so this test reaches the - # intended nested-symlink guard even when CI/root uses a permissive umask. - out.chmod(0o700) - (out / "inventory").chmod(0o700) escape.mkdir() (out / "inventory" / "host_vars").symlink_to(escape, target_is_directory=True) diff --git a/tests/test_manifest_safety.py b/tests/test_manifest_safety.py index a04c6a5..fa43490 100644 --- a/tests/test_manifest_safety.py +++ b/tests/test_manifest_safety.py @@ -36,11 +36,7 @@ def test_prepare_manifest_output_dir_allows_existing_clean_tree_in_site_mode( ): out = tmp_path / "site" out.mkdir() - # Match Enroll's root-run output safety expectations regardless of the - # ambient CI/container umask. - out.chmod(0o700) (out / ".git").mkdir() - (out / ".git").chmod(0o700) (out / ".git" / "ignored-link").symlink_to(tmp_path, target_is_directory=True) assert prepare_manifest_output_dir(out, allow_existing=True) == out @@ -49,9 +45,6 @@ def test_prepare_manifest_output_dir_allows_existing_clean_tree_in_site_mode( def test_prepare_manifest_output_dir_rejects_existing_tree_symlink(tmp_path: Path): out = tmp_path / "site" out.mkdir() - # Keep the root-safety check from masking the specific symlink assertion on - # Forgejo/Docker hosts that run with umask 0002. - out.chmod(0o700) (out / "bad-link").symlink_to(tmp_path, target_is_directory=True) with pytest.raises(ManifestOutputError, match="contains a symlink"):