Compare commits

..

2 commits

Author SHA1 Message Date
4146aa997b
Fix tests
Some checks failed
CI / test (push) Successful in 50s
CI / test (almalinux, docker.io/library/almalinux:9, python3.11) (push) Failing after 2m36s
CI / test (debian, docker.io/library/debian:13, python3) (push) Failing after 3m2s
Lint / test (push) Successful in 1m15s
2026-06-30 11:11:38 +10:00
737316d507
More phrases to catch as potentially sensitive 2026-06-30 11:10:57 +10:00
5 changed files with 25 additions and 3 deletions

View file

@ -108,7 +108,7 @@ HIGH_CONFIDENCE_SECRET_PATTERNS = [
(
[A-Za-z0-9_.-]*
(
password|passwd|passphrase|
password|passwd|passphrase|pass|pin|pwd|
token|auth[_-]?token|access[_-]?token|refresh[_-]?token|
secret|client[_-]?secret|secret[_-]?key|
api[_-]?key|access[_-]?key|private[_-]?key|
@ -116,7 +116,8 @@ HIGH_CONFIDENCE_SECRET_PATTERNS = [
aws[_-]?access[_-]?key[_-]?id|aws[_-]?secret[_-]?access[_-]?key|
azure[_-]?client[_-]?secret|azure[_-]?tenant[_-]?id|azure[_-]?client[_-]?id|
google[_-]?application[_-]?credentials|gcp[_-]?service[_-]?account|
service[_-]?account[_-]?key
service[_-]?account[_-]?key|
session_key
)
[A-Za-z0-9_.-]*
)

View file

@ -2,6 +2,11 @@
set -Eeuo pipefail
# These tests intentionally run as root and exercise Enroll's root-output
# safety checks. Keep test-created directories private even on Forgejo/Docker
# images that default to a permissive umask such as 0002.
umask 077
PROJECT_ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
TMP_PARENT="${TMPDIR:-/tmp}"
KEEP_WORKDIR=0
@ -9,6 +14,7 @@ if [[ -n "${ENROLL_TEST_WORKDIR:-}" ]]; then
WORK_DIR="${ENROLL_TEST_WORKDIR}"
KEEP_WORKDIR=1
mkdir -p "${WORK_DIR}"
chmod 700 "${WORK_DIR}" || true
else
WORK_DIR="$(mktemp -d "${TMP_PARENT%/}/enroll-tests.XXXXXX")"
fi

View file

@ -645,7 +645,9 @@ def test_cli_harvest_remote_sops_encrypts_and_prints_path(
assert calls.get("encrypt")
def test_cli_harvest_remote_password_required_exits_cleanly(monkeypatch):
def test_cli_harvest_remote_password_required_exits_cleanly(
tmp_path: Path, monkeypatch
):
def boom(**kwargs):
raise RemoteSudoPasswordRequired("pw required")
@ -660,6 +662,8 @@ def test_cli_harvest_remote_password_required_exits_cleanly(monkeypatch):
"example.com",
"--remote-user",
"root",
"--out",
str(tmp_path / "remote-harvest"),
],
)
with pytest.raises(SystemExit) as e:

View file

@ -969,6 +969,10 @@ def test_manifest_fqdn_existing_output_rejects_symlink_component(tmp_path: Path)
_write_state(bundle, state)
(out / "inventory").mkdir(parents=True)
# The output path itself must be root-safe so this test reaches the
# intended nested-symlink guard even when CI/root uses a permissive umask.
out.chmod(0o700)
(out / "inventory").chmod(0o700)
escape.mkdir()
(out / "inventory" / "host_vars").symlink_to(escape, target_is_directory=True)

View file

@ -36,7 +36,11 @@ def test_prepare_manifest_output_dir_allows_existing_clean_tree_in_site_mode(
):
out = tmp_path / "site"
out.mkdir()
# Match Enroll's root-run output safety expectations regardless of the
# ambient CI/container umask.
out.chmod(0o700)
(out / ".git").mkdir()
(out / ".git").chmod(0o700)
(out / ".git" / "ignored-link").symlink_to(tmp_path, target_is_directory=True)
assert prepare_manifest_output_dir(out, allow_existing=True) == out
@ -45,6 +49,9 @@ def test_prepare_manifest_output_dir_allows_existing_clean_tree_in_site_mode(
def test_prepare_manifest_output_dir_rejects_existing_tree_symlink(tmp_path: Path):
out = tmp_path / "site"
out.mkdir()
# Keep the root-safety check from masking the specific symlink assertion on
# Forgejo/Docker hosts that run with umask 0002.
out.chmod(0o700)
(out / "bad-link").symlink_to(tmp_path, target_is_directory=True)
with pytest.raises(ManifestOutputError, match="contains a symlink"):