test(p7-privilege): skip copy-as refusal test when workspace is not traversable by the unprivileged uid
CI / lint (push) Successful in 1m30s
CI / sanitizers (undefined) (push) Successful in 58s
CI / sanitizers (address) (push) Successful in 58s
CI / fuzz-build (push) Successful in 23s
CI / coverage (push) Successful in 47s
CI / valgrind (push) Successful in 39s
CI / build-and-test (push) Successful in 5m3s

This commit is contained in:
2026-09-12 13:08:22 +02:00
parent 549a23993f
commit 58409cee10
+11
View File
@@ -5207,6 +5207,17 @@ class TestCopyAs:
if os.geteuid() == 0:
if shutil.which("setpriv") is None:
pytest.skip("root runner without setpriv cannot start an unprivileged receiver")
# The unprivileged receiver must execute the server binary out of the
# test workspace, so the workspace path has to be traversable by uid
# 65534. A checkout under a 0700 directory (e.g. /root) is not; skip
# rather than fail — CI runs from a traversable workspace and still
# exercises this behavior.
probe = subprocess.run(
["setpriv", "--reuid=65534", "--regid=65534", "--clear-groups",
"test", "-x", os.path.abspath(SERVER_CMD[0])],
stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
if probe.returncode != 0:
pytest.skip("workspace is not traversable by the unprivileged receiver uid")
os.chmod(dest, 0o777)
proc, port = _start_captured_server(
prefix=["setpriv", "--reuid=65534", "--regid=65534", "--clear-groups"])