fix(p7-privilege): close re-review gaps (implicit dir ownership, daemon --super, write-devices gate)
This commit is contained in:
@@ -341,6 +341,28 @@ class TestDaemonRejection:
|
||||
f"daemon did not log the copy-as refusal: {tail[-400:]!r}"
|
||||
)
|
||||
|
||||
def test_super_refused_by_daemon(self, daemon):
|
||||
"""P7 Wave E: --super (SUPER_MODE_ON) implies raw numeric-id ownership
|
||||
with no explicit identity flag, so a daemon refuses it for the same
|
||||
reason it refuses --copy-as: there is no per-module opt-in for
|
||||
client-chosen ownership. The refusal happens at the config handshake,
|
||||
before any data lands."""
|
||||
log_path = os.path.join(TEST_DATA_DIR, "fastsyncd.log")
|
||||
before = os.path.getsize(log_path) if os.path.exists(log_path) else 0
|
||||
before_files = self._tree_files()
|
||||
result, _ = run_client(SOURCE_DIR, "127.0.0.1::files", port=daemon.port,
|
||||
flags=["--super", "--preserve"])
|
||||
assert result.returncode != 0, "the daemon must refuse --super"
|
||||
assert self._tree_files() == before_files, \
|
||||
"--super refusal wrote under the module root"
|
||||
time.sleep(0.3)
|
||||
with open(log_path, "rb") as f:
|
||||
f.seek(before)
|
||||
tail = f.read().decode("utf-8", "replace")
|
||||
assert "super is refused by the daemon" in tail, (
|
||||
f"daemon did not log the --super refusal: {tail[-400:]!r}"
|
||||
)
|
||||
|
||||
@pytest.mark.daemon_detach
|
||||
def test_real_detach_path(self):
|
||||
"""--daemon WITHOUT --no-detach double-forks a real background daemon;
|
||||
|
||||
@@ -5291,6 +5291,38 @@ class TestCopyAs:
|
||||
f"--copy-as did not own the directory: uid={st.st_uid} gid={st.st_gid}"
|
||||
)
|
||||
|
||||
@pytest.mark.ci
|
||||
@pytest.mark.skipif(os.geteuid() != 0, reason="requires a root receiver to chown")
|
||||
def test_root_copy_as_owns_implicit_parent_dirs(self, shared_server):
|
||||
"""--copy-as must also own the intermediate directories that the receiver
|
||||
creates implicitly while writing a nested file (the scanner does not emit
|
||||
STATUS_MKDIR entries for ordinary traversal directories), not just the
|
||||
file itself."""
|
||||
source = os.path.join(TEST_DATA_DIR, "copyas_nested_src")
|
||||
dest = os.path.join(TEST_DATA_DIR, "copyas_nested_dst")
|
||||
clean_dir(source)
|
||||
clean_dir(dest)
|
||||
nested = os.path.join(source, "top", "mid", "leaf")
|
||||
os.makedirs(nested, exist_ok=True)
|
||||
with open(os.path.join(nested, "deep.txt"), "wb") as fh:
|
||||
fh.write(b"nested copy-as ownership\n")
|
||||
|
||||
result, _ = run_client(source, dest,
|
||||
flags=["--copy-as=@65534:@65534"],
|
||||
port=shared_server.port)
|
||||
assert result.returncode == 0, (
|
||||
f"--copy-as nested transfer failed: {(result.stderr or result.stdout)[:400]}"
|
||||
)
|
||||
received = get_dest_received_dir(dest, source)
|
||||
for rel in ("top", os.path.join("top", "mid"), os.path.join("top", "mid", "leaf")):
|
||||
target = os.path.join(received, rel)
|
||||
assert os.path.isdir(target), f"implicit directory missing at {target}"
|
||||
st = os.stat(target)
|
||||
assert (st.st_uid, st.st_gid) == (65534, 65534), (
|
||||
f"--copy-as did not own implicit directory {rel}: "
|
||||
f"uid={st.st_uid} gid={st.st_gid}"
|
||||
)
|
||||
|
||||
@pytest.mark.ci
|
||||
@pytest.mark.skipif(os.geteuid() != 0, reason="requires a root receiver to chown")
|
||||
def test_root_copy_as_owns_fifo(self, shared_server):
|
||||
|
||||
Reference in New Issue
Block a user