from pathlib import Path from tempfile import TemporaryDirectory import os import unittest from runtime_preflight import SOURCE_DIRS, SOURCE_FILES, verify_access class ContainerAccessTest(unittest.TestCase): def fixture(self, tmp): root = Path(tmp) / "app" root.mkdir() for name in SOURCE_DIRS: (root / name).mkdir() (root / name / "sample.txt").write_text("readable") for name in SOURCE_FILES: (root / name).write_text("readable") return root, Path(tmp) / "reports" def test_code_readable_and_reports_outside_readonly_tree(self): with TemporaryDirectory() as tmp: root, reports = self.fixture(tmp) self.assertEqual(verify_access(root, reports), 8) self.assertEqual(list(reports.iterdir()), []) def test_missing_runner_is_reported(self): with TemporaryDirectory() as tmp: root, reports = self.fixture(tmp) (root / "run_tests.py").unlink() with self.assertRaises(FileNotFoundError): verify_access(root, reports) @unittest.skipIf(os.geteuid() == 0, "Permission semantics require an unprivileged user") def test_unreadable_source_fails(self): with TemporaryDirectory() as tmp: root, reports = self.fixture(tmp) path = root / "netplan_v4" / "sample.txt" path.chmod(0) try: with self.assertRaises(PermissionError): verify_access(root, reports) finally: path.chmod(0o600) @unittest.skipIf(os.geteuid() == 0, "Permission semantics require an unprivileged user") def test_untraversable_directory_is_not_silently_skipped(self): with TemporaryDirectory() as tmp: root, reports = self.fixture(tmp) path = root / "tests" path.chmod(0) try: with self.assertRaises(PermissionError): verify_access(root, reports) finally: path.chmod(0o700) def test_reports_cannot_target_application_tree(self): with TemporaryDirectory() as tmp: root, _ = self.fixture(tmp) with self.assertRaises(ValueError): verify_access(root, root / "test-results")