55 lines
2.2 KiB
Go
55 lines
2.2 KiB
Go
package supervisor
|
|
|
|
import (
|
|
"errors"
|
|
"testing"
|
|
|
|
rvboxv1 "github.com/rvbox/rvbox/gen/go/rvbox/v1"
|
|
"github.com/rvbox/rvbox/internal/domain"
|
|
)
|
|
|
|
func TestStartSpecValidation_BH_SUPERVISOR_01(t *testing.T) {
|
|
t.Parallel()
|
|
issue, err := domain.ParseUUIDv7("019c46f1-1d02-7000-8000-000000000091")
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
cases := []StartSpec{
|
|
{},
|
|
{IssueUUID: issue, CommandRevision: 1, WorkingDirectory: `C:\work`},
|
|
{IssueUUID: issue, CommandRevision: 1, Execution: &rvboxv1.ExecutionSpec{}, WorkingDirectory: `C:\work`},
|
|
{IssueUUID: issue, CommandRevision: 1, Execution: &rvboxv1.ExecutionSpec{Source: &rvboxv1.ExecutionSpec_CommandText{CommandText: "echo ok"}}},
|
|
}
|
|
for index, spec := range cases {
|
|
if !errors.Is(spec.Validate(), ErrInvalidStartSpec) {
|
|
t.Fatalf("case %d validation = %v, want ErrInvalidStartSpec", index, spec.Validate())
|
|
}
|
|
}
|
|
valid := StartSpec{IssueUUID: issue, CommandRevision: 1, Execution: &rvboxv1.ExecutionSpec{Source: &rvboxv1.ExecutionSpec_CommandText{CommandText: "echo ok"}}, WorkingDirectory: `C:\work`}
|
|
if err := valid.Validate(); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
}
|
|
|
|
func TestWindowsIdentityMapsSelectionEvidence_HP_SUPERVISOR_05(t *testing.T) {
|
|
t.Parallel()
|
|
identity := EffectiveIdentity{
|
|
Context: "ACTIVE_SYSTEM",
|
|
SessionID: 7,
|
|
SessionUserSID: "S-1-5-21-user",
|
|
UserSID: "S-1-5-18",
|
|
AttemptedContexts: []string{"ACTIVE_USER_ELEVATED", "ACTIVE_SYSTEM"},
|
|
SelectionDetail: "ACTIVE_USER_ELEVATED: ELEVATION_UNAVAILABLE",
|
|
}
|
|
encoded := identity.WindowsIdentity()
|
|
if encoded == nil || encoded.GetEffectiveContext() != rvboxv1.WindowsExecutionContext_WINDOWS_EXECUTION_CONTEXT_ACTIVE_SYSTEM || encoded.GetSessionId() != 7 || encoded.GetSessionUserSid() != "S-1-5-21-user" || encoded.GetEffectiveUserSid() != "S-1-5-18" {
|
|
t.Fatalf("mapped identity = %#v", encoded)
|
|
}
|
|
if len(encoded.GetAttemptedContexts()) != 2 || encoded.GetAttemptedContexts()[0] != rvboxv1.WindowsExecutionContext_WINDOWS_EXECUTION_CONTEXT_ACTIVE_USER_ELEVATED {
|
|
t.Fatalf("attempted contexts = %v", encoded.GetAttemptedContexts())
|
|
}
|
|
if got := (EffectiveIdentity{AttemptedContexts: []string{"not-a-context"}}).WindowsIdentity(); got != nil {
|
|
t.Fatalf("unknown context evidence = %#v", got)
|
|
}
|
|
}
|