felis-nano runs as a systemd DynamicUser, so it can read /etc/felis/felis.toml only if others may search /etc/felis. write_nano_config made the directory with a bare mkdir -p, which takes its mode from root's umask. On a host hardened to umask 027 that is 0750: nano exits on "permission denied", the unit restarts every five seconds, and no login gets through. A missing directory is now created 0755 explicitly. An existing one keeps its mode, because the full install sets it to 0700 to protect its secrets and widening that from the nano path would expose them. A nano unit locked out that way is left for the install to report. The harness runs the extracted function under umask 027 and checks both cases. Reverting to the bare mkdir fails the first; an unconditional chmod 0755 fails the second. The mode checks skip on filesystems that ignore chmod, such as Git Bash on NTFS.
216 lines
9.7 KiB
Bash
216 lines
9.7 KiB
Bash
#!/bin/sh
|
|
# Checks for deploy/bootstrap.sh. Run it as: sh deploy/bootstrap_test.sh
|
|
#
|
|
# The script it tests cannot be run here — it wants root, a package manager, k3s and the
|
|
# network — so each case extracts the block it is about out of bootstrap.sh verbatim and runs
|
|
# that with die/log stubbed. Extraction rather than a transcribed copy is the point: a copy
|
|
# passes forever after someone edits the original.
|
|
set -u
|
|
|
|
BS="${1:-$(dirname "$0")/bootstrap.sh}"
|
|
[ -f "$BS" ] || { echo "no such script: $BS"; exit 1; }
|
|
fails=0
|
|
|
|
expect() { # label needle haystack
|
|
case "$3" in
|
|
*"$2"*) echo "PASS $1" ;;
|
|
*) echo "FAIL $1: expected <$2> in:"; echo "$3"; fails=$((fails + 1)) ;;
|
|
esac
|
|
}
|
|
|
|
# --- the FELIS_VELOCITY_FORK_JAR digest gate -------------------------------------------
|
|
# This jar becomes the proxy every player connects through, so the interesting cases are the
|
|
# two refusals, not the happy path.
|
|
|
|
gate="$(awk '/have="\$\(sha256sum <"\$FELIS_VELOCITY_FORK_JAR"/,/^ log "installing the Felis-Legacy/' "$BS")"
|
|
[ -n "$gate" ] || { echo "FAIL: no fork-jar digest gate found in $BS"; exit 1; }
|
|
# awk runs an unmatched end pattern to EOF, which would quietly pipe the rest of bootstrap.sh
|
|
# into the `sh -c` below. The emptiness check above only catches a broken start pattern.
|
|
[ "$(printf '%s\n' "$gate" | wc -l)" -lt 40 ] \
|
|
|| { echo "FAIL: the extracted block is not the gate -- did its last line move?"; exit 1; }
|
|
|
|
jar="$(mktemp)"
|
|
trap 'rm -f "$jar"' EXIT
|
|
printf 'stand-in for a fork build\n' > "$jar"
|
|
want="$(sha256sum <"$jar" | cut -d' ' -f1)"
|
|
|
|
run_gate() { # digest
|
|
FELIS_VELOCITY_FORK_JAR="$jar" FELIS_VELOCITY_FORK_JAR_SHA256="$1" sh -c '
|
|
die() { printf "DIE: %s\n" "$*"; exit 1; }
|
|
log() { printf "LOG: %s\n" "$*"; }
|
|
'"$gate"
|
|
}
|
|
|
|
out="$(run_gate '')"
|
|
expect "fork jar without a digest is refused" "DIE: FELIS_VELOCITY_FORK_JAR_SHA256 is required" "$out"
|
|
expect "the refusal names the jar's real digest" "$want" "$out"
|
|
|
|
out="$(run_gate 'deadbeef')"
|
|
expect "a mismatched digest is refused" "checksum mismatch: got ${want}, expected deadbeef" "$out"
|
|
|
|
out="$(run_gate "$want")"
|
|
expect "the matching digest installs" "LOG: installing the Felis-Legacy Velocity fork" "$out"
|
|
expect "the install line records the digest" "(sha256 ${want})" "$out"
|
|
|
|
# The build host is usually Windows, where nothing prints the digest the way sha256sum does:
|
|
# Get-FileHash returns uppercase and certutil has shipped the bytes space-separated. Feeding
|
|
# the gate its own output can never catch that -- these two cases are the operator's paste.
|
|
out="$(run_gate "$(printf '%s' "$want" | tr 'a-z' 'A-Z')")"
|
|
expect "an uppercase digest is the same digest" "LOG: installing the Felis-Legacy Velocity fork" "$out"
|
|
|
|
out="$(run_gate "$(printf '%s' "$want" | sed 's/../& /g')")"
|
|
expect "a space-separated digest is the same digest" "LOG: installing the Felis-Legacy Velocity fork" "$out"
|
|
|
|
# --- papermc_latest_jar answers "url sha256" from one response --------------------------
|
|
# Fill's download URLs are content-addressed (/v1/objects/<sha256>/<name>.jar), and the
|
|
# resolver's contract is to hand both halves back from the same grep — or refuse a URL
|
|
# that carries no digest, rather than wave the download through unchecked. Run under
|
|
# bash, not sh: bootstrap.sh is bash and the function uses $'\n'.
|
|
|
|
fn="$(awk '/^papermc_latest_jar\(\)/,/^}/' "$BS")"
|
|
[ -n "$fn" ] || { echo "FAIL: no papermc_latest_jar in $BS"; exit 1; }
|
|
[ "$(printf '%s\n' "$fn" | wc -l)" -lt 30 ] \
|
|
|| { echo "FAIL: the extracted papermc_latest_jar is not just the function -- did its closing brace move?"; exit 1; }
|
|
|
|
rsha=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
|
|
|
|
run_resolver() { # canned-fill-response
|
|
CANNED="$1" bash -c '
|
|
curl() { printf "%s" "$CANNED"; }
|
|
'"$fn"'
|
|
if out="$(papermc_latest_jar velocity 3.5.1)"; then
|
|
printf "RESOLVED %s\n" "$out"
|
|
else
|
|
printf "REFUSED\n"
|
|
fi
|
|
'
|
|
}
|
|
|
|
out="$(run_resolver "{\"url\":\"https://fill-data.papermc.io/v1/objects/${rsha}/velocity-3.5.1-615.jar\"}")"
|
|
expect "the resolver pairs the url with its own digest" \
|
|
"RESOLVED https://fill-data.papermc.io/v1/objects/${rsha}/velocity-3.5.1-615.jar ${rsha}" "$out"
|
|
|
|
out="$(run_resolver '{"url":"https://fill-data.papermc.io/mirror/velocity-3.5.1-615.jar"}')"
|
|
expect "a URL that carries no digest is refused" "REFUSED" "$out"
|
|
|
|
# --- the resolved-Velocity digest gate --------------------------------------------------
|
|
# The download must hash to what the content-addressed URL promised, BEFORE
|
|
# atomic_install_file — the same refusal the Via plugins and the fork jar already get.
|
|
|
|
# The end pattern spells ${VELOCITY_DIR} with dots: escaped braces are literal in gawk
|
|
# and mawk but undefined in POSIX awk, and CI's awk is whatever ubuntu ships.
|
|
vblock="$(awk '/log "resolving the newest Velocity/,/atomic_install_file "\$tmp" "\$.VELOCITY_DIR.\/velocity\.jar"/' "$BS")"
|
|
[ -n "$vblock" ] || { echo "FAIL: no resolved-Velocity install block found in $BS"; exit 1; }
|
|
[ "$(printf '%s\n' "$vblock" | wc -l)" -lt 30 ] \
|
|
|| { echo "FAIL: the extracted block is not the velocity install -- did its last line move?"; exit 1; }
|
|
|
|
vdir="$(mktemp -d)"
|
|
trap 'rm -f "$jar"; rm -rf "$vdir"' EXIT
|
|
vwant="$(printf 'stand-in velocity build\n' | sha256sum | cut -d' ' -f1)"
|
|
|
|
run_velocity_install() { # digest-the-resolver-reports
|
|
WANT="$1" VELOCITY_DIR="$vdir" FELIS_VELOCITY_VERSION=3.5.1 bash -c '
|
|
die() { printf "DIE: %s\n" "$*"; exit 1; }
|
|
log() { printf "LOG: %s\n" "$*"; }
|
|
remember_temp() { :; }
|
|
papermc_latest_jar() {
|
|
printf "%s %s\n" "https://fill-data.papermc.io/v1/objects/${WANT}/velocity-3.5.1-615.jar" "$WANT"
|
|
}
|
|
curl() { while [ "$#" -gt 1 ] && [ "$1" != "-o" ]; do shift; done; printf "stand-in velocity build\n" > "$2"; }
|
|
atomic_install_file() { printf "INSTALL: %s\n" "$2"; }
|
|
'"$vblock"
|
|
}
|
|
|
|
out="$(run_velocity_install deadbeef)"
|
|
expect "a download that does not hash to the promised digest is refused" \
|
|
"DIE: Velocity 3.5.1 checksum mismatch: got ${vwant}, expected deadbeef" "$out"
|
|
case "$out" in
|
|
*INSTALL:*) echo "FAIL a refused download must not reach atomic_install_file"; fails=$((fails + 1)) ;;
|
|
*) echo "PASS a refused download is not installed" ;;
|
|
esac
|
|
|
|
out="$(run_velocity_install "$vwant")"
|
|
expect "the matching download installs" "INSTALL: ${vdir}/velocity.jar" "$out"
|
|
|
|
# --- [[auth_source]] carry-forward -----------------------------------------------------
|
|
# write_felis_toml regenerates felis.toml wholesale on every run; this is what keeps the
|
|
# operator's Yggdrasil roots from being reset to the shipped default.
|
|
|
|
ablock="$(awk '/^persisted_auth_source_blocks\(\) \{/,/^}/' "$BS")"
|
|
[ -n "$ablock" ] || { echo "FAIL: no persisted_auth_source_blocks found in $BS"; exit 1; }
|
|
[ "$(printf '%s\n' "$ablock" | wc -l)" -lt 20 ] \
|
|
|| { echo "FAIL: the extracted block is not the function -- did its closing brace move?"; exit 1; }
|
|
|
|
sdir="$(mktemp -d)"
|
|
trap 'rm -f "$jar"; rm -rf "$vdir" "$sdir"' EXIT
|
|
|
|
run_carry() {
|
|
STATE_DIR="$sdir" bash -c "$ablock"'
|
|
persisted_auth_source_blocks'
|
|
}
|
|
|
|
out="$(run_carry)"
|
|
expect "a first install gets the LittleSkin default" 'tag = "littleskin"' "$out"
|
|
|
|
printf '%s\n' '[server]' 'listen = "0.0.0.0:8080"' '' '[[auth_source]]' 'tag = "guild"' \
|
|
'prefix = "GD"' 'url = "https://guild.example/hasJoined"' '' '[smtp]' 'host = "mail.example"' \
|
|
> "$sdir/felis.host.toml"
|
|
out="$(run_carry)"
|
|
expect "an operator's root is carried forward" 'tag = "guild"' "$out"
|
|
case "$out" in
|
|
*littleskin*|*"[smtp]"*) echo "FAIL the carried list must be exactly the operator's tables:"; echo "$out"; fails=$((fails + 1)) ;;
|
|
*) echo "PASS the carried list stops at the next section and adds no default" ;;
|
|
esac
|
|
|
|
printf '%s\n' '[server]' 'listen = "0.0.0.0:8080"' > "$sdir/felis.host.toml"
|
|
out="$(run_carry)"
|
|
if [ -z "$out" ]; then
|
|
echo "PASS a config with no sources stays Mojang-only"
|
|
else
|
|
echo "FAIL a config with no sources must not get the default back:"; echo "$out"; fails=$((fails + 1))
|
|
fi
|
|
|
|
# The felis setup TUI re-encodes the whole file, which indents keys under each table.
|
|
rm -f "$sdir/felis.host.toml"
|
|
printf '%s\n' '[[auth_source]]' ' tag = "littleskin"' ' prefix = "LS"' ' url = "https://a.example"' \
|
|
'' '[[auth_source]]' ' tag = "guild"' ' prefix = "GD"' ' url = "https://b.example"' \
|
|
> "$sdir/felis.pod.toml"
|
|
out="$(run_carry)"
|
|
expect "both encoder-written tables are carried (first)" ' tag = "littleskin"' "$out"
|
|
expect "both encoder-written tables are carried (second)" ' tag = "guild"' "$out"
|
|
|
|
# --- write_nano_config leaves the unit able to read its config ---------------------------
|
|
# felis-nano runs as a DynamicUser, so the directory must be searchable by others under a
|
|
# hardened umask too -- but an existing one, which the full install locks to 0700 for its
|
|
# secrets, must not be widened.
|
|
|
|
wblock="$(awk '/^write_nano_config\(\) \{/,/^}/' "$BS")"
|
|
[ -n "$wblock" ] || { echo "FAIL: no write_nano_config found in $BS"; exit 1; }
|
|
[ "$(printf '%s\n' "$wblock" | wc -l)" -lt 40 ] \
|
|
|| { echo "FAIL: the extracted block is not the function -- did its closing brace move?"; exit 1; }
|
|
|
|
run_nano_config() { # state-dir
|
|
STATE_DIR="$1" bash -c 'umask 027
|
|
ok() { printf "OK: %s\n" "$*"; }
|
|
'"$wblock"'
|
|
write_nano_config'
|
|
}
|
|
|
|
mkdir "$sdir/probe" && chmod 0700 "$sdir/probe"
|
|
if [ "$(stat -c %a "$sdir/probe")" = 700 ]; then
|
|
run_nano_config "$sdir/nano" >/dev/null
|
|
expect "a fresh config dir is searchable under umask 027" 755 "$(stat -c %a "$sdir/nano")"
|
|
run_nano_config "$sdir/probe" >/dev/null
|
|
expect "an existing 0700 dir is not widened" 700 "$(stat -c %a "$sdir/probe")"
|
|
else
|
|
echo "SKIP directory modes: this filesystem ignores chmod"
|
|
fi
|
|
|
|
# ---------------------------------------------------------------------------------------
|
|
if [ "$fails" -eq 0 ]; then
|
|
echo "ALL PASS"
|
|
else
|
|
echo "$fails FAILED"
|
|
fi
|
|
exit "$fails"
|