From 1fb1413f5ba31f31e41fc31abcf2c2a9f3d0cf74 Mon Sep 17 00:00:00 2001 From: reachableceo Date: Mon, 27 Jul 2026 10:48:50 -0500 Subject: [PATCH] fix(tests): repair test-runner arithmetic and false-positive checks MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Three bugs prevented the validation suite from running cleanly: - run-tests.sh used `((TESTS_PASSED++))` under `set -e`. Post-increment evaluates to the old value, so the first passing test (0 -> 1) made `(( ))` return 1 and errexit aborted the whole run after exactly one test. Use plain arithmetic assignment instead. - https-enforcement.sh's comment filter ran `grep -n` (which prefixes "linenum:") and then tried to drop comment lines with `^[[:space:]]*#`, which never matched the line-number prefix. Every http:// URL in a comment (deprecated curl lines, the strict-mode attribution comment) was flagged as a violation. Match the prefix. - 2fa-validation.sh hardcoded `/home/$user/` for the setup-instructions check, so for root it looked in /home/root (which does not exist) instead of /root. Resolve the home directory with getent. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush --- Project-Tests/run-tests.sh | 4 ++-- Project-Tests/security/2fa-validation.sh | 4 +++- Project-Tests/security/https-enforcement.sh | 4 +++- 3 files changed, 8 insertions(+), 4 deletions(-) diff --git a/Project-Tests/run-tests.sh b/Project-Tests/run-tests.sh index f0190ba..cbd490d 100755 --- a/Project-Tests/run-tests.sh +++ b/Project-Tests/run-tests.sh @@ -58,10 +58,10 @@ function run_single_test() { if timeout 300 bash "$test_file"; then print_success "✅ $test_name PASSED" - ((TESTS_PASSED++)) + TESTS_PASSED=$((TESTS_PASSED + 1)) else print_error "❌ $test_name FAILED" - ((TESTS_FAILED++)) + TESTS_FAILED=$((TESTS_FAILED + 1)) fi } diff --git a/Project-Tests/security/2fa-validation.sh b/Project-Tests/security/2fa-validation.sh index f1b9b78..ade228a 100755 --- a/Project-Tests/security/2fa-validation.sh +++ b/Project-Tests/security/2fa-validation.sh @@ -158,6 +158,8 @@ function test_user_2fa_setup() { for user in "${users[@]}"; do if id "$user" &>/dev/null; then + local user_home; user_home="$(getent passwd "$user" | cut -d: -f6)" + # Check if setup script exists if [[ -f "/tmp/setup-2fa-$user.sh" ]]; then echo "✅ 2FA setup script exists for user: $user" @@ -167,7 +169,7 @@ function test_user_2fa_setup() { fi # Check if instructions exist - if [[ -f "/home/$user/2fa-setup-instructions.txt" ]]; then + if [[ -n "$user_home" && -f "$user_home/2fa-setup-instructions.txt" ]]; then echo "✅ 2FA instructions exist for user: $user" else echo "❌ 2FA instructions missing for user: $user" diff --git a/Project-Tests/security/https-enforcement.sh b/Project-Tests/security/https-enforcement.sh index 08f1073..e2a2d12 100755 --- a/Project-Tests/security/https-enforcement.sh +++ b/Project-Tests/security/https-enforcement.sh @@ -18,7 +18,9 @@ function test_no_http_urls() { if [[ -d "$dir" ]]; then # Find HTTP URLs in shell scripts (excluding comments) while IFS= read -r -d '' file; do - if grep -n "http://" "$file" | grep -v "^[[:space:]]*#" | grep -v "schema.org" | grep -v "xmlns"; then + # grep -n prefixes "linenum:", so the comment filter must allow + # for that prefix before the leading '#' of a comment line. + if grep -n "http://" "$file" | grep -vE '^[0-9]+:[[:space:]]*#' | grep -v "schema.org" | grep -v "xmlns"; then echo "❌ HTTP URL found in: $file" ((++http_violations)) fi