fix(tests): repair test-runner arithmetic and false-positive checks
Three bugs prevented the validation suite from running cleanly: - run-tests.sh used `((TESTS_PASSED++))` under `set -e`. Post-increment evaluates to the old value, so the first passing test (0 -> 1) made `(( ))` return 1 and errexit aborted the whole run after exactly one test. Use plain arithmetic assignment instead. - https-enforcement.sh's comment filter ran `grep -n` (which prefixes "linenum:") and then tried to drop comment lines with `^[[:space:]]*#`, which never matched the line-number prefix. Every http:// URL in a comment (deprecated curl lines, the strict-mode attribution comment) was flagged as a violation. Match the prefix. - 2fa-validation.sh hardcoded `/home/$user/` for the setup-instructions check, so for root it looked in /home/root (which does not exist) instead of /root. Resolve the home directory with getent. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
This commit is contained in:
@@ -58,10 +58,10 @@ function run_single_test() {
|
||||
|
||||
if timeout 300 bash "$test_file"; then
|
||||
print_success "✅ $test_name PASSED"
|
||||
((TESTS_PASSED++))
|
||||
TESTS_PASSED=$((TESTS_PASSED + 1))
|
||||
else
|
||||
print_error "❌ $test_name FAILED"
|
||||
((TESTS_FAILED++))
|
||||
TESTS_FAILED=$((TESTS_FAILED + 1))
|
||||
fi
|
||||
}
|
||||
|
||||
|
||||
@@ -158,6 +158,8 @@ function test_user_2fa_setup() {
|
||||
|
||||
for user in "${users[@]}"; do
|
||||
if id "$user" &>/dev/null; then
|
||||
local user_home; user_home="$(getent passwd "$user" | cut -d: -f6)"
|
||||
|
||||
# Check if setup script exists
|
||||
if [[ -f "/tmp/setup-2fa-$user.sh" ]]; then
|
||||
echo "✅ 2FA setup script exists for user: $user"
|
||||
@@ -167,7 +169,7 @@ function test_user_2fa_setup() {
|
||||
fi
|
||||
|
||||
# Check if instructions exist
|
||||
if [[ -f "/home/$user/2fa-setup-instructions.txt" ]]; then
|
||||
if [[ -n "$user_home" && -f "$user_home/2fa-setup-instructions.txt" ]]; then
|
||||
echo "✅ 2FA instructions exist for user: $user"
|
||||
else
|
||||
echo "❌ 2FA instructions missing for user: $user"
|
||||
|
||||
@@ -18,7 +18,9 @@ function test_no_http_urls() {
|
||||
if [[ -d "$dir" ]]; then
|
||||
# Find HTTP URLs in shell scripts (excluding comments)
|
||||
while IFS= read -r -d '' file; do
|
||||
if grep -n "http://" "$file" | grep -v "^[[:space:]]*#" | grep -v "schema.org" | grep -v "xmlns"; then
|
||||
# grep -n prefixes "linenum:", so the comment filter must allow
|
||||
# for that prefix before the leading '#' of a comment line.
|
||||
if grep -n "http://" "$file" | grep -vE '^[0-9]+:[[:space:]]*#' | grep -v "schema.org" | grep -v "xmlns"; then
|
||||
echo "❌ HTTP URL found in: $file"
|
||||
((++http_violations))
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user