fix(tests): correct root/SSL/package false failures in validation suite
Three tests produced false failures when run on the deployed host: - safe-download: the read-only-location assertion expects a write to fail, but the suite runs as root and root bypasses filesystem permissions, so the write succeeded. Skip that assertion as root. - 2fa-validation: package presence used `dpkg -l | grep`, whose fixed-width output wraps long names when COLUMNS is narrow (as in a non-interactive shell), falsely reporting libpam-google-authenticator and qrencode as missing even though they were installed. Use dpkg -s. - https-enforcement: SSL validation passed --cert-status, which requires OCSP stapling that many valid CDNs do not provide, flagging valid certificates as invalid. Drop it; --ssl-reqd still enforces TLS and certificate-chain verification. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
This commit is contained in:
@@ -14,7 +14,7 @@ function test_2fa_packages() {
|
||||
local failed=0
|
||||
|
||||
for package in "${packages[@]}"; do
|
||||
if dpkg -l | grep -q "^ii.*$package"; then
|
||||
if dpkg -s "$package" 2>/dev/null | grep -q "^Status:.*installed"; then
|
||||
echo "✅ Package installed: $package"
|
||||
else
|
||||
echo "❌ Package missing: $package"
|
||||
|
||||
@@ -76,8 +76,10 @@ function test_ssl_certificate_validation() {
|
||||
local ssl_failures=0
|
||||
|
||||
for url in "${test_urls[@]}"; do
|
||||
# Test with strict SSL verification
|
||||
if curl -s --fail --ssl-reqd --cert-status "$url" >/dev/null 2>&1; then
|
||||
# Verify TLS is required and the certificate chain is valid. Do NOT use
|
||||
# --cert-status: that requires OCSP stapling, which many valid CDNs do
|
||||
# not provide, producing false negatives for otherwise-valid certs.
|
||||
if curl -s --fail --ssl-reqd "$url" >/dev/null 2>&1; then
|
||||
echo "✅ SSL certificate valid: $url"
|
||||
else
|
||||
echo "❌ SSL certificate validation failed: $url"
|
||||
|
||||
Reference in New Issue
Block a user