fix(tests): correct root/SSL/package false failures in validation suite
Three tests produced false failures when run on the deployed host: - safe-download: the read-only-location assertion expects a write to fail, but the suite runs as root and root bypasses filesystem permissions, so the write succeeded. Skip that assertion as root. - 2fa-validation: package presence used `dpkg -l | grep`, whose fixed-width output wraps long names when COLUMNS is narrow (as in a non-interactive shell), falsely reporting libpam-google-authenticator and qrencode as missing even though they were installed. Use dpkg -s. - https-enforcement: SSL validation passed --cert-status, which requires OCSP stapling that many valid CDNs do not provide, flagging valid certificates as invalid. Drop it; --ssl-reqd still enforces TLS and certificate-chain verification. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
This commit is contained in:
@@ -218,8 +218,12 @@ function test_download_error_handling() {
|
||||
echo "✅ Download with empty destination failed as expected"
|
||||
fi
|
||||
|
||||
# Test download to read-only location (should fail)
|
||||
if safe_download "https://github.com" "/test-readonly-$$" 2>/dev/null; then
|
||||
# Test download to read-only location (should fail). Only meaningful for
|
||||
# non-root users: root bypasses filesystem permissions, so the expected
|
||||
# write failure never happens and the assertion is invalid.
|
||||
if [[ $EUID -eq 0 ]]; then
|
||||
echo "⏭️ Skipping read-only-location test (running as root; root bypasses FS perms)"
|
||||
elif safe_download "https://github.com" "/test-readonly-$$" 2>/dev/null; then
|
||||
echo "❌ Download to read-only location should have failed"
|
||||
((++failed))
|
||||
else
|
||||
|
||||
Reference in New Issue
Block a user