#!/usr/bin/env bash # Exercise the real Linux Secret Service provider in a disposable session. # No credential is written to the user's actual HOME, session bus, or keyring. set -euo pipefail if [[ "$(uname -s)" != Linux ]]; then echo "ERROR: native-keyring-smoke.sh is Linux-only." >&2 exit 2 fi for command in dbus-run-session gnome-keyring-daemon secret-tool cargo mktemp timeout; do command -v "$command" >/dev/null || { echo "ERROR: required command is unavailable: $command" >&2 exit 2 } done # Preserve the already-installed toolchain/cache locations before HOME is # redirected. Standard hosted Rust runners keep both beneath the real HOME. original_home="$HOME" export CARGO_HOME="${CARGO_HOME:-$original_home/.cargo}" export RUSTUP_HOME="${RUSTUP_HOME:-$original_home/.rustup}" if [[ $# -eq 0 ]]; then work_root="$(mktemp -d /tmp/nigig-site-keyring.XXXXXX)" else work_root="$1" [[ "$work_root" == /tmp/nigig-site-* ]] || { echo "ERROR: disposable keyring path must be beneath /tmp/nigig-site-*" >&2 exit 2 } [[ ! -e "$work_root" ]] || { echo "ERROR: disposable keyring path already exists: $work_root" >&2 exit 2 } # Plain mkdir is atomic and refuses a symlink/path created after the check. mkdir -m 700 -- "$work_root" fi home="$work_root/home" runtime="$work_root/runtime" mkdir -m 700 "$home" "$runtime" cleanup() { rm -rf "$work_root" } trap cleanup EXIT INT TERM export HOME="$home" export XDG_RUNTIME_DIR="$runtime" export NIGIG_SITE_KEYRING_TEST_HOME="$home" export NIGIG_SITE_LIVE_KEYRING_TEST=disposable-secret-service-v1 # The fixed string unlocks only this newly-created disposable keyring. It is # neither an application credential nor persisted outside work_root. dbus-run-session -- bash -euo pipefail -c ' eval "$(printf site02-test-only-unlock | \ gnome-keyring-daemon --unlock --components=secrets)" # This command is also a supported standalone smoke: allow a cold, low-core # host to compile the desktop dependency graph while retaining a hard bound. timeout --signal=TERM --kill-after=10s 600s \ cargo test --locked -p nigig-site --lib \ repository::tests::linux_native_provider_real_vault_lifecycle -- \ --ignored --exact --test-threads=1 ' echo "native keyring smoke passed: disposable Secret Service lifecycle and encrypted repository"