nigig-org/crates/apps/nigig-site/tools/native-keyring-smoke.sh

65 lines
2.3 KiB
Bash
Executable file

#!/usr/bin/env bash
# Exercise the real Linux Secret Service provider in a disposable session.
# No credential is written to the user's actual HOME, session bus, or keyring.
set -euo pipefail
if [[ "$(uname -s)" != Linux ]]; then
echo "ERROR: native-keyring-smoke.sh is Linux-only." >&2
exit 2
fi
for command in dbus-run-session gnome-keyring-daemon secret-tool cargo mktemp timeout; do
command -v "$command" >/dev/null || {
echo "ERROR: required command is unavailable: $command" >&2
exit 2
}
done
# Preserve the already-installed toolchain/cache locations before HOME is
# redirected. Standard hosted Rust runners keep both beneath the real HOME.
original_home="$HOME"
export CARGO_HOME="${CARGO_HOME:-$original_home/.cargo}"
export RUSTUP_HOME="${RUSTUP_HOME:-$original_home/.rustup}"
if [[ $# -eq 0 ]]; then
work_root="$(mktemp -d /tmp/nigig-site-keyring.XXXXXX)"
else
work_root="$1"
[[ "$work_root" == /tmp/nigig-site-* ]] || {
echo "ERROR: disposable keyring path must be beneath /tmp/nigig-site-*" >&2
exit 2
}
[[ ! -e "$work_root" ]] || {
echo "ERROR: disposable keyring path already exists: $work_root" >&2
exit 2
}
# Plain mkdir is atomic and refuses a symlink/path created after the check.
mkdir -m 700 -- "$work_root"
fi
home="$work_root/home"
runtime="$work_root/runtime"
mkdir -m 700 "$home" "$runtime"
cleanup() {
rm -rf "$work_root"
}
trap cleanup EXIT INT TERM
export HOME="$home"
export XDG_RUNTIME_DIR="$runtime"
export NIGIG_SITE_KEYRING_TEST_HOME="$home"
export NIGIG_SITE_LIVE_KEYRING_TEST=disposable-secret-service-v1
# The fixed string unlocks only this newly-created disposable keyring. It is
# neither an application credential nor persisted outside work_root.
dbus-run-session -- bash -euo pipefail -c '
eval "$(printf site02-test-only-unlock | \
gnome-keyring-daemon --unlock --components=secrets)"
# This command is also a supported standalone smoke: allow a cold, low-core
# host to compile the desktop dependency graph while retaining a hard bound.
timeout --signal=TERM --kill-after=10s 600s \
cargo test --locked -p nigig-site --lib \
repository::tests::linux_native_provider_real_vault_lifecycle -- \
--ignored --exact --test-threads=1
'
echo "native keyring smoke passed: disposable Secret Service lifecycle and encrypted repository"