65 lines
2.3 KiB
Bash
Executable file
65 lines
2.3 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Exercise the real Linux Secret Service provider in a disposable session.
|
|
# No credential is written to the user's actual HOME, session bus, or keyring.
|
|
set -euo pipefail
|
|
|
|
if [[ "$(uname -s)" != Linux ]]; then
|
|
echo "ERROR: native-keyring-smoke.sh is Linux-only." >&2
|
|
exit 2
|
|
fi
|
|
for command in dbus-run-session gnome-keyring-daemon secret-tool cargo mktemp timeout; do
|
|
command -v "$command" >/dev/null || {
|
|
echo "ERROR: required command is unavailable: $command" >&2
|
|
exit 2
|
|
}
|
|
done
|
|
|
|
# Preserve the already-installed toolchain/cache locations before HOME is
|
|
# redirected. Standard hosted Rust runners keep both beneath the real HOME.
|
|
original_home="$HOME"
|
|
export CARGO_HOME="${CARGO_HOME:-$original_home/.cargo}"
|
|
export RUSTUP_HOME="${RUSTUP_HOME:-$original_home/.rustup}"
|
|
|
|
if [[ $# -eq 0 ]]; then
|
|
work_root="$(mktemp -d /tmp/nigig-site-keyring.XXXXXX)"
|
|
else
|
|
work_root="$1"
|
|
[[ "$work_root" == /tmp/nigig-site-* ]] || {
|
|
echo "ERROR: disposable keyring path must be beneath /tmp/nigig-site-*" >&2
|
|
exit 2
|
|
}
|
|
[[ ! -e "$work_root" ]] || {
|
|
echo "ERROR: disposable keyring path already exists: $work_root" >&2
|
|
exit 2
|
|
}
|
|
# Plain mkdir is atomic and refuses a symlink/path created after the check.
|
|
mkdir -m 700 -- "$work_root"
|
|
fi
|
|
home="$work_root/home"
|
|
runtime="$work_root/runtime"
|
|
mkdir -m 700 "$home" "$runtime"
|
|
|
|
cleanup() {
|
|
rm -rf "$work_root"
|
|
}
|
|
trap cleanup EXIT INT TERM
|
|
|
|
export HOME="$home"
|
|
export XDG_RUNTIME_DIR="$runtime"
|
|
export NIGIG_SITE_KEYRING_TEST_HOME="$home"
|
|
export NIGIG_SITE_LIVE_KEYRING_TEST=disposable-secret-service-v1
|
|
|
|
# The fixed string unlocks only this newly-created disposable keyring. It is
|
|
# neither an application credential nor persisted outside work_root.
|
|
dbus-run-session -- bash -euo pipefail -c '
|
|
eval "$(printf site02-test-only-unlock | \
|
|
gnome-keyring-daemon --unlock --components=secrets)"
|
|
# This command is also a supported standalone smoke: allow a cold, low-core
|
|
# host to compile the desktop dependency graph while retaining a hard bound.
|
|
timeout --signal=TERM --kill-after=10s 600s \
|
|
cargo test --locked -p nigig-site --lib \
|
|
repository::tests::linux_native_provider_real_vault_lifecycle -- \
|
|
--ignored --exact --test-threads=1
|
|
'
|
|
|
|
echo "native keyring smoke passed: disposable Secret Service lifecycle and encrypted repository"
|