import importlib.util from pathlib import Path import sys import tomllib ROOT=Path(__file__).resolve().parents[1] sys.path.insert(0,str(ROOT/'deploy')) spec=importlib.util.spec_from_file_location('deployment_v2',ROOT/'deploy/deploy.py') deployment=importlib.util.module_from_spec(spec);sys.modules[spec.name]=deployment;spec.loader.exec_module(deployment) def test_units_have_no_sudo_or_root_runtime(): for mode,executor,user in [('serve',False,'aim-web'),('worker',False,'aim-web'),('executor',True,'svc_bf-ansible')]: text=deployment.unit_text(user,991,Path('/etc/ansible/scripts/config/webgui.toml'),mode,executor=executor,executor_group=1001 if executor else None,supplementary_group=991 if executor else None,executor_local_home='/home/svc_bf-ansible' if executor else None) assert f'User={user}\n'in text assert 'NoNewPrivileges=true' in text assert 'CapabilityBoundingSet=\n'in text assert 'CAP_SETUID'not in text and 'sudo'not in text assert 'RuntimeDirectory=aim-web-executor' in text if executor else 'RuntimeDirectory='not in text if executor: assert 'RuntimeDirectoryMode=0711' in text if executor: assert 'Group=1001\n' in text assert 'SupplementaryGroups=991\n' in text assert 'Environment=HOME=/var/lib/aim-web-executor' in text assert 'ReadWritePaths=/var/lib/aim-web-executor /var/lib/aim-web-executor/.ansible/tmp /home/svc_bf-ansible/.ansible/tmp -/etc/ansible/inventories' in text assert 'core-staging-check' in text def test_no_private_core_import_and_no_old_stage_bridge(): text=(ROOT/'deploy/deploy.py').read_text() assert 'from aim.config'not in text and 'sys.path.insert'not in text assert 'key_export.py'not in text assert 'core_transport="stdio"'in text assert '--migrate-core'in text assert "'db','migrate'"in text assert text.index("os.replace(stage, target)")