Skip to main content

cortexkit_test_support/
lib.rs

1//! Portable helpers for CortexKit tests. Use this crate as a **dev-dependency only**.
2//!
3//! Scratch fixtures preserve failure evidence, executables are published as
4//! immutable `ckdev-*` copies, and daemon builders enforce an ambient-root fence.
5#![forbid(unsafe_code)]
6
7mod binaries;
8mod daemon;
9mod fence;
10mod scratch;
11mod sibling_cache;
12mod spawn_guard;
13mod stable;
14
15pub use binaries::*;
16pub use daemon::{TestDaemon, TestDaemonCommand};
17pub use fence::*;
18pub use scratch::{scratch_root, shared_scratch_root, wait_until_gone, ScratchDir, STABLE_BIN_DIR};
19pub use sibling_cache::*;
20pub use spawn_guard::assert_test_binary_spawns;
21#[cfg(unix)]
22pub use stable::{stable_executable, stable_executable_dir};
23
24/// Opt-in variable for tests requiring passwordless sudo, namespaces, or root.
25pub const PRIVILEGED_TESTS_ENV: &str = "CORTEXKIT_PRIVILEGED_TESTS";
26
27/// Returns true only for `CORTEXKIT_PRIVILEGED_TESTS=1`; otherwise prints a skip reason.
28pub fn privileged_tests_enabled(test: &str, needs: &str) -> bool {
29    if std::env::var(PRIVILEGED_TESTS_ENV).as_deref() == Ok("1") {
30        return true;
31    }
32    eprintln!("skipped: {test} needs {needs}; set {PRIVILEGED_TESTS_ENV}=1 to run it");
33    false
34}
35
36#[cfg(test)]
37#[test]
38fn privileged_gate_only_accepts_exact_one() {
39    let previous = std::env::var_os(PRIVILEGED_TESTS_ENV);
40    for value in [None, Some("0"), Some("true"), Some("1")] {
41        match value {
42            Some(value) => std::env::set_var(PRIVILEGED_TESTS_ENV, value),
43            None => std::env::remove_var(PRIVILEGED_TESTS_ENV),
44        }
45        assert_eq!(
46            privileged_tests_enabled("probe", "privilege"),
47            value == Some("1")
48        );
49    }
50    match previous {
51        Some(value) => std::env::set_var(PRIVILEGED_TESTS_ENV, value),
52        None => std::env::remove_var(PRIVILEGED_TESTS_ENV),
53    }
54}