#[cfg(unix)]
pub(crate) fn permission_bits_are_enforced() -> bool {
use std::os::unix::fs::PermissionsExt;
let Ok(directory) = tempfile::tempdir() else {
return false;
};
let path = directory.path().join("unreadable");
if std::fs::write(&path, b"probe").is_err() {
return false;
}
if std::fs::set_permissions(&path, std::fs::Permissions::from_mode(0o000)).is_err() {
return false;
}
std::fs::read(&path).is_err()
}
#[cfg(unix)]
pub(crate) fn require_permission_bits() -> bool {
if permission_bits_are_enforced() {
return true;
}
if std::env::var_os("FDU_TEST_ALLOW_NO_PERMISSION_BITS").as_deref()
== Some(std::ffi::OsStr::new("1"))
{
eprintln!(
"skipped by FDU_TEST_ALLOW_NO_PERMISSION_BITS=1: this host does not enforce Unix \
permission bits for the test process"
);
return false;
}
panic!(
"permission fixture precondition failed: this process can read a mode-000 file; \
run on a host that enforces Unix permission bits, or explicitly opt out with \
FDU_TEST_ALLOW_NO_PERMISSION_BITS=1"
);
}
pub(crate) fn observing_controls() -> crate::ScanScope {
crate::ScanConfig { read_controls: true, ..crate::ScanConfig::default() }.scope()
}
pub(crate) fn not_observing_controls() -> crate::ScanScope {
crate::ScanConfig { read_controls: false, ..crate::ScanConfig::default() }.scope()
}
pub(crate) fn read_of(index: &crate::Index, query: crate::query::Query) -> crate::query::Request {
crate::query::Request::new(crate::query::Basis::held_by(index), query, std::time::UNIX_EPOCH)
}