#[test]
fn foreign_owned_symlink_component_is_refused() {
let euid = unsafe { libc::geteuid() } as u32;
if euid == 0 {
eprintln!(
"skipped: root-owned symlinks are trusted, so this fixture requires a non-root uid"
);
return;
}
let tmp_owner = std::fs::metadata("/tmp").expect("stat /tmp").uid();
if tmp_owner != 0 {
eprintln!("skipped: /tmp is owned by uid {tmp_owner}, not root");
return;
}
let link = std::path::PathBuf::from(format!("/tmp/khive-swaptest-link-{}", std::process::id()));
let _ = std::fs::remove_file(&link);
std::os::unix::fs::symlink("/tmp", &link).expect("symlink");
let not_my_euid = euid.wrapping_add(1);
let result = ensure_socket_path_is_swap_resistant(&link, not_my_euid);
std::fs::remove_file(&link).expect("cleanup");
let err = result.expect_err("a symlink owned by another uid must be refused");
assert!(
err.to_string().contains("symlink component"),
"the refusal should strike the symlink itself, got: {err}"
);
assert!(
err.to_string().contains("khive-swaptest-link"),
"the refusal should name the offending link, got: {err}"
);
}