# `checks.module-eval-agent-user` — see ./lib.nix for the shared # rationale (why this suite exists, naming convention, "evaluates # not executes"). { pkgs, lib, self, nixosSystem, }: let inherit (import ./lib.nix { inherit pkgs lib self nixosSystem ; }) agentWith runGroup ; # A named agent, so the rendered script carries a name no default supplies. migrate = (agentWith { services.hyperhive.agent.user.name = "iris"; }) .system.activationScripts.hive-agent-user-migrate.text; cases = [ { # hive-priv creates the host socket dir `0751 root` and never chowns it, # so this activation is the only thing that lets the harness bind there. name = "the agent's activation hands its socket dir to the agent user at 0751"; ok = lib.hasInfix "userName=${lib.escapeShellArg "iris"}" migrate && lib.hasInfix ''socketDir="/run/hive-agent/$userName"'' migrate && lib.hasInfix ''chown -h "$userName:$userName" "$socketDir"'' migrate && lib.hasInfix ''chmod 0751 "$socketDir"'' migrate; } { # `test -d` and `chmod` follow symlinks, so without this refusal ahead # of the chown branch a link at the socket dir is chmodded at its target. name = "the agent's activation refuses a symlinked or non-directory socket dir"; ok = lib.hasInfix ''if [ -L "$socketDir" ] || { [ -e "$socketDir" ] && [ ! -d "$socketDir" ]; }; then'' migrate && lib.hasInfix ''elif [ -d "$socketDir" ]; then'' migrate; } ]; in runGroup "agent-user" cases