feat: initial wipe implementation - block device safety, HDD overwrite, NVMe/secure-discard, verification
This commit is contained in:
@@ -0,0 +1,46 @@
|
||||
#![allow(unused_imports, dead_code, unused_variables)]
|
||||
use assert_cmd::Command;
|
||||
use predicates::prelude::*;
|
||||
|
||||
fn wipe_cmd() -> Command {
|
||||
Command::cargo_bin("wipe").unwrap()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_device_validation_symlink_escape() {
|
||||
wipe_cmd()
|
||||
.args(["/dev", "--whole-disk", "--dry-run", "--yes"])
|
||||
.assert()
|
||||
.failure()
|
||||
.code(2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_device_validation_regular_file_rejected() {
|
||||
let tmp = tempfile::NamedTempFile::new().unwrap();
|
||||
let path = tmp.path().to_str().unwrap();
|
||||
// Need to be under /dev to pass first check, but we give tmp path which is not in /dev, so code 2
|
||||
wipe_cmd()
|
||||
.args([path, "--whole-disk", "--dry-run", "--yes"])
|
||||
.assert()
|
||||
.failure()
|
||||
.code(2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_lsblk_json_inspection() {
|
||||
// Verify that lsblk --json works and our tool can parse it via dry-run
|
||||
// Use a known device
|
||||
let path = "/dev/nvme0n1";
|
||||
if !std::path::Path::new(path).exists() {
|
||||
return;
|
||||
}
|
||||
// Just ensure dry-run doesn't crash due to lsblk parsing
|
||||
let output = wipe_cmd()
|
||||
.args([path, "--whole-disk", "--dry-run", "--yes"])
|
||||
.output()
|
||||
.unwrap();
|
||||
// Should be 8 (system device) or 0 if not system, but not 14 (external command failed)
|
||||
let code = output.status.code().unwrap_or(1);
|
||||
assert!(code != 14, "lsblk should not fail");
|
||||
}
|
||||
Reference in New Issue
Block a user