feat: initial wipe implementation - block device safety, HDD overwrite, NVMe/secure-discard, verification
This commit is contained in:
+118
@@ -0,0 +1,118 @@
|
||||
#![allow(unused_imports, dead_code, unused_variables)]
|
||||
use assert_cmd::Command;
|
||||
use predicates::prelude::*;
|
||||
|
||||
fn wipe_cmd() -> Command {
|
||||
Command::cargo_bin("wipe").unwrap()
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_system_device_protection() {
|
||||
let candidate = "/dev/nvme0n1";
|
||||
if !std::path::Path::new(candidate).exists() {
|
||||
return;
|
||||
}
|
||||
wipe_cmd()
|
||||
.args([
|
||||
candidate,
|
||||
"--whole-disk",
|
||||
"--dry-run",
|
||||
"--yes",
|
||||
"--method",
|
||||
"zero",
|
||||
])
|
||||
.assert()
|
||||
.failure()
|
||||
.code(8);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_system_device_protection_force_still_blocked() {
|
||||
let candidate = "/dev/nvme0n1";
|
||||
if !std::path::Path::new(candidate).exists() {
|
||||
return;
|
||||
}
|
||||
wipe_cmd()
|
||||
.args([
|
||||
candidate,
|
||||
"--whole-disk",
|
||||
"--dry-run",
|
||||
"--yes",
|
||||
"--force",
|
||||
"--method",
|
||||
"zero",
|
||||
])
|
||||
.assert()
|
||||
.failure()
|
||||
.code(8);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_dry_run_does_not_modify() {
|
||||
// Use a loop device or any block device with dry-run should succeed or fail with safety but not modify
|
||||
// Test with /dev/sda if exists but protected; use json to check
|
||||
let path = "/dev/sda";
|
||||
if !std::path::Path::new(path).exists() {
|
||||
return;
|
||||
}
|
||||
// If sda is not system device, dry-run should succeed with code 0
|
||||
// But in our env, /dev/sda is /opt/agents mount, not system, so may be considered non-system?
|
||||
// Actually /opt/agents is on sda1, so sda is backing device for /opt/agents, but not protected as critical mount.
|
||||
// Our protection only covers /, /boot, /boot/efi, swap, so sda may not be blocked. Then dry-run should pass.
|
||||
// Let's test that dry-run passes or fails gracefully
|
||||
let output = wipe_cmd()
|
||||
.args([
|
||||
path,
|
||||
"--whole-disk",
|
||||
"--dry-run",
|
||||
"--yes",
|
||||
"--method",
|
||||
"zero",
|
||||
])
|
||||
.output()
|
||||
.unwrap();
|
||||
// Should be 0 or 6/7/8 if mounted/holder, but not crash
|
||||
assert!(output.status.code().unwrap() == 0 || output.status.code().unwrap() >= 2);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_json_error_format() {
|
||||
let output = wipe_cmd()
|
||||
.args(["/dev/nonexistent_xyz", "--whole-disk", "--json", "--yes"])
|
||||
.output()
|
||||
.unwrap();
|
||||
assert!(!output.status.success());
|
||||
let stdout = String::from_utf8_lossy(&output.stdout);
|
||||
// JSON error should contain success false and error code
|
||||
// Since device not found, stdout JSON should be valid
|
||||
if let Ok(v) = serde_json::from_str::<serde_json::Value>(&stdout) {
|
||||
assert_eq!(v.get("success").and_then(|x| x.as_bool()), Some(false));
|
||||
assert!(v.get("error").is_some());
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_json_success_format_dry_run() {
|
||||
let path = "/dev/sda";
|
||||
if !std::path::Path::new(path).exists() {
|
||||
return;
|
||||
}
|
||||
let output = wipe_cmd()
|
||||
.args([
|
||||
path,
|
||||
"--whole-disk",
|
||||
"--dry-run",
|
||||
"--yes",
|
||||
"--json",
|
||||
"--method",
|
||||
"zero",
|
||||
])
|
||||
.output()
|
||||
.unwrap();
|
||||
if output.status.success() {
|
||||
let stdout = String::from_utf8_lossy(&output.stdout);
|
||||
let v: serde_json::Value = serde_json::from_str(&stdout).unwrap();
|
||||
assert_eq!(v.get("success").and_then(|x| x.as_bool()), Some(true));
|
||||
assert!(v.get("device").is_some());
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user