import os import tempfile import unittest from pathlib import Path from unittest.mock import patch from auth import CredentialStore from server import Server from deploy import install as installer from network.client import NetworkClient class InstallTests(unittest.TestCase): def test_refuses_foreign_container(self): with patch.object(installer,'inspect',return_value={'Config':{'Labels':{}}}): with self.assertRaises(RuntimeError):installer.owned('athena-deck-test',Path('/opt/test')) def test_launch_is_loopback_and_unprivileged(self): config=dict(base='/opt/athena-deck-test',name='athena-deck-test',port=8119,image='test:only',gpu_telemetry=False) with patch.object(installer,'run') as run: installer.launch(config) args=run.call_args.args self.assertIn('127.0.0.1:8119:8108',args) self.assertIn('--read-only',args) self.assertEqual(args[args.index('--cap-drop')+1],'ALL') for forbidden in ('--privileged','--gpus','--cap-add','host','/var/run/docker.sock'): self.assertNotIn(forbidden,args) def test_failed_update_restores_only_owned_container(self): with tempfile.TemporaryDirectory() as directory: base=Path(directory);(base/'state').mkdir();(base/'backups').mkdir() config=dict(base=str(base),owner=installer.LABEL,name='athena-deck-test',port=8110,image='old:build',previous_image=None,gpu_telemetry=False) installer.write_manifest(base,config) with patch.object(installer,'owned',return_value={'State':{'Running':True}}),patch.object(installer,'inspect',return_value=None),patch.object(installer,'build',return_value='new:build'),patch.object(installer,'launch',side_effect=RuntimeError('failed')),patch.object(installer,'run') as run: with self.assertRaises(RuntimeError):installer.update(base) self.assertEqual(installer.load_manifest(base)['image'],'old:build') calls=[c.args for c in run.call_args_list] self.assertIn(('docker','rename','athena-deck-test-previous','athena-deck-test'),calls) self.assertIn(('docker','start','athena-deck-test'),calls) self.assertTrue(all('mike-ai' not in ' '.join(c) for c in calls)) def test_standalone_never_attempts_ssh(self): with patch.dict(os.environ,{'DECK_NETWORK_MODE':'disabled'}):client=NetworkClient() with patch('network.client.subprocess.run') as remote: self.assertFalse(client.status()['install_supported']) with self.assertRaises(ValueError):client.call('connect') with self.assertRaises(ValueError):client.install('x'*16,'y'*32) remote.assert_not_called() def test_requires_preprovisioned_credentials(self): with tempfile.TemporaryDirectory() as directory,patch.dict(os.environ,{'DECK_REQUIRE_SETUP':'1'}): with self.assertRaises(RuntimeError):Server(0,state_dir=directory) def test_source_allowlist_exists(self): for name in installer.FILES:self.assertTrue((installer.ROOT/name).is_file()) if __name__=='__main__':unittest.main()