package ca import ( "strings" "testing" ) // withCommands temporarily replaces commandExists with a fake that only // reports the given names as present, restoring the real one after. func withCommands(t *testing.T, present ...string) { t.Helper() set := make(map[string]bool, len(present)) for _, p := range present { set[p] = true } orig := commandExists commandExists = func(name string) bool { return set[name] } t.Cleanup(func() { commandExists = orig }) } func TestLinuxInstructionsPrefersTrust(t *testing.T) { withCommands(t, "trust", "update-ca-trust", "update-ca-certificates") got := linuxInstructions("/tmp/ca.pem") if !strings.Contains(got, "sudo trust anchor --store /tmp/ca.pem") { t.Errorf("expected trust anchor command when trust is available, got:\n%s", got) } } func TestLinuxInstructionsFallsBackToUpdateCaTrust(t *testing.T) { withCommands(t, "update-ca-trust") got := linuxInstructions("/tmp/ca.pem") if !strings.Contains(got, "update-ca-trust") || strings.Contains(got, "trust anchor") { t.Errorf("expected update-ca-trust path, got:\n%s", got) } } func TestLinuxInstructionsFallsBackToUpdateCaCertificates(t *testing.T) { withCommands(t, "update-ca-certificates") got := linuxInstructions("/tmp/ca.pem") if !strings.Contains(got, "update-ca-certificates") { t.Errorf("expected update-ca-certificates path, got:\n%s", got) } } func TestLinuxInstructionsNoneFound(t *testing.T) { withCommands(t) got := linuxInstructions("/tmp/ca.pem") if !strings.Contains(got, "No known trust-store tool") { t.Errorf("expected a no-tool-found message, got:\n%s", got) } } func TestLinuxInstructionsCertutilPresence(t *testing.T) { withCommands(t, "certutil") withCert := linuxInstructions("/tmp/ca.pem") if !strings.Contains(withCert, "certutil -d sql:") { t.Errorf("expected certutil NSS instructions when certutil is present, got:\n%s", withCert) } withCommands(t) withoutCert := linuxInstructions("/tmp/ca.pem") if !strings.Contains(withoutCert, "Import manually") { t.Errorf("expected manual-import fallback when certutil is absent, got:\n%s", withoutCert) } } func TestInstallInstructionsDispatchesByOS(t *testing.T) { withCommands(t) tests := []struct { goos string want string }{ {"linux", "trust store"}, {"darwin", "security add-trusted-cert"}, {"windows", "certutil -addstore"}, {"plan9", "No install steps known"}, } for _, tt := range tests { got := InstallInstructions(tt.goos, "/tmp/ca.pem") if !strings.Contains(got, tt.want) { t.Errorf("InstallInstructions(%q, ...) = %q, want it to contain %q", tt.goos, got, tt.want) } } }