#include #include #include "packeteer/privileges.hpp" // The actual drop sequence (setuid/setgid) can only be meaningfully // exercised by literally running as root, which a unit test shouldn't // do - permanently dropping the test runner's own privileges mid-suite // would be a real, surprising side effect, not a safe thing to assert // on. That path is verified live instead (running the real binary via // sudo and checking the dropped-to UID actually took effect - see // PLAN.md). This only covers the no-op path any non-root test run // takes, which is still worth locking in: it must never attempt to // touch privileges it doesn't have. TEST_CASE("drop_privileges_if_root is a no-op when not running as root") { if (geteuid() == 0) return; // this test only makes sense unprivileged CHECK_FALSE(packeteer::drop_privileges_if_root().has_value()); }