summaryrefslogtreecommitdiff
path: root/tests/integration_tests/test_logging.py
blob: b31a043482c2ed56f29d49abe85c9b5615062c90 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
"""Integration tests relating to cloud-init's logging."""


class TestVarLogCloudInitOutput:
    """Integration tests relating to /var/log/cloud-init-output.log."""

    def test_var_log_cloud_init_output_not_world_readable(self, client):
        """
        The log can contain sensitive data, it shouldn't be world-readable.

        LP: #1918303
        """
        # Check the file exists
        assert client.execute("test -f /var/log/cloud-init-output.log").ok

        # Check its permissions are as we expect
        perms, user, group = client.execute(
            "stat -c %a:%U:%G /var/log/cloud-init-output.log"
        ).split(":")
        assert "640" == perms
        assert "root" == user
        assert "adm" == group