summary refs log tree commit diff
path: root/src/tests/check-systemd-unit.sh
diff options
context:
space:
mode:
authorMichael Biebl <biebl@debian.org>2025-02-12 13:46:50 +0100
committerMichael Biebl <biebl@debian.org>2025-02-12 13:46:50 +0100
commit8bdf070ff046f482f6eb5e2b15ebc216f5d1e3da (patch)
treef706478d189d54c6532e8863d4b0d5ff5575af60 /src/tests/check-systemd-unit.sh
parent818258cf34b83fbc754633295e1052d4752d7b15 (diff)
New upstream version 1.51.90 upstream/1.51.90
Diffstat (limited to 'src/tests/check-systemd-unit.sh')
-rwxr-xr-xsrc/tests/check-systemd-unit.sh22
1 files changed, 22 insertions, 0 deletions
diff --git a/src/tests/check-systemd-unit.sh b/src/tests/check-systemd-unit.sh
new file mode 100755
index 00000000..b16f2a33
--- /dev/null
+++ b/src/tests/check-systemd-unit.sh
@@ -0,0 +1,22 @@
+#!/bin/bash
+# SPDX-License-Identifier: LGPL-2.1-or-later
+
+set -e
+set -o pipefail
+
+if systemd-analyze --offline=true security 2>/dev/null </dev/null; then
+
+	# We're using "security" as opposed to "verify" because (as of 2024)
+	# the latter doesn't support --offline runs.
+	#
+	# The point is that if anything appears before the security report
+	# header, there's an error or a warning while parsing the unit file.
+	env -i systemd-analyze --offline=true security "$1" 2>&1 |awk '
+		/NAME.*DESCRIPTION.*EXPOSURE/ {suppress=1}
+		{if (!suppress) {print; failed++}}
+		END {exit failed}
+	'
+
+else
+	echo "SKIP: systemd-analyze --offline=true security not supported" >&2
+fi