Add tests which, when run as root, will ensure we can't write