fix(auth): close cancellation and workspace races

This commit is contained in:
2026-08-17 19:32:03 +02:00
parent d12b629420
commit 0a2c667231
10 changed files with 822 additions and 221 deletions
@@ -3,38 +3,44 @@
package compose
import (
"context"
"errors"
"path/filepath"
"reflect"
"os/exec"
"testing"
"unsafe"
"golang.org/x/sys/windows"
)
func TestWindowsTreeKillCommandUsesTrustedAbsoluteSystemPathAndExactPIDArgumentArray(t *testing.T) {
original := windowsSystemDirectory
windowsSystemDirectory = func() (string, error) { return `C:\\Windows\\System32`, nil }
t.Cleanup(func() { windowsSystemDirectory = original })
taskkillPath, err := systemTaskkillPath()
func TestWindowsProcessJobUsesKillOnClose(t *testing.T) {
job, err := newWindowsProcessJob()
if err != nil {
t.Fatal(err)
}
if !filepath.IsAbs(taskkillPath) {
t.Fatalf("taskkill path = %q, want absolute trusted system path", taskkillPath)
t.Cleanup(func() {
if closeErr := job.close(); closeErr != nil {
t.Error(closeErr)
}
})
var limits windows.JOBOBJECT_EXTENDED_LIMIT_INFORMATION
if err := windows.QueryInformationJobObject(
job.handle,
windows.JobObjectExtendedLimitInformation,
uintptr(unsafe.Pointer(&limits)),
uint32(unsafe.Sizeof(limits)),
nil,
); err != nil {
t.Fatal(err)
}
command := windowsTreeKillCommand(context.Background(), taskkillPath, 4242)
want := []string{taskkillPath, "/PID", "4242", "/T", "/F"}
if !reflect.DeepEqual(command.Args, want) {
t.Fatalf("taskkill args = %#v, want %#v", command.Args, want)
if limits.BasicLimitInformation.LimitFlags&windows.JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE == 0 {
t.Fatalf("job limits = %#x, want JOB_OBJECT_LIMIT_KILL_ON_JOB_CLOSE", limits.BasicLimitInformation.LimitFlags)
}
}
func TestWindowsSystemTaskkillPathRejectsRelativeSystemDirectory(t *testing.T) {
original := windowsSystemDirectory
windowsSystemDirectory = func() (string, error) { return `System32`, nil }
t.Cleanup(func() { windowsSystemDirectory = original })
func TestWindowsProcessConfigurationStartsSuspendedBeforeJobAssignment(t *testing.T) {
command := exec.Command("docker")
configureProcess(command)
if _, err := systemTaskkillPath(); !errors.Is(err, ErrProcessReap) {
t.Fatalf("systemTaskkillPath() error = %v, want ErrProcessReap", err)
if command.SysProcAttr == nil || command.SysProcAttr.CreationFlags&createSuspendedProcess == 0 {
t.Fatalf("configureProcess() flags = %#x, want CREATE_SUSPENDED", command.SysProcAttr.CreationFlags)
}
}