fix(auth): complete Task 13 deployment review

This commit is contained in:
2026-08-17 22:15:41 +02:00
parent 7e52df2702
commit 0d0c15b4b8
11 changed files with 228 additions and 50 deletions
@@ -233,6 +233,60 @@ func TestPreflightRejectsTraversalAndSymlinkInsideVolumeTar(t *testing.T) {
}
}
func TestPreflightAcceptsCanonicalTarRootDirectoryAndRelativeMembers(t *testing.T) {
installation := preflightTestInstallation(t)
var payload strings.Builder
writer := tar.NewWriter(&stringWriter{value: &payload})
for _, header := range []tar.Header{
{Name: "./", Mode: 0o755, Typeflag: tar.TypeDir},
{Name: "./payload", Mode: 0o600, Size: 1, Typeflag: tar.TypeReg},
} {
if err := writer.WriteHeader(&header); err != nil {
t.Fatal(err)
}
if header.Size > 0 {
if _, err := writer.Write([]byte("x")); err != nil {
t.Fatal(err)
}
}
}
if err := writer.Close(); err != nil {
t.Fatal(err)
}
archive := filepath.Join(t.TempDir(), "canonical-volume.zip")
writePreflightArchive(t, archive, preflightArchiveSpec{entries: []preflightArchiveEntry{{
path: "volumes/sessions.tar", body: []byte(payload.String()), kind: EntryVolume,
}}})
result, err := Preflight(context.Background(), installation, PreflightRequest{Archive: archive, Confirm: true}, permissivePreflightDependencies())
if err != nil {
t.Fatal(err)
}
result.CloseArchive()
}
func TestPreflightRejectsNonDirectoryTarRootMarker(t *testing.T) {
installation := preflightTestInstallation(t)
var payload strings.Builder
writer := tar.NewWriter(&stringWriter{value: &payload})
header := tar.Header{Name: ".", Mode: 0o600, Size: 1, Typeflag: tar.TypeReg}
if err := writer.WriteHeader(&header); err != nil {
t.Fatal(err)
}
if _, err := writer.Write([]byte("x")); err != nil {
t.Fatal(err)
}
if err := writer.Close(); err != nil {
t.Fatal(err)
}
archive := filepath.Join(t.TempDir(), "unsafe-root-volume.zip")
writePreflightArchive(t, archive, preflightArchiveSpec{entries: []preflightArchiveEntry{{
path: "volumes/sessions.tar", body: []byte(payload.String()), kind: EntryVolume,
}}})
if _, err := Preflight(context.Background(), installation, PreflightRequest{Archive: archive, Confirm: true}, permissivePreflightDependencies()); err == nil {
t.Fatal("Preflight accepted a non-directory TAR root marker")
}
}
func TestPreflightRejectsArchivesThatExceedConfiguredProcessingLimits(t *testing.T) {
installation := preflightTestInstallation(t)
tests := []struct {