test: close remaining workspace preprocessing gates
This commit is contained in:
@@ -58,6 +58,16 @@ func TestReadCanonicalUTF8RejectsNonUTF8AndBounds(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestReadCanonicalUTF8RejectsSQLLargerThanOneMiB(t *testing.T) {
|
||||
path := filepath.Join(t.TempDir(), "schema.sql")
|
||||
if err := os.WriteFile(path, make([]byte, (1<<20)+1), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := ReadCanonicalUTF8(path, 1<<20); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("ReadCanonicalUTF8 1 MiB + 1 SQL = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestWriteCanonicalExclusiveRejectsExistingAndCreatesPrivateFile(t *testing.T) {
|
||||
root, err := filepath.EvalSymlinks(t.TempDir())
|
||||
if err != nil {
|
||||
|
||||
@@ -3,10 +3,12 @@
|
||||
package safeio
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"errors"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"golang.org/x/sys/unix"
|
||||
)
|
||||
@@ -31,6 +33,56 @@ func TestReadCanonicalRegularRejectsNamedPipeWithoutBlocking(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestReadCanonicalRegularRejectsReplacementDuringRead(t *testing.T) {
|
||||
root := t.TempDir()
|
||||
path := filepath.Join(root, "schema.sql")
|
||||
replacement := filepath.Join(root, "replacement.sql")
|
||||
parked := filepath.Join(root, "parked.sql")
|
||||
contents := bytes.Repeat([]byte("x"), 64<<20)
|
||||
if err := os.WriteFile(path, contents, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.WriteFile(replacement, contents, 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
var caught bool
|
||||
for attempt := 0; attempt < 3 && !caught; attempt++ {
|
||||
result := make(chan error, 1)
|
||||
go func() {
|
||||
_, err := ReadCanonicalRegular(path, int64(len(contents)))
|
||||
result <- err
|
||||
}()
|
||||
time.Sleep(time.Millisecond)
|
||||
var finalErr error
|
||||
for i := 0; i < 20; i++ {
|
||||
if err := os.Rename(path, parked); err == nil {
|
||||
if err := os.Rename(replacement, path); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
time.Sleep(time.Millisecond)
|
||||
if err := os.Rename(parked, replacement); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
select {
|
||||
case finalErr = <-result:
|
||||
i = 20
|
||||
default:
|
||||
}
|
||||
}
|
||||
if finalErr == nil {
|
||||
finalErr = <-result
|
||||
}
|
||||
if errors.Is(finalErr, ErrUnsafeFile) {
|
||||
caught = true
|
||||
}
|
||||
}
|
||||
if !caught {
|
||||
t.Fatal("replacement during read was not rejected")
|
||||
}
|
||||
}
|
||||
|
||||
func TestCanonicalDescriptorOwnershipDoesNotLeakAcrossNestedOperations(t *testing.T) {
|
||||
root, err := filepath.EvalSymlinks(t.TempDir())
|
||||
if err != nil {
|
||||
|
||||
Reference in New Issue
Block a user