fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 16:39:54 +02:00
parent 3ed00ff086
commit 30ee9433dc
20 changed files with 1034 additions and 57 deletions
+40
View File
@@ -9,6 +9,7 @@ import (
"path/filepath"
"strings"
"testing"
"time"
"github.com/aritmolab/thothii/tools/tht/internal/config"
)
@@ -30,6 +31,45 @@ func TestRunnerPassesEachArgumentWithoutShellSplitting(t *testing.T) {
}
}
func TestRunnerBoundsFloodingOutputDuringCapture(t *testing.T) {
t.Parallel()
runner := NewRunner(writeExecutable(t, "#!/bin/sh\nwhile :; do printf '0123456789abcdef'; printf 'fedcba9876543210' >&2; done\n"))
started := time.Now()
result, err := RunBounded(runner, context.Background(), []string{"compose", "run", "--rm", "core"}, nil, CaptureLimits{
StdoutBytes: 1024,
StderrBytes: 1024,
})
if !errors.Is(err, ErrOutputLimit) {
t.Fatalf("RunBounded() error = %v, want ErrOutputLimit", err)
}
if len(result.Stdout) > 1024 || len(result.Stderr) > 1024 {
t.Fatalf("captured output exceeded limits: stdout=%d stderr=%d", len(result.Stdout), len(result.Stderr))
}
if elapsed := time.Since(started); elapsed > 5*time.Second {
t.Fatalf("overflow teardown took %s", elapsed)
}
}
func TestRunnerCancelsAndReapsAHangingChildWithinFinalBound(t *testing.T) {
t.Parallel()
runner := NewRunner(writeExecutable(t, "#!/bin/sh\ntrap '' TERM INT\nwhile :; do sleep 1; done\n"))
ctx, cancel := context.WithTimeout(context.Background(), 50*time.Millisecond)
defer cancel()
started := time.Now()
_, err := RunBounded(runner, ctx, []string{"compose", "run", "--rm", "core"}, nil, CaptureLimits{
StdoutBytes: 1024,
StderrBytes: 1024,
})
if !errors.Is(err, context.DeadlineExceeded) {
t.Fatalf("RunBounded() error = %v, want deadline exceeded", err)
}
if elapsed := time.Since(started); elapsed > 5*time.Second {
t.Fatalf("cancellation teardown took %s", elapsed)
}
}
func TestRunnerReturnsTheChildExitCode(t *testing.T) {
t.Parallel()