fix(auth): close diagnostic filesystem races
This commit is contained in:
@@ -9,6 +9,7 @@ import (
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"sync"
|
||||
"testing"
|
||||
@@ -119,6 +120,53 @@ func TestProtocolPreflightsRootWithoutCreatingOrFollowingLinks(t *testing.T) {
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: filepath.Join(parent, "auth\n")})
|
||||
}
|
||||
|
||||
func TestProtocolValidatesTheCompleteSessionLayoutWithoutCreatingIt(t *testing.T) {
|
||||
root := filepath.Join(privateTestRoot(t), "auth")
|
||||
if err := safeio.EnsurePrivateDirectory(root); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
validated := runRequest(t, request{Version: 1, Operation: "validate-root", Root: root})
|
||||
if !validated.Validated {
|
||||
t.Fatal("layout with safely creatable children was not validated")
|
||||
}
|
||||
for _, child := range []string{"sessions", "oidc"} {
|
||||
if _, err := os.Lstat(filepath.Join(root, child)); !errors.Is(err, os.ErrNotExist) {
|
||||
t.Fatalf("validate-root created %s: %v", child, err)
|
||||
}
|
||||
}
|
||||
|
||||
outside := privateTestRoot(t)
|
||||
testsupport.SymlinkOrSkip(t, outside, filepath.Join(root, "sessions"))
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: root})
|
||||
if entries, err := os.ReadDir(outside); err != nil || len(entries) != 0 {
|
||||
t.Fatalf("linked child target was mutated: entries=%v error=%v", entries, err)
|
||||
}
|
||||
if err := os.Remove(filepath.Join(root, "sessions")); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.Mkdir(filepath.Join(root, "sessions"), 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if runtime.GOOS == "windows" {
|
||||
return // Native DACL coverage lives in storage_windows_test.go.
|
||||
}
|
||||
if err := os.Chmod(filepath.Join(root, "sessions"), 0o750); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
runRejected(t, request{Version: 1, Operation: "validate-root", Root: root})
|
||||
}
|
||||
|
||||
func TestProtocolEnsuresTheCompletePrivateSessionLayout(t *testing.T) {
|
||||
root := filepath.Join(privateTestRoot(t), "auth")
|
||||
runRequest(t, request{Version: 1, Operation: "ensure-layout", Root: root})
|
||||
for _, path := range []string{root, filepath.Join(root, "sessions"), filepath.Join(root, "oidc")} {
|
||||
if err := safeio.ValidatePrivateDirectory(path); err != nil {
|
||||
t.Fatalf("private layout path %q: %v", filepath.Base(path), err)
|
||||
}
|
||||
}
|
||||
runRejected(t, request{Version: 1, Operation: "ensure-layout", Root: root, Directory: "sessions"})
|
||||
}
|
||||
|
||||
func TestProtocolReadsOnlyBoundedPrivateAuthConfig(t *testing.T) {
|
||||
root := privateTestRoot(t)
|
||||
filename := "auth.yaml"
|
||||
|
||||
Reference in New Issue
Block a user