fix: harden task1 workspace output and publication

This commit is contained in:
2026-08-11 03:14:58 +02:00
parent 3564817409
commit ad80180381
9 changed files with 410 additions and 67 deletions
@@ -4,6 +4,7 @@ import (
"errors"
"os"
"path/filepath"
"strings"
"testing"
"github.com/aritmolab/thothii/tools/thothctl/internal/testsupport"
@@ -86,6 +87,29 @@ func TestWriteCanonicalExclusiveRejectsExistingAndCreatesPrivateFile(t *testing.
}
}
func TestWriteCanonicalExclusiveCleansPrivateStageWhenPublicationRacesExistingLeaf(t *testing.T) {
root, err := filepath.EvalSymlinks(t.TempDir())
if err != nil {
t.Fatal(err)
}
path := filepath.Join(root, "candidate.yaml")
if err := os.WriteFile(path, []byte("attacker"), 0o600); err != nil {
t.Fatal(err)
}
if err := WriteCanonicalExclusive(path, []byte("candidate"), 0o600); !errors.Is(err, ErrUnsafeFile) {
t.Fatalf("write error=%v", err)
}
entries, err := os.ReadDir(root)
if err != nil {
t.Fatal(err)
}
for _, entry := range entries {
if strings.HasPrefix(entry.Name(), ".thothctl-candidate-") {
t.Fatalf("private stage leaked: %s", entry.Name())
}
}
}
func TestReadCanonicalRegularRejectsHardlinkAndDirectory(t *testing.T) {
root, err := filepath.EvalSymlinks(t.TempDir())
if err != nil {