fix: harden task1 workspace output and publication

This commit is contained in:
2026-08-11 03:14:58 +02:00
parent 3564817409
commit ad80180381
9 changed files with 410 additions and 67 deletions
@@ -22,6 +22,14 @@ var _ [expectedWindowsRetainedHandleShareMode - windowsRetainedHandleShareMode]s
var _ [windowsOutputHandleShareMode - expectedWindowsOutputHandleShareMode]struct{}
var _ [expectedWindowsOutputHandleShareMode - windowsOutputHandleShareMode]struct{}
func TestValidateCanonicalPathRejectsWindowsNamespacesAndAlternateStreams(t *testing.T) {
for _, path := range []string{`C:\dir\existing.txt:candidate`, `\\?\C:\dir\candidate`, `\\.\pipe\candidate`, `\Device\HarddiskVolume1\candidate`, `\??\C:\candidate`} {
if err := ValidateCanonicalPath(path); !errors.Is(err, ErrUnsafeFile) {
t.Errorf("ValidateCanonicalPath(%q) = %v, want ErrUnsafeFile", path, err)
}
}
}
func TestOpenWindowsComponentBlocksMutationWhileHandleIsRetained(t *testing.T) {
t.Run("parent rename", func(t *testing.T) {
parent := filepath.Join(t.TempDir(), "parent")