fix Task1 publication and secret preflight

This commit is contained in:
2026-08-11 04:06:23 +02:00
parent fcc45520ad
commit c7f7a6e1b0
8 changed files with 324 additions and 215 deletions
@@ -13,7 +13,7 @@ import (
)
const expectedWindowsRetainedHandleShareMode = windows.FILE_SHARE_READ | windows.FILE_SHARE_WRITE
const expectedWindowsOutputHandleShareMode = windows.FILE_SHARE_READ
const expectedWindowsOutputHandleShareMode = 0
// Keep this contract compile-enforced so Windows cross-test compilation catches a future
// FILE_SHARE_DELETE regression even when the tests are compiled on a non-Windows host.
@@ -80,6 +80,51 @@ func TestOpenWindowsComponentBlocksMutationWhileHandleIsRetained(t *testing.T) {
})
}
func TestWindowsStageHandleDeniesReadRenameDeleteAndHardlink(t *testing.T) {
root := filepath.Join(t.TempDir(), "parent")
if err := os.Mkdir(root, 0o700); err != nil {
t.Fatal(err)
}
securityDescriptor, securityAttributes, err := ownerOnlySecurityAttributes()
if err != nil {
t.Fatal(err)
}
_ = securityDescriptor
stagePath := filepath.Join(root, ".thothctl-candidate-test")
h, err := windows.CreateFile(windows.StringToUTF16Ptr(stagePath), windows.GENERIC_WRITE|windows.DELETE, 0, securityAttributes, windows.CREATE_NEW, windows.FILE_ATTRIBUTE_NORMAL|windows.FILE_FLAG_OPEN_REPARSE_POINT, 0)
if err != nil {
t.Fatal(err)
}
closed := false
defer func() {
if !closed {
_ = windows.CloseHandle(h)
}
}()
if _, err := windows.CreateFile(windows.StringToUTF16Ptr(stagePath), windows.GENERIC_READ, windows.FILE_SHARE_READ|windows.FILE_SHARE_WRITE|windows.FILE_SHARE_DELETE, nil, windows.OPEN_EXISTING, windows.FILE_ATTRIBUTE_NORMAL|windows.FILE_FLAG_OPEN_REPARSE_POINT, 0); err == nil {
t.Fatal("stage read succeeded while zero-share handle was open")
}
if err := os.Rename(stagePath, stagePath+"-renamed"); err == nil {
t.Fatal("stage rename succeeded while handle was open")
}
if err := os.Link(stagePath, filepath.Join(root, "stolen")); err == nil {
t.Fatal("stage hardlink succeeded while handle was open")
}
if err := os.Remove(stagePath); err == nil {
t.Fatal("stage delete succeeded while handle was open")
}
if err := deleteWindowsHandle(h); err != nil {
t.Fatal(err)
}
if err := windows.CloseHandle(h); err != nil {
t.Fatal(err)
}
closed = true
if _, err := os.Stat(stagePath); !os.IsNotExist(err) {
t.Fatalf("disposed stage remains: %v", err)
}
}
func TestWriteCanonicalExclusiveRequiresRestrictiveMode(t *testing.T) {
if err := writeCanonicalExclusive(`C:\\tmp\\thothctl-output.yaml`, []byte("x"), 0o640); err == nil {
t.Fatal("accepted non-restrictive output mode")