fix: harden thothctl Windows safe I/O
This commit is contained in:
@@ -4,8 +4,9 @@ import (
|
||||
"errors"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"testing"
|
||||
|
||||
"github.com/aritmolab/thothii/tools/thothctl/internal/testsupport"
|
||||
)
|
||||
|
||||
func TestReadCanonicalRegularRejectsFinalAndParentSymlinks(t *testing.T) {
|
||||
@@ -29,24 +30,14 @@ func TestReadCanonicalRegularRejectsFinalAndParentSymlinks(t *testing.T) {
|
||||
}
|
||||
|
||||
parentLink := filepath.Join(root, "parent-link")
|
||||
symlinkOrSkip(t, realDirectory, parentLink)
|
||||
testsupport.SymlinkOrSkip(t, realDirectory, parentLink)
|
||||
if _, err := ReadCanonicalRegular(filepath.Join(parentLink, "secret"), 1024); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("parent symlink error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
|
||||
finalLink := filepath.Join(root, "final-link")
|
||||
symlinkOrSkip(t, realFile, finalLink)
|
||||
testsupport.SymlinkOrSkip(t, realFile, finalLink)
|
||||
if _, err := ReadCanonicalRegular(finalLink, 1024); !errors.Is(err, ErrUnsafeFile) {
|
||||
t.Fatalf("final symlink error = %v, want ErrUnsafeFile", err)
|
||||
}
|
||||
}
|
||||
|
||||
func symlinkOrSkip(t *testing.T, target, link string) {
|
||||
t.Helper()
|
||||
if err := os.Symlink(target, link); err != nil {
|
||||
if runtime.GOOS == "windows" && errors.Is(err, os.ErrPermission) {
|
||||
t.Skip("Windows symlink privilege is unavailable")
|
||||
}
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user