fix(auth): harden diagnostic cleanup races
This commit is contained in:
@@ -13,14 +13,19 @@ func TestWindowsTerminationUsesBoundedExactPIDTreeKillWithoutAShell(t *testing.T
|
||||
}
|
||||
text := string(source)
|
||||
for _, required := range []string{
|
||||
"context.WithTimeout", "exec.CommandContext", `"taskkill.exe"`, `"/PID"`,
|
||||
"strconv.Itoa", `"/T"`, `"/F"`, "io.Discard", "ErrProcessReap",
|
||||
"context.WithTimeout", "windows.GetSystemDirectory", "filepath.Clean", "filepath.IsAbs",
|
||||
`filepath.Join(systemDirectory, "taskkill.exe")`, "systemTaskkillPath",
|
||||
`exec.CommandContext(ctx, taskkillPath, "/PID", strconv.Itoa(pid), "/T", "/F")`,
|
||||
"io.Discard", "ErrProcessReap",
|
||||
} {
|
||||
if !strings.Contains(text, required) {
|
||||
t.Errorf("process_windows.go is missing %q", required)
|
||||
}
|
||||
}
|
||||
for _, forbidden := range []string{"cmd.exe", "powershell", `exec.Command("taskkill.exe"`} {
|
||||
for _, forbidden := range []string{
|
||||
"cmd.exe", "powershell", `exec.Command("taskkill.exe"`,
|
||||
`exec.CommandContext(ctx, "taskkill.exe"`, `exec.LookPath("taskkill.exe")`,
|
||||
} {
|
||||
if strings.Contains(strings.ToLower(text), strings.ToLower(forbidden)) {
|
||||
t.Errorf("process_windows.go contains unsafe command form %q", forbidden)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user