fix: close workspace preprocessing contract gaps
This commit is contained in:
@@ -72,3 +72,29 @@ func TestWriteCanonicalExclusiveRequiresRestrictiveMode(t *testing.T) {
|
||||
t.Fatal("accepted non-restrictive output mode")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWriteCanonicalExclusiveCreatesProtectedOwnerOnlyDACL(t *testing.T) {
|
||||
root, err := filepath.EvalSymlinks(t.TempDir())
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
path := filepath.Join(root, "candidate.yaml")
|
||||
if err := writeCanonicalExclusive(path, []byte("x"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
sd, err := windows.GetNamedSecurityInfo(path, windows.SE_FILE_OBJECT, windows.DACL_SECURITY_INFORMATION)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
control, _, err := sd.Control()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if control&windows.SE_DACL_PROTECTED == 0 {
|
||||
t.Fatalf("output DACL control = %#x, want protected", control)
|
||||
}
|
||||
acl, _, err := sd.DACL()
|
||||
if err != nil || acl == nil || acl.AceCount != 1 {
|
||||
t.Fatalf("output DACL = %#v, err=%v; want one owner ACE", acl, err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user