fix(auth): harden unified diagnostic execution
This commit is contained in:
@@ -55,7 +55,7 @@ func TestRunnerCancelsAndReapsAHangingChildWithinFinalBound(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
runner := NewRunner(writeExecutable(t, "#!/bin/sh\ntrap '' TERM INT\nwhile :; do sleep 1; done\n"))
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 50*time.Millisecond)
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 200*time.Millisecond)
|
||||
defer cancel()
|
||||
started := time.Now()
|
||||
_, err := RunBounded(runner, ctx, []string{"compose", "run", "--rm", "core"}, nil, CaptureLimits{
|
||||
@@ -70,6 +70,98 @@ func TestRunnerCancelsAndReapsAHangingChildWithinFinalBound(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunnerCleansUpNamedComposeContainerAfterOverflow(t *testing.T) {
|
||||
logFile := filepath.Join(t.TempDir(), "calls.log")
|
||||
marker := filepath.Join(t.TempDir(), "container-present")
|
||||
if err := os.WriteFile(marker, []byte("present"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("THT_RUNNER_TEST_LOG", logFile)
|
||||
t.Setenv("THT_RUNNER_TEST_MARKER", marker)
|
||||
t.Setenv("THT_RUNNER_TEST_MODE", "flood")
|
||||
runner := NewRunner(writeExecutable(t, cleanupAwareDockerScript))
|
||||
name := "thothii-cleanup-overflow-sentinel"
|
||||
|
||||
_, err := RunBounded(runner, context.Background(), []string{
|
||||
"compose", "run", "--rm", "--name", name, "core",
|
||||
}, nil, CaptureLimits{StdoutBytes: 1024, StderrBytes: 1024})
|
||||
|
||||
if !errors.Is(err, ErrOutputLimit) {
|
||||
t.Fatalf("RunBounded() error = %v, want ErrOutputLimit", err)
|
||||
}
|
||||
assertContainerCleanup(t, logFile, marker, name)
|
||||
}
|
||||
|
||||
func TestRunnerCleansUpNamedComposeContainerAfterCancellation(t *testing.T) {
|
||||
logFile := filepath.Join(t.TempDir(), "calls.log")
|
||||
marker := filepath.Join(t.TempDir(), "container-present")
|
||||
if err := os.WriteFile(marker, []byte("present"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("THT_RUNNER_TEST_LOG", logFile)
|
||||
t.Setenv("THT_RUNNER_TEST_MARKER", marker)
|
||||
t.Setenv("THT_RUNNER_TEST_MODE", "hang")
|
||||
runner := NewRunner(writeExecutable(t, cleanupAwareDockerScript))
|
||||
name := "thothii-cleanup-cancel-sentinel"
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 200*time.Millisecond)
|
||||
defer cancel()
|
||||
|
||||
_, err := RunBounded(runner, ctx, []string{
|
||||
"compose", "run", "--rm", "--name", name, "core",
|
||||
}, nil, CaptureLimits{StdoutBytes: 1024, StderrBytes: 1024})
|
||||
|
||||
if !errors.Is(err, context.DeadlineExceeded) {
|
||||
t.Fatalf("RunBounded() error = %v, want deadline exceeded", err)
|
||||
}
|
||||
assertContainerCleanup(t, logFile, marker, name)
|
||||
}
|
||||
|
||||
func TestRunnerSurfacesCleanupFailureWithoutContainerName(t *testing.T) {
|
||||
logFile := filepath.Join(t.TempDir(), "calls.log")
|
||||
marker := filepath.Join(t.TempDir(), "container-present")
|
||||
if err := os.WriteFile(marker, []byte("present"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("THT_RUNNER_TEST_LOG", logFile)
|
||||
t.Setenv("THT_RUNNER_TEST_MARKER", marker)
|
||||
t.Setenv("THT_RUNNER_TEST_MODE", "cleanup-fails")
|
||||
runner := NewRunner(writeExecutable(t, cleanupAwareDockerScript))
|
||||
name := "thothii-cleanup-secret-sentinel"
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 50*time.Millisecond)
|
||||
defer cancel()
|
||||
|
||||
_, err := RunBounded(runner, ctx, []string{
|
||||
"compose", "run", "--rm", "--name", name, "core",
|
||||
}, nil, CaptureLimits{StdoutBytes: 1024, StderrBytes: 1024})
|
||||
|
||||
if err == nil || !strings.Contains(err.Error(), "one-shot container cleanup failed") {
|
||||
t.Fatalf("RunBounded() error = %v, want safe cleanup failure", err)
|
||||
}
|
||||
if strings.Contains(err.Error(), name) {
|
||||
t.Fatalf("RunBounded() exposed the container name: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunnerPropagatesAReapingFailure(t *testing.T) {
|
||||
original := terminateProcessForRunner
|
||||
terminateProcessForRunner = func(command *exec.Cmd, done <-chan error) error {
|
||||
_ = terminateProcess(command, done)
|
||||
return ErrProcessReap
|
||||
}
|
||||
t.Cleanup(func() { terminateProcessForRunner = original })
|
||||
runner := NewRunner(writeExecutable(t, "#!/bin/sh\ntrap '' TERM INT\nwhile :; do sleep 1; done\n"))
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
|
||||
defer cancel()
|
||||
|
||||
_, err := RunBounded(runner, ctx, []string{"version"}, nil, CaptureLimits{
|
||||
StdoutBytes: 1024, StderrBytes: 1024,
|
||||
})
|
||||
|
||||
if !errors.Is(err, context.DeadlineExceeded) || !errors.Is(err, ErrProcessReap) {
|
||||
t.Fatalf("RunBounded() error = %v, want deadline and reap failure", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunnerReturnsTheChildExitCode(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -86,6 +178,22 @@ func TestRunnerReturnsTheChildExitCode(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunnerRetainsTheExactNormalRmInvocationForAnUnnamedOneShot(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
runner := NewRunner(writeExecutable(t, "#!/bin/sh\nprintf '%s\\n' \"$@\"\n"))
|
||||
result, err := runner.Run(context.Background(), []string{
|
||||
"compose", "run", "--rm", "--no-deps", "core", "node", "diagnostic.js",
|
||||
}, nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got := strings.Fields(result.Stdout)
|
||||
if strings.Join(got, " ") != "compose run --rm --no-deps core node diagnostic.js" {
|
||||
t.Fatalf("one-shot argv = %#v, want exact original --rm invocation", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestRunnerReportsMissingDocker(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
@@ -140,3 +248,35 @@ func writeExecutable(t *testing.T, contents string) string {
|
||||
}
|
||||
return path
|
||||
}
|
||||
|
||||
func assertContainerCleanup(t *testing.T, logFile, marker, name string) {
|
||||
t.Helper()
|
||||
calls, err := os.ReadFile(logFile)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.Contains(string(calls), "container rm -f "+name) {
|
||||
t.Fatalf("Docker calls = %q, want bounded container cleanup", calls)
|
||||
}
|
||||
if _, err := os.Stat(marker); !os.IsNotExist(err) {
|
||||
t.Fatalf("one-shot container marker still exists: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
const cleanupAwareDockerScript = `#!/bin/sh
|
||||
printf '%s\n' "$*" >> "$THT_RUNNER_TEST_LOG"
|
||||
if [ "$1" = "container" ] && [ "$2" = "ls" ]; then
|
||||
if [ -f "$THT_RUNNER_TEST_MARKER" ]; then printf '%s\n' container-id; fi
|
||||
exit 0
|
||||
fi
|
||||
if [ "$1" = "container" ] && [ "$2" = "rm" ]; then
|
||||
if [ "$THT_RUNNER_TEST_MODE" = "cleanup-fails" ]; then exit 9; fi
|
||||
rm -f "$THT_RUNNER_TEST_MARKER"
|
||||
exit 0
|
||||
fi
|
||||
if [ "$THT_RUNNER_TEST_MODE" = "flood" ]; then
|
||||
while :; do printf '0123456789abcdef'; printf 'fedcba9876543210' >&2; done
|
||||
fi
|
||||
trap '' TERM INT
|
||||
while :; do sleep 1; done
|
||||
`
|
||||
|
||||
Reference in New Issue
Block a user