fix(auth): harden unified diagnostic execution

This commit is contained in:
2026-08-17 17:25:26 +02:00
parent 30ee9433dc
commit ef244ab56d
18 changed files with 670 additions and 68 deletions
+141 -1
View File
@@ -55,7 +55,7 @@ func TestRunnerCancelsAndReapsAHangingChildWithinFinalBound(t *testing.T) {
t.Parallel()
runner := NewRunner(writeExecutable(t, "#!/bin/sh\ntrap '' TERM INT\nwhile :; do sleep 1; done\n"))
ctx, cancel := context.WithTimeout(context.Background(), 50*time.Millisecond)
ctx, cancel := context.WithTimeout(context.Background(), 200*time.Millisecond)
defer cancel()
started := time.Now()
_, err := RunBounded(runner, ctx, []string{"compose", "run", "--rm", "core"}, nil, CaptureLimits{
@@ -70,6 +70,98 @@ func TestRunnerCancelsAndReapsAHangingChildWithinFinalBound(t *testing.T) {
}
}
func TestRunnerCleansUpNamedComposeContainerAfterOverflow(t *testing.T) {
logFile := filepath.Join(t.TempDir(), "calls.log")
marker := filepath.Join(t.TempDir(), "container-present")
if err := os.WriteFile(marker, []byte("present"), 0o600); err != nil {
t.Fatal(err)
}
t.Setenv("THT_RUNNER_TEST_LOG", logFile)
t.Setenv("THT_RUNNER_TEST_MARKER", marker)
t.Setenv("THT_RUNNER_TEST_MODE", "flood")
runner := NewRunner(writeExecutable(t, cleanupAwareDockerScript))
name := "thothii-cleanup-overflow-sentinel"
_, err := RunBounded(runner, context.Background(), []string{
"compose", "run", "--rm", "--name", name, "core",
}, nil, CaptureLimits{StdoutBytes: 1024, StderrBytes: 1024})
if !errors.Is(err, ErrOutputLimit) {
t.Fatalf("RunBounded() error = %v, want ErrOutputLimit", err)
}
assertContainerCleanup(t, logFile, marker, name)
}
func TestRunnerCleansUpNamedComposeContainerAfterCancellation(t *testing.T) {
logFile := filepath.Join(t.TempDir(), "calls.log")
marker := filepath.Join(t.TempDir(), "container-present")
if err := os.WriteFile(marker, []byte("present"), 0o600); err != nil {
t.Fatal(err)
}
t.Setenv("THT_RUNNER_TEST_LOG", logFile)
t.Setenv("THT_RUNNER_TEST_MARKER", marker)
t.Setenv("THT_RUNNER_TEST_MODE", "hang")
runner := NewRunner(writeExecutable(t, cleanupAwareDockerScript))
name := "thothii-cleanup-cancel-sentinel"
ctx, cancel := context.WithTimeout(context.Background(), 200*time.Millisecond)
defer cancel()
_, err := RunBounded(runner, ctx, []string{
"compose", "run", "--rm", "--name", name, "core",
}, nil, CaptureLimits{StdoutBytes: 1024, StderrBytes: 1024})
if !errors.Is(err, context.DeadlineExceeded) {
t.Fatalf("RunBounded() error = %v, want deadline exceeded", err)
}
assertContainerCleanup(t, logFile, marker, name)
}
func TestRunnerSurfacesCleanupFailureWithoutContainerName(t *testing.T) {
logFile := filepath.Join(t.TempDir(), "calls.log")
marker := filepath.Join(t.TempDir(), "container-present")
if err := os.WriteFile(marker, []byte("present"), 0o600); err != nil {
t.Fatal(err)
}
t.Setenv("THT_RUNNER_TEST_LOG", logFile)
t.Setenv("THT_RUNNER_TEST_MARKER", marker)
t.Setenv("THT_RUNNER_TEST_MODE", "cleanup-fails")
runner := NewRunner(writeExecutable(t, cleanupAwareDockerScript))
name := "thothii-cleanup-secret-sentinel"
ctx, cancel := context.WithTimeout(context.Background(), 50*time.Millisecond)
defer cancel()
_, err := RunBounded(runner, ctx, []string{
"compose", "run", "--rm", "--name", name, "core",
}, nil, CaptureLimits{StdoutBytes: 1024, StderrBytes: 1024})
if err == nil || !strings.Contains(err.Error(), "one-shot container cleanup failed") {
t.Fatalf("RunBounded() error = %v, want safe cleanup failure", err)
}
if strings.Contains(err.Error(), name) {
t.Fatalf("RunBounded() exposed the container name: %v", err)
}
}
func TestRunnerPropagatesAReapingFailure(t *testing.T) {
original := terminateProcessForRunner
terminateProcessForRunner = func(command *exec.Cmd, done <-chan error) error {
_ = terminateProcess(command, done)
return ErrProcessReap
}
t.Cleanup(func() { terminateProcessForRunner = original })
runner := NewRunner(writeExecutable(t, "#!/bin/sh\ntrap '' TERM INT\nwhile :; do sleep 1; done\n"))
ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
defer cancel()
_, err := RunBounded(runner, ctx, []string{"version"}, nil, CaptureLimits{
StdoutBytes: 1024, StderrBytes: 1024,
})
if !errors.Is(err, context.DeadlineExceeded) || !errors.Is(err, ErrProcessReap) {
t.Fatalf("RunBounded() error = %v, want deadline and reap failure", err)
}
}
func TestRunnerReturnsTheChildExitCode(t *testing.T) {
t.Parallel()
@@ -86,6 +178,22 @@ func TestRunnerReturnsTheChildExitCode(t *testing.T) {
}
}
func TestRunnerRetainsTheExactNormalRmInvocationForAnUnnamedOneShot(t *testing.T) {
t.Parallel()
runner := NewRunner(writeExecutable(t, "#!/bin/sh\nprintf '%s\\n' \"$@\"\n"))
result, err := runner.Run(context.Background(), []string{
"compose", "run", "--rm", "--no-deps", "core", "node", "diagnostic.js",
}, nil)
if err != nil {
t.Fatal(err)
}
got := strings.Fields(result.Stdout)
if strings.Join(got, " ") != "compose run --rm --no-deps core node diagnostic.js" {
t.Fatalf("one-shot argv = %#v, want exact original --rm invocation", got)
}
}
func TestRunnerReportsMissingDocker(t *testing.T) {
t.Parallel()
@@ -140,3 +248,35 @@ func writeExecutable(t *testing.T, contents string) string {
}
return path
}
func assertContainerCleanup(t *testing.T, logFile, marker, name string) {
t.Helper()
calls, err := os.ReadFile(logFile)
if err != nil {
t.Fatal(err)
}
if !strings.Contains(string(calls), "container rm -f "+name) {
t.Fatalf("Docker calls = %q, want bounded container cleanup", calls)
}
if _, err := os.Stat(marker); !os.IsNotExist(err) {
t.Fatalf("one-shot container marker still exists: %v", err)
}
}
const cleanupAwareDockerScript = `#!/bin/sh
printf '%s\n' "$*" >> "$THT_RUNNER_TEST_LOG"
if [ "$1" = "container" ] && [ "$2" = "ls" ]; then
if [ -f "$THT_RUNNER_TEST_MARKER" ]; then printf '%s\n' container-id; fi
exit 0
fi
if [ "$1" = "container" ] && [ "$2" = "rm" ]; then
if [ "$THT_RUNNER_TEST_MODE" = "cleanup-fails" ]; then exit 9; fi
rm -f "$THT_RUNNER_TEST_MARKER"
exit 0
fi
if [ "$THT_RUNNER_TEST_MODE" = "flood" ]; then
while :; do printf '0123456789abcdef'; printf 'fedcba9876543210' >&2; done
fi
trap '' TERM INT
while :; do sleep 1; done
`