fix: harden thothctl file access
This commit is contained in:
@@ -3,8 +3,12 @@ package main
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
@@ -151,9 +155,7 @@ func TestRunFailsClosedForTraversalAndParentSymlinkSecretSources(t *testing.T) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
linkDirectory := filepath.Join(fixture.root, "linked")
|
||||
if err := os.Symlink(realDirectory, linkDirectory); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
symlinkOrSkip(t, realDirectory, linkDirectory)
|
||||
return filepath.Join(linkDirectory, "secret")
|
||||
},
|
||||
"final symlink": func(t *testing.T, fixture cliFixture) string {
|
||||
@@ -162,9 +164,7 @@ func TestRunFailsClosedForTraversalAndParentSymlinkSecretSources(t *testing.T) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
linkSecret := filepath.Join(fixture.root, "linked-secret")
|
||||
if err := os.Symlink(realSecret, linkSecret); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
symlinkOrSkip(t, realSecret, linkSecret)
|
||||
return linkSecret
|
||||
},
|
||||
} {
|
||||
@@ -185,6 +185,7 @@ func TestRunFailsClosedForTraversalAndParentSymlinkSecretSources(t *testing.T) {
|
||||
if strings.Contains(stderr.String(), unsafeSource) {
|
||||
t.Errorf("stderr revealed unsafe source path: %q", stderr.String())
|
||||
}
|
||||
assertDockerNotInvoked(t, fixture)
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -199,6 +200,7 @@ func TestRunFailsClosedForOversizedEnvAndSecretFiles(t *testing.T) {
|
||||
if exitCode != 2 || !strings.Contains(stderr.String(), "installation secret declarations could not be read") {
|
||||
t.Errorf("exit=%d stderr=%q, want sanitized oversized-env failure", exitCode, stderr.String())
|
||||
}
|
||||
assertDockerNotInvoked(t, fixture)
|
||||
})
|
||||
t.Run("secret", func(t *testing.T) {
|
||||
fixture := newCLIFixture(t, "")
|
||||
@@ -213,6 +215,49 @@ func TestRunFailsClosedForOversizedEnvAndSecretFiles(t *testing.T) {
|
||||
if exitCode != 2 || !strings.Contains(stderr.String(), "declared secret file could not be read") {
|
||||
t.Errorf("exit=%d stderr=%q, want sanitized oversized-secret failure", exitCode, stderr.String())
|
||||
}
|
||||
assertDockerNotInvoked(t, fixture)
|
||||
})
|
||||
}
|
||||
|
||||
func TestRunFailsClosedForTooManyOrTooLargeSecretSources(t *testing.T) {
|
||||
t.Run("too many sources", func(t *testing.T) {
|
||||
fixture := newCLIFixture(t, "")
|
||||
var declarations strings.Builder
|
||||
for index := range 33 {
|
||||
secretPath := filepath.Join(fixture.root, "secret-count-"+strconv.Itoa(index))
|
||||
if err := os.WriteFile(secretPath, []byte("secret"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
fmt.Fprintf(&declarations, "SECRET_%d_FILE=%s\n", index, secretPath)
|
||||
}
|
||||
fixture.setEnvContents(t, declarations.String())
|
||||
|
||||
var stdout, stderr bytes.Buffer
|
||||
exitCode := run(context.Background(), []string{"--installation", fixture.installationPath, "logs"}, &stdout, &stderr)
|
||||
if exitCode != 2 || !strings.Contains(stderr.String(), "installation secret declarations could not be read") {
|
||||
t.Errorf("exit=%d stderr=%q, want sanitized source-count failure", exitCode, stderr.String())
|
||||
}
|
||||
assertDockerNotInvoked(t, fixture)
|
||||
})
|
||||
|
||||
t.Run("total source bytes", func(t *testing.T) {
|
||||
fixture := newCLIFixture(t, "")
|
||||
var declarations strings.Builder
|
||||
for index := range 5 {
|
||||
secretPath := filepath.Join(fixture.root, "secret-total-"+strconv.Itoa(index))
|
||||
if err := os.WriteFile(secretPath, bytes.Repeat([]byte("x"), 60*1024), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
fmt.Fprintf(&declarations, "SECRET_%d_SOURCE=%s\n", index, secretPath)
|
||||
}
|
||||
fixture.setEnvContents(t, declarations.String())
|
||||
|
||||
var stdout, stderr bytes.Buffer
|
||||
exitCode := run(context.Background(), []string{"--installation", fixture.installationPath, "logs"}, &stdout, &stderr)
|
||||
if exitCode != 2 || !strings.Contains(stderr.String(), "declared secret file could not be read") {
|
||||
t.Errorf("exit=%d stderr=%q, want sanitized total-size failure", exitCode, stderr.String())
|
||||
}
|
||||
assertDockerNotInvoked(t, fixture)
|
||||
})
|
||||
}
|
||||
|
||||
@@ -406,3 +451,20 @@ func (f cliFixture) invocations(t *testing.T) [][]string {
|
||||
}
|
||||
return invocations
|
||||
}
|
||||
|
||||
func assertDockerNotInvoked(t *testing.T, fixture cliFixture) {
|
||||
t.Helper()
|
||||
if _, err := os.Stat(fixture.argsFile); !os.IsNotExist(err) {
|
||||
t.Errorf("Docker was invoked: stat error = %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func symlinkOrSkip(t *testing.T, target, link string) {
|
||||
t.Helper()
|
||||
if err := os.Symlink(target, link); err != nil {
|
||||
if runtime.GOOS == "windows" && errors.Is(err, os.ErrPermission) {
|
||||
t.Skip("Windows symlink privilege is unavailable")
|
||||
}
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user