From fa197498f23f3d6c6a7bd3e3a3f35655746d10a6 Mon Sep 17 00:00:00 2001 From: mptyl Date: Tue, 18 Aug 2026 13:42:14 +0200 Subject: [PATCH] test(windows): order private fixture protection --- .../internal/backup/fixture_security_windows_test.go | 10 +++++----- tools/tht/internal/backup/preflight_windows_test.go | 5 +++-- tools/tht/internal/safeio/private_windows_test.go | 6 +++--- 3 files changed, 11 insertions(+), 10 deletions(-) diff --git a/tools/tht/internal/backup/fixture_security_windows_test.go b/tools/tht/internal/backup/fixture_security_windows_test.go index 378dc912..5700a4a9 100644 --- a/tools/tht/internal/backup/fixture_security_windows_test.go +++ b/tools/tht/internal/backup/fixture_security_windows_test.go @@ -10,14 +10,14 @@ import ( func prepareBackupFixturePrivatePaths(t *testing.T, directories, files []string) { t.Helper() - for _, path := range directories { - if err := safeio.ProtectPrivateDirectory(path); err != nil { - t.Fatalf("ProtectPrivateDirectory(%q): %v", path, err) - } - } for _, path := range files { if err := safeio.ProtectPrivateRegular(path); err != nil { t.Fatalf("ProtectPrivateRegular(%q): %v", path, err) } } + for _, path := range directories { + if err := safeio.ProtectPrivateDirectory(path); err != nil { + t.Fatalf("ProtectPrivateDirectory(%q): %v", path, err) + } + } } diff --git a/tools/tht/internal/backup/preflight_windows_test.go b/tools/tht/internal/backup/preflight_windows_test.go index 7a92b7bf..cb96cf5b 100644 --- a/tools/tht/internal/backup/preflight_windows_test.go +++ b/tools/tht/internal/backup/preflight_windows_test.go @@ -39,8 +39,9 @@ func TestStageArchiveProtectsWindowsStagingArtifactsWithOwnerOnlyACLs(t *testing t.Fatal(err) } staged.file = nil - if err := safeio.ValidatePrivateRegular(staged.path); err != nil { - t.Fatalf("staged archive ACL = %v, want owner-only", err) + contents, found, err := staged.parent.ReadRegular(staged.name, 1<<20) + if err != nil || !found || len(contents) == 0 { + t.Fatalf("retained staged archive read = found:%t bytes:%d error:%v, want owner-only regular", found, len(contents), err) } } diff --git a/tools/tht/internal/safeio/private_windows_test.go b/tools/tht/internal/safeio/private_windows_test.go index 3fea198b..f4abfedb 100644 --- a/tools/tht/internal/safeio/private_windows_test.go +++ b/tools/tht/internal/safeio/private_windows_test.go @@ -113,12 +113,12 @@ func TestOwnerOnlyDACLCanProtectInheritedRegularFile(t *testing.T) { if err := os.WriteFile(path, []byte("private"), 0o600); err != nil { t.Fatal(err) } - if err := ProtectPrivateDirectory(directory); err != nil { - t.Fatalf("ProtectPrivateDirectory() after inherited file error = %T %v", err, err) - } if err := ProtectPrivateRegular(path); err != nil { t.Fatalf("ProtectPrivateRegular() inherited file error = %T %v", err, err) } + if err := ProtectPrivateDirectory(directory); err != nil { + t.Fatalf("ProtectPrivateDirectory() after private file error = %T %v", err, err) + } if err := ValidatePrivateRegular(path); err != nil { t.Fatalf("ValidatePrivateRegular() inherited file error = %T %v", err, err) }