fix(auth): close Task 15 review round two
This commit is contained in:
@@ -57,6 +57,49 @@ func TestPreflightReturnsValidatedMetadataAndCallsAllTargetChecksWithoutExtracti
|
||||
}
|
||||
}
|
||||
|
||||
func TestPreflightStagesOnTheAccountedInstallationFilesystemInsteadOfTMPDIR(t *testing.T) {
|
||||
installation := preflightTestInstallation(t)
|
||||
if err := os.MkdirAll(installation.ControlDirectory(), 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
archive := filepath.Join(t.TempDir(), "valid.zip")
|
||||
writePreflightArchive(t, archive, preflightArchiveSpec{
|
||||
entries: []preflightArchiveEntry{{path: "configuration/operator.env", body: []byte("safe")}},
|
||||
})
|
||||
|
||||
blockedTMPDIR := filepath.Join(t.TempDir(), "not-a-directory")
|
||||
if err := os.WriteFile(blockedTMPDIR, []byte("blocked"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("TMPDIR", blockedTMPDIR)
|
||||
|
||||
var capacityTargets []string
|
||||
dependencies := permissivePreflightDependencies()
|
||||
dependencies.FreeBytes = func(target string) (uint64, error) {
|
||||
capacityTargets = append(capacityTargets, target)
|
||||
return 1 << 30, nil
|
||||
}
|
||||
result, err := Preflight(context.Background(), installation, PreflightRequest{Archive: archive, Confirm: true}, dependencies)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer result.CloseArchive()
|
||||
|
||||
staged, err := result.StageArchive(context.Background())
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
defer staged.Close()
|
||||
|
||||
if len(capacityTargets) == 0 || capacityTargets[0] != installation.ControlDirectory() {
|
||||
t.Fatalf("free-space targets = %q, want installation control directory %q", capacityTargets, installation.ControlDirectory())
|
||||
}
|
||||
stagingRoot := filepath.Join(installation.ControlDirectory(), "restore-staging")
|
||||
if relative, err := filepath.Rel(stagingRoot, staged.directory); err != nil || relative == "." || strings.HasPrefix(relative, "..") {
|
||||
t.Fatalf("staging directory = %q, want a child of %q", staged.directory, stagingRoot)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPreflightRejectsAdversarialArchiveEntriesAndManifestIdentity(t *testing.T) {
|
||||
installation := preflightTestInstallation(t)
|
||||
tests := []struct {
|
||||
@@ -359,6 +402,9 @@ func TestPreflightRevalidationRefusesAnArchivePathThatWasReplaced(t *testing.T)
|
||||
|
||||
func TestPreflightStagesArchiveIntoImmutablePrivateBytes(t *testing.T) {
|
||||
installation := preflightTestInstallation(t)
|
||||
if err := os.MkdirAll(installation.ControlDirectory(), 0o700); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
archive := filepath.Join(t.TempDir(), "checked.zip")
|
||||
writePreflightArchive(t, archive, preflightArchiveSpec{
|
||||
entries: []preflightArchiveEntry{{path: "configuration/operator.env", body: []byte("before")}},
|
||||
|
||||
Reference in New Issue
Block a user