fix(auth): close Task 15 review round two

This commit is contained in:
2026-08-18 07:21:24 +02:00
parent 225ffc8e20
commit fe190e7046
10 changed files with 305 additions and 64 deletions
@@ -57,6 +57,49 @@ func TestPreflightReturnsValidatedMetadataAndCallsAllTargetChecksWithoutExtracti
}
}
func TestPreflightStagesOnTheAccountedInstallationFilesystemInsteadOfTMPDIR(t *testing.T) {
installation := preflightTestInstallation(t)
if err := os.MkdirAll(installation.ControlDirectory(), 0o700); err != nil {
t.Fatal(err)
}
archive := filepath.Join(t.TempDir(), "valid.zip")
writePreflightArchive(t, archive, preflightArchiveSpec{
entries: []preflightArchiveEntry{{path: "configuration/operator.env", body: []byte("safe")}},
})
blockedTMPDIR := filepath.Join(t.TempDir(), "not-a-directory")
if err := os.WriteFile(blockedTMPDIR, []byte("blocked"), 0o600); err != nil {
t.Fatal(err)
}
t.Setenv("TMPDIR", blockedTMPDIR)
var capacityTargets []string
dependencies := permissivePreflightDependencies()
dependencies.FreeBytes = func(target string) (uint64, error) {
capacityTargets = append(capacityTargets, target)
return 1 << 30, nil
}
result, err := Preflight(context.Background(), installation, PreflightRequest{Archive: archive, Confirm: true}, dependencies)
if err != nil {
t.Fatal(err)
}
defer result.CloseArchive()
staged, err := result.StageArchive(context.Background())
if err != nil {
t.Fatal(err)
}
defer staged.Close()
if len(capacityTargets) == 0 || capacityTargets[0] != installation.ControlDirectory() {
t.Fatalf("free-space targets = %q, want installation control directory %q", capacityTargets, installation.ControlDirectory())
}
stagingRoot := filepath.Join(installation.ControlDirectory(), "restore-staging")
if relative, err := filepath.Rel(stagingRoot, staged.directory); err != nil || relative == "." || strings.HasPrefix(relative, "..") {
t.Fatalf("staging directory = %q, want a child of %q", staged.directory, stagingRoot)
}
}
func TestPreflightRejectsAdversarialArchiveEntriesAndManifestIdentity(t *testing.T) {
installation := preflightTestInstallation(t)
tests := []struct {
@@ -359,6 +402,9 @@ func TestPreflightRevalidationRefusesAnArchivePathThatWasReplaced(t *testing.T)
func TestPreflightStagesArchiveIntoImmutablePrivateBytes(t *testing.T) {
installation := preflightTestInstallation(t)
if err := os.MkdirAll(installation.ControlDirectory(), 0o700); err != nil {
t.Fatal(err)
}
archive := filepath.Join(t.TempDir(), "checked.zip")
writePreflightArchive(t, archive, preflightArchiveSpec{
entries: []preflightArchiveEntry{{path: "configuration/operator.env", body: []byte("before")}},