//go:build !windows package safeio import ( "errors" "os" "path/filepath" "testing" "golang.org/x/sys/unix" ) func TestReadCanonicalRegularRejectsNamedPipeWithoutBlocking(t *testing.T) { temporaryRoot, err := filepath.EvalSymlinks(os.TempDir()) if err != nil { t.Fatal(err) } root, err := os.MkdirTemp(temporaryRoot, "thothctl-safeio-") if err != nil { t.Fatal(err) } t.Cleanup(func() { _ = os.RemoveAll(root) }) pipe := filepath.Join(root, "secret-pipe") if err := unix.Mkfifo(pipe, 0o600); err != nil { t.Fatal(err) } if _, err := ReadCanonicalRegular(pipe, 1024); !errors.Is(err, ErrUnsafeFile) { t.Fatalf("named pipe error = %v, want ErrUnsafeFile", err) } }