cmd/gitbay-runner/home_test.go

8e6fc2062ca26f7a848bdf6ad6345fd345351231
gitbay/cmd/gitbay-runner/home_test.go history · blame · raw

53 lines · 1497 bytes

 1package main
 2
 3import (
 4	"os"
 5	"path/filepath"
 6	"testing"
 7)
 8
 9// The build home is per repository: one shared home let a step poison
10// the module cache or plant a .gitconfig that another repository's build
11// would honour (#184).
12func TestBuildHomeIsPerRepository(t *testing.T) {
13	work := t.TempDir()
14	a, err := buildHomeFor(work, "alice/app")
15	if err != nil {
16		t.Fatal(err)
17	}
18	b, err := buildHomeFor(work, "bob/app")
19	if err != nil {
20		t.Fatal(err)
21	}
22	if a == b {
23		t.Fatalf("two repositories share a build home: %s", a)
24	}
25	for _, dir := range []string{a, b} {
26		rel, err := filepath.Rel(filepath.Join(work, "home"), dir)
27		if err != nil || rel == "." || filepath.IsAbs(rel) || rel[0] == '.' {
28			t.Fatalf("build home %s is not under %s/home", dir, work)
29		}
30		st, err := os.Stat(dir)
31		if err != nil {
32			t.Fatalf("build home not created: %v", err)
33		}
34		if st.Mode().Perm() != 0o700 {
35			t.Fatalf("build home mode %o, want 0700", st.Mode().Perm())
36		}
37	}
38	// The same repository gets the same home back: that is what makes it
39	// a cache.
40	again, _ := buildHomeFor(work, "alice/app")
41	if again != a {
42		t.Fatalf("build home moved between builds: %s then %s", a, again)
43	}
44}
45
46// A repository path is server-validated, but the home must still never
47// resolve outside the runner's home root.
48func TestBuildHomeRefusesTraversal(t *testing.T) {
49	work := t.TempDir()
50	if _, err := buildHomeFor(work, "../../etc"); err == nil {
51		t.Fatal("a traversing repository path produced a build home")
52	}
53}