e2e/tagprotect_test.go
77 lines · 3433 bytes
1package e2e
2
3import (
4 "os"
5 "path/filepath"
6 "strings"
7 "testing"
8)
9
10// Protected-tag globs refuse moving and deleting matching tags; a tag a
11// release is anchored to refuses both on its own (#201).
12func TestTagProtection(t *testing.T) {
13 inst := startInstance(t)
14 aliceKey := inst.newKey(t, "alice")
15 inst.admin(t, "admin", "user", "create", "alice", "--key", aliceKey+".pub")
16 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "create", "alice/app"); code != 0 {
17 t.Fatalf("repo create: %s", errOut)
18 }
19 work := t.TempDir()
20 env := inst.gitEnv(aliceKey)
21 mustGit(t, work, env, "clone", "-q", inst.sshURL("alice/app"), "w")
22 dir := filepath.Join(work, "w")
23 if err := os.WriteFile(filepath.Join(dir, "a.txt"), []byte("a\n"), 0o644); err != nil {
24 t.Fatal(err)
25 }
26 mustGit(t, dir, env, "checkout", "-q", "-b", "main")
27 mustGit(t, dir, env, "add", ".")
28 mustGit(t, dir, env, "commit", "-q", "-m", "base")
29 mustGit(t, dir, env, "tag", "v1.0")
30 mustGit(t, dir, env, "tag", "nightly")
31 mustGit(t, dir, env, "push", "-q", "origin", "main", "v1.0", "nightly")
32
33 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "protect-tag", "alice/app", "'['"); code != 2 {
34 t.Fatalf("bad glob accepted: %d %s", code, errOut)
35 }
36 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "protect-tag", "alice/app", "'v*'"); code != 0 {
37 t.Fatalf("protect-tag: %s", errOut)
38 }
39 out, _, _ := inst.ssh(t, aliceKey, "", "repo", "settings", "show", "alice/app", "--json")
40 if !strings.Contains(out, `"protected_tags":["v*"]`) {
41 t.Fatalf("settings show: %s", out)
42 }
43
44 // Delete and move are refused for a matching tag; an unmatched tag is
45 // free, and a new matching tag can still be created.
46 if out, code := gitRun(t, dir, env, "push", "origin", ":v1.0"); code == 0 || !strings.Contains(out, "protected") {
47 t.Fatalf("protected tag deleted: %d\n%s", code, out)
48 }
49 mustGit(t, dir, env, "commit", "-q", "--allow-empty", "-m", "second")
50 mustGit(t, dir, env, "tag", "-f", "v1.0")
51 if out, code := gitRun(t, dir, env, "push", "--force", "origin", "v1.0"); code == 0 || !strings.Contains(out, "protected") {
52 t.Fatalf("protected tag moved: %d\n%s", code, out)
53 }
54 mustGit(t, dir, env, "push", "-q", "origin", ":nightly")
55 mustGit(t, dir, env, "tag", "v1.1")
56 mustGit(t, dir, env, "push", "-q", "origin", "v1.1")
57
58 // Unprotected again, the tag can go — unless a release anchors it.
59 if _, errOut, code := inst.ssh(t, aliceKey, "", "repo", "settings", "unprotect-tag", "alice/app", "'v*'"); code != 0 {
60 t.Fatalf("unprotect-tag: %s", errOut)
61 }
62 if _, errOut, code := inst.ssh(t, aliceKey, "", "release", "create", "alice/app", "v1.1", "--title", "'one one'"); code != 0 {
63 t.Fatalf("release create: %s", errOut)
64 }
65 if out, code := gitRun(t, dir, env, "push", "origin", ":v1.1"); code == 0 || !strings.Contains(out, "anchors a release") {
66 t.Fatalf("release tag deleted: %d\n%s", code, out)
67 }
68 mustGit(t, dir, env, "commit", "-q", "--allow-empty", "-m", "third")
69 mustGit(t, dir, env, "tag", "-f", "v1.1")
70 if out, code := gitRun(t, dir, env, "push", "--force", "origin", "v1.1"); code == 0 || !strings.Contains(out, "anchors a release") {
71 t.Fatalf("release tag moved: %d\n%s", code, out)
72 }
73 if _, errOut, code := inst.ssh(t, aliceKey, "", "release", "delete", "alice/app", "v1.1", "--yes"); code != 0 {
74 t.Fatalf("release delete: %s", errOut)
75 }
76 mustGit(t, dir, env, "push", "-q", "origin", ":v1.1")
77}