Compare commits
3
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c015956559 | ||
|
|
a3749e9e9b | ||
|
|
fa97c4519c |
@@ -23,8 +23,9 @@ javascript library is planned.
|
||||
|
||||
# Build Status
|
||||
|
||||
CI runs via `script/cibuild` (`docker build .`), which executes `make check`
|
||||
(formatting, linting, tests). The `main` branch must always be green.
|
||||
CI runs `script/cibuild`, which builds the Docker image with `--no-cache`, so
|
||||
the formatting, lint and test steps in the `Dockerfile` run on every build. The
|
||||
`main` branch must always be green.
|
||||
|
||||
# Entrypoints
|
||||
|
||||
@@ -56,8 +57,8 @@ provide:
|
||||
Docker lint stage, whose image has no node
|
||||
- `script/check` — run `script/test`, `script/lint`, and `script/fmt-check`
|
||||
- `script/docker` — build the Docker image tagged with the project name
|
||||
- `script/cibuild` — CI entrypoint: `docker build .` (the Dockerfile runs the
|
||||
checks)
|
||||
- `script/cibuild` — CI entrypoint: builds the image with the same command as
|
||||
`script/docker`, uncached, so the checks in the Dockerfile run every time
|
||||
- `script/precommit` — pre-commit checks: `go mod tidy` verification, then
|
||||
`script/check`
|
||||
- `script/install-precommit` — install the git pre-commit hook that runs
|
||||
|
||||
@@ -27,6 +27,12 @@ only thing left of the `chore/align-repo-policies` branch is the list below.
|
||||
- 2026-10-03: pinned the CLI error messages by driving the functions that emit
|
||||
them in `internal/cli/errmsg_test.go`, and made the freshen mtime-presence
|
||||
test distinguish an absent mtime from the epoch (#87)
|
||||
- 2026-10-03: `script/cibuild` builds the image with the same command as
|
||||
`script/docker`, `--no-cache` included, so the checks in the Dockerfile run on
|
||||
every build, also on an unchanged tree (#89)
|
||||
- 2026-10-03: `fetch` removes whatever sits at a file's temp name and then
|
||||
creates the temp file only if that name is free, so a hard link left there
|
||||
cannot make it write into a file outside the destination directory (#115)
|
||||
- 2026-10-03: `fetch` refuses any manifest path that runs through a symlink
|
||||
already in the destination directory, checked before each of its writes
|
||||
(directories, temp file, rename), so such a symlink cannot send a write
|
||||
|
||||
@@ -126,7 +126,7 @@ func TestHelpCommand(t *testing.T) {
|
||||
stdout := testStdout(t, opts)
|
||||
assert.Contains(t, stdout, cmdGenerate)
|
||||
assert.Contains(t, stdout, cmdCheck)
|
||||
assert.Contains(t, stdout, "fetch")
|
||||
assert.Contains(t, stdout, cmdFetch)
|
||||
}
|
||||
|
||||
func TestGenerateCommand(t *testing.T) {
|
||||
|
||||
+15
-2
@@ -36,6 +36,11 @@ const (
|
||||
// traversal bit for group and other must stay set.
|
||||
dirPerms os.FileMode = 0o755
|
||||
|
||||
// filePerms is the permission mode, before the umask, for downloaded
|
||||
// files. It is the mode os.Create uses; like dirPerms, it keeps group
|
||||
// and other read access.
|
||||
filePerms os.FileMode = 0o666
|
||||
|
||||
// Bitrate unit thresholds in bits per second.
|
||||
bpsPerGbps = 1e9
|
||||
bpsPerMbps = 1e6
|
||||
@@ -489,12 +494,20 @@ func downloadFile(
|
||||
return err
|
||||
}
|
||||
|
||||
// Create temp file.
|
||||
// Remove whatever is at tmpPath, such as a leftover from an
|
||||
// interrupted run, rather than write into it: it may be a hard link
|
||||
// to a file outside the target directory, and removing a hard link
|
||||
// removes only this name. If the removal fails, O_EXCL below makes
|
||||
// the create fail.
|
||||
_ = os.Remove(tmpPath)
|
||||
|
||||
// Create the temp file only if nothing is at tmpPath (O_EXCL).
|
||||
//
|
||||
// G304: tmpPath is a relative path that sanitizePath keeps inside the
|
||||
// target directory as text, and checkNoSymlinks just found no symlink
|
||||
// in it.
|
||||
out, err := os.Create(tmpPath) //nolint:gosec // G304: see comment above
|
||||
out, err := os.OpenFile( //nolint:gosec // G304: see comment above
|
||||
tmpPath, os.O_RDWR|os.O_CREATE|os.O_EXCL, filePerms)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to create temp file: %w", err)
|
||||
}
|
||||
|
||||
@@ -478,7 +478,7 @@ func TestFetchRefusesSymlinks(t *testing.T) {
|
||||
require.NoError(t, os.MkdirAll(filepath.Dir(tt.link), 0o750))
|
||||
require.NoError(t, os.Symlink(filepath.Join(outside, tt.target), tt.link))
|
||||
|
||||
opts := testOpts([]string{testApp, "fetch", "-q", server.URL}, afero.NewOsFs())
|
||||
opts := testOpts([]string{testApp, cmdFetch, "-q", server.URL}, afero.NewOsFs())
|
||||
assert.Equal(t, 1, runCLI(opts))
|
||||
assert.Contains(t, testStderr(t, opts), "failed to download "+tt.entry+
|
||||
": symlink in path not allowed: "+tt.link)
|
||||
@@ -489,3 +489,37 @@ func TestFetchRefusesSymlinks(t *testing.T) {
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
// TestFetchReplacesHardLinkAtTempName runs fetch into a destination
|
||||
// directory that holds, at the temp file's name, a hard link to a file
|
||||
// outside it. To fetch that is an ordinary leftover from an interrupted
|
||||
// earlier run: it must replace it and succeed, and the outside file must
|
||||
// not change.
|
||||
//
|
||||
//nolint:paralleltest // changes the process-global working directory
|
||||
func TestFetchReplacesHardLinkAtTempName(t *testing.T) {
|
||||
content := []byte("fetched")
|
||||
sourceFs := afero.NewMemMapFs()
|
||||
require.NoError(t, afero.WriteFile(sourceFs, "/"+testFileTxt, content, 0o644))
|
||||
|
||||
server := httptest.NewServer(fetchTestHandler(
|
||||
scanToManifest(t, sourceFs), map[string][]byte{testFileTxt: content}))
|
||||
defer server.Close()
|
||||
|
||||
outsideFile := filepath.Join(t.TempDir(), "secret.txt")
|
||||
require.NoError(t, os.WriteFile(outsideFile, []byte("outside"), 0o600))
|
||||
|
||||
chdirTemp(t)
|
||||
require.NoError(t, os.Link(outsideFile, ".file.txt.tmp"))
|
||||
|
||||
opts := testOpts([]string{testApp, cmdFetch, "-q", server.URL}, afero.NewOsFs())
|
||||
require.Equal(t, 0, runCLI(opts), testStderr(t, opts))
|
||||
|
||||
fetched, err := os.ReadFile(testFileTxt)
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, content, fetched)
|
||||
|
||||
outside, err := os.ReadFile(outsideFile) //nolint:gosec // test-controlled path
|
||||
require.NoError(t, err)
|
||||
assert.Equal(t, "outside", string(outside), "fetch wrote outside the destination")
|
||||
}
|
||||
|
||||
@@ -18,6 +18,7 @@ const (
|
||||
cmdGenerate = "generate"
|
||||
cmdCheck = "check"
|
||||
cmdExport = "export"
|
||||
cmdFetch = "fetch"
|
||||
|
||||
flagProgress = "progress"
|
||||
|
||||
@@ -300,7 +301,7 @@ func (mfa *CLIApp) listCommand() *cli.Command {
|
||||
|
||||
func (mfa *CLIApp) fetchCommand() *cli.Command {
|
||||
return &cli.Command{
|
||||
Name: "fetch",
|
||||
Name: cmdFetch,
|
||||
Usage: "fetch manifest and referenced files",
|
||||
Action: func(c *cli.Context) error {
|
||||
mfa.setVerbosity(c)
|
||||
|
||||
+15
-5
@@ -1,14 +1,24 @@
|
||||
#!/bin/sh
|
||||
# script/cibuild: run the CI build. The Dockerfile runs script/check
|
||||
# (via make check), so a successful build implies all checks pass.
|
||||
# Generic: needs no adaptation. The Gitea workflow runs this on push.
|
||||
# script/cibuild: run the CI build; the Gitea workflow runs this on push.
|
||||
# It builds the image with the same command as script/docker. --no-cache
|
||||
# because the checks the final stage depends on are RUN steps, and a
|
||||
# cached one is a check that did not run.
|
||||
set -eu
|
||||
|
||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||
ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
||||
|
||||
main() {
|
||||
cd "$ROOT"
|
||||
docker build .
|
||||
# Own line: a failing command substitution inside an argument does
|
||||
# not trip `set -e`, so the inline form degrades silently to an
|
||||
# empty constant. The VERSION build argument takes precedence over
|
||||
# the version a build stage derives from the .git in the context.
|
||||
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||
[ -n "$version" ] || version="unknown"
|
||||
docker build --no-cache \
|
||||
--build-arg VERSION="$version" \
|
||||
-t "$("$SCRIPT_DIR/projectname")" .
|
||||
}
|
||||
|
||||
main "$@"
|
||||
|
||||
Reference in New Issue
Block a user