Compare commits
1
Commits
next
..
30f6471666
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
30f6471666 |
@@ -27,12 +27,6 @@ regress.
|
|||||||
and `.dockerignore` are always sent. An ignore file that cannot be read, or
|
and `.dockerignore` are always sent. An ignore file that cannot be read, or
|
||||||
holds a pattern Docker rejects, fails the build (#274).
|
holds a pattern Docker rejects, fails the build (#274).
|
||||||
|
|
||||||
- 2026-10-03: `make test`, and so `docker build .`, fits a machine with 4 GiB of
|
|
||||||
memory: tests hash passwords with 1 MiB instead of upaasd's 64 MiB, so
|
|
||||||
`GOMAXPROCS=4 make test` peaks at about 1.4 GiB instead of 2.7 GiB. upaasd
|
|
||||||
still hashes with 64 MiB, and one test hashes and verifies a password at that
|
|
||||||
cost (#261).
|
|
||||||
|
|
||||||
- 2026-10-02: In a window too narrow for the top bar, such as 390 px, the New
|
- 2026-10-02: In a window too narrow for the top bar, such as 390 px, the New
|
||||||
App and Logout buttons move to a second row instead of running into "by
|
App and Logout buttons move to a second row instead of running into "by
|
||||||
@sneak"; the bar keeps a gap between its two sides at every width (#272).
|
@sneak"; the bar keeps a gap between its two sides at every width (#272).
|
||||||
|
|||||||
@@ -7,7 +7,6 @@ import (
|
|||||||
"io/fs"
|
"io/fs"
|
||||||
"os"
|
"os"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"strings"
|
|
||||||
|
|
||||||
"github.com/docker/docker/pkg/archive"
|
"github.com/docker/docker/pkg/archive"
|
||||||
"github.com/moby/patternmatcher"
|
"github.com/moby/patternmatcher"
|
||||||
@@ -42,11 +41,6 @@ func tarBuildContext(contextDir, dockerfile string) (io.ReadCloser, error) {
|
|||||||
// Dockerfile if there is one, otherwise from .dockerignore at the root of the
|
// Dockerfile if there is one, otherwise from .dockerignore at the root of the
|
||||||
// context. Without either file there are no patterns.
|
// context. Without either file there are no patterns.
|
||||||
func readDockerignore(contextDir, dockerfile string) ([]string, error) {
|
func readDockerignore(contextDir, dockerfile string) ([]string, error) {
|
||||||
// Docker reads the Dockerfile path as a path inside the build context:
|
|
||||||
// cleaned, with a leading / and any .. that would lead out of the context
|
|
||||||
// dropped, so ./Dockerfile and /Dockerfile both name the Dockerfile at the
|
|
||||||
// root.
|
|
||||||
dockerfile = strings.TrimPrefix(filepath.Join("/", dockerfile), "/")
|
|
||||||
if dockerfile == "" {
|
if dockerfile == "" {
|
||||||
dockerfile = defaultDockerfileName
|
dockerfile = defaultDockerfileName
|
||||||
}
|
}
|
||||||
@@ -60,20 +54,6 @@ func readDockerignore(contextDir, dockerfile string) ([]string, error) {
|
|||||||
|
|
||||||
defer func() { _ = root.Close() }()
|
defer func() { _ = root.Close() }()
|
||||||
|
|
||||||
// When a Dockerfile named Dockerfile is missing, Docker builds a
|
|
||||||
// lowercase dockerfile in the same directory instead, and docker build
|
|
||||||
// then reads dockerfile.dockerignore as its ignore file.
|
|
||||||
if filepath.Base(dockerfile) == defaultDockerfileName {
|
|
||||||
lowercase := filepath.Join(filepath.Dir(dockerfile), "dockerfile")
|
|
||||||
|
|
||||||
_, dockerfileErr := root.Lstat(dockerfile)
|
|
||||||
_, lowercaseErr := root.Lstat(lowercase)
|
|
||||||
|
|
||||||
if errors.Is(dockerfileErr, fs.ErrNotExist) && lowercaseErr == nil {
|
|
||||||
dockerfile = lowercase
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
name := dockerfile + defaultDockerignoreName
|
name := dockerfile + defaultDockerignoreName
|
||||||
|
|
||||||
file, err := root.Open(name)
|
file, err := root.Open(name)
|
||||||
|
|||||||
@@ -22,7 +22,6 @@ const (
|
|||||||
testMainGo = "main.go"
|
testMainGo = "main.go"
|
||||||
testSecretFile = "secret.txt"
|
testSecretFile = "secret.txt"
|
||||||
testDeployDockerfile = "deploy/Dockerfile"
|
testDeployDockerfile = "deploy/Dockerfile"
|
||||||
testLowercaseDockerfile = "dockerfile"
|
|
||||||
)
|
)
|
||||||
|
|
||||||
// TestPerformBuildFollowsDockerignore runs builds against a fake Docker API
|
// TestPerformBuildFollowsDockerignore runs builds against a fake Docker API
|
||||||
@@ -106,94 +105,6 @@ func TestPerformBuildFollowsDockerignore(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestPerformBuildKeepsLowercaseDockerfile checks that when the Dockerfile
|
|
||||||
// named Dockerfile is missing, the lowercase dockerfile Docker builds instead
|
|
||||||
// stays in the build context, and its own ignore file is read.
|
|
||||||
func TestPerformBuildKeepsLowercaseDockerfile(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
tests := []struct {
|
|
||||||
name string
|
|
||||||
files map[string]string // path in the context: contents
|
|
||||||
want []string // files sent in the build context
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "kept when the ignore file names it",
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "*\n",
|
|
||||||
testLowercaseDockerfile: "",
|
|
||||||
},
|
|
||||||
want: []string{defaultDockerignoreName, testLowercaseDockerfile},
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "its own ignore file wins over .dockerignore",
|
|
||||||
files: map[string]string{
|
|
||||||
defaultDockerignoreName: "main.go\n",
|
|
||||||
testLowercaseDockerfile: "",
|
|
||||||
"dockerfile.dockerignore": "secret.txt\n",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
},
|
|
||||||
want: []string{
|
|
||||||
defaultDockerignoreName,
|
|
||||||
testLowercaseDockerfile,
|
|
||||||
"dockerfile.dockerignore",
|
|
||||||
testMainGo,
|
|
||||||
},
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range tests {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
writeFiles(t, contextDir, tt.files)
|
|
||||||
|
|
||||||
got, err := buildContextFiles(t, contextDir, defaultDockerfileName)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
if !slices.Equal(got, tt.want) {
|
|
||||||
t.Errorf("build context holds %q, want %q", got, tt.want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPerformBuildReadsDockerfilePathInsideContext checks that ./Dockerfile
|
|
||||||
// and /Dockerfile name the Dockerfile at the root of the context, as Docker
|
|
||||||
// reads them, so an ignore file that names the Dockerfile does not leave it
|
|
||||||
// out.
|
|
||||||
func TestPerformBuildReadsDockerfilePathInsideContext(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
for _, dockerfile := range []string{"./Dockerfile", "/Dockerfile"} {
|
|
||||||
t.Run(dockerfile, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
contextDir := t.TempDir()
|
|
||||||
writeFiles(t, contextDir, map[string]string{
|
|
||||||
defaultDockerignoreName: "Dockerfile\nsecret.txt\n",
|
|
||||||
defaultDockerfileName: "",
|
|
||||||
testMainGo: "",
|
|
||||||
testSecretFile: "",
|
|
||||||
})
|
|
||||||
|
|
||||||
got, err := buildContextFiles(t, contextDir, dockerfile)
|
|
||||||
if err != nil {
|
|
||||||
t.Fatal(err)
|
|
||||||
}
|
|
||||||
|
|
||||||
want := []string{defaultDockerignoreName, defaultDockerfileName, testMainGo}
|
|
||||||
if !slices.Equal(got, want) {
|
|
||||||
t.Errorf("build context holds %q, want %q", got, want)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestPerformBuildFailsOnMalformedDockerignore checks that a pattern the
|
// TestPerformBuildFailsOnMalformedDockerignore checks that a pattern the
|
||||||
// docker command line would reject fails the build.
|
// docker command line would reject fails the build.
|
||||||
func TestPerformBuildFailsOnMalformedDockerignore(t *testing.T) {
|
func TestPerformBuildFailsOnMalformedDockerignore(t *testing.T) {
|
||||||
|
|||||||
@@ -109,9 +109,6 @@ func createAppServices(
|
|||||||
})
|
})
|
||||||
require.NoError(t, authErr)
|
require.NoError(t, authErr)
|
||||||
|
|
||||||
// 1 MiB per password hash instead of 64 MiB; see auth.Service.ArgonMemory.
|
|
||||||
authSvc.ArgonMemory = 1024
|
|
||||||
|
|
||||||
appSvc, appErr := app.New(fx.Lifecycle(nil), app.ServiceParams{
|
appSvc, appErr := app.New(fx.Lifecycle(nil), app.ServiceParams{
|
||||||
Logger: logInstance,
|
Logger: logInstance,
|
||||||
Database: dbInstance,
|
Database: dbInstance,
|
||||||
|
|||||||
@@ -59,13 +59,6 @@ type ServiceParams struct {
|
|||||||
|
|
||||||
// Service provides authentication functionality.
|
// Service provides authentication functionality.
|
||||||
type Service struct {
|
type Service struct {
|
||||||
// ArgonMemory is the memory each argon2id hash takes, in KiB. New sets
|
|
||||||
// argonMemory, 64 MiB, and upaasd never changes it. Tests lower it, since
|
|
||||||
// many 64 MiB hashes at once under the race detector need more memory
|
|
||||||
// than a 4 GiB build machine has. A hash verifies only with the value it
|
|
||||||
// was made with.
|
|
||||||
ArgonMemory uint32
|
|
||||||
|
|
||||||
log *slog.Logger
|
log *slog.Logger
|
||||||
db *database.Database
|
db *database.Database
|
||||||
store *sessions.CookieStore
|
store *sessions.CookieStore
|
||||||
@@ -84,7 +77,6 @@ func New(_ fx.Lifecycle, params ServiceParams) (*Service, error) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
return &Service{
|
return &Service{
|
||||||
ArgonMemory: argonMemory,
|
|
||||||
log: params.Logger.Get(),
|
log: params.Logger.Get(),
|
||||||
db: params.Database,
|
db: params.Database,
|
||||||
store: store,
|
store: store,
|
||||||
@@ -105,7 +97,7 @@ func (svc *Service) HashPassword(password string) (string, error) {
|
|||||||
[]byte(password),
|
[]byte(password),
|
||||||
salt,
|
salt,
|
||||||
argonTime,
|
argonTime,
|
||||||
svc.ArgonMemory,
|
argonMemory,
|
||||||
argonThreads,
|
argonThreads,
|
||||||
argonKeyLen,
|
argonKeyLen,
|
||||||
)
|
)
|
||||||
@@ -140,7 +132,7 @@ func (svc *Service) VerifyPassword(hashedPassword, password string) bool {
|
|||||||
[]byte(password),
|
[]byte(password),
|
||||||
salt,
|
salt,
|
||||||
argonTime,
|
argonTime,
|
||||||
svc.ArgonMemory,
|
argonMemory,
|
||||||
argonThreads,
|
argonThreads,
|
||||||
argonKeyLen,
|
argonKeyLen,
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -65,10 +65,6 @@ func setupTestService(t *testing.T) (*auth.Service, func()) {
|
|||||||
})
|
})
|
||||||
require.NoError(t, err)
|
require.NoError(t, err)
|
||||||
|
|
||||||
// 1 MiB per hash instead of 64 MiB; see Service.ArgonMemory. The tests
|
|
||||||
// that use setupAuthService keep 64 MiB.
|
|
||||||
svc.ArgonMemory = 1024
|
|
||||||
|
|
||||||
// t.TempDir() automatically cleans up after test
|
// t.TempDir() automatically cleans up after test
|
||||||
cleanup := func() {}
|
cleanup := func() {}
|
||||||
|
|
||||||
@@ -241,21 +237,6 @@ func TestVerifyPassword(testingT *testing.T) {
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
// TestHashPasswordWithUpaasdMemory hashes and verifies a password with the
|
|
||||||
// memory New sets, which upaasd uses. setupTestService lowers it.
|
|
||||||
func TestHashPasswordWithUpaasdMemory(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
svc := setupAuthService(t, false)
|
|
||||||
require.Equal(t, uint32(64*1024), svc.ArgonMemory)
|
|
||||||
|
|
||||||
hash, err := svc.HashPassword("correctpassword")
|
|
||||||
require.NoError(t, err)
|
|
||||||
|
|
||||||
assert.True(t, svc.VerifyPassword(hash, "correctpassword"))
|
|
||||||
assert.False(t, svc.VerifyPassword(hash, "wrongpassword"))
|
|
||||||
}
|
|
||||||
|
|
||||||
func TestIsSetupRequired(testingT *testing.T) {
|
func TestIsSetupRequired(testingT *testing.T) {
|
||||||
testingT.Parallel()
|
testingT.Parallel()
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user