| 1 | //go:build windows |
| 2 | |
| 3 | package config |
| 4 | |
| 5 | import ( |
| 6 | "os" |
| 7 | "os/exec" |
| 8 | "path/filepath" |
| 9 | "testing" |
| 10 | ) |
| 11 | |
| 12 | // Run on Windows; Unix string simulations do not exercise junction identity. |
| 13 | func TestProjectWindowsJunctionAndUNC(t *testing.T) { |
| 14 | root, external := t.TempDir(), t.TempDir() |
| 15 | c := Default() |
| 16 | if !c.equivalentConfigPath(root, root, filepath.ToSlash(root)) { |
| 17 | t.Fatal("slash variants differ") |
| 18 | } |
| 19 | junction := filepath.Join(root, "external-junction") |
| 20 | if output, err := exec.Command("cmd", "/c", "mklink", "/J", junction, external).CombinedOutput(); err != nil { |
| 21 | t.Fatalf("create junction: %v: %s", err, output) |
| 22 | } |
| 23 | t.Cleanup(func() { _ = os.Remove(junction) }) |
| 24 | if c.authorizedPath(root, []string{root}, filepath.Join(junction, "new")) { |
| 25 | t.Fatal("junction escaped project grant") |
| 26 | } |
| 27 | if !c.authorizedPath(root, []string{external}, filepath.Join(junction, "new")) { |
| 28 | t.Fatal("external grant did not cover junction target") |
| 29 | } |
| 30 | t.Run("UNC", func(t *testing.T) { |
| 31 | unc := os.Getenv("REASONIX_TEST_UNC_ROOT") |
| 32 | if unc == "" { |
| 33 | t.Skip("set REASONIX_TEST_UNC_ROOT to a writable Windows share for native UNC evidence") |
| 34 | } |
| 35 | share, err := os.MkdirTemp(unc, "reasonix-diagnostics-") |
| 36 | if err != nil { |
| 37 | t.Fatal(err) |
| 38 | } |
| 39 | t.Cleanup(func() { _ = os.RemoveAll(share) }) |
| 40 | if !c.equivalentConfigPath(root, share, filepath.ToSlash(share)) { |
| 41 | t.Fatal("UNC separator variants differ") |
| 42 | } |
| 43 | if !c.authorizedPath(root, []string{share}, filepath.Join(share, "new")) { |
| 44 | t.Fatal("UNC descendant rejected") |
| 45 | } |
| 46 | if c.authorizedPath(root, []string{share}, share+"-other") { |
| 47 | t.Fatal("UNC sibling granted") |
| 48 | } |
| 49 | }) |
| 50 | } |
| 51 |