返回 DeepSeek-Reasonix
lsremote_env_test.go
根目录 / internal / plugin / lsremote_env_test.go
1 package plugin
2
3 import (
4 "context"
5 "os"
6 "os/exec"
7 "path/filepath"
8 "runtime"
9 "testing"
10 "time"
11 )
12
13 // A launcher's declared environment must not reach the pre-approval ls-remote:
14 // GIT_* variables there can name a program even under an https or ssh URL.
15 func TestLocatorSpecEnvDoesNotReachLsRemote(t *testing.T) {
16 if runtime.GOOS == "windows" {
17 t.Skip("POSIX payload")
18 }
19 if _, err := exec.LookPath("git"); err != nil {
20 t.Skip("git not installed")
21 }
22 for _, tc := range []struct {
23 name, locator string
24 env map[string]string
25 }{
26 {"GIT_SSH_COMMAND", "git+ssh://example.invalid/x.git@main", map[string]string{"GIT_SSH_COMMAND": "%P"}},
27 {"GIT_CONFIG_COUNT insteadOf ext", "git+https://example.invalid/x.git@main", map[string]string{
28 "GIT_CONFIG_COUNT": "2", "GIT_CONFIG_KEY_0": "url.ext::%P .insteadOf", "GIT_CONFIG_VALUE_0": "https://",
29 "GIT_CONFIG_KEY_1": "protocol.ext.allow", "GIT_CONFIG_VALUE_1": "always"}},
30 } {
31 t.Run(tc.name, func(t *testing.T) {
32 dir := t.TempDir()
33 marker := filepath.Join(dir, "executed")
34 payload := filepath.Join(dir, "p.sh")
35 if err := os.WriteFile(payload, []byte("#!/bin/sh\necho ran >> '"+marker+"'\nexit 1\n"), 0o755); err != nil {
36 t.Fatal(err)
37 }
38 env := map[string]string{}
39 for k, v := range tc.env {
40 if v == "%P" {
41 v = payload
42 }
43 if k == "GIT_CONFIG_KEY_0" {
44 v = "url.ext::" + payload + " .insteadOf"
45 }
46 env[k] = v
47 }
48 ctx, cancel := context.WithTimeout(context.Background(), 30*time.Second)
49 defer cancel()
50 _, _, err := resolveGitLocator(ctx, Spec{Name: "probe", Env: env}, tc.locator)
51 t.Logf("err: %v", err)
52 if _, statErr := os.Stat(marker); statErr == nil {
53 t.Fatal("ls-remote ran a program named by the spec env")
54 }
55 })
56 }
57 }
58
58 lines GO