| 1 | package sandbox |
| 2 | |
| 3 | import ( |
| 4 | "path/filepath" |
| 5 | "strings" |
| 6 | "testing" |
| 7 | ) |
| 8 | |
| 9 | // $TMPDIR sits in /private/var/folders, which every jailed command may write, |
| 10 | // so a command can replace it with a link; the next profile must not follow it. |
| 11 | func TestSeatbeltDoesNotFollowATempDirReplacedByALink(t *testing.T) { |
| 12 | base := planDir(t, filepath.Join(t.TempDir(), "fake")) |
| 13 | if !strings.HasPrefix(base, "/private/var/folders/") { |
| 14 | t.Skip("temp tree is not under /private/var/folders") |
| 15 | } |
| 16 | ws := t.TempDir() |
| 17 | tmp := filepath.Join(base, "T") |
| 18 | planLink(t, "/usr", tmp) |
| 19 | t.Setenv("TMPDIR", tmp+"/") |
| 20 | if profile := seatbeltProfile(Spec{Mode: "enforce", WriteRoots: []string{ws}}); strings.Contains(profile, `(subpath "/usr")`) { |
| 21 | t.Fatalf("profile follows the replaced temp dir:\n%s", profile) |
| 22 | } |
| 23 | } |
| 24 |