| 1 | package sandbox |
| 2 | |
| 3 | import ( |
| 4 | "path/filepath" |
| 5 | "slices" |
| 6 | "testing" |
| 7 | ) |
| 8 | |
| 9 | func TestBwrapBindsOnlyOutermostExistingResolvedRoots(t *testing.T) { |
| 10 | base := t.TempDir() |
| 11 | ws := planDir(t, filepath.Join(base, "ws")) |
| 12 | outside := planDir(t, filepath.Join(base, "outside")) |
| 13 | planDir(t, filepath.Join(ws, "sub")) |
| 14 | link := filepath.Join(base, "wslink") |
| 15 | planLink(t, ws, link) |
| 16 | later := filepath.Join(ws, "later") |
| 17 | planLink(t, outside, later) |
| 18 | spec := Spec{Mode: "enforce", MinimalWrites: true, |
| 19 | WriteRoots: []string{link, filepath.Join(ws, "sub"), filepath.Join(ws, "missing"), later}} |
| 20 | if got := bwrapWriteBinds(linuxWritePlan(spec)); !slices.Equal(got, []string{ws}) { |
| 21 | t.Fatalf("binds = %v, want only the resolved workspace", got) |
| 22 | } |
| 23 | args := bwrapBaseArgs(spec) |
| 24 | for i := range args { |
| 25 | if args[i] == "--bind" && (args[i+1] == link || args[i+1] == later || args[i+1] == outside) { |
| 26 | t.Fatalf("bwrap binds an unresolved or redirected root: %v", args) |
| 27 | } |
| 28 | } |
| 29 | } |
| 30 |