Sanitized root snapshot from private source commit a72903c63e1753f9e6ffbf40453c0830bdfc05c5 and tree 295641e67eef5979da76746d8ae271249568263e. Private development history and workflows are excluded by the exact allowlist. AI-assisted: OpenAI Codex helped implement, test, and audit this preview. Signed-off-by: Cole Speelman <crspeelman@gmail.com>
42 lines
1.0 KiB
Go
42 lines
1.0 KiB
Go
// SPDX-License-Identifier: AGPL-3.0-only
|
|
|
|
package deploy
|
|
|
|
import (
|
|
"archive/tar"
|
|
"compress/gzip"
|
|
"os"
|
|
"path/filepath"
|
|
"testing"
|
|
)
|
|
|
|
func writeHostileArchive(t *testing.T, name string, typeflag byte) {
|
|
t.Helper()
|
|
path := filepath.Join(t.TempDir(), "bad.tar.gz")
|
|
file, err := os.Create(path)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
gz := gzip.NewWriter(file)
|
|
tw := tar.NewWriter(gz)
|
|
body := []byte("x")
|
|
if err := tw.WriteHeader(&tar.Header{Name: name, Typeflag: typeflag, Mode: 0o644, Size: int64(len(body))}); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if typeflag == tar.TypeReg {
|
|
_, _ = tw.Write(body)
|
|
}
|
|
_ = tw.Close()
|
|
_ = gz.Close()
|
|
_ = file.Close()
|
|
stage := filepath.Join(t.TempDir(), "stage")
|
|
_ = os.Mkdir(stage, 0o700)
|
|
if err := extractArtifact(path, stage); err == nil {
|
|
t.Fatalf("accepted hostile entry %q type %d", name, typeflag)
|
|
}
|
|
}
|
|
func TestExtractionRejectsTraversalAndLinks(t *testing.T) {
|
|
writeHostileArchive(t, "bundle/../../escape", tar.TypeReg)
|
|
writeHostileArchive(t, "bundle/link", tar.TypeSymlink)
|
|
}
|