mirror of
https://github.com/openai/codex.git
synced 2026-09-05 15:18:41 +00:00
test(git-utils): use native lexical authority decoy
This commit is contained in:
@@ -750,8 +750,6 @@ async fn checked_has_changes_accepts_non_utf8_repository_root() {
|
||||
#[tokio::test]
|
||||
async fn checked_has_changes_preserves_lexical_repository_ancestry_for_git_selection() {
|
||||
if std::env::var_os("CODEX_GIT_UTILS_SAFE_GIT_ENV_CHILD").is_none() {
|
||||
use std::os::unix::fs::PermissionsExt;
|
||||
|
||||
let fixture = tempfile::tempdir().expect("fixture");
|
||||
let outer = fixture.path().join("outer");
|
||||
let physical_nested = fixture.path().join("physical-nested");
|
||||
@@ -764,58 +762,49 @@ async fn checked_has_changes_preserves_lexical_repository_ancestry_for_git_selec
|
||||
std::os::unix::fs::symlink(&physical_nested, &lexical_nested)
|
||||
.expect("symlink nested repository");
|
||||
|
||||
let output = std::process::Command::new("/bin/sh")
|
||||
.args(["-c", "command -v git"])
|
||||
.output()
|
||||
.expect("resolve Git executable");
|
||||
assert!(output.status.success(), "resolve Git executable");
|
||||
let real_git = PathBuf::from(
|
||||
String::from_utf8(output.stdout)
|
||||
.expect("Git path UTF-8")
|
||||
.trim(),
|
||||
);
|
||||
let marker = fixture.path().join("outer-git-ran");
|
||||
let native_false = std::env::split_paths(&std::env::var_os("PATH").expect("PATH"))
|
||||
.find_map(|directory| {
|
||||
let candidate = std::fs::canonicalize(directory.join("false")).ok()?;
|
||||
crate::git_executable::is_native_executable_file(&candidate).then_some(candidate)
|
||||
})
|
||||
.expect("native false executable");
|
||||
let outer_git = outer_bin.join("git");
|
||||
std::fs::write(
|
||||
&outer_git,
|
||||
"#!/bin/sh\nprintf ran > \"$CODEX_GIT_UTILS_LEXICAL_GIT_MARKER\"\nexec \"$CODEX_GIT_UTILS_REAL_GIT\" \"$@\"\n",
|
||||
)
|
||||
.expect("write outer Git wrapper");
|
||||
let mut permissions = std::fs::metadata(&outer_git)
|
||||
.expect("outer Git metadata")
|
||||
.permissions();
|
||||
permissions.set_mode(0o755);
|
||||
std::fs::set_permissions(&outer_git, permissions).expect("make outer Git executable");
|
||||
std::fs::copy(native_false, &outer_git).expect("copy native false as outer Git");
|
||||
assert!(
|
||||
crate::git_executable::is_native_executable_file(&outer_git),
|
||||
"decoy Git must pass production native-executable selection"
|
||||
);
|
||||
|
||||
let search_path = std::env::join_paths([
|
||||
outer_bin.as_path(),
|
||||
real_git.parent().expect("Git executable directory"),
|
||||
])
|
||||
.expect("construct controlled PATH");
|
||||
let search_path =
|
||||
std::env::join_paths([outer_bin.as_path()]).expect("construct single-candidate PATH");
|
||||
run_isolated_test(
|
||||
"safe_git::tests::checked_has_changes_preserves_lexical_repository_ancestry_for_git_selection",
|
||||
&[
|
||||
("CODEX_GIT_UTILS_TARGET_REPO", lexical_nested.as_os_str()),
|
||||
("CODEX_GIT_UTILS_LEXICAL_GIT_MARKER", marker.as_os_str()),
|
||||
("CODEX_GIT_UTILS_REAL_GIT", real_git.as_os_str()),
|
||||
("CODEX_GIT_UTILS_PHYSICAL_REPO", physical_nested.as_os_str()),
|
||||
("PATH", search_path.as_os_str()),
|
||||
],
|
||||
);
|
||||
assert!(
|
||||
!marker.exists(),
|
||||
"Git from the lexical enclosing repository must not run"
|
||||
);
|
||||
return;
|
||||
}
|
||||
|
||||
let physical_nested = PathBuf::from(
|
||||
std::env::var_os("CODEX_GIT_UTILS_PHYSICAL_REPO").expect("physical repository"),
|
||||
);
|
||||
assert_eq!(
|
||||
try_get_has_changes(&physical_nested).await,
|
||||
Err(GitReadError::CommandFailed {
|
||||
operation: "statusFilterPreparation".to_string(),
|
||||
exit_code: None,
|
||||
}),
|
||||
"the canonical spelling must select and fail on the first eligible native decoy"
|
||||
);
|
||||
let lexical_nested =
|
||||
PathBuf::from(std::env::var_os("CODEX_GIT_UTILS_TARGET_REPO").expect("target repository"));
|
||||
assert_eq!(try_get_has_changes(&lexical_nested).await, Ok(false));
|
||||
let marker =
|
||||
PathBuf::from(std::env::var_os("CODEX_GIT_UTILS_LEXICAL_GIT_MARKER").expect("Git marker"));
|
||||
assert!(
|
||||
!marker.exists(),
|
||||
"Git from the lexical enclosing repository must not run"
|
||||
assert_eq!(
|
||||
try_get_has_changes(&lexical_nested).await,
|
||||
Err(GitReadError::NoTrustedGit),
|
||||
"the lexical spelling must exclude the enclosing repository's native Git decoy"
|
||||
);
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user