Fix: Make contract execution safe and diagnostic
This commit is contained in:
Executable
+192
@@ -0,0 +1,192 @@
|
||||
#!/usr/bin/env bash
|
||||
|
||||
# The public seam is the installed `panama` command. This fixture repository
|
||||
# proves the runner's manifest policy and diagnostics without touching the host.
|
||||
|
||||
set -uo pipefail
|
||||
|
||||
repo_dir="$(cd "$(dirname "${BASH_SOURCE[0]}")/../.." && pwd)"
|
||||
fixture="$(mktemp -d)"
|
||||
output=""
|
||||
status=0
|
||||
|
||||
cleanup() { rm -rf -- "$fixture"; }
|
||||
trap cleanup EXIT INT TERM
|
||||
|
||||
fail() { printf 'test runner: %s\n' "$*" >&2; exit 1; }
|
||||
|
||||
assert_contains() {
|
||||
local needle="$1" haystack="$2"
|
||||
[[ "$haystack" == *"$needle"* ]] || fail "expected output to contain: $needle\n$haystack"
|
||||
}
|
||||
|
||||
assert_not_contains() {
|
||||
local needle="$1" haystack="$2"
|
||||
[[ "$haystack" != *"$needle"* ]] || fail "expected output not to contain: $needle\n$haystack"
|
||||
}
|
||||
|
||||
assert_execution() {
|
||||
local expected="$1" actual
|
||||
actual="$(sort "$fixture/executions" 2>/dev/null || true)"
|
||||
[[ "$actual" == "$expected" ]] || fail "expected executions '$expected', got '$actual'"
|
||||
}
|
||||
|
||||
reset_executions() { : > "$fixture/executions"; }
|
||||
|
||||
run_panama() {
|
||||
output="$(cd "$fixture" && TMPDIR="$fixture" PANAMA_TEST_FIXTURE="$fixture" "$fixture/bin/panama" "$@" </dev/null 2>&1)"
|
||||
status=$?
|
||||
}
|
||||
|
||||
mkdir -p "$fixture/bin" "$fixture/tests" "$fixture/config"
|
||||
cp "$repo_dir/bin/panama" "$fixture/bin/panama"
|
||||
chmod +x "$fixture/bin/panama"
|
||||
touch "$fixture/config/subject"
|
||||
git -C "$fixture" init --quiet
|
||||
|
||||
cat > "$fixture/tests/contracts.manifest" <<'EOF'
|
||||
# Maps the live desktop.
|
||||
live-desktop tests/desktop-contract
|
||||
hermetic tests/fail-contract
|
||||
hermetic tests/hang-contract
|
||||
# Reads a host fixture.
|
||||
live-host tests/host-contract
|
||||
# Contacts a fixture endpoint.
|
||||
network tests/network-contract
|
||||
hermetic tests/pass-contract
|
||||
hermetic tests/stderr-contract
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/pass-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'pass\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
printf 'pass stdout\n'
|
||||
# config/subject
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/fail-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'fail\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
printf 'failure stdout\n'
|
||||
printf 'failure stderr\n' >&2
|
||||
exit 7
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/stderr-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'stderr\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
printf 'warning on success\n' >&2
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/hang-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'hang\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
trap 'printf terminated >"$PANAMA_TEST_FIXTURE/terminated"; exit 124' TERM
|
||||
while :; do sleep 1; done
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/host-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'host\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/desktop-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'desktop\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
# config/subject
|
||||
EOF
|
||||
|
||||
cat > "$fixture/tests/network-contract" <<'EOF'
|
||||
#!/usr/bin/env bash
|
||||
printf 'network\n' >> "$PANAMA_TEST_FIXTURE/executions"
|
||||
EOF
|
||||
|
||||
chmod +x "$fixture/tests"/{desktop,fail,host,network,pass,stderr}-contract
|
||||
: > "$fixture/executions"
|
||||
|
||||
# --safe must select hermetic entries from the manifest, not merely omit a
|
||||
# legacy desktop list. The failing fixture makes the command nonzero, but all
|
||||
# three selected hermetic contracts still run and every other capability skips.
|
||||
run_panama test --safe
|
||||
[[ $status -ne 0 ]] || fail '--safe unexpectedly passed a failing fixture'
|
||||
assert_execution $'fail\npass\nstderr'
|
||||
assert_contains 'Skipped 1 live-host contract(s).' "$output"
|
||||
assert_contains 'Skipped 0 live-compositor contract(s).' "$output"
|
||||
assert_contains 'Skipped 1 live-desktop contract(s).' "$output"
|
||||
assert_contains 'Skipped 1 network contract(s).' "$output"
|
||||
|
||||
reset_executions
|
||||
run_panama test desktop
|
||||
[[ $status -ne 0 ]] || fail 'non-TTY desktop run unexpectedly passed without a grant'
|
||||
assert_execution ''
|
||||
assert_contains 'pass --allow live-desktop' "$output"
|
||||
|
||||
run_panama test --allow live-desktop desktop
|
||||
[[ $status -eq 0 ]] || fail "explicit desktop grant failed: $output"
|
||||
assert_execution 'desktop'
|
||||
|
||||
reset_executions
|
||||
run_panama test --allow live-desktop --allow live-host host
|
||||
[[ $status -eq 0 ]] || fail "repeatable grants failed: $output"
|
||||
assert_execution 'host'
|
||||
|
||||
reset_executions
|
||||
run_panama test --allow live-desktop network
|
||||
[[ $status -ne 0 ]] || fail 'desktop grant incorrectly allowed network'
|
||||
assert_execution ''
|
||||
assert_contains 'network' "$output"
|
||||
|
||||
for args in '--unknown' 'pass-contract second-pattern' '--allow unknown' '--safe --allow live-desktop'; do
|
||||
# shellcheck disable=SC2086
|
||||
run_panama test $args
|
||||
[[ $status -eq 2 ]] || fail "usage error did not exit 2 for: $args\n$output"
|
||||
done
|
||||
|
||||
chmod +x "$fixture/tests/hang-contract"
|
||||
|
||||
reset_executions
|
||||
output="$(cd "$fixture" && TMPDIR="$fixture" PANAMA_TEST_TIMEOUT_SECONDS=1 PANAMA_TEST_FIXTURE="$fixture" "$fixture/bin/panama" test hang </dev/null 2>&1)"
|
||||
status=$?
|
||||
[[ $status -ne 0 ]] || fail 'timed-out contract unexpectedly passed'
|
||||
assert_execution 'hang'
|
||||
[[ -f "$fixture/terminated" ]] || fail 'timed-out contract was not terminated with TERM'
|
||||
assert_contains 'timed out' "$output"
|
||||
|
||||
reset_executions
|
||||
run_panama test fail
|
||||
[[ $status -ne 0 ]] || fail 'failed contract unexpectedly passed'
|
||||
assert_contains 'failure stdout' "$output"
|
||||
assert_contains 'failure stderr' "$output"
|
||||
|
||||
reset_executions
|
||||
run_panama test stderr
|
||||
[[ $status -eq 0 ]] || fail "stderr success contract failed: $output"
|
||||
assert_contains 'warning on success' "$output"
|
||||
|
||||
reset_executions
|
||||
run_panama test pass
|
||||
[[ $status -eq 0 ]] || fail "pass contract failed: $output"
|
||||
assert_not_contains 'pass stdout' "$output"
|
||||
|
||||
reset_executions
|
||||
run_panama test --safe desktop
|
||||
[[ $status -ne 0 ]] || fail 'only-skipped pattern unexpectedly passed'
|
||||
assert_contains 'Every contract matching' "$output"
|
||||
assert_not_contains 'No contracts match' "$output"
|
||||
|
||||
output="$(cd "$fixture" && "$fixture/bin/panama" contracts config/subject 2>&1)"
|
||||
status=$?
|
||||
[[ $status -eq 0 ]] || fail "contracts lookup failed: $output"
|
||||
assert_contains 'tests/desktop-contract [live-desktop]' "$output"
|
||||
assert_contains 'tests/pass-contract [hermetic]' "$output"
|
||||
|
||||
mv "$fixture/tests/contracts.manifest" "$fixture/tests/contracts.manifest.missing"
|
||||
run_panama test pass
|
||||
[[ $status -ne 0 ]] || fail 'missing manifest unexpectedly allowed test execution'
|
||||
assert_contains 'contracts.manifest' "$output"
|
||||
mv "$fixture/tests/contracts.manifest.missing" "$fixture/tests/contracts.manifest"
|
||||
|
||||
capture_dirs="$(find "$fixture" -mindepth 1 -maxdepth 1 -type d -name 'tmp.*' -print)"
|
||||
[[ -z "$capture_dirs" ]] || fail "runner leaked capture directory: $capture_dirs"
|
||||
|
||||
printf 'test runner: PASS\n'
|
||||
Reference in New Issue
Block a user