Merge pull request 'fix: normalize Debian payload modes' (#68) from build/63-normalize-deb-modes into main
All checks were successful
ci / test (push) Successful in 1m31s
All checks were successful
ci / test (push) Successful in 1m31s
Reviewed-on: #68 Reviewed-by: claude-bot-andresmgsl <andres+1@heavyduty.builders> Reviewed-by: glm-bot-andresmgsl <andres+5@heavyduty.builders> Reviewed-by: kimi-bot-andresmgsl <andres+4@heavyduty.builders>
This commit is contained in:
commit
33d583892e
3 changed files with 69 additions and 3 deletions
1
changelog.d/63.md
Normal file
1
changelog.d/63.md
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
- Normalize Debian package payload modes independently of the builder's umask. (#63).
|
||||||
|
|
@ -67,9 +67,9 @@ EOF
|
||||||
# Native package (no Debian revision in the version), so plain changelog.gz.
|
# Native package (no Debian revision in the version), so plain changelog.gz.
|
||||||
gzip -9n -c "$STAGE/changelog" > "$DOC/changelog.gz"
|
gzip -9n -c "$STAGE/changelog" > "$DOC/changelog.gz"
|
||||||
|
|
||||||
# Normalize permissions regardless of the builder's umask: no group/other
|
# Normalize permissions regardless of the builder's umask: traversable
|
||||||
# write anywhere, executable entry point.
|
# directories, readable files, and execute bits retained only where intended.
|
||||||
chmod -R go-w "$PKG/usr"
|
chmod -R u+rwX,go=rX "$PKG/usr"
|
||||||
chmod 0755 "$LIB/src/cli.js"
|
chmod 0755 "$LIB/src/cli.js"
|
||||||
|
|
||||||
# --- control -----------------------------------------------------------------
|
# --- control -----------------------------------------------------------------
|
||||||
|
|
|
||||||
65
test/build-deb.test.js
Normal file
65
test/build-deb.test.js
Normal file
|
|
@ -0,0 +1,65 @@
|
||||||
|
const { test } = require('node:test');
|
||||||
|
const assert = require('node:assert/strict');
|
||||||
|
const { spawnSync } = require('node:child_process');
|
||||||
|
const fs = require('node:fs');
|
||||||
|
const os = require('node:os');
|
||||||
|
const path = require('node:path');
|
||||||
|
|
||||||
|
const ROOT = path.join(__dirname, '..');
|
||||||
|
|
||||||
|
function copyTree(source, destination) {
|
||||||
|
fs.cpSync(source, destination, { recursive: true });
|
||||||
|
}
|
||||||
|
|
||||||
|
function buildPackage(umask) {
|
||||||
|
const root = fs.mkdtempSync(path.join(os.tmpdir(), 'stoke-build-deb-test-'));
|
||||||
|
const bin = path.join(root, 'bin');
|
||||||
|
fs.mkdirSync(path.join(root, 'scripts'));
|
||||||
|
fs.mkdirSync(bin);
|
||||||
|
fs.copyFileSync(path.join(ROOT, 'scripts', 'build-deb.sh'), path.join(root, 'scripts', 'build-deb.sh'));
|
||||||
|
copyTree(path.join(ROOT, 'src'), path.join(root, 'src'));
|
||||||
|
fs.copyFileSync(path.join(ROOT, 'package.json'), path.join(root, 'package.json'));
|
||||||
|
fs.copyFileSync(path.join(ROOT, 'package-lock.json'), path.join(root, 'package-lock.json'));
|
||||||
|
|
||||||
|
const npm = path.join(bin, 'npm');
|
||||||
|
fs.writeFileSync(npm, '#!/usr/bin/env bash\nexit 0\n');
|
||||||
|
fs.chmodSync(npm, 0o755);
|
||||||
|
|
||||||
|
const result = spawnSync(
|
||||||
|
'bash',
|
||||||
|
['-c', 'umask "$1"; exec bash "$2"', 'build-deb-test', umask, path.join(root, 'scripts', 'build-deb.sh')],
|
||||||
|
{
|
||||||
|
encoding: 'utf8',
|
||||||
|
env: { ...process.env, PATH: `${bin}:${process.env.PATH}` },
|
||||||
|
},
|
||||||
|
);
|
||||||
|
assert.equal(result.status, 0, result.stderr);
|
||||||
|
|
||||||
|
const deb = path.join(root, 'dist', 'stoke_1.5.0_all.deb');
|
||||||
|
const listing = spawnSync('dpkg-deb', ['-c', deb], { encoding: 'utf8' });
|
||||||
|
assert.equal(listing.status, 0, listing.stderr);
|
||||||
|
|
||||||
|
const modes = new Map();
|
||||||
|
for (const line of listing.stdout.trim().split('\n')) {
|
||||||
|
const fields = line.trim().split(/\s+/);
|
||||||
|
const archivePath = fields.find((field) => field.startsWith('./usr/'));
|
||||||
|
if (archivePath && (fields[0].startsWith('d') || fields[0].startsWith('-'))) {
|
||||||
|
modes.set(archivePath, fields[0]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return { root, modes };
|
||||||
|
}
|
||||||
|
|
||||||
|
test('Debian payload modes are identical under umask 077 and 022', (t) => {
|
||||||
|
const restrictive = buildPackage('077');
|
||||||
|
const standard = buildPackage('022');
|
||||||
|
t.after(() => {
|
||||||
|
fs.rmSync(restrictive.root, { recursive: true, force: true });
|
||||||
|
fs.rmSync(standard.root, { recursive: true, force: true });
|
||||||
|
});
|
||||||
|
|
||||||
|
assert.deepEqual(restrictive.modes, standard.modes);
|
||||||
|
for (const [archivePath, mode] of restrictive.modes) {
|
||||||
|
assert.equal(mode, archivePath.endsWith('/') ? 'drwxr-xr-x' : archivePath === './usr/lib/stoke/src/cli.js' ? '-rwxr-xr-x' : '-rw-r--r--', archivePath);
|
||||||
|
}
|
||||||
|
});
|
||||||
Loading…
Reference in a new issue