3344b8372d
message: rename TrunkCommit to ChangeCommit, in accordance with the new SPEC change_hash: ALR1AfczQ9gwz9WHk4G9U4pOdDLu8frv19TmrwtNx90W credentials: - type: pgp_signature pub_key_id: 95C46FA6A41148AC body: iQIzBAABAgAdFiEEJ6tQKp6olvZKJ0lwlcRvpqQRSKwFAl5PZT8ACgkQlcRvpqQRSKxiyA//T2UObXqMmKntv7ogT4Atel4J6HzzV1sq4HNdvuuRiq7I1Jjzlluh+U1MsODOYuoS8tWWW3YK5ND0D03vhPO/tahUxnAbJXNdhHPDmvu95CCTqiF5X6x47PIBg9M4Z3s8PAipcNVfyWsciLhIXSP9TgJ6mpxy13cqsV7qpoQi0SX1olClxvU5N1oNtTk3swvec0vZnH4nYt2iFt28yRRTyKJuzSPDHqdAxqSYfCn0kLfOyMaycWi3PkslL78j9aXWQ8bzSArmcYeAO6RYu7CFGUbTf4mNKj4F/DusV4CO87ld8xGyHwVXCuShBb8wW7UYyrlbNJxXFVSxrIARSxXwtw/CuO7kQvB+IplBnWgpUiqzASKjXrwzZ+LMMUzmKCWyQphkW2fUU8d9FIh2NIEUmFCJfnmnnULmFDfecP2crU3Fxjv5ATsOi/F4IiGcJb6N9TxQAWK8ezC/Kk4UUSfNDBD99Qq3yfzJcMNrkK1ZkQgQ/SOSFC1MSoGiatzYJAU9wmO4S6+W6SX9abP5cr2OrI2kwiQbQ+XoJd+ywSJk0f3nP/5d50u5d/ddT9udUwmPnn9cc99Ikt6gXgRgzK//ktn5A5rQwGO+cfxmZkHbxzGATo2LHC2lEKiQMyFzvrXXD8TKJ6HbwX2krYREe4hfDP8iHsuM6eRZblImlraV+Z8= account: mediocregopher
160 lines
4.4 KiB
Go
160 lines
4.4 KiB
Go
package dehub
|
|
|
|
import (
|
|
"dehub/accessctl"
|
|
"dehub/sigcred"
|
|
"errors"
|
|
"reflect"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/davecgh/go-spew/spew"
|
|
"gopkg.in/src-d/go-git.v4/plumbing"
|
|
yaml "gopkg.in/yaml.v2"
|
|
)
|
|
|
|
func TestChangeCommitVerify(t *testing.T) {
|
|
type step struct {
|
|
msg string
|
|
msgHead string // defaults to msg
|
|
tree map[string]string
|
|
}
|
|
testCases := []struct {
|
|
descr string
|
|
steps []step
|
|
}{
|
|
{
|
|
descr: "single commit",
|
|
steps: []step{
|
|
{
|
|
msg: "first commit",
|
|
tree: map[string]string{"a": "0", "b": "1"},
|
|
},
|
|
},
|
|
},
|
|
{
|
|
descr: "multiple commits",
|
|
steps: []step{
|
|
{
|
|
msg: "first commit",
|
|
tree: map[string]string{"a": "0", "b": "1"},
|
|
},
|
|
{
|
|
msg: "second commit, changing a",
|
|
tree: map[string]string{"a": "1"},
|
|
},
|
|
{
|
|
msg: "third commit, empty",
|
|
},
|
|
{
|
|
msg: "fourth commit, adding c, removing b",
|
|
tree: map[string]string{"b": "", "c": "2"},
|
|
},
|
|
},
|
|
},
|
|
{
|
|
descr: "big body commits",
|
|
steps: []step{
|
|
{
|
|
msg: "first commit, single line but with newline\n",
|
|
},
|
|
{
|
|
msg: "second commit, single line but with two newlines\n\n",
|
|
msgHead: "second commit, single line but with two newlines\n\n",
|
|
},
|
|
{
|
|
msg: "third commit, multi-line with one newline\nanother line!",
|
|
msgHead: "third commit, multi-line with one newline\n\n",
|
|
},
|
|
{
|
|
msg: "fourth commit, multi-line with two newlines\n\nanother line!",
|
|
msgHead: "fourth commit, multi-line with two newlines\n\n",
|
|
},
|
|
},
|
|
},
|
|
}
|
|
|
|
for _, test := range testCases {
|
|
t.Run(test.descr, func(t *testing.T) {
|
|
h := newHarness(t)
|
|
for _, step := range test.steps {
|
|
h.stage(step.tree)
|
|
account := h.cfg.Accounts[0]
|
|
|
|
changeCommit, hash := h.changeCommit(step.msg, account.ID, h.sig)
|
|
if err := h.repo.VerifyChangeCommit(hash); err != nil {
|
|
t.Fatalf("could not verify hash %v: %v", hash, err)
|
|
}
|
|
|
|
commit, err := h.repo.GitRepo.CommitObject(hash)
|
|
if err != nil {
|
|
t.Fatalf("failed to retrieve commit %v: %v", hash, err)
|
|
} else if step.msgHead == "" {
|
|
step.msgHead = strings.TrimSpace(step.msg) + "\n\n"
|
|
}
|
|
|
|
if !strings.HasPrefix(commit.Message, step.msgHead) {
|
|
t.Fatalf("commit message %q does not start with expected head %q", commit.Message, step.msgHead)
|
|
}
|
|
|
|
var actualChangeCommit ChangeCommit
|
|
if err := actualChangeCommit.UnmarshalText([]byte(commit.Message)); err != nil {
|
|
t.Fatalf("error unmarshaling commit body: %v", err)
|
|
} else if !reflect.DeepEqual(actualChangeCommit, changeCommit) {
|
|
t.Fatalf("returned change commit:\n%s\ndoes not match actual one:\n%s",
|
|
spew.Sdump(changeCommit), spew.Sdump(actualChangeCommit))
|
|
}
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestConfigChange(t *testing.T) {
|
|
h := newHarness(t)
|
|
|
|
var hashes []plumbing.Hash
|
|
|
|
// commit the initial staged changes, which merely include the config and
|
|
// public key
|
|
_, hash := h.changeCommit("commit configuration", h.cfg.Accounts[0].ID, h.sig)
|
|
hashes = append(hashes, hash)
|
|
|
|
// create a new account and add it to the configuration. It should not be
|
|
// able to actually make that commit though.
|
|
newSig, newPubKeyBody := sigcred.SignifierPGPTmp(h.rand)
|
|
h.cfg.Accounts = append(h.cfg.Accounts, Account{
|
|
ID: "toot",
|
|
Signifiers: []sigcred.Signifier{{PGPPublicKey: &sigcred.SignifierPGP{
|
|
Body: string(newPubKeyBody),
|
|
}}},
|
|
})
|
|
h.cfg.AccessControls[0].Condition.Signature.AccountIDs = []string{"root", "toot"}
|
|
h.cfg.AccessControls[0].Condition.Signature.Count = "1"
|
|
|
|
cfgBody, err := yaml.Marshal(h.cfg)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
h.stage(map[string]string{ConfigPath: string(cfgBody)})
|
|
|
|
_, err = h.repo.NewChangeCommit("add toot user", h.cfg.Accounts[1].ID, newSig)
|
|
if aclErr := (accessctl.ErrConditionSignatureUnsatisfied{}); !errors.As(err, &aclErr) {
|
|
t.Fatalf("NewChangeCommit should have returned an ErrConditionSignatureUnsatisfied, but returned %v", err)
|
|
}
|
|
|
|
// now add with the root user, this should work.
|
|
_, hash = h.changeCommit("add toot user", h.cfg.Accounts[0].ID, h.sig)
|
|
hashes = append(hashes, hash)
|
|
|
|
// _now_ the toot user should be able to do things.
|
|
h.stage(map[string]string{"foo/bar": "what a cool file"})
|
|
_, hash = h.changeCommit("add a cool file", h.cfg.Accounts[1].ID, newSig)
|
|
hashes = append(hashes, hash)
|
|
|
|
for i, hash := range hashes {
|
|
if err := h.repo.VerifyChangeCommit(hash); err != nil {
|
|
t.Fatalf("commit %d (%v) should have been verified but wasn't: %v", i, hash, err)
|
|
}
|
|
}
|
|
}
|