mirror of
https://github.com/4gray/iptvnator.git
synced 2026-10-10 10:06:15 -08:00
test(packaging): lock Flatpak ELF inspection contract
This commit is contained in:
1 parent
7df496505d
commit
fc76dd1ad2
1 file changed
+59
@@ -56,6 +56,10 @@ const packageLayoutVerifier = fs.readFileSync(
|
||||
join(currentDir, 'verify-electron-package-layout.mjs'),
|
||||
'utf8'
|
||||
);
|
||||
const flatpakLauncherValidationSource = fs.readFileSync(
|
||||
join(currentDir, 'flatpak-launcher-validation.cjs'),
|
||||
'utf8'
|
||||
);
|
||||
const electronAfterPackSource = fs.readFileSync(
|
||||
join(currentDir, 'electron-after-pack.cjs'),
|
||||
'utf8'
|
||||
@@ -343,6 +347,61 @@ test('package layout verifier uses canonical helpers and direct dependencies', (
|
||||
);
|
||||
});
|
||||
|
||||
test('Flatpak launcher validation locks descriptor-based ELF inspection', () => {
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/const expectedElfMagic = Buffer\.from\(\[\s*0x7f,\s*0x45,\s*0x4c,\s*0x46,?\s*\]\)/
|
||||
);
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/descriptor = fs\.openSync\(\s*launcherPath,\s*fs\.constants\.O_RDONLY\s*\|\s*fs\.constants\.O_NOFOLLOW\s*\)/
|
||||
);
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/launcherStat = fs\.fstatSync\(descriptor\)/
|
||||
);
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/const elfMagic = Buffer\.alloc\(expectedElfMagic\.length\)/
|
||||
);
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/bytesRead = fs\.readSync\(\s*descriptor,\s*elfMagic,\s*0,\s*elfMagic\.length,\s*0\s*\)/
|
||||
);
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/bytesRead !== expectedElfMagic\.length/
|
||||
);
|
||||
assert.match(
|
||||
flatpakLauncherValidationSource,
|
||||
/finally\s*{\s*try\s*{\s*fs\.closeSync\(descriptor\)/
|
||||
);
|
||||
|
||||
const openOffset = flatpakLauncherValidationSource.indexOf(
|
||||
'descriptor = fs.openSync('
|
||||
);
|
||||
const statOffset = flatpakLauncherValidationSource.indexOf(
|
||||
'launcherStat = fs.fstatSync(descriptor)'
|
||||
);
|
||||
const readOffset = flatpakLauncherValidationSource.indexOf(
|
||||
'bytesRead = fs.readSync('
|
||||
);
|
||||
const finallyOffset = flatpakLauncherValidationSource.indexOf(
|
||||
'} finally {',
|
||||
readOffset
|
||||
);
|
||||
const closeOffset = flatpakLauncherValidationSource.indexOf(
|
||||
'fs.closeSync(descriptor)',
|
||||
finallyOffset
|
||||
);
|
||||
assert.ok(
|
||||
openOffset < statOffset &&
|
||||
statOffset < readOffset &&
|
||||
readOffset < finallyOffset &&
|
||||
finallyOffset < closeOffset
|
||||
);
|
||||
});
|
||||
|
||||
test('nx-electron packaging does not copy duplicate root package metadata', () => {
|
||||
const nxElectronExecutorPath =
|
||||
require.resolve('nx-electron/src/executors/package/executor.js');
|
||||
|
||||
Reference in new issue
Block a user