-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Merge branch 'mm/mkstemps-mode-for-packfiles' into maint
* mm/mkstemps-mode-for-packfiles: Use git_mkstemp_mode instead of plain mkstemp to create object files git_mkstemps_mode: don't set errno to EINVAL on exit. Use git_mkstemp_mode and xmkstemp_mode in odb_mkstemp, not chmod later. git_mkstemp_mode, xmkstemp_mode: variants of gitmkstemps with mode argument. Move gitmkstemps to path.c Add a testcase for ACL with restrictive umask.
- Loading branch information
Showing
8 changed files
with
172 additions
and
93 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,67 @@ | ||
#!/bin/sh | ||
# | ||
# Copyright (c) 2010 Matthieu Moy | ||
# | ||
|
||
test_description='Test repository with default ACL' | ||
|
||
# Create the test repo with restrictive umask | ||
# => this must come before . ./test-lib.sh | ||
umask 077 | ||
|
||
. ./test-lib.sh | ||
|
||
# We need an arbitrary other user give permission to using ACLs. root | ||
# is a good candidate: exists on all unices, and it has permission | ||
# anyway, so we don't create a security hole running the testsuite. | ||
|
||
if ! setfacl -m u:root:rwx .; then | ||
say "Skipping ACL tests: unable to use setfacl" | ||
test_done | ||
fi | ||
|
||
modebits () { | ||
ls -l "$1" | sed -e 's|^\(..........\).*|\1|' | ||
} | ||
|
||
check_perms_and_acl () { | ||
actual=$(modebits "$1") && | ||
case "$actual" in | ||
-r--r-----*) | ||
: happy | ||
;; | ||
*) | ||
echo "Got permission '$actual', expected '-r--r-----'" | ||
false | ||
;; | ||
esac && | ||
getfacl "$1" > actual && | ||
grep -q "user:root:rwx" actual && | ||
grep -q "user:${LOGNAME}:rwx" actual && | ||
grep -q "mask::r--" actual && | ||
grep -q "group::---" actual || false | ||
} | ||
|
||
dirs_to_set="./ .git/ .git/objects/ .git/objects/pack/" | ||
|
||
test_expect_success 'Setup test repo' ' | ||
setfacl -m u:root:rwx $dirs_to_set && | ||
setfacl -d -m u:"$LOGNAME":rwx $dirs_to_set && | ||
setfacl -d -m u:root:rwx $dirs_to_set && | ||
touch file.txt && | ||
git add file.txt && | ||
git commit -m "init" | ||
' | ||
|
||
test_expect_success 'Objects creation does not break ACLs with restrictive umask' ' | ||
# SHA1 for empty blob | ||
check_perms_and_acl .git/objects/e6/9de29bb2d1d6434b8b29ae775ad8c2e48c5391 | ||
' | ||
|
||
test_expect_success 'git gc does not break ACLs with restrictive umask' ' | ||
git gc && | ||
check_perms_and_acl .git/objects/pack/*.pack | ||
' | ||
|
||
test_done |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters