From c7dc1a0173a14e9cb52adcb09ae566cf7eeb314a Mon Sep 17 00:00:00 2001 From: Hermes Agent Date: Wed, 12 Aug 2026 06:02:57 +0000 Subject: Protect companion manifests from overwrite --- tests/build.rs | 23 +++++++++++++++++++++++ tests/compare.rs | 15 +++++++++++++++ 2 files changed, 38 insertions(+) (limited to 'tests') diff --git a/tests/build.rs b/tests/build.rs index 6613cc7..c6ed70d 100644 --- a/tests/build.rs +++ b/tests/build.rs @@ -112,6 +112,29 @@ fn rejects_an_existing_artifact_before_creating_the_workspace_or_installing() { assert!(installer.requests.borrow().is_empty()); } +#[test] +fn rejects_an_existing_companion_manifest_before_creating_the_workspace_or_installing() { + let fixture = tempdir().expect("fixture directory"); + let spec = ImageSpec::load(std::path::Path::new("profiles/alt-controller.toml")) + .expect("load controller spec"); + let plan = BuildPlan::compile(spec).expect("compile build plan"); + let installer = FixtureInstaller::default(); + let mut executor = BuildExecutor::new(&installer, FixtureInitramfsBuilder); + let workspace = fixture.path().join("work"); + let artifact = fixture.path().join("controller.tar"); + let companion = ArtifactManifest::path_beside(&artifact).expect("companion manifest path"); + fs::write(&companion, "do not replace").expect("write pre-existing companion manifest"); + + let error = executor + .execute(&plan, &workspace, "profiles/apt.conf", &artifact) + .expect_err("pre-existing companion manifest must be rejected"); + + assert!(error.to_string().contains("output manifest already exists")); + assert_eq!(fs::read_to_string(&companion).expect("read companion manifest"), "do not replace"); + assert!(!workspace.exists()); + assert!(installer.requests.borrow().is_empty()); +} + #[test] fn rejects_a_missing_apt_configuration_before_creating_the_workspace() { let fixture = tempdir().expect("fixture directory"); diff --git a/tests/compare.rs b/tests/compare.rs index f7b3a04..4f48721 100644 --- a/tests/compare.rs +++ b/tests/compare.rs @@ -158,6 +158,21 @@ fn writes_distinct_manifests_for_artifacts_in_the_same_directory() { assert_eq!(ArtifactManifest::load(&native_path).expect("load native manifest"), native_manifest); } +#[test] +fn refuses_to_overwrite_an_existing_companion_manifest() { + let fixture = tempdir().expect("temporary directory"); + let artifact = fixture.path().join("controller.tar"); + let manifest_path = ArtifactManifest::path_beside(&artifact).expect("manifest path"); + fs::write(&manifest_path, "preserve this manifest").expect("write existing manifest"); + + let error = baseline() + .write_beside(&artifact) + .expect_err("existing companion manifests must not be overwritten"); + + assert!(error.to_string().contains("create artifact manifest")); + assert_eq!(fs::read_to_string(&manifest_path).expect("read existing manifest"), "preserve this manifest"); +} + #[test] fn rejects_duplicate_semantic_keys() { let error = ArtifactManifest::new( -- cgit v1.2.3