mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-08-28 05:25:25 +00:00
fix(test): remove TOCTOU file-system race in golden test + format
CodeQL flagged a high-severity 'potential file system race condition': the golden test did fs.existsSync(GOLDEN_FILE) then later writeFileSync/readFileSync on it. Replace the existsSync-then-use with a single race-free read (ENOENT => missing), reusing the read content for the compare path. Behaviour is unchanged (the pure resolveGoldenAction helper still decides regenerate/compare/fail). Also applies prettier formatting to the file (fixes the quality/format check). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
cfe4e49c41
commit
b9008024ab
1 changed files with 18 additions and 5 deletions
|
|
@ -154,9 +154,19 @@ function resolveGoldenAction(opts: {
|
|||
describe('Go scope captures — golden parity', () => {
|
||||
it('matches the committed golden snapshot across all go-* fixtures + DAO shape', () => {
|
||||
const snapshot = buildSnapshot();
|
||||
|
||||
// Read the golden once (no existsSync-then-use, which is a TOCTOU race):
|
||||
// ENOENT means the golden is missing; reuse `existing` for the compare path.
|
||||
let existing: string | undefined;
|
||||
try {
|
||||
existing = fs.readFileSync(GOLDEN_FILE, 'utf8');
|
||||
} catch (err) {
|
||||
if ((err as NodeJS.ErrnoException).code !== 'ENOENT') throw err;
|
||||
}
|
||||
|
||||
const action = resolveGoldenAction({
|
||||
update: UPDATE,
|
||||
exists: fs.existsSync(GOLDEN_FILE),
|
||||
exists: existing !== undefined,
|
||||
isCI: !!process.env.CI, // truthy check: fires on any CI runner, not just CI==='true'
|
||||
});
|
||||
|
||||
|
|
@ -176,7 +186,7 @@ describe('Go scope captures — golden parity', () => {
|
|||
return;
|
||||
}
|
||||
|
||||
const expected: Snapshot = JSON.parse(fs.readFileSync(GOLDEN_FILE, 'utf8'));
|
||||
const expected: Snapshot = JSON.parse(existing!);
|
||||
expect(
|
||||
snapshot,
|
||||
'emitGoScopeCaptures output drifted from the committed golden. If this drift is intentional ' +
|
||||
|
|
@ -192,9 +202,12 @@ describe('Go scope captures — golden parity', () => {
|
|||
{ update: false, exists: false, isCI: false, expected: 'regenerate' },
|
||||
{ update: false, exists: true, isCI: true, expected: 'compare' },
|
||||
{ update: false, exists: true, isCI: false, expected: 'compare' },
|
||||
])('resolveGoldenAction($update,$exists,$isCI) -> $expected', ({ update, exists, isCI, expected }) => {
|
||||
expect(resolveGoldenAction({ update, exists, isCI })).toBe(expected);
|
||||
});
|
||||
])(
|
||||
'resolveGoldenAction($update,$exists,$isCI) -> $expected',
|
||||
({ update, exists, isCI, expected }) => {
|
||||
expect(resolveGoldenAction({ update, exists, isCI })).toBe(expected);
|
||||
},
|
||||
);
|
||||
|
||||
it('produces a deterministic digest across repeated runs', () => {
|
||||
const src = generateDao(8);
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue