test: seal the fake PATH instead of prepending it
The old harness put .tests/fakebin at the front of $PATH, which fails OPEN: a package manager with no fake fell through to the real one, and an audit of this suite invoked the host's actual `brew`. The twelve one-line fakes are replaced by a single dispatcher every fake symlinks to, plus seal.sh, which builds the WHOLE of $PATH for a run — real binaries for the pure tools, fakes for anything that installs, downloads or needs root, and command-not-found for everything else. Runs go under `env -i` so they inherit nothing. Two audits ship with it: any `have`/`find_tool` probe the seal has never heard of is an error, and the four absolute paths find_tool probes are written to .shadowed so a test needing a tool to be genuinely absent can say so. The dispatcher also fails on demand (FAKE_FAIL), which is what makes the installers' failure paths reachable at all — the apt and npm one-at-a-time retries, note_fail, and cmd_install's non-zero exit had all been unreachable, and all three survived being deleted outright. _curl stands in for every remote the installer talks to and for nothing else: an unrecognised URL is a failed download, so a typo'd host shows up as the failure it would really be. The fzf fake records its argv, which is what makes the picker's bindings testable.
This commit is contained in:
@@ -0,0 +1,96 @@
|
||||
# Sourced by _fake when it is invoked as `curl`. Stands in for every remote the
|
||||
# installer talks to, and for nothing else: a URL this file does not recognise
|
||||
# is a failed download, not a silent success, so a typo'd host or a moved path
|
||||
# shows up as the failure it would really be.
|
||||
#
|
||||
# Knobs, all set by the caller:
|
||||
# FAKE_BOOT_BLOB file whose contents the bootstrap endpoint returns on 200
|
||||
# FAKE_BOOT_PW the password that gets a 200; anything else gets a 401
|
||||
# FAKE_BOOT_CODE force a code (404, 000, 500 ...) whatever the password
|
||||
# FAKE_BWS_SUMS match (default) | mismatch | absent
|
||||
# FAKE_FAIL=curl:deb | curl:chezmoi | curl:fzf fail just that one download
|
||||
|
||||
_fb=$(dirname "$0") # the fakebin directory
|
||||
url=; out=; prev=; readcfg=0
|
||||
for a in "$@"; do
|
||||
case $prev in -o) out=$a ;; -K) [ "$a" = - ] && readcfg=1 ;; esac
|
||||
case $a in http://*|https://*|get.chezmoi.io|*.io|*.sh) [ -z "$url" ] && url=$a ;; esac
|
||||
prev=$a
|
||||
done
|
||||
cfg=
|
||||
[ "$readcfg" = 1 ] && cfg=$(cat) # always drain: the writer is a pipe
|
||||
|
||||
emit() { if [ -n "$out" ]; then cat > "$out"; else cat; fi; }
|
||||
|
||||
# A tiny installer script, printed the way get.chezmoi.io and astral.sh print
|
||||
# theirs. It installs the FAKE of the same name, so whatever it drops behaves
|
||||
# like every other fake in this directory.
|
||||
installer() { # $1 tool, $2 default dir
|
||||
printf '%s\n' \
|
||||
"b=$2" \
|
||||
'while [ $# -gt 0 ]; do case $1 in -b) b=$2; shift 2 ;; *) shift ;; esac; done' \
|
||||
"mkdir -p \"\$b\" && ln -sf $_fb/_fake \"\$b/$1\" && echo \"installed $1 to \$b\""
|
||||
}
|
||||
|
||||
case $url in
|
||||
*get.chezmoi.io*)
|
||||
[ "$mode" = chezmoi ] && exit 22
|
||||
installer chezmoi "\$HOME/.local/bin"; exit 0 ;;
|
||||
*astral.sh/uv/install.sh*)
|
||||
installer uv "\$HOME/.local/bin"; exit 0 ;;
|
||||
*go.dev/VERSION*)
|
||||
echo go1.99.0; exit 0 ;;
|
||||
*api.github.com*)
|
||||
echo ' "browser_download_url": "https://example.invalid/fake_amd64.deb"'; exit 0 ;;
|
||||
|
||||
# ------------------------------------------------------------------- fzf ----
|
||||
# Only the real release path answers. The tarball is built here from the
|
||||
# version in the URL, so `dotup preflight` reporting "0.74.2" is evidence that
|
||||
# the pinned version travelled through the URL and into the binary -- not that
|
||||
# a fixture happened to say so.
|
||||
https://github.com/junegunn/fzf/releases/download/*)
|
||||
[ "$mode" = fzf ] && exit 22
|
||||
f=${url##*/} # fzf-0.74.2-linux_amd64.tar.gz
|
||||
v=${f#fzf-}; v=${v%%-*}
|
||||
d=$(mktemp -d); printf '#!/bin/sh\ncase ${1:-} in --version) echo "%s (fake)" ;; esac\nexit 0\n' "$v" > "$d/fzf"
|
||||
chmod 755 "$d/fzf"; tar -czf - -C "$d" fzf; rm -rf "$d"; exit 0 ;;
|
||||
|
||||
# ------------------------------------------------------------------- bws ----
|
||||
*/sdk-sm/releases/download/*bws-sha256-checksums-*)
|
||||
case ${FAKE_BWS_SUMS:-match} in
|
||||
absent) exit 22 ;;
|
||||
mismatch) s=0000000000000000000000000000000000000000000000000000000000000000 ;;
|
||||
*) s=$(printf 'PK-fake-bws-zip\n' | sha256sum | cut -d' ' -f1) ;;
|
||||
esac
|
||||
v=${url##*bws-sha256-checksums-}; v=${v%.txt}
|
||||
for t in x86_64-unknown-linux-musl aarch64-unknown-linux-musl macos-universal; do
|
||||
printf '%s bws-%s-%s.zip\n' "$s" "$t" "$v"
|
||||
done | emit
|
||||
exit 0 ;;
|
||||
*/sdk-sm/releases/download/*.zip)
|
||||
printf 'PK-fake-bws-zip\n' | emit; exit 0 ;;
|
||||
|
||||
# -------------------------------------------------------------- bootstrap ---
|
||||
*/bootstrap.env)
|
||||
pw=$(printf '%s\n' "$cfg" | sed -n 's/^user = "[^:]*:\(.*\)"$/\1/p' | head -1)
|
||||
code=${FAKE_BOOT_CODE:-}
|
||||
if [ -z "$code" ]; then
|
||||
if [ "$pw" = "${FAKE_BOOT_PW:-}" ]; then code=200; else code=401; fi
|
||||
fi
|
||||
if [ "$code" = 200 ]; then cat "${FAKE_BOOT_BLOB:?FAKE_BOOT_BLOB unset}"; fi
|
||||
printf '\n%s' "$code"
|
||||
[ "$code" = 000 ] && exit 7
|
||||
exit 0 ;;
|
||||
esac
|
||||
|
||||
# --------------------------------------------------------------- anything ---
|
||||
# A download to a file still has to produce the file; a download of something
|
||||
# this stand-in has never heard of is a failure, which is the honest answer.
|
||||
case $url in
|
||||
*.deb|*.tar.gz|*.tgz)
|
||||
[ "$mode" = deb ] && exit 22
|
||||
[ -n "$out" ] && { : > "$out"; exit 0; }
|
||||
exit 0 ;;
|
||||
esac
|
||||
[ -n "$out" ] && { : > "$out"; exit 0; }
|
||||
exit 22
|
||||
Reference in New Issue
Block a user