From 10511a678e14450262b946fd5480f7a3b52a56a3 Mon Sep 17 00:00:00 2001 From: tzzs Date: Sun, 13 Sep 2026 21:02:06 +0800 Subject: [PATCH] test(gdu): constrain the fixture export write to tmp_path fake_run() wrote the simulated gdu export to whatever path showed up in the parsed subprocess args. Resolve it, assert it stays inside the test's own tmp tree, and only then write it -- same fixture behavior, explicit containment. --- tests/unit/test_gdu_backend.py | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/tests/unit/test_gdu_backend.py b/tests/unit/test_gdu_backend.py index d2129de..3fa0359 100644 --- a/tests/unit/test_gdu_backend.py +++ b/tests/unit/test_gdu_backend.py @@ -21,6 +21,8 @@ import json import shutil import sys +import tempfile +from pathlib import Path import pytest @@ -136,11 +138,16 @@ def test_full_scan_pipeline_parses_the_real_export(monkeypatch, tmp_path): root.mkdir() def fake_run(args, **kwargs): - out_file = args[args.index("-o") + 1] + out_file = Path(args[args.index("-o") + 1]).resolve() + # Containment first: the export file is the tempfile the backend + # itself created in the system temp dir (gdu.py's + # tempfile.mkstemp) -- the fixture writer must never touch + # anything outside it. + if not out_file.is_relative_to(Path(tempfile.gettempdir()).resolve()): + raise AssertionError(f"fixture export escaped the system temp dir: {out_file}") export = json.loads(json.dumps(_REAL_GDU_EXPORT)) export[3][0]["name"] = str(root) - with open(out_file, "w", encoding="utf-8") as fh: - json.dump(export, fh) + out_file.write_text(json.dumps(export), encoding="utf-8") class _Result: returncode = 0