Skip to content

Commit 3bff76f

Browse files
senamakelmedullabot
andcommitted
test(audit): classify child command and receipt failure locations
Co-authored-by: Medulla <medulla@tinyhumans.ai>
1 parent e932197 commit 3bff76f

2 files changed

Lines changed: 10 additions & 3 deletions

File tree

‎crates/tinysecurity-audit/src/sink_windows_negative_tests.rs‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -352,7 +352,7 @@ exit 0
352352
$file = Join-Path $PSHOME 'powershell.exe'
353353
$start = [Diagnostics.ProcessStartInfo]::new()
354354
$start.FileName = $file
355-
$start.Arguments = '-NoProfile -NonInteractive -Command "try { [Console]::InputEncoding=[Text.UTF8Encoding]::new($false); $s=[Console]::In.ReadToEnd(); if(-not $s.StartsWith(''$ErrorActionPreference'')){exit 89}; [Console]::WriteLine(''audit-account-stage=94 utf8-prefix=1''); $b=[ScriptBlock]::Create($s); [Console]::WriteLine(''audit-account-stage=94 parsed=1''); & $b } catch { $n=$_.Exception.GetType().Name; $k=0; switch($n){ParseException{$k=1} CommandNotFoundException{$k=2} MethodInvocationException{$k=3} RuntimeException{$k=4} UnauthorizedAccessException{$k=5}}; [Console]::WriteLine((''audit-account-stage=95 kind={0} category={1} hresult={2}'' -f $k,[int]$_.CategoryInfo.Category,$_.Exception.HResult)); exit 89 }"'
355+
$start.Arguments = '-NoProfile -NonInteractive -Command "try { [Console]::InputEncoding=[Text.UTF8Encoding]::new($false); $s=[Console]::In.ReadToEnd(); if(-not $s.StartsWith(''$ErrorActionPreference'')){exit 89}; $b=[ScriptBlock]::Create($s); $a=$b.Ast.EndBlock.Statements; [Console]::WriteLine((''audit-account-stage=94 parsed=1 prefix=1 block={0} first={1} count={2} length={3}'' -f [int]($b -is [ScriptBlock]),[int]($a[0].Extent.Text -ceq ''$ErrorActionPreference = ''''Stop''''''),$a.Count,$s.Length)); & $b } catch { $i=$_.InvocationInfo; $n=[Array]::IndexOf(@(''$ErrorActionPreference'',''Write-Output'',''Join-Path'',''&'',''$b''),$_.TargetObject)+1; [Console]::WriteLine((''audit-account-stage=95 command={0} length={1} line={2} offset={3} category={4} hresult={5}'' -f $n,([string]$_.TargetObject).Length,$i.ScriptLineNumber,$i.OffsetInLine,[int]$_.CategoryInfo.Category,$_.Exception.HResult)); exit 89 }"'
356356
$start.UseShellExecute = $false
357357
$start.UserName = $network.UserName
358358
$start.Domain = $network.Domain
@@ -386,7 +386,7 @@ exit 0
386386
$requiredPhases = @('audit-account-stage=90 foreign-identity=1 nonadmin=1', 'audit-account-stage=91 exact-control-read=1', 'audit-account-stage=92 private-file-denials=6', 'audit-account-stage=93 namespace-denial=1')
387387
$allLines = @($stdout.Result.Split([char]10) | ForEach-Object { $_.TrimEnd([char]13) } | Where-Object { $_.Length -gt 0 })
388388
$lines = @($allLines | Where-Object { $requiredPhases -ccontains $_ })
389-
$diagnostics = @($allLines | Where-Object { $_ -cmatch '^audit-account-stage=94 (utf8-prefix|parsed)=1$|^audit-account-stage=95 kind=[0-5] category=[0-9]+ hresult=-?[0-9]+$|^audit-account-stage=96 (child-entry|identity-read)=1$' })
389+
$diagnostics = @($allLines | Where-Object { $_ -cmatch '^audit-account-stage=94 parsed=1 prefix=1 block=[01] first=[01] count=[0-9]+ length=[0-9]+$|^audit-account-stage=95 command=[0-5] length=[0-9]+ line=-?[0-9]+ offset=-?[0-9]+ category=[0-9]+ hresult=-?[0-9]+$|^audit-account-stage=96 (child-entry|identity-read)=1$' })
390390
foreach ($line in $allLines) {
391391
if (($requiredPhases -ccontains $line) -or ($diagnostics -ccontains $line)) { Write-Output $line }
392392
}

‎crates/tinysecurity-module/src/callbacks_tests.rs‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -350,7 +350,14 @@ async fn native_storage_returns_exact_receipts_and_capacity_denies_without_phant
350350
registry.clone(),
351351
)?;
352352
let first = client.append(batch()).await;
353-
assert!(first.committed && first.permitted);
353+
assert!(
354+
first.committed && first.permitted,
355+
"native receipt committed={} permitted={} health={:?} receipt-present={}",
356+
first.committed,
357+
first.permitted,
358+
first.health,
359+
first.receipt.is_some()
360+
);
354361
assert_eq!(first.health, AuditHealth2::Healthy);
355362
assert_eq!(client.append(batch()).await, first);
356363
let stored = std::fs::read(&path)?;

0 commit comments

Comments
 (0)