Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 2 additions & 14 deletions crates/socket-patch-cli/tests/apply/in_process_npm_multicopy.rs
Original file line number Diff line number Diff line change
Expand Up @@ -12,24 +12,12 @@
//! assert EVERY physical copy is patched (and later restored) AND that the
//! JSON summary counts every copy.

use crate::common::{binary, git_sha256};

use std::ffi::OsStr;
use std::path::{Path, PathBuf};
use std::process::Command;

use sha2::{Digest, Sha256};

fn binary() -> PathBuf {
env!("CARGO_BIN_EXE_socket-patch").into()
}

fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

/// Write `node_modules/.../<name>/{package.json,index.js}` at the given
/// `pkg_dir` (which already encodes the nesting), returning the index.js path.
fn write_copy(pkg_dir: &Path, name: &str, version: &str, index_bytes: &[u8]) -> PathBuf {
Expand Down
6 changes: 2 additions & 4 deletions crates/socket-patch-cli/tests/cli/covgap_api_client.rs
Original file line number Diff line number Diff line change
Expand Up @@ -6,17 +6,15 @@
//! stderr *text* — the "you configured the sha512- storage hash, not the
//! token" hint — which only a spawned process can observe.

use crate::common::binary;

use std::process::Command;

use wiremock::matchers::{method, path};
use wiremock::{Mock, MockServer, ResponseTemplate};

const UUID: &str = "11111111-1111-4111-8111-111111111111";

fn binary() -> std::path::PathBuf {
env!("CARGO_BIN_EXE_socket-patch").into()
}

/// Parse the command's stdout as JSON, failing with the raw bytes on error
/// (same discipline as `api_client_errors_e2e::json_stdout`).
fn json_stdout(out: &std::process::Output) -> serde_json::Value {
Expand Down
12 changes: 2 additions & 10 deletions crates/socket-patch-cli/tests/cli/output_modes_e2e.rs
Original file line number Diff line number Diff line change
Expand Up @@ -11,20 +11,12 @@
//! like SOCKET_DRY_RUN — an ambient SOCKET_DRY_RUN=true turned every
//! apply below into a silent no-op and failed the on-disk assertions.

use std::path::Path;
use crate::common::git_sha256;

use sha2::{Digest, Sha256};
use std::path::Path;

use crate::common;

fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

fn write_root(root: &Path) {
std::fs::write(
root.join("package.json"),
Expand Down
40 changes: 0 additions & 40 deletions crates/socket-patch-cli/tests/cli/shared_helper_copies.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,38 +15,10 @@ use std::path::Path;
/// another red.
const PENDING_PRIVATE_HELPERS: &[&str] = &[
"apply/apply_network.rs",
"apply/in_process_npm_multicopy.rs",
"cli/api_client_errors_e2e.rs",
"cli/covgap_api_client.rs",
"cli/output_modes_e2e.rs",
"cli/telemetry_e2e.rs",
"cli_scan_silent.rs",
"covgap_commands_scan_mod.rs",
"diff_created_file_e2e.rs",
"docker_e2e_npm.rs",
"docker_e2e_nuget.rs",
"docker_e2e_pypi.rs",
"e2e_embedded_vex.rs",
"e2e_gem.rs",
"e2e_hosted_production.rs",
"e2e_npm.rs",
"e2e_pypi.rs",
"e2e_redirect_gem_build.rs",
"e2e_redirect_gradle_build.rs",
"e2e_redirect_npm_build.rs",
"e2e_redirect_pnpm_build.rs",
"e2e_scan.rs",
"e2e_vendor_composer_build.rs",
"e2e_vendor_npm_build.rs",
"e2e_vendor_pnpm_build.rs",
"e2e_vendor_pypi_build.rs",
"e2e_vex_lockfile/cargo.rs",
"e2e_vex_lockfile/maven.rs",
"e2e_vex_lockfile/uv.rs",
"e2e_vex_lockfile/yarn.rs",
"e2e_vex_redirect.rs",
"e2e_vex_vendor.rs",
"get/get_batch_paths_e2e.rs",
"get/global_packages_e2e.rs",
"in_process_agent_reapply.rs",
"in_process_alternate_installers.rs",
Expand All @@ -59,28 +31,16 @@ const PENDING_PRIVATE_HELPERS: &[&str] = &[
"in_process_pypi_multi_release.rs",
"in_process_remote_ecosystems_apply.rs",
"in_process_remove_repair_lifecycle.rs",
"mode_migration_cargo.rs",
"mode_migration_npm.rs",
"remove/covgap_commands_remove.rs",
"remove_rollback_api_overrides.rs",
"repair/coverage_fix_repair_vendor_predelete.rs",
"repair/covgap_commands_repair.rs",
"repair/covgap_commands_repair_vendor.rs",
"repair/repair_invariants.rs",
"repair/repair_vendor_e2e.rs",
"repair/repair_vendor_flavors_e2e.rs",
"rollback/rollback_invariants.rs",
"rollback/rollback_multicopy_blob_gate.rs",
"scan/covgap_commands_fetch_stage.rs",
"scan/covgap_commands_scan_vendor_flow.rs",
"scan/scan_invariants.rs",
"scan/scan_paths_e2e.rs",
"scan/scan_sync_e2e.rs",
"scan/scan_vendor_step_error_e2e.rs",
"scan_rollout_e2e.rs",
"scan_vendor_e2e.rs",
"vendor_ecosystem_fixtures/mod.rs",
"vendor_jvm_cli.rs",
"vex_e2e_common/mod.rs",
"vlt_e2e_common/mod.rs",
"vlt_hosted_common/mod.rs",
Expand Down
8 changes: 3 additions & 5 deletions crates/socket-patch-cli/tests/cli/telemetry_e2e.rs
Original file line number Diff line number Diff line change
Expand Up @@ -8,18 +8,16 @@
//! count). Each test runs the released binary in a tempdir against
//! the mock URI.

use std::path::{Path, PathBuf};
use crate::common::binary;

use std::path::Path;
use std::process::Command;

use wiremock::matchers::{method, path};
use wiremock::{Mock, MockServer, ResponseTemplate};

const ORG_SLUG: &str = "telemetry-test-org";

fn binary() -> PathBuf {
PathBuf::from(env!("CARGO_BIN_EXE_socket-patch"))
}

fn write_root_package_json(root: &Path) {
std::fs::write(
root.join("package.json"),
Expand Down
19 changes: 5 additions & 14 deletions crates/socket-patch-cli/tests/cli_scan_silent.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,33 +15,24 @@
//! `get_api_client_with_overrides` in core for every command and is
//! out of scope for `scan`'s `--silent` gating.

#[path = "common/mod.rs"]
mod common;
use common::{binary, git_sha256};

#[path = "prebuilt_common/mod.rs"]
mod prebuilt_common;

use std::path::{Path, PathBuf};
use std::path::Path;
use std::process::Command;

use sha2::{Digest, Sha256};
use wiremock::matchers::{method, path};
use wiremock::{Mock, MockServer, ResponseTemplate};

use socket_patch_cli::args::GLOBAL_ARG_ENV_VARS;

fn binary() -> PathBuf {
env!("CARGO_BIN_EXE_socket-patch").into()
}

const ORG_SLUG: &str = "test-org";
const UUID: &str = "11111111-1111-4111-8111-111111111111";

fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

fn write_root(root: &Path) {
std::fs::write(
root.join("package.json"),
Expand Down
19 changes: 5 additions & 14 deletions crates/socket-patch-cli/tests/covgap_commands_scan_mod.rs
Original file line number Diff line number Diff line change
Expand Up @@ -32,37 +32,28 @@
//! `cli_scan_silent.rs` pattern) so ambient developer/CI configuration
//! cannot reroute the branch under test. Network tests use wiremock.

#[path = "common/mod.rs"]
mod common;
use common::{binary, git_sha256};

#[path = "common/pty_io.rs"]
mod pty_io;
#[path = "vlt_hosted_common/mod.rs"]
mod vlt_hosted_common;
#[path = "vlt_hosted_common/vendored.rs"]
mod vlt_vendored;
use std::path::{Path, PathBuf};
use std::path::Path;
use std::process::Command;

use sha2::{Digest, Sha256};
use wiremock::matchers::{method, path};
use wiremock::{Mock, MockServer, ResponseTemplate};

use socket_patch_cli::args::{GLOBAL_ARG_ENV_VARS, LOCAL_ARG_ENV_VARS};

fn binary() -> PathBuf {
env!("CARGO_BIN_EXE_socket-patch").into()
}

const ORG_SLUG: &str = "test-org";
const UUID: &str = "11111111-1111-4111-8111-111111111111";
const OLD_UUID: &str = "99999999-9999-4999-8999-999999999999";

fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

fn write_root_package_json(root: &Path) {
std::fs::write(
root.join("package.json"),
Expand Down
15 changes: 4 additions & 11 deletions crates/socket-patch-cli/tests/docker_e2e_npm.rs
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,10 @@

#![cfg(feature = "docker-e2e")]

#[path = "common/mod.rs"]
mod common;
use common::git_sha256;

#[path = "docker_vendor_common/mod.rs"]
mod docker_vendor_common;

Expand All @@ -33,7 +37,6 @@ use std::path::{Path, PathBuf};
use std::process::Command;
use std::time::Duration;

use sha2::{Digest, Sha256};
use wiremock::matchers::{method, path, path_regex};
use wiremock::{Mock, MockServer, ResponseTemplate};

Expand All @@ -50,16 +53,6 @@ const GHSA: &str = "GHSA-agent-npm-real";
const PATCHED_BYTES: &[u8] =
b"/* SOCKET-PATCH-E2E-MARKER */\nmodule.exports = function () { return {}; };\n";

/// Git-SHA256: SHA256("blob <len>\0" ++ content). Matches the binary's
/// content-addressable hashing for fetched blobs.
fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

/// Coverage instrumentation hook. The CI coverage-docker job sets
/// SOCKET_PATCH_COV_BIN (host path to an llvm-cov-instrumented
/// socket-patch binary) and SOCKET_PATCH_COV_PROFRAW_DIR (host dir
Expand Down
12 changes: 4 additions & 8 deletions crates/socket-patch-cli/tests/docker_e2e_nuget.rs
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,10 @@

#![cfg(feature = "docker-e2e")]

#[path = "common/mod.rs"]
mod common;
use common::git_sha256;

use std::process::Command;

use base64::Engine;
Expand Down Expand Up @@ -61,14 +65,6 @@ fn cov_docker_args() -> Vec<String> {
]
}

fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

/// Plain SHA-256 of the bytes (what `sha256sum` in the container
/// reports). Used to verify the patched file's EXACT contents, not just
/// that it contains the marker substring.
Expand Down
12 changes: 4 additions & 8 deletions crates/socket-patch-cli/tests/docker_e2e_pypi.rs
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,10 @@

#![cfg(feature = "docker-e2e")]

#[path = "common/mod.rs"]
mod common;
use common::git_sha256;

use std::process::Command;

use base64::Engine;
Expand Down Expand Up @@ -63,14 +67,6 @@ fn cov_docker_args() -> Vec<String> {
]
}

fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

/// Plain SHA256 (NOT git-blob) of the content — used as an independent
/// oracle for the on-disk file after apply. The marker grep alone only
/// proves the marker is *somewhere* in the file; comparing the full
Expand Down
8 changes: 4 additions & 4 deletions crates/socket-patch-cli/tests/e2e_embedded_vex.rs
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,10 @@
//! All offline: `apply` runs against a pre-seeded `.socket/blobs/` cache,
//! and the `scan` cases find zero installed packages so no API call fires.

#[path = "common/mod.rs"]
mod common;
use common::binary;

use std::collections::HashMap;
use std::path::Path;
use std::process::Command;
Expand All @@ -20,10 +24,6 @@ use socket_patch_core::manifest::schema::{
PatchFileInfo, PatchManifest, PatchRecord, VulnerabilityInfo,
};

fn binary() -> &'static str {
env!("CARGO_BIN_EXE_socket-patch")
}

/// Build a `Command` for the CLI with the entire `SOCKET_*` environment
/// scrubbed from the child process.
///
Expand Down
21 changes: 5 additions & 16 deletions crates/socket-patch-cli/tests/e2e_gem.rs
Original file line number Diff line number Diff line change
Expand Up @@ -18,15 +18,17 @@
//! cargo test -p socket-patch-cli --test e2e_gem -- --ignored
//! ```

#[path = "common/mod.rs"]
mod common;
use common::{binary, git_sha256};

use std::path::{Path, PathBuf};
use std::process::{Command, Output};

use sha2::{Digest, Sha256};
use wiremock::matchers::{method, path_regex};
use wiremock::{Mock, MockServer, ResponseTemplate};

#[path = "common/cache_env.rs"]
mod cache_env;
use common::cache_env;

// ---------------------------------------------------------------------------
// Constants
Expand All @@ -42,10 +44,6 @@ const GEM_PURL: &str = "pkg:gem/activestorage@5.2.0?platform=ruby";
// Helpers
// ---------------------------------------------------------------------------

fn binary() -> PathBuf {
env!("CARGO_BIN_EXE_socket-patch").into()
}

fn has_command(cmd: &str) -> bool {
let mut probe = Command::new(cmd);
probe.arg("--version");
Expand All @@ -57,15 +55,6 @@ fn has_command(cmd: &str) -> bool {
.is_ok()
}

/// Compute Git SHA-256: `SHA256("blob <len>\0" ++ content)`.
fn git_sha256(content: &[u8]) -> String {
let header = format!("blob {}\0", content.len());
let mut hasher = Sha256::new();
hasher.update(header.as_bytes());
hasher.update(content);
hex::encode(hasher.finalize())
}

fn git_sha256_file(path: &Path) -> String {
let content = std::fs::read(path).unwrap_or_else(|e| panic!("read {}: {e}", path.display()));
git_sha256(&content)
Expand Down
Loading
Loading