]>
Commit | Line | Data |
---|---|---|
7aba6185 MM |
1 | #!/bin/sh |
2 | # | |
3 | # Copyright (c) 2010 Matthieu Moy | |
4 | # | |
5 | ||
6 | test_description='Test repository with default ACL' | |
7 | ||
8 | # Create the test repo with restrictive umask | |
9 | # => this must come before . ./test-lib.sh | |
10 | umask 077 | |
11 | ||
12 | . ./test-lib.sh | |
13 | ||
14 | # We need an arbitrary other user give permission to using ACLs. root | |
15 | # is a good candidate: exists on all unices, and it has permission | |
16 | # anyway, so we don't create a security hole running the testsuite. | |
17 | ||
fadb5156 ÆAB |
18 | setfacl_out="$(setfacl -m u:root:rwx . 2>&1)" |
19 | setfacl_ret=$? | |
20 | ||
21 | if [ $setfacl_ret != 0 ]; then | |
22 | skip_all="Skipping ACL tests: unable to use setfacl (output: '$setfacl_out'; return code: '$setfacl_ret')" | |
23 | test_done | |
7aba6185 MM |
24 | fi |
25 | ||
7aba6185 | 26 | check_perms_and_acl () { |
71c4d6c6 | 27 | test -r "$1" && |
7aba6185 MM |
28 | getfacl "$1" > actual && |
29 | grep -q "user:root:rwx" actual && | |
30 | grep -q "user:${LOGNAME}:rwx" actual && | |
80700fde | 31 | egrep "mask::?r--" actual > /dev/null 2>&1 && |
7aba6185 MM |
32 | grep -q "group::---" actual || false |
33 | } | |
34 | ||
35 | dirs_to_set="./ .git/ .git/objects/ .git/objects/pack/" | |
36 | ||
37 | test_expect_success 'Setup test repo' ' | |
ab04a905 | 38 | setfacl -m d:u::rwx,d:g::---,d:o:---,d:m:rwx $dirs_to_set && |
2e85575a | 39 | setfacl -m m:rwx $dirs_to_set && |
7aba6185 | 40 | setfacl -m u:root:rwx $dirs_to_set && |
db826571 BC |
41 | setfacl -m d:u:"$LOGNAME":rwx $dirs_to_set && |
42 | setfacl -m d:u:root:rwx $dirs_to_set && | |
7aba6185 MM |
43 | |
44 | touch file.txt && | |
45 | git add file.txt && | |
46 | git commit -m "init" | |
47 | ' | |
48 | ||
5256b006 | 49 | test_expect_success 'Objects creation does not break ACLs with restrictive umask' ' |
7aba6185 MM |
50 | # SHA1 for empty blob |
51 | check_perms_and_acl .git/objects/e6/9de29bb2d1d6434b8b29ae775ad8c2e48c5391 | |
52 | ' | |
53 | ||
f80c7ae8 | 54 | test_expect_success 'git gc does not break ACLs with restrictive umask' ' |
7aba6185 MM |
55 | git gc && |
56 | check_perms_and_acl .git/objects/pack/*.pack | |
57 | ' | |
58 | ||
59 | test_done |