Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 4 additions & 1 deletion cmd/coordinator/wasm_gate_server_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,10 @@ func mustOrderWasmHex(t *testing.T) string {
p := filepath.Join("..", "..", "tasks", "artifacts", "security", "rust_script_push_bounds_guard.wasm")
raw, err := os.ReadFile(p)
if err != nil {
t.Fatal(err)
if !os.IsNotExist(err) {
t.Fatal(err)
}
t.Skipf("order gate wasm %s not built (run scripts/build_security_task_pack.sh): %v", filepath.Base(p), err)
Comment thread
coderabbitai[bot] marked this conversation as resolved.
}
return hex.EncodeToString(raw)
}
Expand Down
27 changes: 25 additions & 2 deletions cmd/fuzzingclient/wizard_test.go
Original file line number Diff line number Diff line change
@@ -1,13 +1,35 @@
package main

import (
"errors"
"os"
"os/exec"
"path/filepath"
"testing"

"hackme/internal/fuzzengine"
"hackme/internal/fuzzingcli"
)

// requireSecurityWasm skips tests that depend on the rust/wasm toolchain pack when
// the artifact has not been built AND rustc is unavailable, so a Go-only checkout
// gets a clear signal instead of hard failures (same convention as internal/sandbox
// and tools/fluxtap_wasm_compare). With rustc on PATH the pre-existing behavior is
// kept: pack tests self-build via buildPackWasm, explicit-path tests fail loudly.
func requireSecurityWasm(t *testing.T, name string) string {
t.Helper()
p := filepath.Join("..", "..", "tasks", "artifacts", "security", name)
if _, err := os.Stat(p); err != nil {
if !errors.Is(err, os.ErrNotExist) {
t.Fatalf("cannot stat security wasm %s: %v", name, err)
}
if _, lerr := exec.LookPath("rustc"); lerr != nil {
t.Skipf("security wasm %s not built and rustc unavailable (run scripts/build_security_task_pack.sh; toolchain: docs/RUST_CPP_TASKS_QUICKSTART.md): %v", name, err)
Comment thread
coderabbitai[bot] marked this conversation as resolved.
}
}
return p
}

func TestWizardRefusesPublicBase(t *testing.T) {
if fuzzingcli.IsLoopbackBase("https://hackme.tech") {
t.Fatal("hackme.tech must not be loopback")
Expand All @@ -19,7 +41,7 @@ func TestWizardRefusesPublicBase(t *testing.T) {
}

func TestWizardDryRunScanPackage(t *testing.T) {
wasm := filepath.Join("..", "..", "tasks", "artifacts", "security", "rust_script_push_bounds_guard.wasm")
wasm := requireSecurityWasm(t, "rust_script_push_bounds_guard.wasm")
m, err := doWizardDryRun("scan", wasm)
if err != nil {
t.Fatal(err)
Expand All @@ -40,6 +62,7 @@ func TestWizardDryRunScanPackage(t *testing.T) {
}

func TestWizardDryRunPackSecrets(t *testing.T) {
requireSecurityWasm(t, "rust_tracefuse_detector_bytes_guard.wasm")
m, err := doWizardDryRunPack("audit", "secrets", "")
if err != nil {
t.Fatal(err)
Expand All @@ -62,7 +85,7 @@ func TestWizardDryRunPackSecrets(t *testing.T) {
}

func TestWizardDryRunPackagesDiffer(t *testing.T) {
wasm := filepath.Join("..", "..", "tasks", "artifacts", "security", "rust_script_push_bounds_guard.wasm")
wasm := requireSecurityWasm(t, "rust_script_push_bounds_guard.wasm")
scan, err := doWizardDryRun("scan", wasm)
if err != nil {
t.Fatal(err)
Expand Down
5 changes: 4 additions & 1 deletion internal/poolfuzz/service_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -140,7 +140,10 @@ func mustReadWasmHex(t *testing.T, path string) string {
t.Helper()
b, err := os.ReadFile(path)
if err != nil {
t.Fatal(err)
if !os.IsNotExist(err) {
t.Fatal(err)
}
t.Skipf("security wasm %s not built (run scripts/build_security_task_pack.sh): %v", filepath.Base(path), err)
Comment thread
qodo-code-review[bot] marked this conversation as resolved.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
}
return hex.EncodeToString(b)
}
Expand Down
5 changes: 4 additions & 1 deletion internal/sandbox/cve_guards_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -66,7 +66,10 @@ func TestScriptPushKnownViolation(t *testing.T) {
wasm := filepath.Join("..", "..", "tasks", "artifacts", "security", "rust_script_push_bounds_guard.wasm")
raw, err := os.ReadFile(wasm)
if err != nil {
t.Fatal(err)
if !os.IsNotExist(err) {
t.Fatal(err)
}
t.Skip("script push guard wasm not built (run scripts/build_security_task_pack.sh):", err)
Comment thread
coderabbitai[bot] marked this conversation as resolved.
}
ctx := context.Background()
violation := uint64(0x4c | (521 << 8))
Expand Down
6 changes: 5 additions & 1 deletion pack_e2e_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@ import (
"context"
"encoding/hex"
"encoding/json"
"errors"
"net/http"
"net/http/httptest"
"os"
Expand Down Expand Up @@ -32,7 +33,10 @@ func TestPackSecretsE2EAuditReportExplain(t *testing.T) {
cmd := exec.Command("rustc", "--target", "wasm32-unknown-unknown", "-O", "--crate-type=cdylib", src, "-o", wasmPath)
cmd.Dir = root
if out, err := cmd.CombinedOutput(); err != nil {
t.Fatalf("build wasm: %v\n%s", err, out)
if !errors.Is(err, exec.ErrNotFound) {
t.Fatalf("build wasm: %v\n%s", err, out)
}
t.Skipf("rustc/wasm32 toolchain unavailable (run scripts/build_security_task_pack.sh; see docs/RUST_CPP_TASKS_QUICKSTART.md): %v\n%s", err, out)
}
}
raw, err := os.ReadFile(wasmPath)
Expand Down
Loading