(t *testing.T)
| 344 | } |
| 345 | |
| 346 | func TestExtractZip(t *testing.T) { |
| 347 | t.Run("extracts files correctly", func(t *testing.T) { |
| 348 | zipDir := t.TempDir() |
| 349 | zipPath := filepath.Join(zipDir, "archive.zip") |
| 350 | content := []byte("hello world") |
| 351 | archive := createZipBuffer(t, map[string][]byte{ |
| 352 | "copilot.exe": content, |
| 353 | }) |
| 354 | require.NoError(t, os.WriteFile(zipPath, archive, 0x755)) |
| 355 | |
| 356 | destDir := t.TempDir() |
| 357 | |
| 358 | err := extractZip(zipPath, destDir) |
| 359 | require.NoError(t, err, "extractZip() error") |
| 360 | |
| 361 | extracted, err := os.ReadFile(filepath.Join(destDir, "copilot.exe")) |
| 362 | require.NoError(t, err, "failed to read extracted file") |
| 363 | require.Equal(t, content, extracted, "extracted content mismatch") |
| 364 | }) |
| 365 | |
| 366 | t.Run("extracts nested files", func(t *testing.T) { |
| 367 | zipDir := t.TempDir() |
| 368 | zipPath := filepath.Join(zipDir, "archive.zip") |
| 369 | content := []byte("hello world") |
| 370 | archive := createZipBuffer(t, map[string][]byte{ |
| 371 | "subdir/file.txt": content, |
| 372 | }) |
| 373 | require.NoError(t, os.WriteFile(zipPath, archive, 0x755)) |
| 374 | |
| 375 | destDir := t.TempDir() |
| 376 | |
| 377 | err := extractZip(zipPath, destDir) |
| 378 | require.NoError(t, err, "extractZip() error") |
| 379 | |
| 380 | extracted, err := os.ReadFile(filepath.Join(destDir, "subdir", "file.txt")) |
| 381 | require.NoError(t, err, "failed to read extracted file") |
| 382 | require.Equal(t, content, extracted, "extracted content mismatch") |
| 383 | }) |
| 384 | |
| 385 | t.Run("rejects path traversal", func(t *testing.T) { |
| 386 | zipDir := t.TempDir() |
| 387 | zipPath := filepath.Join(zipDir, "archive.zip") |
| 388 | |
| 389 | var buf bytes.Buffer |
| 390 | zw := zip.NewWriter(&buf) |
| 391 | |
| 392 | fh := &zip.FileHeader{ |
| 393 | Name: "../evil.txt", |
| 394 | Method: zip.Store, |
| 395 | } |
| 396 | fw, _ := zw.CreateHeader(fh) |
| 397 | _, _ = fw.Write([]byte("evil")) |
| 398 | _ = zw.Close() |
| 399 | |
| 400 | require.NoError(t, os.WriteFile(zipPath, buf.Bytes(), 0x755)) |
| 401 | destDir := t.TempDir() |
| 402 | |
| 403 | err := extractZip(zipPath, destDir) |
nothing calls this directly
no test coverage detected