Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Create 'security' directory test should try writing files too #3941

Merged
merged 1 commit into from
Dec 14, 2021

Conversation

yim-lee
Copy link
Contributor

@yim-lee yim-lee commented Dec 13, 2021

Motivation:
Source compat test continues to fail even with #3928:

"You don’t have permission to save the file “fingerprints” in the folder “security”

https://ci.swift.org/job/swift-PR-source-compat-suite/5709/artifact/

The tests we did with #3938 shows that we can create directories but not write files.

Modifications:
Test creating security directory and writing file in it, and disable TOFU feature if the test fails.

Motivation:
Source compat test continues to fail even with swiftlang#3928:

```
"You don’t have permission to save the file “fingerprints” in the folder “security”
```

https://ci.swift.org/job/swift-PR-source-compat-suite/5709/artifact/

The tests we did with swiftlang#3938 shows that we can create directories but not write files.

Modifications:
Test creating `security` directory and writing file in it, and disable TOFU feature if the test fails.
@yim-lee
Copy link
Contributor Author

yim-lee commented Dec 13, 2021

@swift-ci please smoke test

@yim-lee yim-lee self-assigned this Dec 13, 2021
@tomerd
Copy link
Contributor

tomerd commented Dec 13, 2021

thanks @yim-lee

@yim-lee yim-lee changed the title [DO NOT MERGE] Create 'security' directory test should try writing files too Create 'security' directory test should try writing files too Dec 14, 2021
@yim-lee
Copy link
Contributor Author

yim-lee commented Dec 14, 2021

Source compat test passes with this change: https://ci.swift.org/job/swift-PR-source-compat-suite/5716/

There was a warning message (e.g., https://ci.swift.org/job/swift-PR-source-compat-suite/5716/artifact/swift-source-compat-suite/PASS_swift-crypto_5.0_BuildSwiftPackage.log):

warning: Failed creating shared security directory: unknown system error while operating on /Users/buildnode/.swiftpm/security.lock

So TOFU was disabled as expected.

I will merge this PR tomorrow morning.

@yim-lee yim-lee merged commit b057481 into swiftlang:main Dec 14, 2021
@yim-lee yim-lee deleted the lock-security branch December 14, 2021 17:47
yim-lee added a commit to yim-lee/swift-package-manager that referenced this pull request Dec 14, 2021
…ang#3941)

Motivation:
Source compat test continues to fail even with swiftlang#3928:

```
"You don’t have permission to save the file “fingerprints” in the folder “security”
```

https://ci.swift.org/job/swift-PR-source-compat-suite/5709/artifact/

The tests we did with swiftlang#3938 shows that we can create directories but not write files.

Modifications:
Test creating `security` directory and writing file in it, and disable TOFU feature if the test fails.
yim-lee added a commit that referenced this pull request Dec 15, 2021
* Disable fingerprint checking when storage is not available

Motivation:

Source compat test failure: https://ci.swift.org/job/swift-PR-source-compat-suite/5701/artifact/swift-source-compat-suite/

```
error: Failed to get source control fingerprint for swift-log remoteSourceControl /~https://github.com/apple/swift-log.git version 1.4.2 from storage: Error Domain=NSCocoaErrorDomain Code=513 "You don't have permission to save the file "fingerprints" in the folder "security"." UserInfo={NSFilePath=/Users/buildnode/.swiftpm/security/fingerprints, NSUnderlyingError=0x7feaae439370 {Error Domain=NSPOSIXErrorDomain Code=1 "Operation not permitted"}}
error: Error Domain=NSCocoaErrorDomain Code=513 "You don't have permission to save the file "fingerprints" in the folder "security"." UserInfo={NSFilePath=/Users/buildnode/.swiftpm/security/fingerprints, NSUnderlyingError=0x7feaae439370 {Error Domain=NSPOSIXErrorDomain Code=1 "Operation not permitted"}}
```

Modifications:
- Make `PackageFingerprintStorage` optional in `RegistryClient` and `SourceControlPackageContainer`, which would turn off fingerprint read/write and essentially disable the TOFU feature.
- `SwiftTool` will try to create the shared security directory (under which fingerprints are stored), and if it fails (e.g., permission errors) set `PackageFingerprintStorage` to none.
- Don't perform integrity check on fingerprint write. The validation failure will happen on read.

* Throw fingerprint write errors

Per review feedback, reverting part of the changes introduced in #3928.

* Create 'security' directory test should try writing files too (#3941)

Motivation:
Source compat test continues to fail even with #3928:

```
"You don’t have permission to save the file “fingerprints” in the folder “security”
```

https://ci.swift.org/job/swift-PR-source-compat-suite/5709/artifact/

The tests we did with #3938 shows that we can create directories but not write files.

Modifications:
Test creating `security` directory and writing file in it, and disable TOFU feature if the test fails.

* Fix test that fails to compile (#3936)

Co-authored-by: Doug Gregor <dgregor@apple.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants