Conversation
ValidateRootPath 会调 filepath.EvalSymlinks 解析软链——这是刻意的,
用于防止用软链绕过共享根目录校验。macOS 的 t.TempDir() 返回
/var/folders/...,它是指向 /private/var/folders/... 的符号链接,
而测试拿未解析软链的 dir 做期望值,导致断言失败:
got=/private/var/folders/... want=/var/folders/...
该失败只在含软链的系统上出现(Linux CI 无此问题),
此前一直被 CI 的绿灯掩盖。
- 期望值改为同样先 EvalSymlinks;Linux 上 /tmp 非软链,行为不变
- 新增 TestValidateRootPathResolvesSymlink:覆盖「传入软链时返回解析后
的真实路径」——这正是该函数防绕过的语义,此前无测试覆盖
验证:go test ./... 全量通过。
This was referenced Sep 30, 2026
Open
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
问题
service/storage的TestValidateRootPath在 macOS 上失败:根因
这不是被测函数的 bug,而是测试断言写错了。
ValidateRootPath会调filepath.EvalSymlinks解析软链:这是刻意设计——防止用户用软链把共享根目录指到
smb.conf等敏感文件上绕过校验。而 macOS 的
t.TempDir()返回/var/folders/...,它本身是指向/private/var/folders/...的符号链接。测试却拿未解析软链的dir做期望值:为什么一直没被发现
该失败只在路径中存在符号链接的系统上出现。GitHub Actions 跑
ubuntu-latest,/tmp不是软链,EvalSymlinks返回原值——断言恰好成立,CI 一直是绿的。也就是说,CI 的绿灯掩盖了这个测试在真实 macOS 开发环境下的失败。
修复
EvalSymlinks。Linux 上/tmp非软链,EvalSymlinks返回原值,行为与之前完全一致,不影响现有 CITestValidateRootPathResolvesSymlink,覆盖「传入指向别处的软链时,必须返回解析后的真实路径」——这正是该函数防绕过的核心语义,此前无任何测试覆盖验证
配合 #130 的编译修复,
go test ./...全量通过。建议合并顺序
本 PR 与 #130(caddy 编译错误修复)无依赖关系,可独立评审。但 #130 合入前
go test ./...无法在本地跑通——验证本 PR 时需两个都在本地。