Skip to content

Commit 259845b

Browse files
hsbtclaude
andcommitted
Exercise the malicious extensions check on Windows
The example built a gem on disk, and util_build_gem writes every entry of spec.files, which includes spec.extensions. On Windows the extension name embedding a newline cannot become a file name, so the example was skipped and the check went uncovered. Build the installer from the spec in memory with Installer.for_spec instead, matching the sibling non_string checks, so verify_spec still runs before the spec is eval'd without the newline ever reaching the disk. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
1 parent 13b5af4 commit 259845b

1 file changed

Lines changed: 2 additions & 10 deletions

File tree

‎test/rubygems/test_gem_installer.rb‎

Lines changed: 2 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1901,22 +1901,14 @@ def spec.validate(*args); end
19011901
end
19021902

19031903
def test_pre_install_checks_malicious_extensions_before_eval
1904-
pend "mswin environment disallow to create file contained the carriage return code." if Gem.win_platform?
1905-
19061904
spec = util_spec "malicious", "1"
1907-
def spec.full_name # so the spec is buildable
1908-
"malicious-1"
1909-
end
1910-
19111905
def spec.validate(*args); end
19121906
spec.extensions = ["malicious\n``"]
19131907

1914-
util_build_gem spec
1915-
1916-
gem = File.join(@gemhome, "cache", spec.file_name)
1908+
installer = Gem::Installer.for_spec spec
1909+
installer.gem_home = @gemhome
19171910

19181911
use_ui @ui do
1919-
installer = Gem::Installer.at gem
19201912
e = assert_raise Gem::InstallError do
19211913
installer.pre_install_checks
19221914
end

0 commit comments

Comments
 (0)