|
8 | 8 | APP_UPDATE_SESSION_KEY, |
9 | 9 | AppUpdateError, |
10 | 10 | DEFAULT_MANIFEST_URL, |
| 11 | + applyAppUpdate, |
| 12 | + assertSafeUpdatePath, |
11 | 13 | checkAppUpdate, |
12 | 14 | compareSemver, |
13 | 15 | downloadAndVerify, |
@@ -699,3 +701,112 @@ describe('showUpdateInFolder', () => { |
699 | 701 | expect(showInFolder).toHaveBeenCalledWith('/tmp/ok-updates/OnlyKey.exe'); |
700 | 702 | }); |
701 | 703 | }); |
| 704 | + |
| 705 | +describe('applyAppUpdate', () => { |
| 706 | + const body = new Uint8Array([1, 2, 3]); |
| 707 | + const hash = sha256(body); |
| 708 | + |
| 709 | + it('re-hashes, spawns, then quits on win32 (19)', async () => { |
| 710 | + const tmp = path.join(os.tmpdir(), 'ok-apply-win'); |
| 711 | + const dest = path.join(tmp, 'OnlyKey.exe'); |
| 712 | + const spawnInstaller = vi.fn().mockResolvedValue(undefined); |
| 713 | + const quitApp = vi.fn(); |
| 714 | + const showInFolder = vi.fn(); |
| 715 | + await applyAppUpdate(dest, { sha256: hash }, { |
| 716 | + platform: () => 'win32', |
| 717 | + tmpDir: () => tmp, |
| 718 | + readFile: () => body, |
| 719 | + spawnInstaller, |
| 720 | + quitApp, |
| 721 | + showInFolder, |
| 722 | + applyDelayMs: 0, |
| 723 | + }); |
| 724 | + expect(spawnInstaller).toHaveBeenCalledWith(path.resolve(dest), 'win32'); |
| 725 | + expect(quitApp).toHaveBeenCalledOnce(); |
| 726 | + expect(showInFolder).not.toHaveBeenCalled(); |
| 727 | + }); |
| 728 | + |
| 729 | + it('refuses a tampered dest file and unlinks (19b)', async () => { |
| 730 | + const tmp = path.join(os.tmpdir(), 'ok-apply-tamper'); |
| 731 | + const dest = path.join(tmp, 'OnlyKey.exe'); |
| 732 | + const unlink = vi.fn(); |
| 733 | + const spawnInstaller = vi.fn(); |
| 734 | + const quitApp = vi.fn(); |
| 735 | + await expect( |
| 736 | + applyAppUpdate(dest, { sha256: hash }, { |
| 737 | + platform: () => 'win32', |
| 738 | + tmpDir: () => tmp, |
| 739 | + readFile: () => new Uint8Array([9, 9, 9]), |
| 740 | + unlink, |
| 741 | + spawnInstaller, |
| 742 | + quitApp, |
| 743 | + applyDelayMs: 0, |
| 744 | + }), |
| 745 | + ).rejects.toMatchObject({ code: 'sha256-mismatch' }); |
| 746 | + expect(unlink).toHaveBeenCalled(); |
| 747 | + expect(spawnInstaller).not.toHaveBeenCalled(); |
| 748 | + expect(quitApp).not.toHaveBeenCalled(); |
| 749 | + }); |
| 750 | + |
| 751 | + it('rejects destPath outside tmpDir, ADS names, and wrong extension (19c)', () => { |
| 752 | + const tmp = path.join(os.tmpdir(), 'ok-apply-safe'); |
| 753 | + expect(() => |
| 754 | + assertSafeUpdatePath(path.join(os.tmpdir(), 'other', 'OnlyKey.exe'), tmp, 'win32'), |
| 755 | + ).toThrow(/outside/); |
| 756 | + expect(() => assertSafeUpdatePath(path.join(tmp, 'OnlyKey.exe:ads'), tmp, 'win32')).toThrow( |
| 757 | + /not allowed/, |
| 758 | + ); |
| 759 | + expect(() => assertSafeUpdatePath(path.join(tmp, 'OnlyKey.dmg'), tmp, 'win32')).toThrow( |
| 760 | + /file type/, |
| 761 | + ); |
| 762 | + }); |
| 763 | + |
| 764 | + it('spawns open / xdg-open then quits on darwin and linux (20)', async () => { |
| 765 | + const spawnInstaller = vi.fn().mockResolvedValue(undefined); |
| 766 | + const quitApp = vi.fn(); |
| 767 | + const macTmp = path.join(os.tmpdir(), 'ok-apply-mac'); |
| 768 | + const macDest = path.join(macTmp, 'OnlyKey.dmg'); |
| 769 | + await applyAppUpdate(macDest, { sha256: hash }, { |
| 770 | + platform: () => 'darwin', |
| 771 | + tmpDir: () => macTmp, |
| 772 | + readFile: () => body, |
| 773 | + spawnInstaller, |
| 774 | + quitApp, |
| 775 | + applyDelayMs: 0, |
| 776 | + }); |
| 777 | + expect(spawnInstaller).toHaveBeenCalledWith(path.resolve(macDest), 'darwin'); |
| 778 | + |
| 779 | + const linTmp = path.join(os.tmpdir(), 'ok-apply-lin'); |
| 780 | + const linDest = path.join(linTmp, 'OnlyKey.deb'); |
| 781 | + await applyAppUpdate(linDest, { sha256: hash }, { |
| 782 | + platform: () => 'linux', |
| 783 | + tmpDir: () => linTmp, |
| 784 | + readFile: () => body, |
| 785 | + spawnInstaller, |
| 786 | + quitApp, |
| 787 | + applyDelayMs: 0, |
| 788 | + }); |
| 789 | + expect(spawnInstaller).toHaveBeenCalledWith(path.resolve(linDest), 'linux'); |
| 790 | + expect(quitApp).toHaveBeenCalledTimes(2); |
| 791 | + }); |
| 792 | + |
| 793 | + it('shows the folder and does not quit when spawn fails (21)', async () => { |
| 794 | + const tmp = path.join(os.tmpdir(), 'ok-apply-fail'); |
| 795 | + const dest = path.join(tmp, 'OnlyKey.exe'); |
| 796 | + const showInFolder = vi.fn(); |
| 797 | + const quitApp = vi.fn(); |
| 798 | + await expect( |
| 799 | + applyAppUpdate(dest, { sha256: hash }, { |
| 800 | + platform: () => 'win32', |
| 801 | + tmpDir: () => tmp, |
| 802 | + readFile: () => body, |
| 803 | + spawnInstaller: vi.fn().mockRejectedValue(new Error('ENOENT')), |
| 804 | + showInFolder, |
| 805 | + quitApp, |
| 806 | + applyDelayMs: 0, |
| 807 | + }), |
| 808 | + ).rejects.toMatchObject({ code: 'apply-failed' }); |
| 809 | + expect(showInFolder).toHaveBeenCalled(); |
| 810 | + expect(quitApp).not.toHaveBeenCalled(); |
| 811 | + }); |
| 812 | +}); |
0 commit comments