feat: prepare EvoScientist 0.3.0
Docker / build (push) Has been cancelled
Build / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
Docker / build (push) Has been cancelled
Build / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
Add bounded document ingestion, controlled web search, recoverable session support, subagent timeouts, and the native sandbox runtime contract. Unify package versioning and add release-focused regression coverage.
This commit is contained in:
@@ -1,6 +1,8 @@
|
||||
from __future__ import annotations
|
||||
|
||||
import json
|
||||
import sys
|
||||
import types
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
@@ -21,6 +23,18 @@ def _installation(tmp_path: Path) -> sandbox.NativeSandboxInstallation:
|
||||
)
|
||||
|
||||
|
||||
def test_existing_read_paths_resolve_and_deduplicate_symlink_aliases(tmp_path: Path):
|
||||
usr = tmp_path / "usr"
|
||||
usr.mkdir()
|
||||
bin_alias = tmp_path / "bin"
|
||||
bin_alias.symlink_to(usr, target_is_directory=True)
|
||||
missing = tmp_path / "missing"
|
||||
|
||||
paths = sandbox._existing_resolved_paths((str(usr), str(bin_alias), str(missing)))
|
||||
|
||||
assert paths == (str(usr.resolve()),)
|
||||
|
||||
|
||||
def test_policy_denies_root_and_only_writes_scope_and_command_tmp(tmp_path: Path):
|
||||
files = tmp_path / "files"
|
||||
command_tmp = tmp_path / "runtime" / "tmp" / "run"
|
||||
@@ -38,6 +52,7 @@ def test_policy_denies_root_and_only_writes_scope_and_command_tmp(tmp_path: Path
|
||||
"/dev/null",
|
||||
]
|
||||
assert policy["filesystem"]["denyWrite"] == [
|
||||
str(files / "uploads"),
|
||||
"/tmp/claude",
|
||||
"/private/tmp/claude",
|
||||
"/dev/tty",
|
||||
@@ -50,6 +65,48 @@ def test_policy_denies_root_and_only_writes_scope_and_command_tmp(tmp_path: Path
|
||||
assert "control" not in json.dumps(policy)
|
||||
|
||||
|
||||
def test_weaker_nested_mode_requires_explicit_environment_opt_in(tmp_path: Path, monkeypatch):
|
||||
monkeypatch.delenv("EVOSCIENTIST_NATIVE_SANDBOX_WEAKER_NESTED", raising=False)
|
||||
files = tmp_path / "files"
|
||||
command_tmp = tmp_path / "runtime" / "tmp" / "run"
|
||||
files.mkdir()
|
||||
command_tmp.mkdir(parents=True)
|
||||
installation = _installation(tmp_path)
|
||||
|
||||
assert sandbox._sandbox_settings(installation, files, command_tmp)[
|
||||
"enableWeakerNestedSandbox"
|
||||
] is False
|
||||
|
||||
monkeypatch.setenv("EVOSCIENTIST_NATIVE_SANDBOX_WEAKER_NESTED", "true")
|
||||
assert sandbox._sandbox_settings(installation, files, command_tmp)[
|
||||
"enableWeakerNestedSandbox"
|
||||
] is True
|
||||
|
||||
|
||||
def test_network_preflight_probe_accepts_kernel_denied_unix_socket(monkeypatch):
|
||||
monkeypatch.delenv("OPENAI_API_KEY", raising=False)
|
||||
|
||||
class FakeSocket:
|
||||
def __init__(self, family=None, *_args):
|
||||
if family == 1:
|
||||
raise PermissionError("blocked by seccomp")
|
||||
|
||||
def connect_ex(self, _address):
|
||||
return 1
|
||||
|
||||
def close(self):
|
||||
return None
|
||||
|
||||
fake_socket = types.SimpleNamespace(
|
||||
AF_UNIX=1,
|
||||
socket=lambda family=None, *args: FakeSocket(family, *args),
|
||||
)
|
||||
monkeypatch.setitem(sys.modules, "socket", fake_socket)
|
||||
|
||||
namespace: dict[str, object] = {}
|
||||
exec(sandbox._network_preflight_probe(1234, Path("/blocked.sock")), namespace)
|
||||
|
||||
|
||||
def test_clean_environment_does_not_inherit_secrets(tmp_path: Path, monkeypatch):
|
||||
command_tmp = tmp_path / "tmp"
|
||||
(command_tmp / "home").mkdir(parents=True)
|
||||
|
||||
Reference in New Issue
Block a user