from __future__ import annotations import runpy from collections.abc import Callable from pathlib import Path from typing import cast import pytest PATCH_SCRIPT = Path(__file__).parents[1] / "runtime" / "native-sandbox" / "patch_merged_usr.py" def test_patch_skips_only_symlink_aliases_covered_by_read_allow(tmp_path: Path): namespace = runpy.run_path(str(PATCH_SCRIPT)) patch_file = cast(Callable[[Path], None], namespace["patch_file"]) source = tmp_path / "linux-sandbox-utils.js" source.write_text( """function pushReadDenyDirMounts(args, normalizedPath, allowedWritePaths, readAllowPaths) { const denySep = normalizedPath === '/' ? '/' : normalizedPath + '/'; args.push('--tmpfs', normalizedPath); for (const writePath of allowedWritePaths) { if (writePath.startsWith(denySep) || writePath === normalizedPath) { args.push('--bind', writePath, writePath); } } for (const allowPath of readAllowPaths) { if (allowPath.startsWith(denySep) || allowPath === normalizedPath) { if (!fs.existsSync(allowPath)) { continue; } if (allowedWritePaths.some(w => (w.startsWith(denySep) || w === normalizedPath) && (allowPath === w || allowPath.startsWith(w + '/')))) { continue; } args.push('--ro-bind', allowPath, allowPath); logForDebugging(`[Sandbox Linux] Re-allowed read access within denied region: ${allowPath}`); } } } const rootSkip = new Set(['proc', 'dev', 'sys']); for (const p of readConfig?.denyOnly || []) { if (normalizePathForSandbox(p) === '/') { for (const child of fs.readdirSync('/')) { if (!rootSkip.has(child)) readDenyPaths.push('/' + child); } } """, encoding="utf-8", ) patch_file(source) patched = source.read_text(encoding="utf-8") assert "isSymbolicLink()" in patched assert "readAllowPaths.some" in patched assert "resolved.startsWith(allowPath + '/')" in patched assert "args.push('--remount-ro', normalizedPath)" in patched assert "!allowedWritePaths.includes(normalizedPath)" in patched with pytest.raises(RuntimeError, match="already patched"): patch_file(source)