5d893c1dc6
Docker / build (push) Has been cancelled
Build / build (push) Has been cancelled
Lint / ruff (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.11) (push) Has been cancelled
Test / pytest (ubuntu-latest, 3.12) (push) Has been cancelled
Test / pytest (windows-latest, 3.11) (push) Has been cancelled
Test / pytest (windows-latest, 3.12) (push) Has been cancelled
68 lines
2.3 KiB
Python
68 lines
2.3 KiB
Python
from __future__ import annotations
|
|
|
|
import runpy
|
|
from collections.abc import Callable
|
|
from pathlib import Path
|
|
from typing import cast
|
|
|
|
import pytest
|
|
|
|
PATCH_SCRIPT = (
|
|
Path(__file__).parents[1]
|
|
/ "EvoScientist"
|
|
/ "native_sandbox_runtime"
|
|
/ "patch_merged_usr.py"
|
|
)
|
|
|
|
|
|
def test_patch_skips_only_symlink_aliases_covered_by_read_allow(tmp_path: Path):
|
|
namespace = runpy.run_path(str(PATCH_SCRIPT))
|
|
patch_file = cast(Callable[[Path], None], namespace["patch_file"])
|
|
|
|
source = tmp_path / "linux-sandbox-utils.js"
|
|
source.write_text(
|
|
"""function pushReadDenyDirMounts(args, normalizedPath, allowedWritePaths, readAllowPaths) {
|
|
const denySep = normalizedPath === '/' ? '/' : normalizedPath + '/';
|
|
args.push('--tmpfs', normalizedPath);
|
|
for (const writePath of allowedWritePaths) {
|
|
if (writePath.startsWith(denySep) || writePath === normalizedPath) {
|
|
args.push('--bind', writePath, writePath);
|
|
}
|
|
}
|
|
for (const allowPath of readAllowPaths) {
|
|
if (allowPath.startsWith(denySep) || allowPath === normalizedPath) {
|
|
if (!fs.existsSync(allowPath)) {
|
|
continue;
|
|
}
|
|
if (allowedWritePaths.some(w => (w.startsWith(denySep) || w === normalizedPath) &&
|
|
(allowPath === w || allowPath.startsWith(w + '/')))) {
|
|
continue;
|
|
}
|
|
args.push('--ro-bind', allowPath, allowPath);
|
|
logForDebugging(`[Sandbox Linux] Re-allowed read access within denied region: ${allowPath}`);
|
|
}
|
|
}
|
|
}
|
|
const rootSkip = new Set(['proc', 'dev', 'sys']);
|
|
for (const p of readConfig?.denyOnly || []) {
|
|
if (normalizePathForSandbox(p) === '/') {
|
|
for (const child of fs.readdirSync('/')) {
|
|
if (!rootSkip.has(child))
|
|
readDenyPaths.push('/' + child);
|
|
}
|
|
}
|
|
""",
|
|
encoding="utf-8",
|
|
)
|
|
|
|
patch_file(source)
|
|
patched = source.read_text(encoding="utf-8")
|
|
|
|
assert "isSymbolicLink()" in patched
|
|
assert "readAllowPaths.some" in patched
|
|
assert "resolved.startsWith(allowPath + '/')" in patched
|
|
assert "args.push('--remount-ro', normalizedPath)" in patched
|
|
assert "!allowedWritePaths.includes(normalizedPath)" in patched
|
|
with pytest.raises(RuntimeError, match="already patched"):
|
|
patch_file(source)
|