compose: add wrapper-first dogfood workspace (#1488)
ci/woodpecker/push/publish Pipeline was successful
ci/woodpecker/push/publish Pipeline was successful
Co-authored-by: marcie <[email protected]>
This commit was merged in pull request #1488.
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { guardPath, guardPathUnsafe, SandboxEscapeError } from './path-guard.js';
|
||||
import { guardPath, guardPathUnsafe, guardWritePath, SandboxEscapeError } from './path-guard.js';
|
||||
import path from 'node:path';
|
||||
import os from 'node:os';
|
||||
import fs from 'node:fs';
|
||||
@@ -101,4 +101,55 @@ describe('guardPath', () => {
|
||||
fs.rmSync(tmpDir, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
it('rejects a symlink inside the sandbox that resolves outside it', () => {
|
||||
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'path-guard-test-'));
|
||||
const outside = fs.mkdtempSync(path.join(os.tmpdir(), 'path-guard-outside-'));
|
||||
try {
|
||||
const target = path.join(outside, 'credential.token');
|
||||
fs.writeFileSync(target, 'OUTSIDE_SYMLINK_SENTINEL');
|
||||
fs.symlinkSync(target, path.join(tmpDir, 'credential.token'));
|
||||
expect(() => guardPath('credential.token', tmpDir)).toThrow(SandboxEscapeError);
|
||||
} finally {
|
||||
fs.rmSync(tmpDir, { recursive: true, force: true });
|
||||
fs.rmSync(outside, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
describe('guardWritePath', () => {
|
||||
it('allows a new file under an existing real sandbox directory', () => {
|
||||
const sandbox = fs.mkdtempSync(path.join(os.tmpdir(), 'path-write-test-'));
|
||||
try {
|
||||
expect(guardWritePath('new.txt', sandbox)).toBe(path.join(sandbox, 'new.txt'));
|
||||
} finally {
|
||||
fs.rmSync(sandbox, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
it('rejects writes through a file symlink that resolves outside the sandbox', () => {
|
||||
const sandbox = fs.mkdtempSync(path.join(os.tmpdir(), 'path-write-test-'));
|
||||
const outside = fs.mkdtempSync(path.join(os.tmpdir(), 'path-write-outside-'));
|
||||
try {
|
||||
const target = path.join(outside, 'credential.token');
|
||||
fs.writeFileSync(target, 'OUTSIDE_WRITE_SENTINEL');
|
||||
fs.symlinkSync(target, path.join(sandbox, 'credential.token'));
|
||||
expect(() => guardWritePath('credential.token', sandbox)).toThrow(SandboxEscapeError);
|
||||
} finally {
|
||||
fs.rmSync(sandbox, { recursive: true, force: true });
|
||||
fs.rmSync(outside, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
it('rejects new files under a directory symlink that leaves the sandbox', () => {
|
||||
const sandbox = fs.mkdtempSync(path.join(os.tmpdir(), 'path-write-test-'));
|
||||
const outside = fs.mkdtempSync(path.join(os.tmpdir(), 'path-write-outside-'));
|
||||
try {
|
||||
fs.symlinkSync(outside, path.join(sandbox, 'outside'));
|
||||
expect(() => guardWritePath('outside/new.txt', sandbox)).toThrow(SandboxEscapeError);
|
||||
} finally {
|
||||
fs.rmSync(sandbox, { recursive: true, force: true });
|
||||
fs.rmSync(outside, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user