| 1 | package boot |
| 2 | |
| 3 | import ( |
| 4 | "os" |
| 5 | "os/exec" |
| 6 | "path/filepath" |
| 7 | "runtime" |
| 8 | "strings" |
| 9 | "testing" |
| 10 | |
| 11 | "reasonix/internal/config" |
| 12 | "reasonix/internal/sandbox" |
| 13 | ) |
| 14 | |
| 15 | func TestRuntimeForbidReadRootsCoverServeLaunchTokens(t *testing.T) { |
| 16 | t.Setenv("REASONIX_HOME", filepath.Join(isolateConfigHome(t), "reasonix-home")) |
| 17 | tokenFile := filepath.Join(t.TempDir(), "serve.token") |
| 18 | config.RegisterHostSecretPath(tokenFile) |
| 19 | |
| 20 | got := runtimeForbidReadRootsForGOOS(config.Default(), ".", "darwin") |
| 21 | for _, want := range []string{config.RemoteStateDir(), tokenFile} { |
| 22 | if !pathListContains(got, want) { |
| 23 | t.Fatalf("runtime forbid roots = %v, missing %s", got, want) |
| 24 | } |
| 25 | } |
| 26 | if windows := runtimeForbidReadRootsForGOOS(config.Default(), ".", "windows"); pathListContains(windows, tokenFile) { |
| 27 | t.Fatalf("Windows runtime forbid roots = %v; the host ACL model cannot deny them", windows) |
| 28 | } |
| 29 | } |
| 30 | |
| 31 | func TestSandboxedShellCannotReadServeLaunchTokens(t *testing.T) { |
| 32 | if runtime.GOOS == "windows" || !sandbox.Available() { |
| 33 | t.Skip("OS sandbox unavailable") |
| 34 | } |
| 35 | isolateConfigHome(t) |
| 36 | // Every file sits inside the write root: Linux masks /tmp with a tmpfs, so a |
| 37 | // file anywhere else under it would read as missing whether denied or not. |
| 38 | work := robustTempDir(t) |
| 39 | t.Setenv("REASONIX_HOME", filepath.Join(work, "reasonix-home")) |
| 40 | remoteDir := config.RemoteStateDir() |
| 41 | if err := os.MkdirAll(remoteDir, 0o700); err != nil { |
| 42 | t.Fatal(err) |
| 43 | } |
| 44 | const secret = "launch-token-sentinel" |
| 45 | remoteToken := filepath.Join(remoteDir, "serve-demo.token") |
| 46 | flagToken := filepath.Join(work, "serve.token") |
| 47 | visible := filepath.Join(work, "visible.txt") |
| 48 | for _, path := range []string{remoteToken, flagToken, visible} { |
| 49 | if err := os.WriteFile(path, []byte(secret), 0o600); err != nil { |
| 50 | t.Fatal(err) |
| 51 | } |
| 52 | } |
| 53 | config.RegisterHostSecretPath(flagToken) |
| 54 | |
| 55 | spec := sandbox.Spec{Mode: "enforce", WriteRoots: []string{work}, ForbidReadRoots: RuntimeForbidReadRoots(config.Default(), work), Network: true} |
| 56 | read := func(path string) (string, error) { |
| 57 | argv, wrapped := sandbox.Command(spec, sandbox.Shell{Kind: sandbox.ShellBash, Path: "bash"}, "cat "+path) |
| 58 | if !wrapped { |
| 59 | t.Fatal("sandbox did not wrap the command") |
| 60 | } |
| 61 | out, err := exec.Command(argv[0], argv[1:]...).CombinedOutput() |
| 62 | return string(out), err |
| 63 | } |
| 64 | if out, err := read(visible); err != nil || !strings.Contains(out, secret) { |
| 65 | t.Fatalf("control read = %q, %v; the sandbox must still read ordinary files", out, err) |
| 66 | } |
| 67 | for _, path := range []string{remoteToken, flagToken} { |
| 68 | if out, err := read(path); err == nil || strings.Contains(out, secret) { |
| 69 | t.Fatalf("sandboxed read of %s = %q, %v; want denied", path, out, err) |
| 70 | } |
| 71 | } |
| 72 | } |
| 73 |