返回 DeepSeek-Reasonix
host_secret_roots_test.go
根目录 / internal / boot / host_secret_roots_test.go
1 package boot
2
3 import (
4 "os"
5 "os/exec"
6 "path/filepath"
7 "runtime"
8 "strings"
9 "testing"
10
11 "reasonix/internal/config"
12 "reasonix/internal/sandbox"
13 )
14
15 func TestRuntimeForbidReadRootsCoverServeLaunchTokens(t *testing.T) {
16 t.Setenv("REASONIX_HOME", filepath.Join(isolateConfigHome(t), "reasonix-home"))
17 tokenFile := filepath.Join(t.TempDir(), "serve.token")
18 config.RegisterHostSecretPath(tokenFile)
19
20 got := runtimeForbidReadRootsForGOOS(config.Default(), ".", "darwin")
21 for _, want := range []string{config.RemoteStateDir(), tokenFile} {
22 if !pathListContains(got, want) {
23 t.Fatalf("runtime forbid roots = %v, missing %s", got, want)
24 }
25 }
26 if windows := runtimeForbidReadRootsForGOOS(config.Default(), ".", "windows"); pathListContains(windows, tokenFile) {
27 t.Fatalf("Windows runtime forbid roots = %v; the host ACL model cannot deny them", windows)
28 }
29 }
30
31 func TestSandboxedShellCannotReadServeLaunchTokens(t *testing.T) {
32 if runtime.GOOS == "windows" || !sandbox.Available() {
33 t.Skip("OS sandbox unavailable")
34 }
35 isolateConfigHome(t)
36 // Every file sits inside the write root: Linux masks /tmp with a tmpfs, so a
37 // file anywhere else under it would read as missing whether denied or not.
38 work := robustTempDir(t)
39 t.Setenv("REASONIX_HOME", filepath.Join(work, "reasonix-home"))
40 remoteDir := config.RemoteStateDir()
41 if err := os.MkdirAll(remoteDir, 0o700); err != nil {
42 t.Fatal(err)
43 }
44 const secret = "launch-token-sentinel"
45 remoteToken := filepath.Join(remoteDir, "serve-demo.token")
46 flagToken := filepath.Join(work, "serve.token")
47 visible := filepath.Join(work, "visible.txt")
48 for _, path := range []string{remoteToken, flagToken, visible} {
49 if err := os.WriteFile(path, []byte(secret), 0o600); err != nil {
50 t.Fatal(err)
51 }
52 }
53 config.RegisterHostSecretPath(flagToken)
54
55 spec := sandbox.Spec{Mode: "enforce", WriteRoots: []string{work}, ForbidReadRoots: RuntimeForbidReadRoots(config.Default(), work), Network: true}
56 read := func(path string) (string, error) {
57 argv, wrapped := sandbox.Command(spec, sandbox.Shell{Kind: sandbox.ShellBash, Path: "bash"}, "cat "+path)
58 if !wrapped {
59 t.Fatal("sandbox did not wrap the command")
60 }
61 out, err := exec.Command(argv[0], argv[1:]...).CombinedOutput()
62 return string(out), err
63 }
64 if out, err := read(visible); err != nil || !strings.Contains(out, secret) {
65 t.Fatalf("control read = %q, %v; the sandbox must still read ordinary files", out, err)
66 }
67 for _, path := range []string{remoteToken, flagToken} {
68 if out, err := read(path); err == nil || strings.Contains(out, secret) {
69 t.Fatalf("sandboxed read of %s = %q, %v; want denied", path, out, err)
70 }
71 }
72 }
73
73 lines GO