| 1 | package plugin |
| 2 | |
| 3 | import ( |
| 4 | "strings" |
| 5 | "testing" |
| 6 | |
| 7 | "reasonix/internal/sandbox" |
| 8 | ) |
| 9 | |
| 10 | // TestWrapConfinedCommandFailsClosedWhenBackendUnavailable pins the fail-closed |
| 11 | // contract for confined MCP processes: when the mode is enforce and the OS |
| 12 | // sandbox backend cannot wrap the command, launching must error instead of |
| 13 | // silently degrading to an unsandboxed process. |
| 14 | func TestWrapConfinedCommandFailsClosedWhenBackendUnavailable(t *testing.T) { |
| 15 | spec := sandbox.Spec{Mode: "enforce"} |
| 16 | _, err := wrapConfinedCommand("my-server", spec, []string{"node", "server.js"}, |
| 17 | func(sandbox.Spec, []string) ([]string, bool) { |
| 18 | return []string{"node", "server.js"}, false |
| 19 | }) |
| 20 | if err == nil { |
| 21 | t.Fatal("confined + enforce + wrapped=false must fail closed, got nil error") |
| 22 | } |
| 23 | if !strings.Contains(err.Error(), `"my-server"`) { |
| 24 | t.Fatalf("error must name the plugin, got %q", err) |
| 25 | } |
| 26 | if !strings.Contains(err.Error(), "sandbox backend") { |
| 27 | t.Fatalf("error must explain the sandbox backend is unavailable, got %q", err) |
| 28 | } |
| 29 | } |
| 30 | |
| 31 | // TestWrapConfinedCommandUsesWrappedArgv verifies a confined process with an |
| 32 | // available backend runs the sandbox-wrapped argv. |
| 33 | func TestWrapConfinedCommandUsesWrappedArgv(t *testing.T) { |
| 34 | spec := sandbox.Spec{Mode: "enforce"} |
| 35 | got, err := wrapConfinedCommand("my-server", spec, []string{"node", "server.js"}, |
| 36 | func(sandbox.Spec, []string) ([]string, bool) { |
| 37 | return []string{"bwrap", "--ro-bind", "/", "/", "node", "server.js"}, true |
| 38 | }) |
| 39 | if err != nil { |
| 40 | t.Fatalf("wrapped=true must succeed, got %v", err) |
| 41 | } |
| 42 | if len(got) != 6 || got[0] != "bwrap" { |
| 43 | t.Fatalf("argv = %v, want the sandbox-wrapped argv", got) |
| 44 | } |
| 45 | } |
| 46 | |
| 47 | // TestWrapConfinedCommandAllowsUnwrappedWhenNotEnforced verifies a sandbox |
| 48 | // spec that does not enforce (e.g. host mode) keeps the raw launch argv and |
| 49 | // never fails closed — the product behavior for authorized user installs. |
| 50 | func TestWrapConfinedCommandAllowsUnwrappedWhenNotEnforced(t *testing.T) { |
| 51 | spec := sandbox.Spec{Mode: "host"} |
| 52 | launchArgs := []string{"node", "server.js"} |
| 53 | got, err := wrapConfinedCommand("my-server", spec, launchArgs, |
| 54 | func(sandbox.Spec, []string) ([]string, bool) { |
| 55 | return []string{"node", "server.js"}, false |
| 56 | }) |
| 57 | if err != nil { |
| 58 | t.Fatalf("non-enforce mode must not fail closed, got %v", err) |
| 59 | } |
| 60 | if got[0] != "node" { |
| 61 | t.Fatalf("argv = %v, want the unchanged launch argv", got) |
| 62 | } |
| 63 | } |
| 64 |