fix: seal P1 acceptance process boundaries
This commit is contained in:
+57
-10
@@ -1,23 +1,70 @@
|
||||
#!/usr/bin/env bash
|
||||
#!/bin/bash
|
||||
set -euo pipefail
|
||||
repo_root="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd -P)"
|
||||
script_path=${BASH_SOURCE[0]}
|
||||
script_dir=${script_path%/*}
|
||||
[[ "$script_dir" != "$script_path" ]] || script_dir=.
|
||||
repo_root="$(cd -P -- "$script_dir/.." && pwd)"
|
||||
if [[ $# -lt 1 || "$1" != "integration" || $# -gt 2 || ( $# -eq 2 && "$2" != "--keep" ) ]]; then
|
||||
printf 'usage: %s integration [--keep]\n' "$0" >&2
|
||||
exit 2
|
||||
fi
|
||||
for command in node npm git python3; do command -v "$command" >/dev/null || { printf 'missing command: %s\n' "$command" >&2; exit 127; }; done
|
||||
node_command="$(command -v node)"
|
||||
node_bin="$(cd "$(dirname "$node_command")" && pwd -P)/$(basename "$node_command")"
|
||||
THT_BIN="${THT_BIN:-$repo_root/harness/.venv/bin/tht}"
|
||||
[[ "$THT_BIN" = /* && -x "$THT_BIN" ]] || { printf 'THT_BIN must be an absolute executable path\n' >&2; exit 127; }
|
||||
npm --prefix "$repo_root/backend" run build
|
||||
safe_env=(env -i "PATH=/usr/bin:/bin" "HOME=/nonexistent" "TMPDIR=/tmp" "LANG=${LANG:-C}" "THT_BIN=$THT_BIN")
|
||||
|
||||
canonical_file() {
|
||||
local path=$1 target parent leaf
|
||||
[[ "$path" = /* ]] || return 1
|
||||
while [[ -L "$path" ]]; do
|
||||
target=$(/usr/bin/readlink "$path") || return 1
|
||||
if [[ "$target" = /* ]]; then path=$target; else path="${path%/*}/$target"; fi
|
||||
done
|
||||
parent=${path%/*}; leaf=${path##*/}
|
||||
parent=$(cd -P -- "$parent" && pwd) || return 1
|
||||
printf '%s/%s\n' "$parent" "$leaf"
|
||||
}
|
||||
|
||||
node_path= npm_path= toolchain_prefix=
|
||||
for pair in \
|
||||
"/usr/bin/node|/usr/bin/npm|/usr" \
|
||||
"/opt/homebrew/bin/node|/opt/homebrew/bin/npm|/opt/homebrew" \
|
||||
"/usr/local/bin/node|/usr/local/bin/npm|/usr/local"; do
|
||||
node_candidate=${pair%%|*}; remainder=${pair#*|}; npm_candidate=${remainder%%|*}; prefix=${remainder##*|}
|
||||
[[ -e "$node_candidate" && -e "$npm_candidate" ]] || continue
|
||||
resolved_node=$(canonical_file "$node_candidate") || continue
|
||||
resolved_npm=$(canonical_file "$npm_candidate") || continue
|
||||
[[ -f "$resolved_node" && ! -L "$resolved_node" && -x "$resolved_node" ]] || continue
|
||||
[[ -f "$resolved_npm" && ! -L "$resolved_npm" ]] || continue
|
||||
[[ "${resolved_npm##*/}" = "npm-cli.js" ]] || continue
|
||||
case "$prefix|$resolved_node|$resolved_npm" in
|
||||
"/usr|/usr/bin/node|/usr/"*"/npm/bin/npm-cli.js"| "/opt/homebrew|/opt/homebrew/Cellar/node/"*"/bin/node|/opt/homebrew/lib/node_modules/npm/bin/npm-cli.js"| "/usr/local|/usr/local/"*"node"*"|/usr/local/lib/node_modules/npm/bin/npm-cli.js") ;;
|
||||
*) continue ;;
|
||||
esac
|
||||
{ IFS= read -r npm_header; IFS= read -r npm_bootstrap; } < "$resolved_npm"
|
||||
[[ "$npm_header" = '#!/usr/bin/env node' && "$npm_bootstrap" = "require('../lib/cli.js')(process)" ]] || continue
|
||||
node_path=$resolved_node; npm_path=$resolved_npm; toolchain_prefix=$prefix
|
||||
break
|
||||
done
|
||||
[[ -n "$node_path" && -n "$npm_path" && -n "$toolchain_prefix" ]] || {
|
||||
printf 'trusted fixed Node/npm toolchain is unavailable\n' >&2
|
||||
exit 127
|
||||
}
|
||||
|
||||
wrapper_root=$(/usr/bin/mktemp -d /tmp/thoth-p1-wrapper.XXXXXXXX)
|
||||
trap '/bin/rm -rf -- "$wrapper_root"' EXIT HUP INT TERM
|
||||
/bin/mkdir -m 700 "$wrapper_root/home" "$wrapper_root/tmp"
|
||||
owned_path="${node_path%/*}:/usr/bin:/bin"
|
||||
build_env=(/usr/bin/env -i "PATH=$owned_path" "HOME=$wrapper_root/home" "TMPDIR=$wrapper_root/tmp" "LANG=${LANG:-C}")
|
||||
for name in LC_ALL TZ; do
|
||||
[[ -n "${!name:-}" ]] && build_env+=("$name=${!name}")
|
||||
done
|
||||
"${build_env[@]}" "$node_path" "$npm_path" --prefix "$repo_root/backend" run build
|
||||
|
||||
safe_env=(/usr/bin/env -i "PATH=$owned_path" "HOME=$wrapper_root/home" "TMPDIR=$wrapper_root/tmp" "LANG=${LANG:-C}"
|
||||
"THT_BIN=$repo_root/harness/.venv/bin/tht" "P1_ACCEPTANCE_NODE_PATH=$node_path" "P1_ACCEPTANCE_NPM_PATH=$npm_path")
|
||||
for name in LC_ALL TZ; do
|
||||
[[ -n "${!name:-}" ]] && safe_env+=("$name=${!name}")
|
||||
done
|
||||
[[ -n "${P1_ACCEPTANCE_FAIL_AT:-}" ]] && safe_env+=("P1_ACCEPTANCE_FAIL_AT=$P1_ACCEPTANCE_FAIL_AT")
|
||||
set +e
|
||||
"${safe_env[@]}" "$node_bin" "$repo_root/backend/scripts/p1-acceptance.mjs" "$@"
|
||||
"${safe_env[@]}" "$node_path" "$repo_root/backend/scripts/p1-acceptance.mjs" "$@"
|
||||
status=$?
|
||||
set -e
|
||||
exit "$status"
|
||||
|
||||
Reference in New Issue
Block a user