fix: harden native workspace root capabilities
This commit is contained in:
@@ -2,7 +2,7 @@ import { describe, expect, it, afterEach } from "vitest";
|
||||
import { mkdtempSync, renameSync, mkdirSync, rmSync, statSync, chmodSync, symlinkSync, writeFileSync } from "node:fs";
|
||||
import { join } from "node:path";
|
||||
import { WorkspaceFsAtV1 } from "../src/workspaces/workspace-fs-at.js";
|
||||
import { VerifiedWorkspaceLockRootLeaseFactory } from "../src/workspaces/workspace-lock-root-lease.js";
|
||||
import { CanonicalWorkspaceLockRootInput, VerifiedWorkspaceLockRootLeaseFactory } from "../src/workspaces/workspace-lock-root-lease.js";
|
||||
const roots: string[] = [];
|
||||
afterEach(() => { for (const root of roots.splice(0)) rmSync(root, { recursive: true, force: true }); });
|
||||
function factory(sessionsRootFromValidatedInstallationConfig: string) { return new VerifiedWorkspaceLockRootLeaseFactory({ workspaceFsAt: new WorkspaceFsAtV1(), installationId: "i", sessionsRootFromValidatedInstallationConfig, serviceUid: process.getuid!(), provisionedWorkspaceMode: 0o700 }); }
|
||||
@@ -41,4 +41,14 @@ describe("retained canonical workspace root", () => {
|
||||
await expect(outcome).rejects.toThrow(/preprocessing/);
|
||||
});
|
||||
|
||||
it("rejects forged canonical inputs even when the prototype is copied", async () => {
|
||||
const parent = mkdtempSync(join(process.cwd(), "thoth-root-")); roots.push(parent); const f = factory(parent);
|
||||
const forged = Object.assign(Object.create(CanonicalWorkspaceLockRootInput.prototype), { workspaceId: "abc-workspace" });
|
||||
await expect(f.acquireOrProvision(forged as CanonicalWorkspaceLockRootInput)).rejects.toThrow(/preprocessing/);
|
||||
});
|
||||
it("rejects symlink sessions roots and special permission bits", () => {
|
||||
const base = mkdtempSync(join(process.cwd(), "thoth-root-")); roots.push(base); const target = mkdtempSync(join(process.cwd(), "thoth-target-")); roots.push(target);
|
||||
const link = join(base, "sessions"); symlinkSync(target, link); expect(() => factory(link)).toThrow();
|
||||
chmodSync(base, 0o1700); expect(() => factory(base)).toThrow();
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user