release r008 add safe read-only shell

This commit is contained in:
Mikei386 committed 2026-08-21 07:53:34 +02:00
1 parent 65922b7f57
commit 6480b9678c
10 files changed
+203 -21

No files matched your search

+17 -1
View File
@@ -1,6 +1,6 @@
import { describe, expect, test } from "bun:test";
import { parseConfig, SAFE_DEFAULT_TOOLS } from "./auth";
import { sanitizeLogOutput } from "./helpers";
import { runReadOnlyCommand, sanitizeLogOutput } from "./helpers";
import { getToolRisk } from "./tools";
describe("secure tool configuration", () => {
@@ -43,5 +43,21 @@ describe("risk classification", () => {
expect(getToolRisk("unraid_docker_restart")).toBe("write");
expect(getToolRisk("unraid_network_lan_probe")).toBe("active");
expect(getToolRisk("unraid_docker_list")).toBe("read");
expect(getToolRisk("unraid_system_shell_readonly")).toBe("read");
});
});
describe("read-only shell", () => {
test("executes an allowlisted program without a shell", async () => {
const result = JSON.parse(await runReadOnlyCommand("ls", ["-ld", "/"], 5));
expect(result.exit_code).toBe(0);
expect(result.mode).toBe("read-only");
});
test("rejects arbitrary programs and mutating subcommands", async () => {
await expect(runReadOnlyCommand("sh", ["-c", "id"], 5)).rejects.toThrow();
await expect(runReadOnlyCommand("ip", ["link", "set", "lo", "down"], 5)).rejects.toThrow();
await expect(runReadOnlyCommand("find", ["/tmp", "-delete"], 5)).rejects.toThrow();
await expect(runReadOnlyCommand("ss", ["-K", "dst", "127.0.0.1"], 5)).rejects.toThrow();
});
});