release r008 add safe read-only shell
This commit is contained in:
1 parent
65922b7f57
commit
6480b9678c
10 files changed
+203
-21
No files matched your search
+17
-1
@@ -1,6 +1,6 @@
|
||||
import { describe, expect, test } from "bun:test";
|
||||
import { parseConfig, SAFE_DEFAULT_TOOLS } from "./auth";
|
||||
import { sanitizeLogOutput } from "./helpers";
|
||||
import { runReadOnlyCommand, sanitizeLogOutput } from "./helpers";
|
||||
import { getToolRisk } from "./tools";
|
||||
|
||||
describe("secure tool configuration", () => {
|
||||
@@ -43,5 +43,21 @@ describe("risk classification", () => {
|
||||
expect(getToolRisk("unraid_docker_restart")).toBe("write");
|
||||
expect(getToolRisk("unraid_network_lan_probe")).toBe("active");
|
||||
expect(getToolRisk("unraid_docker_list")).toBe("read");
|
||||
expect(getToolRisk("unraid_system_shell_readonly")).toBe("read");
|
||||
});
|
||||
});
|
||||
|
||||
describe("read-only shell", () => {
|
||||
test("executes an allowlisted program without a shell", async () => {
|
||||
const result = JSON.parse(await runReadOnlyCommand("ls", ["-ld", "/"], 5));
|
||||
expect(result.exit_code).toBe(0);
|
||||
expect(result.mode).toBe("read-only");
|
||||
});
|
||||
|
||||
test("rejects arbitrary programs and mutating subcommands", async () => {
|
||||
await expect(runReadOnlyCommand("sh", ["-c", "id"], 5)).rejects.toThrow();
|
||||
await expect(runReadOnlyCommand("ip", ["link", "set", "lo", "down"], 5)).rejects.toThrow();
|
||||
await expect(runReadOnlyCommand("find", ["/tmp", "-delete"], 5)).rejects.toThrow();
|
||||
await expect(runReadOnlyCommand("ss", ["-K", "dst", "127.0.0.1"], 5)).rejects.toThrow();
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user