Add local reachability descriptor for same-host extensions (SAND-WP-0013-T04)
Reachability gains pid/workspace_dir, populated by enrich_reachability whenever a backend's wait_ready() returns a pid: endpoint (currently just ext.bwrap). build_reachability_report() now also returns a local_exec_hint (nsenter into the pid's namespaces) alongside the existing ssh_one_liner, so glas-harness can branch on which is populated instead of assuming every sandbox is SSH-reachable. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
parent
76c38e758c
commit
cf490220f4
6 changed files with 67 additions and 6 deletions
|
|
@ -164,3 +164,22 @@ def test_supports_snapshots_is_false() -> None:
|
|||
assert ext.supports_snapshots() is False
|
||||
with pytest.raises(NotImplementedError):
|
||||
ext.snapshot({})
|
||||
|
||||
|
||||
def test_reachability_local_exec_hint_for_bwrap_handle() -> None:
|
||||
from sandboxer.reachability.enrich import enrich_reachability, local_exec_hint
|
||||
from sandboxer.models import Reachability
|
||||
|
||||
handle = {"pid": "555", "workspace_dir": "/tmp/sandboxer-bwrap/abc", "host": "localhost"}
|
||||
reach = {"host": "localhost", "endpoint": "pid:555"}
|
||||
profile = _profile()
|
||||
|
||||
enriched = enrich_reachability(reach, profile, handle)
|
||||
reachability = Reachability(**enriched)
|
||||
|
||||
assert reachability.pid == "555"
|
||||
assert reachability.workspace_dir == "/tmp/sandboxer-bwrap/abc"
|
||||
assert local_exec_hint(reachability) == (
|
||||
"nsenter --target 555 --mount --pid --net --uts --ipc "
|
||||
"-- sh -c 'cd /tmp/sandboxer-bwrap/abc && exec $SHELL'"
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue