sand-boxer/tests/test_runtime_builder.py
tegwick 81b5fcff8e
Some checks are pending
CI Smoke / host-smoke (push) Waiting to run
CI Smoke / container-smoke (push) Waiting to run
fix: relocate long-path runtime console launchers
Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
2026-09-27 23:07:44 +02:00

139 lines
5.7 KiB
Python

import hashlib
import importlib.util
from pathlib import Path
import pytest
spec = importlib.util.spec_from_file_location(
"runtime_builder", Path(__file__).parents[1] / "scripts/build-rein-runtime.py"
)
builder = importlib.util.module_from_spec(spec)
spec.loader.exec_module(builder)
def test_claude_copy_is_pinned_and_excludes_home(tmp_path):
source = tmp_path / "native"
source.write_bytes(b"\x7fELFtest artifact, never executed")
(tmp_path / "credentials.json").write_text("must not enter artifact")
output = tmp_path / "runtime"
(output / "bin").mkdir(parents=True)
digest = hashlib.sha256(source.read_bytes()).hexdigest()
metadata = builder.install_claude(output, source, digest, "test-version")
assert metadata["sha256"] == digest
assert metadata["path"] == "/opt/sandboxer/runtime/bin/claude"
assert list((output / "bin").iterdir()) == [output / "bin/claude"]
assert (output / "bin/claude").read_bytes() == source.read_bytes()
assert (output / "bin/claude").stat().st_mode & 0o777 == 0o755
assert not (output / "credentials.json").exists()
with pytest.raises(FileExistsError):
builder.install_claude(output, source, digest, "test-version")
def test_changed_binary_and_host_wrapper_refuse(tmp_path):
source = tmp_path / "binary"
source.write_bytes(b"#!/usr/bin/env node\n")
output = tmp_path / "runtime"
(output / "bin").mkdir(parents=True)
with pytest.raises(ValueError, match="digest mismatch"):
builder.install_claude(output, source, "0" * 64, "test-version")
digest = hashlib.sha256(source.read_bytes()).hexdigest()
with pytest.raises(ValueError, match="native ELF"):
builder.install_claude(output, source, digest, "test-version")
link = tmp_path / "link"
link.symlink_to(source)
with pytest.raises(ValueError, match="symlink"):
builder.install_claude(output, link, digest, "test-version")
assert not (output / "bin/claude").exists()
def test_incomplete_claude_pin_refuses_before_build(tmp_path):
with pytest.raises(ValueError, match="supplied together"):
builder.build(tmp_path / "out", tmp_path, tmp_path, claude_binary=tmp_path / "claude")
assert not (tmp_path / "out").exists()
def test_owner_build_requires_matching_sibling_lock_before_output(tmp_path, monkeypatch):
import json
rein = tmp_path / "rein"
llm = tmp_path / "llm"
output = tmp_path / "output"
def checked(argv, **kwargs):
if "--porcelain" in argv:
return ""
if "rev-parse" in argv:
return "a" * 40
return json.dumps({"ok": True, "dependencies": [
{"distribution": "llm-connect", "commit": "b" * 40}
]})
monkeypatch.setattr(builder, "checked", checked)
with pytest.raises(ValueError, match="does not match"):
builder.build(output, rein, llm, owner_runtime=True)
assert not output.exists()
@pytest.mark.parametrize("change", [None, "stale", "missing", "extra"])
def test_installed_package_contents_must_match_committed_source(tmp_path, change):
import subprocess
source = tmp_path / "source"
package = source / "fixture"
package.mkdir(parents=True)
(package / "__init__.py").write_text("VERSION = 2\n")
subprocess.run(["git", "init", "-q", str(source)], check=True)
subprocess.run(["git", "-C", str(source), "add", "fixture"], check=True)
site = tmp_path / "site"
installed = site / "fixture"
installed.mkdir(parents=True)
(installed / "__init__.py").write_text("VERSION = 2\n")
if change == "stale":
(installed / "__init__.py").write_text("VERSION = 1\n")
elif change == "missing":
(installed / "__init__.py").unlink()
elif change == "extra":
(installed / "retired.py").write_text("old = True\n")
if change:
with pytest.raises(ValueError, match="owner package"):
builder.verify_source_files(site, [(source, "fixture", "fixture")])
else:
result = builder.verify_source_files(site, [(source, "fixture", "fixture")])
assert result["files_verified"] == 1
@pytest.mark.parametrize("launcher", ["direct", "long-path", "spaces"])
def test_console_entrypoint_runs_after_build_directory_disappears(tmp_path, monkeypatch, launcher):
import shutil
import subprocess
import sys
name = {"long-path": "long-" + "x" * 150, "spaces": "build with spaces"}.get(
launcher, "build"
)
output = tmp_path / name
(output / "bin").mkdir(parents=True)
shutil.copy2(sys.executable, output / "bin/python3")
interpreter = str(output / "bin/python3")
body = "print('entrypoint-ok')\n"
if launcher == "direct":
header = f"#!{interpreter}\n"
else:
header = "#!/bin/sh\n'''exec' '" + interpreter + "' \"$0\" \"$@\"\n' '''\n"
command = output / "bin/rein-aharness"
command.write_text(header + body)
command.chmod(0o755)
binary = output / "bin/native"
binary.write_bytes(b"\x7fELF\x00leave unchanged")
mount = tmp_path / "mounted"
monkeypatch.setattr(builder, "RUNTIME_MOUNT", str(mount))
assert builder.relocate_entrypoints(output) == ["rein-aharness"]
shutil.move(output, mount)
assert not output.exists()
result = subprocess.run([str(mount / "bin/rein-aharness")], capture_output=True, text=True)
assert result.returncode == 0, result.stderr
assert result.stdout.strip() == "entrypoint-ok"
assert (mount / "bin/native").read_bytes() == b"\x7fELF\x00leave unchanged"
def test_unknown_governed_launcher_fails_closed(tmp_path):
(tmp_path / "bin").mkdir()
(tmp_path / "bin/rein-aharness").write_text("#!/bin/sh\nexec /unreviewed/python3\n")
with pytest.raises(ValueError, match="unrelocated governed entrypoint"):
builder.relocate_entrypoints(tmp_path)