Assistant: codex Assistant-Model: gpt-6-astra Assistant-Session: 01a0e387-534d-70e3-ad53-4ea05676db8c
139 lines
5.7 KiB
Python
139 lines
5.7 KiB
Python
import hashlib
|
|
import importlib.util
|
|
from pathlib import Path
|
|
|
|
import pytest
|
|
|
|
spec = importlib.util.spec_from_file_location(
|
|
"runtime_builder", Path(__file__).parents[1] / "scripts/build-rein-runtime.py"
|
|
)
|
|
builder = importlib.util.module_from_spec(spec)
|
|
spec.loader.exec_module(builder)
|
|
|
|
|
|
def test_claude_copy_is_pinned_and_excludes_home(tmp_path):
|
|
source = tmp_path / "native"
|
|
source.write_bytes(b"\x7fELFtest artifact, never executed")
|
|
(tmp_path / "credentials.json").write_text("must not enter artifact")
|
|
output = tmp_path / "runtime"
|
|
(output / "bin").mkdir(parents=True)
|
|
digest = hashlib.sha256(source.read_bytes()).hexdigest()
|
|
metadata = builder.install_claude(output, source, digest, "test-version")
|
|
assert metadata["sha256"] == digest
|
|
assert metadata["path"] == "/opt/sandboxer/runtime/bin/claude"
|
|
assert list((output / "bin").iterdir()) == [output / "bin/claude"]
|
|
assert (output / "bin/claude").read_bytes() == source.read_bytes()
|
|
assert (output / "bin/claude").stat().st_mode & 0o777 == 0o755
|
|
assert not (output / "credentials.json").exists()
|
|
with pytest.raises(FileExistsError):
|
|
builder.install_claude(output, source, digest, "test-version")
|
|
|
|
|
|
def test_changed_binary_and_host_wrapper_refuse(tmp_path):
|
|
source = tmp_path / "binary"
|
|
source.write_bytes(b"#!/usr/bin/env node\n")
|
|
output = tmp_path / "runtime"
|
|
(output / "bin").mkdir(parents=True)
|
|
with pytest.raises(ValueError, match="digest mismatch"):
|
|
builder.install_claude(output, source, "0" * 64, "test-version")
|
|
digest = hashlib.sha256(source.read_bytes()).hexdigest()
|
|
with pytest.raises(ValueError, match="native ELF"):
|
|
builder.install_claude(output, source, digest, "test-version")
|
|
link = tmp_path / "link"
|
|
link.symlink_to(source)
|
|
with pytest.raises(ValueError, match="symlink"):
|
|
builder.install_claude(output, link, digest, "test-version")
|
|
assert not (output / "bin/claude").exists()
|
|
|
|
|
|
def test_incomplete_claude_pin_refuses_before_build(tmp_path):
|
|
with pytest.raises(ValueError, match="supplied together"):
|
|
builder.build(tmp_path / "out", tmp_path, tmp_path, claude_binary=tmp_path / "claude")
|
|
assert not (tmp_path / "out").exists()
|
|
|
|
|
|
def test_owner_build_requires_matching_sibling_lock_before_output(tmp_path, monkeypatch):
|
|
import json
|
|
rein = tmp_path / "rein"
|
|
llm = tmp_path / "llm"
|
|
output = tmp_path / "output"
|
|
def checked(argv, **kwargs):
|
|
if "--porcelain" in argv:
|
|
return ""
|
|
if "rev-parse" in argv:
|
|
return "a" * 40
|
|
return json.dumps({"ok": True, "dependencies": [
|
|
{"distribution": "llm-connect", "commit": "b" * 40}
|
|
]})
|
|
monkeypatch.setattr(builder, "checked", checked)
|
|
with pytest.raises(ValueError, match="does not match"):
|
|
builder.build(output, rein, llm, owner_runtime=True)
|
|
assert not output.exists()
|
|
|
|
|
|
@pytest.mark.parametrize("change", [None, "stale", "missing", "extra"])
|
|
def test_installed_package_contents_must_match_committed_source(tmp_path, change):
|
|
import subprocess
|
|
source = tmp_path / "source"
|
|
package = source / "fixture"
|
|
package.mkdir(parents=True)
|
|
(package / "__init__.py").write_text("VERSION = 2\n")
|
|
subprocess.run(["git", "init", "-q", str(source)], check=True)
|
|
subprocess.run(["git", "-C", str(source), "add", "fixture"], check=True)
|
|
site = tmp_path / "site"
|
|
installed = site / "fixture"
|
|
installed.mkdir(parents=True)
|
|
(installed / "__init__.py").write_text("VERSION = 2\n")
|
|
if change == "stale":
|
|
(installed / "__init__.py").write_text("VERSION = 1\n")
|
|
elif change == "missing":
|
|
(installed / "__init__.py").unlink()
|
|
elif change == "extra":
|
|
(installed / "retired.py").write_text("old = True\n")
|
|
if change:
|
|
with pytest.raises(ValueError, match="owner package"):
|
|
builder.verify_source_files(site, [(source, "fixture", "fixture")])
|
|
else:
|
|
result = builder.verify_source_files(site, [(source, "fixture", "fixture")])
|
|
assert result["files_verified"] == 1
|
|
|
|
|
|
@pytest.mark.parametrize("launcher", ["direct", "long-path", "spaces"])
|
|
def test_console_entrypoint_runs_after_build_directory_disappears(tmp_path, monkeypatch, launcher):
|
|
import shutil
|
|
import subprocess
|
|
import sys
|
|
|
|
name = {"long-path": "long-" + "x" * 150, "spaces": "build with spaces"}.get(
|
|
launcher, "build"
|
|
)
|
|
output = tmp_path / name
|
|
(output / "bin").mkdir(parents=True)
|
|
shutil.copy2(sys.executable, output / "bin/python3")
|
|
interpreter = str(output / "bin/python3")
|
|
body = "print('entrypoint-ok')\n"
|
|
if launcher == "direct":
|
|
header = f"#!{interpreter}\n"
|
|
else:
|
|
header = "#!/bin/sh\n'''exec' '" + interpreter + "' \"$0\" \"$@\"\n' '''\n"
|
|
command = output / "bin/rein-aharness"
|
|
command.write_text(header + body)
|
|
command.chmod(0o755)
|
|
binary = output / "bin/native"
|
|
binary.write_bytes(b"\x7fELF\x00leave unchanged")
|
|
mount = tmp_path / "mounted"
|
|
monkeypatch.setattr(builder, "RUNTIME_MOUNT", str(mount))
|
|
assert builder.relocate_entrypoints(output) == ["rein-aharness"]
|
|
shutil.move(output, mount)
|
|
assert not output.exists()
|
|
result = subprocess.run([str(mount / "bin/rein-aharness")], capture_output=True, text=True)
|
|
assert result.returncode == 0, result.stderr
|
|
assert result.stdout.strip() == "entrypoint-ok"
|
|
assert (mount / "bin/native").read_bytes() == b"\x7fELF\x00leave unchanged"
|
|
|
|
|
|
def test_unknown_governed_launcher_fails_closed(tmp_path):
|
|
(tmp_path / "bin").mkdir()
|
|
(tmp_path / "bin/rein-aharness").write_text("#!/bin/sh\nexec /unreviewed/python3\n")
|
|
with pytest.raises(ValueError, match="unrelocated governed entrypoint"):
|
|
builder.relocate_entrypoints(tmp_path)
|