mirror of
https://github.com/pewdiepie-archdaemon/odysseus.git
synced 2026-10-07 15:32:21 +02:00
Merge commit 'refs/phase3/pre-ajax/publication-tip' into integration/pre-ajax-release
# Conflicts: # routes/chat_routes.py # routes/session_routes.py # src/agent_loop.py # src/agent_tools/filesystem_tools.py # src/teacher_escalation.py # src/tool_capabilities.py # src/tool_execution.py # tests/test_mcp_add_server_args_validation.py # tests/test_token_cache_atomic_swap.py
This commit is contained in:
@@ -18,6 +18,14 @@ from types import SimpleNamespace
|
||||
from unittest.mock import patch
|
||||
|
||||
import pytest
|
||||
from tests.runtime_evidence_helpers import server_authorized_executor
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def standalone_dispatch_authority(monkeypatch):
|
||||
from src import tool_execution
|
||||
monkeypatch.setattr(tool_execution, "execute_tool_block",
|
||||
server_authorized_executor(tool_execution.execute_tool_block))
|
||||
|
||||
|
||||
def _make_block(tool_type, content):
|
||||
@@ -246,7 +254,8 @@ async def test_read_file_dispatch_blocks_etc_shadow(monkeypatch):
|
||||
owner="admin-user",
|
||||
security_context=NO_TOOL_SECURITY_CONTEXT,
|
||||
)
|
||||
assert "outside the allowed roots" in (result.get("error") or "")
|
||||
assert result.get("failure_kind") == "resource_identity_denied"
|
||||
assert "sealed resource root" in (result.get("error") or "")
|
||||
assert result.get("exit_code") == 1
|
||||
|
||||
|
||||
@@ -275,10 +284,45 @@ async def test_write_file_dispatch_blocks_authorized_keys(monkeypatch):
|
||||
owner="admin-user",
|
||||
security_context=NO_TOOL_SECURITY_CONTEXT,
|
||||
)
|
||||
assert "sensitive directory" in (result.get("error") or "")
|
||||
assert result.get("failure_kind") == "resource_identity_denied"
|
||||
assert "sealed resource root" in (result.get("error") or "")
|
||||
assert result.get("exit_code") == 1
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_write_file_dispatch_rejects_empty_directory_like_workspace_path(monkeypatch, tmp_path):
|
||||
"""End-to-end: benchmark agents must not turn a directory path into an empty file."""
|
||||
auth_mod = sys.modules.get("core.auth")
|
||||
if auth_mod is None:
|
||||
import core.auth as _real_auth
|
||||
auth_mod = _real_auth
|
||||
|
||||
class _AdminAuth:
|
||||
is_configured = True
|
||||
def is_admin(self, username):
|
||||
return True
|
||||
|
||||
monkeypatch.setattr(auth_mod, "AuthManager", lambda: _AdminAuth())
|
||||
monkeypatch.setattr(
|
||||
"src.tool_execution.owner_is_admin_or_single_user",
|
||||
lambda owner: True,
|
||||
)
|
||||
|
||||
from src.tool_execution import NO_TOOL_SECURITY_CONTEXT, execute_tool_block
|
||||
desc, result = await execute_tool_block(
|
||||
_make_block("write_file", "/workspace/papers"),
|
||||
owner="admin-user",
|
||||
workspace=str(tmp_path),
|
||||
security_context=NO_TOOL_SECURITY_CONTEXT,
|
||||
)
|
||||
assert "BLOCKED" in desc
|
||||
assert "content required; missing content section" in (
|
||||
result.get("error") or ""
|
||||
)
|
||||
assert result.get("exit_code") == 1
|
||||
assert not (tmp_path / "papers").exists()
|
||||
|
||||
|
||||
@pytest.mark.asyncio
|
||||
async def test_write_file_dispatch_blocks_cron(monkeypatch):
|
||||
"""End-to-end: write_file to /etc/cron.d must be rejected."""
|
||||
@@ -304,5 +348,11 @@ async def test_write_file_dispatch_blocks_cron(monkeypatch):
|
||||
owner="admin-user",
|
||||
security_context=NO_TOOL_SECURITY_CONTEXT,
|
||||
)
|
||||
assert "outside the allowed roots" in (result.get("error") or "")
|
||||
assert result.get("failure_kind") == "resource_identity_denied"
|
||||
assert "sealed resource root" in (result.get("error") or "")
|
||||
assert result.get("exit_code") == 1
|
||||
@pytest.mark.parametrize("filename", ["auth.json", "app.db", "settings.json"])
|
||||
def test_application_secrets_are_sensitive_paths(filename):
|
||||
from src.tool_execution import _is_sensitive_path
|
||||
|
||||
assert _is_sensitive_path(f"/tmp/odysseus-data/{filename}")
|
||||
|
||||
Reference in New Issue
Block a user