fix(runtime): contain every native Python execution (ODY-143)

This commit is contained in:
Alexandre Teixeira
2026-10-01 21:04:12 +01:00
parent 9bb2424e65
commit bf0623a77b
5 changed files with 53 additions and 115 deletions
@@ -104,3 +104,39 @@ async def test_blocked_stdin_is_inside_wall_clock(native_boundary):
), timeout=8)
assert result.timed_out is True
assert result.release.dead is True
@pytest.mark.parametrize("source", ["print(1 + 1)", "import os; print(os.getcwd())",
"exec('print(2)')", "print('/workspace')"])
async def test_python_namespace_is_independent_of_content(source, native_boundary, monkeypatch):
from tests.containment_helpers import capture_owned_spawn
captured = capture_owned_spawn(monkeypatch, native_boundary)
monkeypatch.setattr(containment, "MECHANISMS", (containment.Mechanism(
"bubblewrap", 30, lambda: True, lambda spec: containment.DEFAULT_REQUIRED,
),))
monkeypatch.setattr(containment, "CONTAINMENT_MODE", containment.MODE_ENFORCING)
result = await subprocess_tools.PythonTool().execute(source, {})
assert captured["argv"][0] == "bwrap"
assert "--bind" in captured["argv"]
assert result["containment"]["enforced"] == sorted(containment.DEFAULT_REQUIRED)
assert "-I" in captured["argv"]
async def test_ordinary_python_cannot_bypass_unavailable_containment(monkeypatch):
monkeypatch.setattr(containment, "CONTAINMENT_MODE", containment.MODE_ENFORCING)
async def forbidden(*args, **kwargs):
pytest.fail("ordinary Python bypassed required containment")
monkeypatch.setattr(asyncio, "create_subprocess_exec", forbidden)
result = await subprocess_tools.PythonTool().execute("print(1 + 1)", {})
assert result["containment"]["executed"] is False
async def test_python_final_expression_and_opt_in_imports(native_boundary):
package = native_boundary / "packages"
package.mkdir()
(package / "demo.py").write_text("value = 42\n")
result = await subprocess_tools.PythonTool().execute("import demo; demo.value", {
"subproc_env": {**os.environ, "ODYSSEUS_PYTHON_TOOL_SITE_PACKAGES": str(package)},
})
assert result["output"] == "42"
assert result["teardown"]["dead"] is True
@@ -2210,6 +2210,7 @@ def test_python_loaded_code_sees_virtual_workspace_alias(monkeypatch, tmp_path):
venv.EnvBuilder(with_pip=False).create(environment)
monkeypatch.setattr(subprocess_tools, "sys", SimpleNamespace(
prefix=str(environment),
base_prefix=sys.base_prefix,
executable=str(environment / "bin" / "python"),
version_info=sys.version_info,
))
+2 -1
View File
@@ -287,7 +287,8 @@ async def test_subprocess_cwd_is_workspace_e2e(ws, admin):
"""python tool runs with cwd = workspace (OS-agnostic probe)."""
_, r = await execute_tool_block(_block("python", "import os; print(os.getcwd())"), owner="a", workspace=ws)
assert r["exit_code"] == 0
assert os.path.realpath(r["output"].strip()) == os.path.realpath(ws)
expected_cwd = "/workspace" if "filesystem" in r["containment"]["enforced"] else ws
assert os.path.realpath(r["output"].strip()) == os.path.realpath(expected_cwd)
@pytest.mark.asyncio