Refactor runtime around isolated bot instances
This commit is contained in:
@@ -0,0 +1,45 @@
|
||||
import assert from "node:assert/strict";
|
||||
import fs from "node:fs";
|
||||
import os from "node:os";
|
||||
import path from "node:path";
|
||||
import test from "node:test";
|
||||
import { writeConfigFile } from "../src/cli/config-file.js";
|
||||
import { instanceDirectory, runInstanceCommand } from "../src/cli/instance.js";
|
||||
import { parseConfig } from "../src/config.js";
|
||||
|
||||
test("instance paths reject traversal and config identity mismatch", async () => {
|
||||
const root = await fs.promises.mkdtemp(path.join(os.tmpdir(), "gori-instances-"));
|
||||
const previous = process.env.GORI_AGENT_ROOT;
|
||||
process.env.GORI_AGENT_ROOT = root;
|
||||
try {
|
||||
assert.throws(() => instanceDirectory("../escape"), /Invalid bot ID/);
|
||||
assert.throws(() => instanceDirectory("Uppercase"), /Invalid bot ID/);
|
||||
await assert.rejects(runInstanceCommand("list", ["extra"]), /does not accept/);
|
||||
await assert.rejects(runInstanceCommand("status", ["one", "two"]), /exactly one/);
|
||||
await assert.rejects(runInstanceCommand("unknown", ["bot"]), /Unknown instance command/);
|
||||
await assert.rejects(runInstanceCommand("status", ["missing-bot"]), /Runtime config does not exist/);
|
||||
|
||||
const directory = instanceDirectory("directory-bot");
|
||||
const config = parseConfig({
|
||||
configVersion: 3,
|
||||
bot: { id: "different-bot", workspace: "/tmp", persona: "", agent: { id: "kimi", command: "kimi", args: ["acp"] }, permissions: { mode: "deny" } },
|
||||
gateway: { platform: { type: "webhook", secret: "secret" } },
|
||||
runtime: {}
|
||||
});
|
||||
writeConfigFile(path.join(directory, "config.json"), config);
|
||||
await assert.rejects(runInstanceCommand("status", ["directory-bot"]), /does not match config bot\.id/);
|
||||
|
||||
const privateDirectory = instanceDirectory("private-bot");
|
||||
writeConfigFile(path.join(privateDirectory, "config.json"), parseConfig({
|
||||
configVersion: 3,
|
||||
bot: { id: "private-bot", workspace: "/tmp", persona: "", agent: { id: "kimi", command: "kimi", args: ["acp"] }, permissions: { mode: "deny" } },
|
||||
gateway: { platform: { type: "webhook", secret: "secret" } },
|
||||
runtime: {}
|
||||
}));
|
||||
await fs.promises.chmod(privateDirectory, 0o755);
|
||||
await assert.rejects(runInstanceCommand("status", ["private-bot"]), /mode must be 0700/);
|
||||
} finally {
|
||||
if (previous === undefined) delete process.env.GORI_AGENT_ROOT;
|
||||
else process.env.GORI_AGENT_ROOT = previous;
|
||||
}
|
||||
});
|
||||
Reference in New Issue
Block a user