diff --git a/tests/tools/test_code_execution.py b/tests/tools/test_code_execution.py index 723f4fad85..53fcadc354 100644 --- a/tests/tools/test_code_execution.py +++ b/tests/tools/test_code_execution.py @@ -254,6 +254,7 @@ class TestRemoteSharedHostLockdown(unittest.TestCase): # The kernel path runs first and fails open here (no PID), so both the # kernel.env and sandbox.env ships are recorded. Neither token may # appear in any executed command. + ships, tokens = {}, {} for env_name in ("kernel.env", "sandbox.env"): env_ship = next((c for c in ship_mock.call_args_list if c.args[1].endswith(env_name)), None) @@ -264,6 +265,7 @@ class TestRemoteSharedHostLockdown(unittest.TestCase): self.assertTrue(token) self.assertFalse(any(token in c for c in commands), f"{env_name} token appeared in a remote command line") + ships[env_name], tokens[env_name] = env_ship, token run_cmd = next(c for c in commands if "python3 script.py" in c) self.assertNotIn("HERMES_RPC_TOKEN=", run_cmd) if sys.platform == "win32": @@ -275,8 +277,8 @@ class TestRemoteSharedHostLockdown(unittest.TestCase): import tempfile mkdir_cmd = next(c for c in commands if "mkdir -p" in c and "hermes_exec_" in c) - sandbox = next(c.args[1] for c in ship_mock.call_args_list - if c.args[1].endswith("sandbox.env")).rsplit("/", 1)[0] + env_ship, token = ships["sandbox.env"], tokens["sandbox.env"] + sandbox = env_ship.args[1].rsplit("/", 1)[0] root = tempfile.mkdtemp() self.addCleanup(shutil.rmtree, root, True) local = root + sandbox @@ -285,11 +287,6 @@ class TestRemoteSharedHostLockdown(unittest.TestCase): self.assertEqual(sh(mkdir_cmd).returncode, 0) for d in (local, f"{local}/rpc"): self.assertEqual(os.stat(d).st_mode & 0o777, 0o700, d) - env_ship = next(c for c in ship_mock.call_args_list - if c.args[1].endswith("sandbox.env")) - token = next(l for l in env_ship.args[2].splitlines() - if l.startswith("HERMES_RPC_TOKEN=")) - token = token.split("=", 1)[1].strip("'\"") with open(f"{local}/sandbox.env", "w") as fh: fh.write(env_ship.args[2]) with open(f"{local}/script.py", "w") as fh: diff --git a/tests/tools/test_code_kernel_remote.py b/tests/tools/test_code_kernel_remote.py index a0b1eaba88..e925823b95 100644 --- a/tests/tools/test_code_kernel_remote.py +++ b/tests/tools/test_code_kernel_remote.py @@ -376,9 +376,8 @@ class TestSharedHostLockdown(RemoteKernelBase): self.assertEqual(r.returncode, 0, r.stderr) for d in (local, f"{local}/cells", f"{local}/rpc"): self.assertEqual(os.stat(d).st_mode & 0o777, 0o700, d) - # Ships write owner-only; on a pipe-capable backend the payload rides - # stdin, so the base64 (which decodes to the token for kernel.env) - # never enters argv either. + # Ships write owner-only and carry the base64 as stdin_data, so it + # (which decodes to the token for kernel.env) never enters argv. ship_cmds = [c for c in env.commands if "base64 -d" in c] self.assertTrue(any("kernel.env" in c for c in ship_cmds)) import base64 @@ -386,6 +385,19 @@ class TestSharedHostLockdown(RemoteKernelBase): if p and "kernel.env" in c) env_content = base64.b64decode(env_ship).decode() self.assertIn(f"HERMES_RPC_TOKEN={kernel.rpc_token}", env_content) + # Fail closed on a failed cell ship: the checked write raises and the + # kernel is evicted, so the next call cannot reuse a kernel whose + # state silently missed this cell. + env.handlers.insert(0, ("cell_req_", lambda c: {"output": "ENOSPC", "returncode": 1})) + with self.assertRaises(RuntimeError): + _run(env, timeout=1) + self.assertEqual(len(_REMOTE_KERNELS), 0) + # Fail closed on a failed dir setup: nothing (env file, runner) is + # shipped into a dir that may still be missing or permissive. + env = ScriptedEnv([("mkdir -p", lambda c: {"output": "EACCES", "returncode": 1})] + + _spawn_ok_handlers([_cell()])) + self.assertIsNone(_run(env)) + self.assertFalse(any("base64 -d" in c for c in env.commands), env.commands) if __name__ == "__main__":