mirror of
https://github.com/block/buzz.git
synced 2026-08-18 06:50:31 +02:00
feat(agent): add hardened MCP toolchain shims with config isolation
Add hermit-managed shim scripts for uv/uvx/npx/node that provide config-isolated toolchain execution for MCP servers, preventing ambient system toolchains from leaking user config into agent processes. Security hardening: - Private mktemp temp dir with cleanup trap (no predictable paths) - Lock mutual exclusion via kill-0 + /proc start-time verification - Atomic bootstrap recovery (staged download + validated mv) - Desktop fail-loud validation of shim resources before env export Co-authored-by: Will Pfleger <pfleger.will@gmail.com> Signed-off-by: Will Pfleger <pfleger.will@gmail.com>
This commit is contained in:
@@ -100,6 +100,12 @@ run_unit_tests() {
|
||||
|
||||
run_test_step "buzz-push-gateway tests" \
|
||||
cargo test -p buzz-push-gateway -- --nocapture
|
||||
|
||||
# MCP shim hostile-config suite: infra-free (real wrapper scripts +
|
||||
# stubbed curl/openssl). Contains the Linux-only hostile-path regression
|
||||
# for the CRITICAL temp-execution fix — this is its only CI execution path.
|
||||
run_test_step "buzz-agent shim hostile-config tests" \
|
||||
cargo test -p buzz-agent --test shim_hostile_config -- --nocapture
|
||||
}
|
||||
|
||||
# ---- DB / integration tests (infra required) --------------------------------
|
||||
|
||||
Reference in New Issue
Block a user