Files
pmg/sandbox/util/dangerous_test.go
T
9693428171 feat: Experimental Sandbox Support (#101)
* feat: Sandbox implementation with seatbelt

* refactor: Remove concept of PM_CACHE

* fix: Misc fixes

* refactor: Sandbox for separation of boundaries

* fix: Apply API

* fix: Add support for sandbox cleanup

* test: Add variable interpolation test

* fix: Misc cleanup fixes

* chore: Cleanup sandbox registry

* chore: Cleanup sandbox policy

* chore: Cleanup sandbox

* fix: Misc cleanup fixes

* fix: Remove violation mode

* fix: Update config template

* chore: Go mod cleanup

* fix: Handle the case when package manager policy is explicitly disabled

* fix: Sandbox executor

* Apply suggestions from code review

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>

* test: Remove unused var

* test: Add test for seatbelt sandbox driver

* fix: Sandbox profile loader from file should use path for caching

* test: Add policy test

* feat: Add support for config templates

* fix: Seatbelt translator handle glob

* fix: Merge conflicts

* fix: Fix sandbox policy generator for MacOS min permissions

* fix: Sandbox path handling bugs

* fix: Deny read to dangerous directories

* fix: Deny read to dangerous directories

* add sandbox e2e (#112)

* fix: Sandbox E2E test

* fix: Code review fixes

* fix: Code review fixes

* doc: Add sandbox debugging guide

* doc: Update sandbox doc

* docs: Add sandbox usage doc

* fix: Use better error for sandbox without policy

* fix: Add sandbox for npx

* fix: Enable PTY for npm

---------

Signed-off-by: Abhisek Datta <abhisek.datta@gmail.com>
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Sahil Bansal <bansalsahil315@gmail.com>
2026-01-13 14:52:02 +05:30

80 lines
2.3 KiB
Go

package util
import (
"os"
"path/filepath"
"testing"
"github.com/stretchr/testify/assert"
)
func TestGetMandatoryDenyPatterns(t *testing.T) {
t.Run("always blocks dangerous files", func(t *testing.T) {
patterns := GetMandatoryDenyPatterns(false)
// Should contain patterns for each dangerous file
assert.Contains(t, patterns, "**/.env")
assert.Contains(t, patterns, "**/.ssh")
assert.Contains(t, patterns, "**/.aws")
assert.Contains(t, patterns, "**/.gcloud")
assert.Contains(t, patterns, "**/.kube")
assert.Contains(t, patterns, "**/.gnupg")
assert.Contains(t, patterns, "**/.docker/config.json")
})
t.Run("always blocks git hooks", func(t *testing.T) {
patterns := GetMandatoryDenyPatterns(false)
// Should block git hooks
assert.Contains(t, patterns, "**/.git/hooks")
assert.Contains(t, patterns, "**/.git/hooks/**")
})
t.Run("blocks git config when allowGitConfig is false", func(t *testing.T) {
patterns := GetMandatoryDenyPatterns(false)
// Should block git config
assert.Contains(t, patterns, "**/.git/config")
})
t.Run("allows git config when allowGitConfig is true", func(t *testing.T) {
patterns := GetMandatoryDenyPatterns(true)
// Should NOT block git config
for _, pattern := range patterns {
assert.NotContains(t, pattern, ".git/config")
}
})
t.Run("includes CWD-relative patterns", func(t *testing.T) {
cwd, err := os.Getwd()
assert.NoError(t, err)
patterns := GetMandatoryDenyPatterns(false)
// Should include absolute paths in CWD
assert.Contains(t, patterns, filepath.Join(cwd, ".env"))
assert.Contains(t, patterns, filepath.Join(cwd, ".ssh"))
assert.Contains(t, patterns, filepath.Join(cwd, ".git/hooks"))
})
t.Run("includes HOME-relative patterns", func(t *testing.T) {
home, err := os.UserHomeDir()
assert.NoError(t, err)
patterns := GetMandatoryDenyPatterns(false)
// Should include absolute paths in HOME
assert.Contains(t, patterns, filepath.Join(home, ".env"))
assert.Contains(t, patterns, filepath.Join(home, ".ssh"))
assert.Contains(t, patterns, filepath.Join(home, ".aws"))
})
t.Run("includes glob patterns for env variants", func(t *testing.T) {
patterns := GetMandatoryDenyPatterns(false)
// Should include pattern for .env.* files
assert.Contains(t, patterns, "**/.env.*")
})
}