g1t/services/runner/src/egress.test.ts
Pick any line to see why it is the way it is: the commit, the pull request and issue it came from, and what the agent was thinking.
| Agents get guardrails, run credentials, an audit log, a context hub, repository instructions and mentions; security upkeep; snake_case API | 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; | |
| 3 | ||
| 4 | import { allows, blockedStep, harnessEnv, newlyBlocked, normalizeHost, refusal, sandboxHosts, timeCapMessage } from "./egress.ts"; | |
| 5 | ||
| 6 | const policy = ["g1t.sh", "api.g1t.sh", "registry.npmjs.org", "*.example.com"]; | |
| 7 | ||
| 8 | test("listed hosts are allowed and nothing else is", () => { | |
| 9 | assert.equal(allows(policy, "registry.npmjs.org"), true); | |
| 10 | assert.equal(allows(policy, "api.g1t.sh"), true); | |
| 11 | assert.equal(allows(policy, "evil.com"), false); | |
| 12 | assert.equal(allows(policy, "registry.npmjs.org.evil.com"), false); | |
| 13 | assert.equal(allows(policy, "npmjs.org"), false); | |
| 14 | assert.equal(allows(policy, ""), false); | |
| 15 | assert.equal(allows([], "api.g1t.sh"), false); | |
| 16 | }); | |
| 17 | ||
| 18 | test("hosts are compared without case, port or trailing dot", () => { | |
| 19 | assert.equal(allows(policy, "Registry.NPMJS.org:443"), true); | |
| 20 | assert.equal(allows(policy, "registry.npmjs.org."), true); | |
| 21 | assert.equal(normalizeHost("[::1]:8080"), "[::1]"); | |
| 22 | }); | |
| 23 | ||
| 24 | test("a wildcard covers subdomains at any depth, not the domain itself", () => { | |
| 25 | assert.equal(allows(policy, "api.example.com"), true); | |
| 26 | assert.equal(allows(policy, "a.b.example.com"), true); | |
| 27 | assert.equal(allows(policy, "example.com"), false); | |
| 28 | assert.equal(allows(policy, "badexample.com"), false); | |
| 29 | }); | |
| 30 | ||
| 31 | test("the model and g1t's tools are always reachable", () => { | |
| 32 | const hosts = sandboxHosts( | |
| 33 | ["registry.npmjs.org"], | |
| 34 | { MODELS_URL: "https://models.g1t.sh" }, | |
| 35 | { G1T_API: "https://api.g1t.sh", GIT_REMOTE: "https://g1t.sh/acme/site.git", ANTHROPIC_BASE_URL: "https://models.g1t.sh/anthropic" }, | |
| 36 | ); | |
| 37 | for (const host of ["registry.npmjs.org", "models.g1t.sh", "api.g1t.sh", "g1t.sh"]) { | |
| 38 | assert.ok(hosts.includes(host), host); | |
| 39 | } | |
| 40 | assert.ok(!hosts.includes("gateway.ai.cloudflare.com")); | |
| 41 | }); | |
| 42 | ||
| 43 | test("without the model proxy, the gateway or the provider is added", () => { | |
| 44 | assert.ok(sandboxHosts([], { AI_GATEWAY_ID: "g1t" }, {}).includes("gateway.ai.cloudflare.com")); | |
| 45 | assert.ok(sandboxHosts([], { ANTHROPIC_API_KEY: "k" }, {}).includes("api.anthropic.com")); | |
| 46 | assert.deepEqual(sandboxHosts([], {}, { G1T_API: "not a url" }), []); | |
| 47 | }); | |
| 48 | ||
| 49 | test("a refusal says why and how to allow it", async () => { | |
| 50 | const response = refusal("Evil.com:443"); | |
| 51 | assert.equal(response.status, 403); | |
| 52 | assert.equal(response.headers.get("x-g1t-guardrails"), "blocked"); | |
| 53 | const text = await response.text(); | |
| 54 | assert.match(text, /evil\.com is not on this project's allowed domains/); | |
| 55 | assert.match(text, /Settings, Guardrails/); | |
| 56 | assert.equal(blockedStep("Evil.com"), "Blocked: evil.com (not an allowed domain)"); | |
| 57 | }); | |
| 58 | ||
| 59 | test("the harness is told the run's rules, caps and branch", () => { | |
| 60 | const guard = { | |
| 61 | policy: { | |
| 62 | restrictNetwork: true, | |
| 63 | registries: [], | |
| 64 | domains: [], | |
| 65 | hosts: [], | |
| 66 | rules: { sudo: true }, | |
| 67 | deny: ["Bash(kubectl:*)"], | |
| 68 | budgetUsd: 5, | |
| 69 | minutes: { implement: 90 }, | |
| 70 | }, | |
| 71 | minutes: 90, | |
| 72 | }; | |
| 73 | const restricted = harnessEnv(guard, { UPSTREAM_BRANCH: "trunk" }, true); | |
| 74 | assert.deepEqual(JSON.parse(restricted.GUARDRAILS), { | |
| 75 | rules: { sudo: true }, | |
| 76 | deny: ["Bash(kubectl:*)"], | |
| 77 | budgetUsd: 5, | |
| 78 | minutes: 90, | |
| 79 | restrictNetwork: true, | |
| 80 | defaultBranch: "trunk", | |
| 81 | }); | |
| 82 | assert.equal(restricted.NODE_EXTRA_CA_CERTS, "/etc/cloudflare/certs/cloudflare-containers-ca.crt"); | |
| 83 | // Open, as the operator's switch makes it: no certificate to trust. | |
| 84 | const open = harnessEnv(guard, {}, false); | |
| 85 | assert.equal(JSON.parse(open.GUARDRAILS).restrictNetwork, false); | |
| 86 | assert.equal(open.NODE_EXTRA_CA_CERTS, undefined); | |
| 87 | }); | |
| 88 | ||
| 89 | test("each refused host is one step, up to a limit", () => { | |
| 90 | const first = newlyBlocked([], "evil.com"); | |
| 91 | assert.deepEqual(first, { step: "Blocked: evil.com (not an allowed domain)", seen: ["Blocked: evil.com (not an allowed domain)"] }); | |
| 92 | assert.equal(newlyBlocked(first!.seen, "EVIL.com:443"), null); | |
| 93 | const full = Array.from({ length: 25 }, (_, i) => `Blocked: h${i}.com (not an allowed domain)`); | |
| 94 | assert.equal(newlyBlocked(full, "another.com"), null); | |
| 95 | assert.equal(timeCapMessage(1), "Stopped: it reached its time cap of 1 minute."); | |
| 96 | }); |