pr_01m47d24b0e6n91zwymwxg0vpx/services/runner/src/egress.test.ts
| 1 | import assert from "node:assert/strict"; |
| 2 | import { test } from "node:test"; |
| 3 | |
| 4 | import { allows, blockedStep, harnessEnv, newlyBlocked, normalizeHost, refusal, sandboxHosts, timeCapMessage } from "./egress.ts"; |
| 5 | |
| 6 | const policy = ["g1t.sh", "api.g1t.sh", "registry.npmjs.org", "*.example.com"]; |
| 7 | |
| 8 | test("listed hosts are allowed and nothing else is", () => { |
| 9 | assert.equal(allows(policy, "registry.npmjs.org"), true); |
| 10 | assert.equal(allows(policy, "api.g1t.sh"), true); |
| 11 | assert.equal(allows(policy, "evil.com"), false); |
| 12 | assert.equal(allows(policy, "registry.npmjs.org.evil.com"), false); |
| 13 | assert.equal(allows(policy, "npmjs.org"), false); |
| 14 | assert.equal(allows(policy, ""), false); |
| 15 | assert.equal(allows([], "api.g1t.sh"), false); |
| 16 | }); |
| 17 | |
| 18 | test("hosts are compared without case, port or trailing dot", () => { |
| 19 | assert.equal(allows(policy, "Registry.NPMJS.org:443"), true); |
| 20 | assert.equal(allows(policy, "registry.npmjs.org."), true); |
| 21 | assert.equal(normalizeHost("[::1]:8080"), "[::1]"); |
| 22 | }); |
| 23 | |
| 24 | test("a wildcard covers subdomains at any depth, not the domain itself", () => { |
| 25 | assert.equal(allows(policy, "api.example.com"), true); |
| 26 | assert.equal(allows(policy, "a.b.example.com"), true); |
| 27 | assert.equal(allows(policy, "example.com"), false); |
| 28 | assert.equal(allows(policy, "badexample.com"), false); |
| 29 | }); |
| 30 | |
| 31 | test("the model and g1t's tools are always reachable", () => { |
| 32 | const hosts = sandboxHosts( |
| 33 | ["registry.npmjs.org"], |
| 34 | { MODELS_URL: "https://models.g1t.sh" }, |
| 35 | { G1T_API: "https://api.g1t.sh", GIT_REMOTE: "https://g1t.sh/acme/site.git", ANTHROPIC_BASE_URL: "https://models.g1t.sh/anthropic" }, |
| 36 | ); |
| 37 | for (const host of ["registry.npmjs.org", "models.g1t.sh", "api.g1t.sh", "g1t.sh"]) { |
| 38 | assert.ok(hosts.includes(host), host); |
| 39 | } |
| 40 | assert.ok(!hosts.includes("gateway.ai.cloudflare.com")); |
| 41 | }); |
| 42 | |
| 43 | test("without the model proxy, the gateway or the provider is added", () => { |
| 44 | assert.ok(sandboxHosts([], { AI_GATEWAY_ID: "g1t" }, {}).includes("gateway.ai.cloudflare.com")); |
| 45 | assert.ok(sandboxHosts([], { ANTHROPIC_API_KEY: "k" }, {}).includes("api.anthropic.com")); |
| 46 | assert.deepEqual(sandboxHosts([], {}, { G1T_API: "not a url" }), []); |
| 47 | }); |
| 48 | |
| 49 | test("a refusal says why and how to allow it", async () => { |
| 50 | const response = refusal("Evil.com:443"); |
| 51 | assert.equal(response.status, 403); |
| 52 | assert.equal(response.headers.get("x-g1t-guardrails"), "blocked"); |
| 53 | const text = await response.text(); |
| 54 | assert.match(text, /evil\.com is not on this project's allowed domains/); |
| 55 | assert.match(text, /Settings, Guardrails/); |
| 56 | assert.equal(blockedStep("Evil.com"), "Blocked: evil.com (not an allowed domain)"); |
| 57 | }); |
| 58 | |
| 59 | test("the harness is told the run's rules, caps and branch", () => { |
| 60 | const guard = { |
| 61 | policy: { |
| 62 | restrictNetwork: true, |
| 63 | registries: [], |
| 64 | domains: [], |
| 65 | hosts: [], |
| 66 | rules: { sudo: true }, |
| 67 | deny: ["Bash(kubectl:*)"], |
| 68 | budgetUsd: 5, |
| 69 | minutes: { implement: 90 }, |
| 70 | }, |
| 71 | minutes: 90, |
| 72 | }; |
| 73 | const restricted = harnessEnv(guard, { UPSTREAM_BRANCH: "trunk" }, true); |
| 74 | assert.deepEqual(JSON.parse(restricted.GUARDRAILS), { |
| 75 | rules: { sudo: true }, |
| 76 | deny: ["Bash(kubectl:*)"], |
| 77 | budgetUsd: 5, |
| 78 | minutes: 90, |
| 79 | restrictNetwork: true, |
| 80 | defaultBranch: "trunk", |
| 81 | }); |
| 82 | assert.equal(restricted.NODE_EXTRA_CA_CERTS, "/etc/cloudflare/certs/cloudflare-containers-ca.crt"); |
| 83 | // Open, as the operator's switch makes it: no certificate to trust. |
| 84 | const open = harnessEnv(guard, {}, false); |
| 85 | assert.equal(JSON.parse(open.GUARDRAILS).restrictNetwork, false); |
| 86 | assert.equal(open.NODE_EXTRA_CA_CERTS, undefined); |
| 87 | }); |
| 88 | |
| 89 | test("each refused host is one step, up to a limit", () => { |
| 90 | const first = newlyBlocked([], "evil.com"); |
| 91 | assert.deepEqual(first, { step: "Blocked: evil.com (not an allowed domain)", seen: ["Blocked: evil.com (not an allowed domain)"] }); |
| 92 | assert.equal(newlyBlocked(first!.seen, "EVIL.com:443"), null); |
| 93 | const full = Array.from({ length: 25 }, (_, i) => `Blocked: h${i}.com (not an allowed domain)`); |
| 94 | assert.equal(newlyBlocked(full, "another.com"), null); |
| 95 | assert.equal(timeCapMessage(1), "Stopped: it reached its time cap of 1 minute."); |
| 96 | }); |