Confine Windows command execution through a WRITE_RESTRICTED token whose restricting SIDs carry an orphan-SID write allowlist, ported from https://github.com/huoyaoyuan/windows-acl-restrict-poc (@ 10e4dfb). Every Win32 call is checked and fails closed - the POC silently ran children with the FULL token when CreateRestrictedToken failed. - @deepseek-ai/dsh-sandbox-windows-acl: koffi primitives verified against the MinGW Windows headers (verify/abi-probe.cpp) plus the confinement runner ([node, runner, --workspace, --temp, --mode, --, argv...]: kill-on-close job, stdio passthrough, exit-code mirroring, windows-acl-run: failure signature, grant revocation). read-only = strict zero grants (NUL device not writable; documented). Windows-only execution: exempted from the Linux coverage lane (windowsOnlyCoverageExclusions). - @deepseek-ai/dsh-sandbox-local: PLATFORM_CHAINS.win32 filled with the windows-acl runner (full enforcement, ACL denial dialect, runner-failure rules). - @deepseek-ai/dsh-pwsh-sandbox: sandbox-consuming pwsh executor (call-for-call mirror of dsh-bash-sandbox) over a new argv-level seam in dsh-pwsh-local; per-file coverage complete via the fake-provider spec. - bundle/base: the Windows platform layer mounts the confined pwsh roster - sandbox/policy/fs-sandbox/permission/approval re-enabled, the POSIX bash stack stays disabled. Co-authored-by: Huo Yaoyuan <huoyaoyuan@hotmail.com>
64 lines
2.8 KiB
TypeScript
64 lines
2.8 KiB
TypeScript
/**
|
|
* The bundle's substance is its patch file: the `dsh.bundle.patch` manifest
|
|
* field must name a real, parseable patch list.
|
|
*/
|
|
|
|
import { readFileSync } from 'node:fs'
|
|
import { fileURLToPath } from 'node:url'
|
|
import { resolve } from 'node:path'
|
|
import { describe, expect, it } from 'vitest'
|
|
import * as yaml from 'js-yaml'
|
|
import { entryListSchema } from '@cordisjs/plugin-include'
|
|
|
|
describe('dsh-base bundle', () => {
|
|
it('declares a parseable patch list through the dsh.bundle.patch manifest field', () => {
|
|
const root = fileURLToPath(new URL('..', import.meta.url))
|
|
const manifest = JSON.parse(
|
|
readFileSync(resolve(root, 'package.json'), 'utf8'),
|
|
) as { dsh?: { bundle?: { patch?: string } } }
|
|
expect(manifest.dsh?.bundle?.patch).toBe('./cordis.patch.yml')
|
|
const parsed = yaml.load(
|
|
readFileSync(resolve(root, manifest.dsh!.bundle!.patch!), 'utf8'),
|
|
{ schema: entryListSchema },
|
|
)
|
|
expect(Array.isArray(parsed)).toBe(true)
|
|
// The base layer is one insert list over the empty profile root.
|
|
const rows = (parsed as { insert?: { id?: string }[] }[]).flatMap(
|
|
patch => patch.insert ?? [],
|
|
)
|
|
expect(rows.length).toBeGreaterThan(50)
|
|
expect(rows.some(row => row.id === 'agent-loop')).toBe(true)
|
|
})
|
|
|
|
it('ships the Windows platform layer as the confined pwsh roster over the ACL runner chain', () => {
|
|
const root = fileURLToPath(new URL('..', import.meta.url))
|
|
const parsed = yaml.load(
|
|
readFileSync(resolve(root, 'windows.cordis.patch.yml'), 'utf8'),
|
|
{ schema: entryListSchema },
|
|
) as {
|
|
id?: string
|
|
disabled?: boolean
|
|
insert?: { id?: string; name?: string }[]
|
|
config?: { policy?: string }
|
|
}[]
|
|
const disables = parsed
|
|
.filter(patch => patch.disabled === true)
|
|
.map(patch => patch.id)
|
|
// Only the POSIX bash stack is disabled: the Windows roster confines the
|
|
// pwsh executor through the ACL runner chain, so the sandbox/policy rows,
|
|
// the permission switcher, fs-sandbox, and the approval service all stay
|
|
// enabled exactly as on POSIX — only the shell is swapped.
|
|
expect(disables).toEqual(['bash-sandbox', 'tool-bash'])
|
|
const inserted = parsed
|
|
.flatMap(patch => patch.insert ?? [])
|
|
.map(row => row.id)
|
|
expect(inserted).toEqual(['pwsh-sandbox', 'tool-pwsh', 'fs-local'])
|
|
// The patch no longer touches the permission/approval surface at all.
|
|
expect(parsed.find(patch => patch.id === 'approval')).toBeUndefined()
|
|
expect(parsed.find(patch => patch.id === 'permission')).toBeUndefined()
|
|
expect(parsed.find(patch => patch.id === 'sandbox')).toBeUndefined()
|
|
expect(parsed.find(patch => patch.id === 'sandbox-policy')).toBeUndefined()
|
|
expect(parsed.find(patch => patch.id === 'fs-sandbox')).toBeUndefined()
|
|
})
|
|
})
|