From 22e61003f90c03295cbc86b601d5dfece425dc03 Mon Sep 17 00:00:00 2001 From: yu-xin-c <2182712990@qq.com> Date: Fri, 19 Jun 2026 02:00:15 +0800 Subject: [PATCH] test(exec): make bwrap bind tests portable --- tests/tools/test_exec_platform.py | 13 +++++++------ tests/tools/test_exec_security.py | 6 ++++-- 2 files changed, 11 insertions(+), 8 deletions(-) diff --git a/tests/tools/test_exec_platform.py b/tests/tools/test_exec_platform.py index 4a6277b2..9981e220 100644 --- a/tests/tools/test_exec_platform.py +++ b/tests/tools/test_exec_platform.py @@ -8,7 +8,6 @@ platform-specific binaries (all subprocess calls are mocked). import asyncio import shutil import sys -from pathlib import Path from unittest.mock import AsyncMock, patch import pytest @@ -475,11 +474,13 @@ class TestSandboxPlatform: assert "bwrap" in spawned_cmd @pytest.mark.asyncio - async def test_bwrap_receives_configured_bind_roots(self): + async def test_bwrap_receives_configured_bind_roots(self, tmp_path): """Configured bwrap bind roots should be forwarded to the sandbox wrapper.""" mock_proc = AsyncMock() mock_proc.communicate.return_value = (b"sandboxed", b"") mock_proc.returncode = 0 + tool_bin = tmp_path / "tool-bin" + tool_cache = tmp_path / "tool-cache" with ( patch("nanobot.agent.tools.shell._IS_WINDOWS", False), @@ -490,17 +491,17 @@ class TestSandboxPlatform: tool = ExecTool( sandbox="bwrap", working_dir="/workspace", - sandbox_ro_binds=["/home/user/.local/bin"], - sandbox_rw_binds=["/home/user/.cache/uv"], + sandbox_ro_binds=[str(tool_bin)], + sandbox_rw_binds=[str(tool_cache)], ) await tool.execute(command="ls") kwargs = mock_wrap.call_args.kwargs assert kwargs["sandbox_ro_binds"] == [ - str(Path("/home/user/.local/bin").resolve(strict=False)) + str(tool_bin.resolve(strict=False)) ] assert kwargs["sandbox_rw_binds"] == [ - str(Path("/home/user/.cache/uv").resolve(strict=False)) + str(tool_cache.resolve(strict=False)) ] diff --git a/tests/tools/test_exec_security.py b/tests/tools/test_exec_security.py index 6e3a6f8a..bc6d8a95 100644 --- a/tests/tools/test_exec_security.py +++ b/tests/tools/test_exec_security.py @@ -314,13 +314,14 @@ def test_exec_still_blocks_real_outside_path_via_redirect(tmp_path): assert "path outside working dir" in blocked -def test_exec_allows_absolute_path_inside_bwrap_ro_bind(tmp_path): +def test_exec_allows_absolute_path_inside_bwrap_ro_bind(tmp_path, monkeypatch): workspace = tmp_path / "workspace" workspace.mkdir() tool_bin = tmp_path / "home" / ".local" / "bin" tool_bin.mkdir(parents=True) uv = tool_bin / "uv" uv.write_text("#!/bin/sh\n") + monkeypatch.setattr("nanobot.agent.tools.shell._IS_WINDOWS", False) tool = ExecTool( working_dir=str(workspace), restrict_to_workspace=True, @@ -338,11 +339,12 @@ def test_exec_allows_absolute_path_inside_bwrap_ro_bind(tmp_path): assert blocked is None -def test_exec_allows_absolute_path_inside_bwrap_rw_bind(tmp_path): +def test_exec_allows_absolute_path_inside_bwrap_rw_bind(tmp_path, monkeypatch): workspace = tmp_path / "workspace" workspace.mkdir() cache_dir = tmp_path / "cache" cache_dir.mkdir() + monkeypatch.setattr("nanobot.agent.tools.shell._IS_WINDOWS", False) tool = ExecTool( working_dir=str(workspace), restrict_to_workspace=True,