mirror of
https://github.com/openai/codex.git
synced 2026-04-27 08:05:51 +00:00
migrating execpolicy -> execpolicy-legacy and execpolicy2 -> execpolicy (#6956)
This commit is contained in:
87
codex-rs/execpolicy-legacy/tests/suite/sed.rs
Normal file
87
codex-rs/execpolicy-legacy/tests/suite/sed.rs
Normal file
@@ -0,0 +1,87 @@
|
||||
extern crate codex_execpolicy_legacy;
|
||||
|
||||
use codex_execpolicy_legacy::ArgType;
|
||||
use codex_execpolicy_legacy::Error;
|
||||
use codex_execpolicy_legacy::ExecCall;
|
||||
use codex_execpolicy_legacy::MatchedArg;
|
||||
use codex_execpolicy_legacy::MatchedExec;
|
||||
use codex_execpolicy_legacy::MatchedFlag;
|
||||
use codex_execpolicy_legacy::MatchedOpt;
|
||||
use codex_execpolicy_legacy::Policy;
|
||||
use codex_execpolicy_legacy::Result;
|
||||
use codex_execpolicy_legacy::ValidExec;
|
||||
use codex_execpolicy_legacy::get_default_policy;
|
||||
|
||||
#[expect(clippy::expect_used)]
|
||||
fn setup() -> Policy {
|
||||
get_default_policy().expect("failed to load default policy")
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_sed_print_specific_lines() -> Result<()> {
|
||||
let policy = setup();
|
||||
let sed = ExecCall::new("sed", &["-n", "122,202p", "hello.txt"]);
|
||||
assert_eq!(
|
||||
Ok(MatchedExec::Match {
|
||||
exec: ValidExec {
|
||||
program: "sed".to_string(),
|
||||
flags: vec![MatchedFlag::new("-n")],
|
||||
args: vec![
|
||||
MatchedArg::new(1, ArgType::SedCommand, "122,202p")?,
|
||||
MatchedArg::new(2, ArgType::ReadableFile, "hello.txt")?,
|
||||
],
|
||||
system_path: vec!["/usr/bin/sed".to_string()],
|
||||
..Default::default()
|
||||
}
|
||||
}),
|
||||
policy.check(&sed)
|
||||
);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_sed_print_specific_lines_with_e_flag() -> Result<()> {
|
||||
let policy = setup();
|
||||
let sed = ExecCall::new("sed", &["-n", "-e", "122,202p", "hello.txt"]);
|
||||
assert_eq!(
|
||||
Ok(MatchedExec::Match {
|
||||
exec: ValidExec {
|
||||
program: "sed".to_string(),
|
||||
flags: vec![MatchedFlag::new("-n")],
|
||||
opts: vec![
|
||||
MatchedOpt::new("-e", "122,202p", ArgType::SedCommand)
|
||||
.expect("should validate")
|
||||
],
|
||||
args: vec![MatchedArg::new(3, ArgType::ReadableFile, "hello.txt")?],
|
||||
system_path: vec!["/usr/bin/sed".to_string()],
|
||||
}
|
||||
}),
|
||||
policy.check(&sed)
|
||||
);
|
||||
Ok(())
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_sed_reject_dangerous_command() {
|
||||
let policy = setup();
|
||||
let sed = ExecCall::new("sed", &["-e", "s/y/echo hi/e", "hello.txt"]);
|
||||
assert_eq!(
|
||||
Err(Error::SedCommandNotProvablySafe {
|
||||
command: "s/y/echo hi/e".to_string(),
|
||||
}),
|
||||
policy.check(&sed)
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn test_sed_verify_e_or_pattern_is_required() {
|
||||
let policy = setup();
|
||||
let sed = ExecCall::new("sed", &["122,202p"]);
|
||||
assert_eq!(
|
||||
Err(Error::MissingRequiredOptions {
|
||||
program: "sed".to_string(),
|
||||
options: vec!["-e".to_string()],
|
||||
}),
|
||||
policy.check(&sed)
|
||||
);
|
||||
}
|
||||
Reference in New Issue
Block a user