sandbox: remove superpowerd integration

Elevation is now handled by the integrated broker in olliesrv.
No longer wraps commands with superpowers run-session.
This commit is contained in:
Levi Neely 2026-07-27 10:57:07 +02:00
parent fb8f4acff1
commit bd40dc9637
2 changed files with 3 additions and 94 deletions

View File

@ -3,7 +3,6 @@ package sandbox
import (
"bytes"
"fmt"
"net"
"os"
"path/filepath"
"testing"
@ -99,10 +98,6 @@ func TestExpandPath(t *testing.T) {
// ---- WrapCommand ----
func TestWrapCommand(t *testing.T) {
old := isSuperpowerdRunningFn
isSuperpowerdRunningFn = func() bool { return false }
defer func() { isSuperpowerdRunningFn = old }()
tmpDir := t.TempDir()
rwDir := filepath.Join(tmpDir, "rw")
roDir := filepath.Join(tmpDir, "ro")
@ -630,50 +625,7 @@ func TestWrapCommand_SortTiebreaker(t *testing.T) {
}
}
func TestWrapCommand_Superpowerd(t *testing.T) {
// Create a fake superpowers binary
tmpBin := t.TempDir()
fakeSP := filepath.Join(tmpBin, "superpowers")
os.WriteFile(fakeSP, []byte("#!/bin/sh\n"), 0755)
t.Setenv("PATH", tmpBin+":"+os.Getenv("PATH"))
old := isSuperpowerdRunningFn
isSuperpowerdRunningFn = func() bool { return true }
defer func() { isSuperpowerdRunningFn = old }()
cfg := &Config{}
got := mustWrapCommand(t, cfg, []string{"echo"}, "/tmp")
if got[0] != fakeSP {
t.Errorf("expected superpowers as first arg; got %v", got)
}
assertContains(t, got, "run-session")
assertContains(t, got, "SUPERPOWERD_SESSION_TOKEN")
}
// ---- isSuperpowerdRunning ----
func TestIsSuperpowerdRunning_NoSocket(t *testing.T) {
t.Setenv("SUPERPOWERD_SOCKET_DIR", "")
t.Setenv("XDG_RUNTIME_DIR", "")
if isSuperpowerdRunning() {
t.Error("should return false with no socket dirs")
}
}
func TestIsSuperpowerdRunning_CustomSocketDir(t *testing.T) {
t.Setenv("SUPERPOWERD_SOCKET_DIR", "/nonexistent/socket/dir")
if isSuperpowerdRunning() {
t.Error("should return false with nonexistent socket")
}
}
func TestIsSuperpowerdRunning_XDGFallback(t *testing.T) {
t.Setenv("SUPERPOWERD_SOCKET_DIR", "")
t.Setenv("XDG_RUNTIME_DIR", t.TempDir())
if isSuperpowerdRunning() {
t.Error("should return false with no actual socket")
}
}
func TestWrapCommand_ColonSeparatedPaths(t *testing.T) {
tmpDir := t.TempDir()
@ -740,22 +692,7 @@ func TestCheckPath_ColonSeparatedPaths(t *testing.T) {
}
}
func TestIsSuperpowerdRunning_SocketExists(t *testing.T) {
tmpDir := t.TempDir()
sockPath := filepath.Join(tmpDir, "superpowerd.sock")
// Start a unixpacket listener
ln, err := net.ListenPacket("unixpacket", sockPath)
if err != nil {
t.Skipf("cannot create unixpacket socket: %v", err)
}
defer ln.Close()
t.Setenv("SUPERPOWERD_SOCKET_DIR", tmpDir)
if !isSuperpowerdRunning() {
t.Error("should return true with active socket")
}
}
// ---- helpers ----

View File

@ -2,10 +2,7 @@ package sandbox
import (
"fmt"
"net"
"os"
"os/exec"
"path/filepath"
"sort"
"strings"
)
@ -16,10 +13,9 @@ type pathEntry struct {
flag string // --ro, --rox, --rw, --rwx
}
// isAvailableFn and isSuperpowerdRunningFn are overridable for testing.
// isAvailableFn is overridable for testing.
var (
isAvailableFn = isAvailable
isSuperpowerdRunningFn = isSuperpowerdRunning
isAvailableFn = isAvailable
)
// ErrNotAvailable is returned when landrun is not found on the system.
@ -96,34 +92,10 @@ func WrapCommand(cfg *Config, originalCmd []string, cwd string, getenv EnvFunc)
args = append(args, "--")
args = append(args, originalCmd...)
// Wrap with superpowers run-session if superpowerd is running
if isSuperpowerdRunningFn() {
if superpowersPath, err := exec.LookPath("superpowers"); err == nil {
args = append([]string{args[0], "--env", "SUPERPOWERD_SESSION_TOKEN"}, args[1:]...)
args = append([]string{superpowersPath, "run-session", "--"}, args...)
}
}
return args, nil
}
// isSuperpowerdRunning checks if superpowerd is running by testing socket connectivity
func isSuperpowerdRunning() bool {
socketDir := os.Getenv("SUPERPOWERD_SOCKET_DIR")
if socketDir == "" {
socketDir = os.Getenv("XDG_RUNTIME_DIR")
if socketDir == "" {
return false
}
socketDir = filepath.Join(socketDir, "superpowerd")
}
conn, err := net.Dial("unixpacket", filepath.Join(socketDir, "superpowerd.sock"))
if err != nil {
return false
}
conn.Close()
return true
}
// pathExists checks if a file or directory exists
func pathExists(path string) bool {