sandbox: remove superpowerd integration
Elevation is now handled by the integrated broker in olliesrv. No longer wraps commands with superpowers run-session.
This commit is contained in:
parent
fb8f4acff1
commit
bd40dc9637
|
|
@ -3,7 +3,6 @@ package sandbox
|
|||
import (
|
||||
"bytes"
|
||||
"fmt"
|
||||
"net"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"testing"
|
||||
|
|
@ -99,10 +98,6 @@ func TestExpandPath(t *testing.T) {
|
|||
// ---- WrapCommand ----
|
||||
|
||||
func TestWrapCommand(t *testing.T) {
|
||||
old := isSuperpowerdRunningFn
|
||||
isSuperpowerdRunningFn = func() bool { return false }
|
||||
defer func() { isSuperpowerdRunningFn = old }()
|
||||
|
||||
tmpDir := t.TempDir()
|
||||
rwDir := filepath.Join(tmpDir, "rw")
|
||||
roDir := filepath.Join(tmpDir, "ro")
|
||||
|
|
@ -630,50 +625,7 @@ func TestWrapCommand_SortTiebreaker(t *testing.T) {
|
|||
}
|
||||
}
|
||||
|
||||
func TestWrapCommand_Superpowerd(t *testing.T) {
|
||||
// Create a fake superpowers binary
|
||||
tmpBin := t.TempDir()
|
||||
fakeSP := filepath.Join(tmpBin, "superpowers")
|
||||
os.WriteFile(fakeSP, []byte("#!/bin/sh\n"), 0755)
|
||||
t.Setenv("PATH", tmpBin+":"+os.Getenv("PATH"))
|
||||
|
||||
old := isSuperpowerdRunningFn
|
||||
isSuperpowerdRunningFn = func() bool { return true }
|
||||
defer func() { isSuperpowerdRunningFn = old }()
|
||||
|
||||
cfg := &Config{}
|
||||
got := mustWrapCommand(t, cfg, []string{"echo"}, "/tmp")
|
||||
if got[0] != fakeSP {
|
||||
t.Errorf("expected superpowers as first arg; got %v", got)
|
||||
}
|
||||
assertContains(t, got, "run-session")
|
||||
assertContains(t, got, "SUPERPOWERD_SESSION_TOKEN")
|
||||
}
|
||||
|
||||
// ---- isSuperpowerdRunning ----
|
||||
|
||||
func TestIsSuperpowerdRunning_NoSocket(t *testing.T) {
|
||||
t.Setenv("SUPERPOWERD_SOCKET_DIR", "")
|
||||
t.Setenv("XDG_RUNTIME_DIR", "")
|
||||
if isSuperpowerdRunning() {
|
||||
t.Error("should return false with no socket dirs")
|
||||
}
|
||||
}
|
||||
|
||||
func TestIsSuperpowerdRunning_CustomSocketDir(t *testing.T) {
|
||||
t.Setenv("SUPERPOWERD_SOCKET_DIR", "/nonexistent/socket/dir")
|
||||
if isSuperpowerdRunning() {
|
||||
t.Error("should return false with nonexistent socket")
|
||||
}
|
||||
}
|
||||
|
||||
func TestIsSuperpowerdRunning_XDGFallback(t *testing.T) {
|
||||
t.Setenv("SUPERPOWERD_SOCKET_DIR", "")
|
||||
t.Setenv("XDG_RUNTIME_DIR", t.TempDir())
|
||||
if isSuperpowerdRunning() {
|
||||
t.Error("should return false with no actual socket")
|
||||
}
|
||||
}
|
||||
|
||||
func TestWrapCommand_ColonSeparatedPaths(t *testing.T) {
|
||||
tmpDir := t.TempDir()
|
||||
|
|
@ -740,22 +692,7 @@ func TestCheckPath_ColonSeparatedPaths(t *testing.T) {
|
|||
}
|
||||
}
|
||||
|
||||
func TestIsSuperpowerdRunning_SocketExists(t *testing.T) {
|
||||
tmpDir := t.TempDir()
|
||||
sockPath := filepath.Join(tmpDir, "superpowerd.sock")
|
||||
|
||||
// Start a unixpacket listener
|
||||
ln, err := net.ListenPacket("unixpacket", sockPath)
|
||||
if err != nil {
|
||||
t.Skipf("cannot create unixpacket socket: %v", err)
|
||||
}
|
||||
defer ln.Close()
|
||||
|
||||
t.Setenv("SUPERPOWERD_SOCKET_DIR", tmpDir)
|
||||
if !isSuperpowerdRunning() {
|
||||
t.Error("should return true with active socket")
|
||||
}
|
||||
}
|
||||
|
||||
// ---- helpers ----
|
||||
|
||||
|
|
|
|||
|
|
@ -2,10 +2,7 @@ package sandbox
|
|||
|
||||
import (
|
||||
"fmt"
|
||||
"net"
|
||||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"sort"
|
||||
"strings"
|
||||
)
|
||||
|
|
@ -16,10 +13,9 @@ type pathEntry struct {
|
|||
flag string // --ro, --rox, --rw, --rwx
|
||||
}
|
||||
|
||||
// isAvailableFn and isSuperpowerdRunningFn are overridable for testing.
|
||||
// isAvailableFn is overridable for testing.
|
||||
var (
|
||||
isAvailableFn = isAvailable
|
||||
isSuperpowerdRunningFn = isSuperpowerdRunning
|
||||
isAvailableFn = isAvailable
|
||||
)
|
||||
|
||||
// ErrNotAvailable is returned when landrun is not found on the system.
|
||||
|
|
@ -96,34 +92,10 @@ func WrapCommand(cfg *Config, originalCmd []string, cwd string, getenv EnvFunc)
|
|||
args = append(args, "--")
|
||||
args = append(args, originalCmd...)
|
||||
|
||||
// Wrap with superpowers run-session if superpowerd is running
|
||||
if isSuperpowerdRunningFn() {
|
||||
if superpowersPath, err := exec.LookPath("superpowers"); err == nil {
|
||||
args = append([]string{args[0], "--env", "SUPERPOWERD_SESSION_TOKEN"}, args[1:]...)
|
||||
args = append([]string{superpowersPath, "run-session", "--"}, args...)
|
||||
}
|
||||
}
|
||||
|
||||
return args, nil
|
||||
}
|
||||
|
||||
// isSuperpowerdRunning checks if superpowerd is running by testing socket connectivity
|
||||
func isSuperpowerdRunning() bool {
|
||||
socketDir := os.Getenv("SUPERPOWERD_SOCKET_DIR")
|
||||
if socketDir == "" {
|
||||
socketDir = os.Getenv("XDG_RUNTIME_DIR")
|
||||
if socketDir == "" {
|
||||
return false
|
||||
}
|
||||
socketDir = filepath.Join(socketDir, "superpowerd")
|
||||
}
|
||||
conn, err := net.Dial("unixpacket", filepath.Join(socketDir, "superpowerd.sock"))
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
conn.Close()
|
||||
return true
|
||||
}
|
||||
|
||||
|
||||
// pathExists checks if a file or directory exists
|
||||
func pathExists(path string) bool {
|
||||
|
|
|
|||
Reference in New Issue