Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion crates/openshell-driver-mxc/examples/inference.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -21,4 +21,4 @@ network_policies:
access: read-write
enforcement: enforce
binaries:
- path: '__CMD_EXE__'
- path: '__CURL_EXE__'
Original file line number Diff line number Diff line change
Expand Up @@ -209,7 +209,7 @@ try {
$sharePolicy = $ShareDir.Replace('\', '/')
$policyText = [System.IO.File]::ReadAllText((Join-Path $here "inference.yaml"))
$policyText = $policyText.Replace("__OPENSHELL_DEMO_SHARE__", $sharePolicy)
$policyText = $policyText.Replace("__CMD_EXE__", $cmdExe)
$policyText = $policyText.Replace("__CURL_EXE__", $curlExe)
$policyText = $policyText.Replace("__INFERENCE_HOST__", $apiUri.DnsSafeHost)
$policyText = $policyText.Replace("__INFERENCE_PORT__", [string] $apiUri.Port)
Write-Utf8 $policyUsed $policyText
Expand Down
3 changes: 2 additions & 1 deletion crates/openshell-driver-mxc/src/driver.rs
Original file line number Diff line number Diff line change
Expand Up @@ -2989,7 +2989,8 @@ mod lifecycle_tests {
.replace("__OLLAMA_PORT__", "11434")
.replace("__INFERENCE_HOST__", "integrate.api.nvidia.com")
.replace("__INFERENCE_PORT__", "443")
.replace("__CMD_EXE__", r"C:\Windows\System32\cmd.exe");
.replace("__CMD_EXE__", r"C:\Windows\System32\cmd.exe")
.replace("__CURL_EXE__", r"C:\Windows\System32\curl.exe");
parse_sandbox_policy(&rendered).expect("parse rendered shipped demo policy")
}

Expand Down
19 changes: 15 additions & 4 deletions crates/openshell-driver-mxc/tests/demo_examples.rs
Original file line number Diff line number Diff line change
Expand Up @@ -206,22 +206,31 @@ fn shipped_inference_policies_are_narrow_and_valid_after_rendering() {
"/portable/demo"
};
let fixtures = [
("ollama.yaml", "local_ollama", "127.0.0.1", share),
(
"ollama.yaml",
"local_ollama",
"127.0.0.1",
share,
"__CMD_EXE__",
r"C:\Windows\System32\cmd.exe",
),
(
"inference.yaml",
"nvidia_inference",
"integrate.api.nvidia.com",
share,
"__CURL_EXE__",
r"C:\Windows\System32\curl.exe",
),
];
for (name, rule_name, endpoint, share) in fixtures {
for (name, rule_name, endpoint, share, binary_placeholder, binary_path) in fixtures {
let rendered = read_example(name)
.replace("__OPENSHELL_DEMO_SHARE__", share)
.replace("__OLLAMA_HOST__", "127.0.0.1")
.replace("__OLLAMA_PORT__", "11434")
.replace("__INFERENCE_HOST__", "integrate.api.nvidia.com")
.replace("__INFERENCE_PORT__", "443")
.replace("__CMD_EXE__", r"C:\Windows\System32\cmd.exe");
.replace(binary_placeholder, binary_path);
let policy = parse_sandbox_policy(&rendered)
.unwrap_or_else(|error| panic!("failed to parse rendered {name}: {error}"));
validate_sandbox_policy(&policy)
Expand All @@ -241,7 +250,7 @@ fn shipped_inference_policies_are_narrow_and_valid_after_rendering() {
assert_eq!(rule.binaries.len(), 1);
assert_eq!(
rule.binaries[0].path.to_ascii_lowercase(),
r"c:\windows\system32\cmd.exe"
binary_path.to_ascii_lowercase()
);
}
}
Expand Down Expand Up @@ -288,6 +297,8 @@ fn shipped_runners_supply_sandbox_scoped_workload_configuration() {
assert!(cloud.contains("--noproxy"));
assert!(cloud.contains("in-process wxc shim"));
assert!(cloud.contains("does not provide MXC or AppContainer isolation"));
assert!(cloud.contains("$policyText.Replace(\"__CURL_EXE__\", $curlExe)"));
assert!(!cloud.contains("$policyText.Replace(\"__CMD_EXE__\", $cmdExe)"));
}

#[cfg(target_os = "windows")]
Expand Down
3 changes: 2 additions & 1 deletion crates/openshell-driver-mxc/tests/wxc_exec_real.rs
Original file line number Diff line number Diff line change
Expand Up @@ -982,6 +982,7 @@ async fn pc_https_egress_reads_injected_ca_bundle() {
let post_status_path_string = post_status_path.to_string_lossy().into_owned();
let diagnostic_path_string = diagnostic_path.to_string_lossy().into_owned();
let cmd_string = cmd.to_string_lossy().into_owned();
let curl_string = curl.to_string_lossy().into_owned();
// Schannel's revocation lookup targets are intentionally outside this
// test's example.com-only policy. Disable that network lookup while still
// requiring curl to validate the proxy-issued certificate against the
Expand Down Expand Up @@ -1036,7 +1037,7 @@ async fn pc_https_egress_reads_injected_ca_bundle() {
access: "read-only".to_string(),
..Default::default()
}],
binaries: vec![NetworkBinary { path: cmd_string }],
binaries: vec![NetworkBinary { path: curl_string }],
},
)]),
..Default::default()
Expand Down
Loading