use super::super::Effect;
use super::{effect, judged};
use serde_json::json;
#[test]
fn a_routed_shell_is_classified_by_its_command_line() {
let destructive = judged(
"box2_shell",
json!({"command": "find /srv/data/blobs -mindepth 1 -delete"}),
);
assert_eq!(destructive.effect, Effect::Destructive);
assert!(
destructive.why.contains("/srv/data/blobs"),
"{}",
destructive.why
);
assert_eq!(
effect("box2_shell", json!({"command": "env"})),
Effect::Secret
);
assert_eq!(
effect("box2_shell", json!({"command": "ls -la"})),
Effect::Read
);
assert_eq!(
judged(
"bash",
json!({"command": "find /srv/data/blobs -mindepth 1 -delete"})
),
destructive
);
}
#[test]
fn a_tool_this_control_cannot_read_is_opaque_and_never_a_passing_class() {
for (name, input) in [
("litany-tool-deploy", json!({})),
("box2_install_package", json!({"name": "curl"})),
("box2_rotate_log", json!({"path": "/var/log/x"})),
("box2_shell", json!({"command": 7})),
("box2_shell", json!({"command": " "})),
] {
let c = judged(name, input);
assert_eq!(c.effect, Effect::Opaque, "{name}");
assert!(c.why.contains(name), "{}", c.why);
assert_eq!(
crate::control::judge::Table::ruling(c.effect),
crate::control::judge::Ruling::Hold,
"{name}"
);
}
}
#[test]
fn a_cd_into_the_target_classifies_as_the_direct_form_does() {
let direct = judged("box2_shell", json!({"command": "rm -f /srv/data/blobs/*"}));
assert_eq!(direct.effect, Effect::Destructive);
let chained = judged(
"box2_shell",
json!({"command": "cd /srv/data/blobs && rm -f -- *"}),
);
assert_eq!(chained.effect, Effect::Destructive, "{}", chained.why);
assert_eq!(
effect("box2_shell", json!({"command": "rm -rf /w/agent/build"})),
Effect::Destructive
);
assert_eq!(
effect("bash", json!({"command": "rm -rf /w/agent/build"})),
Effect::TargetWrite
);
assert_eq!(
effect("box2_shell", json!({"command": "ls -la /srv/data"})),
Effect::Read
);
}
#[test]
fn an_input_naming_a_url_is_the_open_world_class() {
let c = judged("box2_fetch", json!({"url": "https://example.invalid/x"}));
assert_eq!(c.effect, Effect::OpenWorld);
assert!(c.why.contains("box2_fetch"), "{}", c.why);
assert!(c.why.contains("url"), "{}", c.why);
assert_eq!(
crate::control::judge::Table::ruling(c.effect),
crate::control::judge::Ruling::Pass
);
assert_eq!(
effect("box2_fetch", json!({"urls": ["https://a.invalid"]})),
Effect::OpenWorld
);
assert_eq!(
effect(
"box2_fetch",
json!({"url": "https://a.invalid", "max_length": 5000, "raw": false})
),
Effect::OpenWorld
);
assert_eq!(
effect(
"box2_shell",
json!({"command": "rm -rf /srv/data", "url": "https://a.invalid"})
),
Effect::Destructive
);
}
#[test]
fn an_input_naming_no_address_stays_opaque() {
for input in [
json!({}),
json!({"name": "curl"}),
json!({"url": ""}),
json!({"url": " "}),
json!({"url": 7}),
json!({"urls": []}),
json!({"urls": [" ", 7]}),
json!({"url_prefix": "https://a.invalid"}),
] {
assert_eq!(
effect("box2_fetch", input.clone()),
Effect::Opaque,
"{input}"
);
}
}