feat(sandbox): per-session windows-acl write grant with dual-mode restricting lists and a private temp subdirectory
This commit is contained in:
@@ -176,7 +176,7 @@ describe('LocalPtyBackend startup rollback', () => {
|
||||
expect(initialized).toHaveBeenCalledWith(undefined)
|
||||
expect((ctx.sandbox as RecordingSandbox).calls).toEqual([{
|
||||
argv: ['/bin/bash', '-i'],
|
||||
policy: { mode: 'workspace-write', workspaceRoot: '/session-workspace' },
|
||||
policy: { mode: 'workspace-write', workspaceRoot: '/session-workspace', sessionId: 'agent' },
|
||||
}])
|
||||
})
|
||||
|
||||
|
||||
@@ -124,7 +124,7 @@ describe('pty-local real shell', () => {
|
||||
const created = await ctx.pty.spawn(agent, { type: 'shell' })
|
||||
expect(sandbox.calls).toEqual([{
|
||||
argv: ['/bin/bash', '--noprofile', '--norc', '-i'],
|
||||
policy: { mode: 'workspace-write', workspaceRoot: realpathSync.native(root) },
|
||||
policy: { mode: 'workspace-write', workspaceRoot: realpathSync.native(root), sessionId: 'agent-workspace-write' },
|
||||
}])
|
||||
await fiber.dispose()
|
||||
expect(ctx.pty.listBackends()).toEqual([])
|
||||
|
||||
Reference in New Issue
Block a user