fix(runner): secure bundled provider entrypoints

This commit is contained in:
Dotta 2026-09-02 16:55:16 -05:00
parent e04611d65d
commit 84f1fa89b4
2 changed files with 18 additions and 0 deletions

View File

@ -1,3 +1,4 @@
import { chmod } from "node:fs/promises";
import { builtinModules } from "node:module";
import { dirname, resolve } from "node:path";
import { fileURLToPath, pathToFileURL } from "node:url";
@ -63,6 +64,9 @@ export async function bundleVerifiedProviderEntrypoints({ write = true } = {}) {
logLevel: "silent",
});
assertSelfContainedBundle(entrypoint, result);
if (write && process.platform !== "win32") {
await chmod(entrypoint.output, 0o755);
}
results.push({ entrypoint, result });
}
return results;

View File

@ -1,4 +1,5 @@
import assert from "node:assert/strict";
import { stat } from "node:fs/promises";
import test from "node:test";
import {
@ -15,3 +16,16 @@ test("verified JS provider entrypoints bundle into one descriptor-safe file", as
assert.match(source, /^#!\/usr\/bin\/env node\n/);
}
});
test("written provider entrypoints satisfy qualified launch permissions", async (t) => {
if (process.platform === "win32") {
t.skip("POSIX launch permissions do not apply on Windows");
return;
}
await bundleVerifiedProviderEntrypoints();
for (const entrypoint of verifiedProviderEntrypoints) {
const mode = (await stat(entrypoint.output)).mode;
assert.equal(mode & 0o022, 0, entrypoint.name);
assert.notEqual(mode & 0o100, 0, entrypoint.name);
}
});