fix(runner): secure bundled provider entrypoints
This commit is contained in:
parent
e04611d65d
commit
84f1fa89b4
|
|
@ -1,3 +1,4 @@
|
|||
import { chmod } from "node:fs/promises";
|
||||
import { builtinModules } from "node:module";
|
||||
import { dirname, resolve } from "node:path";
|
||||
import { fileURLToPath, pathToFileURL } from "node:url";
|
||||
|
|
@ -63,6 +64,9 @@ export async function bundleVerifiedProviderEntrypoints({ write = true } = {}) {
|
|||
logLevel: "silent",
|
||||
});
|
||||
assertSelfContainedBundle(entrypoint, result);
|
||||
if (write && process.platform !== "win32") {
|
||||
await chmod(entrypoint.output, 0o755);
|
||||
}
|
||||
results.push({ entrypoint, result });
|
||||
}
|
||||
return results;
|
||||
|
|
|
|||
|
|
@ -1,4 +1,5 @@
|
|||
import assert from "node:assert/strict";
|
||||
import { stat } from "node:fs/promises";
|
||||
import test from "node:test";
|
||||
|
||||
import {
|
||||
|
|
@ -15,3 +16,16 @@ test("verified JS provider entrypoints bundle into one descriptor-safe file", as
|
|||
assert.match(source, /^#!\/usr\/bin\/env node\n/);
|
||||
}
|
||||
});
|
||||
|
||||
test("written provider entrypoints satisfy qualified launch permissions", async (t) => {
|
||||
if (process.platform === "win32") {
|
||||
t.skip("POSIX launch permissions do not apply on Windows");
|
||||
return;
|
||||
}
|
||||
await bundleVerifiedProviderEntrypoints();
|
||||
for (const entrypoint of verifiedProviderEntrypoints) {
|
||||
const mode = (await stat(entrypoint.output)).mode;
|
||||
assert.equal(mode & 0o022, 0, entrypoint.name);
|
||||
assert.notEqual(mode & 0o100, 0, entrypoint.name);
|
||||
}
|
||||
});
|
||||
|
|
|
|||
Loading…
Reference in New Issue