Files
wehub-resource-sync 426e9eeabd
Voice Workbench / headless workbench (mocked backends) (push) Has been cancelled
Voice Workbench / real acoustic lane (nightly, provisioned only) (push) Has been cancelled
ci / test (push) Has been cancelled
ci / lint-and-format (push) Has been cancelled
ci / build (push) Has been cancelled
ci / dev-startup (push) Has been cancelled
gitleaks / gitleaks (push) Has been cancelled
Markdown Links / Relative Markdown Links (push) Has been cancelled
Quality (Extended) / Homepage Build (PR smoke) (push) Has been cancelled
Quality (Extended) / Comment-only diff guard (push) Has been cancelled
Quality (Extended) / Format + Type Safety Ratchet (push) Has been cancelled
Quality (Extended) / Develop Gate (secret scan + UI determinism) (push) Has been cancelled
Quality (Extended) / Develop Gate (lint) (push) Has been cancelled
Chat shell gestures / Chat shell gesture + parity e2e (push) Has been cancelled
Cloud Gateway Discord / Test (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx @biomejs/biome check packages/lifeops-bench/src, benchmark-lint) (push) Has been cancelled
Benchmark Bridge Tests / benchmark (bunx vitest run --config packages/lifeops-bench/vitest.config.ts --root packages/lifeops-bench --passWithNoTests, benchmark-tests) (push) Has been cancelled
Build Agent Image / build-and-push (push) Has been cancelled
Dev Smoke / bun run dev onboarding chat (push) Has been cancelled
Dev Smoke / Vite HMR dependency-level smoke (push) Has been cancelled
Electrobun Submodule Guard / electrobun gitlink is fetchable (push) Has been cancelled
Publish @elizaos/example-code / check_npm (push) Has been cancelled
Publish @elizaos/example-code / publish_npm (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / verify_version (push) Has been cancelled
Publish @elizaos/plugin-elizacloud / publish_npm (push) Has been cancelled
Sandbox Live Smoke / Sandbox live smoke (push) Has been cancelled
Snap Build & Test / Build Snap (amd64) (push) Has been cancelled
Snap Build & Test / Build Snap (arm64) (push) Has been cancelled
Test Packaging / elizaos CLI global-install smoke (node + bun) (push) Has been cancelled
Cloud Gateway Webhook / Test (push) Has been cancelled
Cloud Tests / lint-and-types (push) Has been cancelled
Cloud Tests / unit-tests (push) Has been cancelled
Cloud Tests / integration-tests (push) Has been cancelled
Cloud Tests / e2e-tests (push) Has been cancelled
CodeQL Advanced / Analyze (javascript-typescript) (push) Has been cancelled
Deploy Apps Worker (Product 2) / Determine environment (push) Has been cancelled
Deploy Apps Worker (Product 2) / Deploy apps worker to apps-control host (${{ needs.determine-env.outputs.environment }}) (push) Has been cancelled
Deploy Eliza Provisioning Worker / Determine environment (push) Has been cancelled
Deploy Eliza Provisioning Worker / Deploy worker to Hetzner host (${{ needs.determine-env.outputs.environment }} @ ${{ needs.determine-env.outputs.deployment_sha }}) (push) Has been cancelled
Dev Smoke / Classify changed paths (push) Has been cancelled
supply-chain / sbom (push) Has been cancelled
supply-chain / vulnerability-scan (push) Has been cancelled
Build, Push & Deploy to Phala Cloud / build-and-push (push) Has been cancelled
Test Packaging / Validate Packaging Configs (push) Has been cancelled
Test Packaging / Build & Test PyPI Package (push) Has been cancelled
Test Packaging / PyPI on Python ${{ matrix.python }} (push) Has been cancelled
Test Packaging / Pack & Test JS Tarballs (push) Has been cancelled
UI Fixture E2E / ui-fixture-e2e (push) Has been cancelled
UI Fixture E2E / fixture-e2e (push) Has been cancelled
UI Story Gate / story-gate (push) Has been cancelled
vault-ci / test (macos-latest) (push) Has been cancelled
vault-ci / test (ubuntu-latest) (push) Has been cancelled
vault-ci / test (windows-latest) (push) Has been cancelled
vault-ci / app-core wiring tests (push) Has been cancelled
verify-patches / verify patches/CHECKSUMS.sha256 (push) Has been cancelled
Voice Benchmark Smoke / voice-emotion fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voiceagentbench fixture smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench-quality unit smoke (push) Has been cancelled
Voice Benchmark Smoke / voicebench TypeScript unit (no audio) (push) Has been cancelled
Voice Benchmark Smoke / voice bench smoke summary (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/app-core test bun run --cwd packages/elizaos test bun run --cwd packages/cloud/shared test], app-and-cli) (push) Has been cancelled
Windows CI / windows ([bun run --cwd packages/scenario-runner test bun run --cwd packages/vault test bun run --cwd packages/security test bun run --cwd plugins/plugin-coding-tools test], framework-packages) (push) Has been cancelled
Windows CI / windows ([bun run --cwd plugins/plugin-elizacloud test bun run --cwd plugins/plugin-discord test bun run --cwd plugins/plugin-anthropic test bun run --cwd plugins/plugin-openai test bun run --cwd plugins/plugin-app-control test bun run --cwd plugins/pl… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run build --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/agent --concurrency=4 node packages/scripts/run-bash-linux-only.mjs scripts/verify-riscv64-buildpaths.sh node packages/scripts/run… (push) Has been cancelled
Windows CI / windows ([node packages/scripts/run-turbo.mjs run typecheck --filter=@elizaos/core --filter=@elizaos/shared --filter=@elizaos/cloud-shared --concurrency=4 bun run --cwd packages/core test bun run --cwd packages/shared test], core-runtime, 75) (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:43:05 +08:00

142 lines
4.7 KiB
TypeScript

/**
* Verifies assertSafeGitRemote.
* Deterministic unit test of pure helpers; no runtime, no live model.
*/
import { describe, expect, it } from "vitest";
import {
assertSafeGitRef,
assertSafeGitRemote,
normalizeRepositoryInput,
UnsafeGitRefError,
UnsafeGitRemoteError,
} from "../../src/services/repo-input.js";
// The coding orchestrator clones repos on behalf of sub-agents whose task text
// is model/attacker-influenced. `git clone` / `git ls-remote` expose command
// execution and local-disclosure vectors through the remote argument, so every
// repo string is run through assertSafeGitRemote before it reaches git.
describe("assertSafeGitRemote", () => {
it("accepts https / http / ssh URLs and scp-style ssh remotes", () => {
for (const ok of [
"https://github.com/owner/repo.git",
"https://github.com/owner/repo",
"http://git.internal.example/owner/repo.git",
"ssh://git@github.com/owner/repo.git",
"git@github.com:owner/repo.git",
"user-name@host.example.com:group/sub/repo",
]) {
expect(assertSafeGitRemote(ok)).toBe(ok);
}
});
it("accepts the output of normalizeRepositoryInput for every shorthand form", () => {
for (const input of [
"owner/repo",
"owner/repo.git",
"github.com/owner/repo",
"https://github.com/owner/repo/",
"git@github.com:owner/repo.git",
]) {
const normalized = normalizeRepositoryInput(input);
expect(() => assertSafeGitRemote(normalized)).not.toThrow();
}
});
it("rejects the ext:: remote-helper (arbitrary command execution / RCE)", () => {
expect(() => assertSafeGitRemote('ext::sh -c "touch /tmp/pwned"')).toThrow(
UnsafeGitRemoteError,
);
// any <helper>:: transport prefix, not just ext
expect(() => assertSafeGitRemote("fd::17/repo")).toThrow(
UnsafeGitRemoteError,
);
expect(() => assertSafeGitRemote("foo::bar")).toThrow(UnsafeGitRemoteError);
});
it("rejects a leading '-' (argument injection, e.g. --upload-pack=…)", () => {
expect(() => assertSafeGitRemote("--upload-pack=touch /tmp/pwned")).toThrow(
UnsafeGitRemoteError,
);
expect(() => assertSafeGitRemote("-oProxyCommand=sh")).toThrow(
UnsafeGitRemoteError,
);
});
it("rejects file:// (local repository disclosure) and git:// (unauthenticated)", () => {
expect(() => assertSafeGitRemote("file:///etc/passwd")).toThrow(
UnsafeGitRemoteError,
);
expect(() => assertSafeGitRemote("git://evil.example/repo")).toThrow(
UnsafeGitRemoteError,
);
});
it("rejects empty / whitespace / bare tokens that are not valid remotes", () => {
expect(() => assertSafeGitRemote("")).toThrow(UnsafeGitRemoteError);
expect(() => assertSafeGitRemote(" ")).toThrow(UnsafeGitRemoteError);
expect(() => assertSafeGitRemote("just-a-word")).toThrow(
UnsafeGitRemoteError,
);
});
it("does not misclassify an IPv6 https URL as a transport helper", () => {
// `::` inside an IPv6 literal must NOT trip the `<helper>::` check.
const ipv6 = "https://[2001:db8::1]/owner/repo.git";
expect(assertSafeGitRemote(ipv6)).toBe(ipv6);
});
it("rejects shell metacharacters / whitespace even behind a valid scheme", () => {
// The unauthenticated clone path in git-workspace-service runs the remote
// through a shell, so an `https://`-prefixed string with metacharacters is
// still command injection. A prefix-only scheme check would wave these
// through — the reason #10980's fix left the RCE reachable.
for (const bad of [
"https://127.0.0.1/x; touch /tmp/pwned",
"https://127.0.0.1/x$(touch /tmp/pwned)",
"https://127.0.0.1/x`id`",
"https://127.0.0.1/x|touch /tmp/pwned",
"https://127.0.0.1/x && touch /tmp/pwned",
"https://127.0.0.1/x\ntouch /tmp/pwned",
]) {
expect(() => assertSafeGitRemote(bad)).toThrow(UnsafeGitRemoteError);
}
});
});
describe("assertSafeGitRef", () => {
it("accepts ordinary branch / ref names", () => {
for (const ok of [
"main",
"develop",
"master",
"feature/foo-bar",
"release/1.2.3",
"v1.0.0",
"eliza/task-abc123",
]) {
expect(assertSafeGitRef(ok)).toBe(ok);
}
});
it("rejects a leading '-' (argument injection)", () => {
expect(() => assertSafeGitRef("--upload-pack=sh")).toThrow(
UnsafeGitRefError,
);
});
it("rejects shell metacharacters / whitespace (branch-name command injection)", () => {
for (const bad of [
"main; touch /tmp/pwned",
"main$(touch /tmp/pwned)",
"main`id`",
"main | sh",
"main && rm -rf /",
"with space",
"",
]) {
expect(() => assertSafeGitRef(bad)).toThrow(UnsafeGitRefError);
}
});
});