//! A grant path is mounted into the tool container as `--volume=::ro`, so a path with //! `:` or `,` in it cannot be granted: the set is invalid, as for any other bad grant (M3b spec, //! section 3). Do not edit. #[path = "support/tmp.rs"] mod tmp; use brokerd::grants::load; use tmp::TempDir; fn grant_with_path(path: &str) -> String { format!( "tool = \"read_file\"\nmode = \"auto\"\nmax_taint = \"secret\"\n[constraints]\npaths = [{path:?}]\n" ) } #[test] fn a_path_with_a_colon_or_a_comma_makes_the_set_invalid() { for path in ["/home/kyle/a:b", "/home/kyle/a,b", "/x:/y", "/n,ro"] { let dir = TempDir::new("mount-bad"); dir.write("notes.toml", &grant_with_path(path)); let problems = load(dir.path()).expect_err(path); assert_eq!(problems.len(), 1, "{path}: {problems:?}"); assert_eq!(problems[0].file, "notes.toml"); assert!( problems[0].problem.contains("cannot be mounted"), "{path}: {}", problems[0].problem ); } } #[test] fn other_punctuation_is_still_fine() { for path in [ "/home/kyle/a b", "/home/kyle/a;b", "/home/kyle/a=b", "/home/kyle/a.b-c_d", ] { let dir = TempDir::new("mount-ok"); dir.write("notes.toml", &grant_with_path(path)); assert!(load(dir.path()).is_ok(), "{path}"); } }