mirror of
https://hubproxy.babadafafafafa.cn/https://github.com/usestrix/strix.git
synced 2026-09-20 16:13:44 +08:00
Compare commits
2 Commits
main
...
fix/writab
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a4f39e1b53 | ||
|
|
fdf8747407 |
@@ -1323,7 +1323,6 @@ def collect_local_sources(targets_info: list[dict[str, Any]]) -> list[dict[str,
|
||||
"source_path": details["target_path"],
|
||||
"workspace_subdir": workspace_subdir,
|
||||
"protect_metadata": True,
|
||||
"read_only": bool(details.get("read_only")),
|
||||
}
|
||||
)
|
||||
|
||||
|
||||
@@ -70,9 +70,8 @@ def build_bind_mounts(local_sources: list[dict[str, Any]]) -> list[dict[str, Any
|
||||
continue
|
||||
resolved = Path(host_path).expanduser().resolve()
|
||||
target = f"{_WORKSPACE_ROOT}/{ws_subdir}"
|
||||
read_only = bool(src.get("read_only"))
|
||||
bind_mounts.append({"source": str(resolved), "target": target, "read_only": read_only})
|
||||
if src.get("protect_metadata") and not read_only:
|
||||
bind_mounts.append({"source": str(resolved), "target": target, "read_only": False})
|
||||
if src.get("protect_metadata"):
|
||||
bind_mounts.extend(_metadata_mounts(resolved, target))
|
||||
return bind_mounts
|
||||
|
||||
|
||||
@@ -1323,12 +1323,6 @@ async def create_vulnerability_report(
|
||||
A restrictive CSP that blocks inline script execution would
|
||||
reduce impact and lower the severity.
|
||||
fix_effort: "low"
|
||||
|
||||
Nice to have: for code findings, if the checkout has git history, a quick
|
||||
``git blame`` (quote the paths) on the vulnerable line is worth weaving into
|
||||
``technical_analysis`` — who last touched it, when, and in which commit, as
|
||||
part of the prose, not a separate section. Skip it if the line is
|
||||
uncommitted or the command fails.
|
||||
"""
|
||||
(
|
||||
http_exchange_ids,
|
||||
|
||||
@@ -30,26 +30,7 @@ def _local_target(target_path: str) -> dict[str, Any]:
|
||||
def test_collect_local_sources_protects_the_users_own_git() -> None:
|
||||
sources = collect_local_sources([_local_target("/code")])
|
||||
assert sources == [
|
||||
{
|
||||
"source_path": "/code",
|
||||
"workspace_subdir": "repo",
|
||||
"protect_metadata": True,
|
||||
"read_only": False,
|
||||
}
|
||||
]
|
||||
|
||||
|
||||
def test_collect_local_sources_forwards_read_only() -> None:
|
||||
target = _local_target("/layout")
|
||||
target["details"]["read_only"] = True
|
||||
sources = collect_local_sources([target])
|
||||
assert sources == [
|
||||
{
|
||||
"source_path": "/layout",
|
||||
"workspace_subdir": "repo",
|
||||
"protect_metadata": True,
|
||||
"read_only": True,
|
||||
}
|
||||
{"source_path": "/code", "workspace_subdir": "repo", "protect_metadata": True}
|
||||
]
|
||||
|
||||
|
||||
|
||||
@@ -1089,16 +1089,6 @@ def test_tool_descriptions_include_formatting_guidance() -> None:
|
||||
assert "reachab" in dep_desc.lower()
|
||||
|
||||
|
||||
def test_git_blame_hint_is_a_trailing_note() -> None:
|
||||
desc = create_vulnerability_report.description
|
||||
assert desc.count("blame") == 1
|
||||
tail = desc[desc.index("Nice to have:") :]
|
||||
assert "git blame" in tail
|
||||
assert "technical_analysis" in tail
|
||||
assert "Example" not in tail
|
||||
assert "blame" not in update_vulnerability_report.description
|
||||
|
||||
|
||||
def test_vuln_tool_exposes_new_params() -> None:
|
||||
props = create_vulnerability_report.params_json_schema["properties"]
|
||||
for field in (
|
||||
|
||||
@@ -27,15 +27,8 @@ from strix.runtime.session_manager import (
|
||||
)
|
||||
|
||||
|
||||
def _source(
|
||||
subdir: str, path: str, *, protect_metadata: bool = False, read_only: bool = False
|
||||
) -> dict[str, Any]:
|
||||
return {
|
||||
"source_path": path,
|
||||
"workspace_subdir": subdir,
|
||||
"protect_metadata": protect_metadata,
|
||||
"read_only": read_only,
|
||||
}
|
||||
def _source(subdir: str, path: str, *, protect_metadata: bool = False) -> dict[str, Any]:
|
||||
return {"source_path": path, "workspace_subdir": subdir, "protect_metadata": protect_metadata}
|
||||
|
||||
|
||||
def test_source_becomes_writable_bind_mount(tmp_path: Path) -> None:
|
||||
@@ -131,16 +124,6 @@ def test_clone_keeps_its_git_writable(tmp_path: Path) -> None:
|
||||
assert [m["target"] for m in mounts] == ["/workspace/clone"]
|
||||
|
||||
|
||||
def test_read_only_source_is_one_read_only_mount(tmp_path: Path) -> None:
|
||||
(tmp_path / ".git").mkdir()
|
||||
mounts = build_bind_mounts(
|
||||
[_source("image", str(tmp_path), protect_metadata=True, read_only=True)]
|
||||
)
|
||||
assert mounts == [
|
||||
{"source": str(tmp_path.resolve()), "target": "/workspace/image", "read_only": True}
|
||||
]
|
||||
|
||||
|
||||
def test_multiple_sources_each_get_a_mount(tmp_path: Path) -> None:
|
||||
first = tmp_path / "first"
|
||||
second = tmp_path / "second"
|
||||
|
||||
Reference in New Issue
Block a user