Repository navigation
[test] Add tests for launcher.canonicalizeRoots and launcher.isUnderRoot - #11564
Conversation
- canonicalizeRoots: cover dropping uncanonicalizable roots, deduping equivalent roots reached via symlink aliases, and empty input. - isUnderRoot: cover exact match, nested path, sibling prefix collision, parent traversal escape, and the filepath.Rel error branch from mixing absolute/relative path+root arguments. Coverage: canonicalizeRoots 82.4% -> 100.0%, isUnderRoot 83.3% -> 100.0% Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Pull request overview
Adds targeted tests for security-sensitive mount path canonicalization and containment.
Changes:
- Tests invalid, duplicate, and empty mount roots.
- Adds table-driven containment edge-case tests.
Show a summary per file
| File | Description |
|---|---|
internal/launcher/mount_policy_test.go |
Expands coverage for canonicalization and root containment. |
Review details
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
- Files reviewed: 1/1 changed files
- Comments generated: 1
- Review effort level: Balanced
| want: false, | ||
| }, | ||
| { | ||
| name: "root is parent of path root itself", |
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
This comment has been minimized.
|
@copilot address review feedback and fix failing ci check https://github.com/github/gh-aw-mcpg/actions/runs/32394432076/job/96512793943?pr=11564 |
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
Addressed in commit
|
🔒 mcpg Read-Only Stress — defaultSurface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Overall: INCONCLUSIVE
No writes leaked. No FAIL conditions observed.
|
🔒 mcpg Read-Only Stress — docker-sbxSurface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Overall: INCONCLUSIVE Notes
References: §32397209354
|
🔒 mcpg Read-Only Stress — gVisorSurface coverage: MCP tool calls + proxied CLI (REST) + GraphQL mutations
Overall: INCONCLUSIVE
Run: §32397209342
|
Test Coverage Improvement:
canonicalizeRoots/isUnderRootFunction Analyzed
internal/launchermount_policy.gocanonicalizeRoots,isUnderRootcanonicalizeRoots82.4%,isUnderRoot83.3%Why This Function?
mount_policy.goimplements the host-mount security boundary described in the MCP Gateway containerization spec.canonicalizeRootsandisUnderRootare the core primitives that decide which host directories are trusted and whether a requested mount path is actually contained within an allowed root. Both had real, untested branches (not just debug-log gates):canonicalizeRootssilently drops any root whose path failscanonicalizePath(e.g. a non-absolute path) — untested.canonicalizeRootsdeduplicates roots that canonicalize to the same path (e.g. a root and a symlink alias pointing at it) — untested.isUnderRoot'sfilepath.Relerror branch, triggered when mixing an absolute path with a relative root (or vice versa) — untested.These are exactly the kind of edge cases where a bug would silently weaken the mount-escape protection, so they're high-value to lock down with tests.
Tests Added
TestCanonicalizeRootsDropsUncanonicalizableRoots— a non-absolute root is silently dropped while a valid root is kept.TestCanonicalizeRootsDeduplicatesEquivalentPaths— a real directory and a symlink pointing at it canonicalize to the same path and collapse to one root, keeping the first-seen entry's writability.TestCanonicalizeRootsEmptyInput— empty input yields an empty (non-nil-panicking) result.TestIsUnderRoot(7 sub-cases) — exact match, nested path, sibling path sharing a string prefix (must not be treated as "under" via naive prefix matching), parent-traversal escape, root pointing above path, and both directions of thefilepath.Relerror branch (absolute path + relative root, and relative path + absolute root).Coverage Report
Test Execution
All new and existing tests in
internal/launcherpass:go vet ./internal/launcher/...andgofmt -lare clean.Generated by Test Coverage Improver
Next run will target the next most complex under-tested function