oclaw/tests/test_skill_runtime_restricted_fs_permissions.py
oliver 420abac9f1 refactor: root-package imports (svc/runtime/interfaces) and fix PYTHONPATH
- Rename platform/ to svc/ to avoid shadowing stdlib platform.
- Replace from oclaw.* with from svc/runtime/interfaces; update -m CLI paths.
- tests/conftest: prepend repo root to sys.path (no parent-folder package name).
- CI: paths and offline_eval script under repo root.
- Ops scripts: PYTHONPATH must be repo root for python -m runtime.* (fixes gateway/WhatsApp sidecar startup).
- Fix default oclaw.json path in tabular/file attachment limits; stabilize attachment test config.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-13 14:51:17 +08:00

36 lines
1.3 KiB
Python

from __future__ import annotations
import os
import tempfile
import unittest
from pathlib import Path
from runtime.tools.skills_runtime.subprocess_exec import run_skill_runtime_entry
class SkillRuntimeRestrictedFsPermissionTests(unittest.TestCase):
def setUp(self) -> None:
self._tmp = tempfile.TemporaryDirectory(ignore_cleanup_errors=True)
self.skill_dir = Path(self._tmp.name) / "skill"
self.skill_dir.mkdir(parents=True, exist_ok=True)
(self.skill_dir / "scripts").mkdir(parents=True, exist_ok=True)
(self.skill_dir / "scripts" / "ok.py").write_text("print('{\"ok\": true}')\n", encoding="utf-8")
def tearDown(self) -> None:
self._tmp.cleanup()
def test_fs_write_disabled_blocks_output_path(self) -> None:
res = run_skill_runtime_entry(
skill_name="demo",
skill_dir=str(self.skill_dir),
runtime={"type": "python", "entry": "scripts/ok.py", "permissions": {"fs_write": False}},
args={"output_path": "out.txt"},
)
self.assertFalse(res.get("ok"))
self.assertEqual(str(res.get("error_code")), "path_restricted")
self.assertIn("fs_write_disabled", str(res.get("error") or ""))
if __name__ == "__main__":
unittest.main()