oclaw/openclaw/apps/macos/Tests/OpenClawIPCTests/ExecApprovalsSocketPathGuardTests.swift
oliver dbbe3add6a 重构主控编排与运行时预热链路,统一工作区提示词/专家调度协议并补齐 wiki 记忆注入与写回闭环。
同时收敛启动与运维脚本默认行为(含 wiki worker)、更新 Admin 可观测性与相关测试,降低首轮时延并提高运行稳定性。

Made-with: Cursor
2026-04-26 08:34:33 +08:00

75 lines
3.2 KiB
Swift

import Foundation
import Testing
@testable import OpenClaw
@Suite(.serialized)
struct ExecApprovalsSocketPathGuardTests {
@Test
func `harden parent directory creates directory with0700 permissions`() throws {
let root = FileManager().temporaryDirectory
.appendingPathComponent("openclaw-socket-guard-\(UUID().uuidString)", isDirectory: true)
defer { try? FileManager().removeItem(at: root) }
let socketPath = root
.appendingPathComponent("nested", isDirectory: true)
.appendingPathComponent("exec-approvals.sock", isDirectory: false)
.path
try ExecApprovalsSocketPathGuard.hardenParentDirectory(for: socketPath)
let parent = URL(fileURLWithPath: socketPath).deletingLastPathComponent()
#expect(FileManager().fileExists(atPath: parent.path))
let attrs = try FileManager().attributesOfItem(atPath: parent.path)
let permissions = (attrs[.posixPermissions] as? NSNumber)?.intValue ?? -1
#expect(permissions & 0o777 == 0o700)
}
@Test
func `remove existing socket rejects symlink path`() throws {
let root = FileManager().temporaryDirectory
.appendingPathComponent("openclaw-socket-guard-\(UUID().uuidString)", isDirectory: true)
defer { try? FileManager().removeItem(at: root) }
try FileManager().createDirectory(at: root, withIntermediateDirectories: true)
let target = root.appendingPathComponent("target.txt")
_ = FileManager().createFile(atPath: target.path, contents: Data("x".utf8))
let symlink = root.appendingPathComponent("exec-approvals.sock")
try FileManager().createSymbolicLink(at: symlink, withDestinationURL: target)
do {
try ExecApprovalsSocketPathGuard.removeExistingSocket(at: symlink.path)
Issue.record("Expected symlink socket path rejection")
} catch let error as ExecApprovalsSocketPathGuardError {
switch error {
case let .socketPathInvalid(path, kind):
#expect(path == symlink.path)
#expect(kind == .symlink)
default:
Issue.record("Unexpected error: \(error)")
}
}
}
@Test
func `remove existing socket rejects regular file path`() throws {
let root = FileManager().temporaryDirectory
.appendingPathComponent("openclaw-socket-guard-\(UUID().uuidString)", isDirectory: true)
defer { try? FileManager().removeItem(at: root) }
try FileManager().createDirectory(at: root, withIntermediateDirectories: true)
let regularFile = root.appendingPathComponent("exec-approvals.sock")
_ = FileManager().createFile(atPath: regularFile.path, contents: Data("x".utf8))
do {
try ExecApprovalsSocketPathGuard.removeExistingSocket(at: regularFile.path)
Issue.record("Expected non-socket path rejection")
} catch let error as ExecApprovalsSocketPathGuardError {
switch error {
case let .socketPathInvalid(path, kind):
#expect(path == regularFile.path)
#expect(kind == .other)
default:
Issue.record("Unexpected error: \(error)")
}
}
}
}