diff --git a/.github/workflows/test-integration-suite.yml b/.github/workflows/test-integration-suite.yml index a1eac262b..cd94f7649 100644 --- a/.github/workflows/test-integration-suite.yml +++ b/.github/workflows/test-integration-suite.yml @@ -14,7 +14,7 @@ jobs: test-domain-network: name: Domain & Network Tests runs-on: ubuntu-latest - timeout-minutes: 30 + timeout-minutes: 45 steps: - name: Checkout repository @@ -71,7 +71,7 @@ jobs: test-protocol-security: name: Protocol & Security Tests runs-on: ubuntu-latest - timeout-minutes: 30 + timeout-minutes: 45 steps: - name: Checkout repository @@ -128,7 +128,7 @@ jobs: test-container-ops: name: Container & Ops Tests runs-on: ubuntu-latest - timeout-minutes: 30 + timeout-minutes: 45 steps: - name: Checkout repository @@ -185,7 +185,7 @@ jobs: test-api-proxy: name: API Proxy Tests runs-on: ubuntu-latest - timeout-minutes: 30 + timeout-minutes: 45 steps: - name: Checkout repository diff --git a/docs-site/package-lock.json b/docs-site/package-lock.json index 4a705e31b..59568765f 100644 --- a/docs-site/package-lock.json +++ b/docs-site/package-lock.json @@ -8,7 +8,7 @@ "name": "gh-aw-firewall-docs", "version": "0.0.1", "dependencies": { - "@astrojs/check": "^0.9.6", + "@astrojs/check": "^0.9.2", "@astrojs/starlight": "^0.37.6", "astro": "^5.17.1", "astro-mermaid": "1.1.0", @@ -30,18 +30,19 @@ } }, "node_modules/@astrojs/check": { - "version": "0.9.6", - "resolved": "https://registry.npmjs.org/@astrojs/check/-/check-0.9.6.tgz", - "integrity": "sha512-jlaEu5SxvSgmfGIFfNgcn5/f+29H61NJzEMfAZ82Xopr4XBchXB1GVlcJsE+elUlsYSbXlptZLX+JMG3b/wZEA==", + "version": "0.9.2", + "resolved": "https://registry.npmjs.org/@astrojs/check/-/check-0.9.2.tgz", + "integrity": "sha512-6rWxtJTbd/ctdAlmla0CAvloGaai5IUTG0K21kctJHHGKJKnGH6Xana7m0zNOtHpVPEJi1SgC/TcsN+ltYt0Cg==", "license": "MIT", "dependencies": { - "@astrojs/language-server": "^2.16.1", - "chokidar": "^4.0.1", + "@astrojs/language-server": "^2.13.2", + "chokidar": "^3.5.3", + "fast-glob": "^3.3.1", "kleur": "^4.1.5", "yargs": "^17.7.2" }, "bin": { - "astro-check": "bin/astro-check.js" + "astro-check": "dist/bin.js" }, "peerDependencies": { "typescript": "^5.0.0" @@ -1426,6 +1427,41 @@ "langium": "^4.0.0" } }, + "node_modules/@nodelib/fs.scandir": { + "version": "2.1.5", + "resolved": "https://registry.npmjs.org/@nodelib/fs.scandir/-/fs.scandir-2.1.5.tgz", + "integrity": "sha512-vq24Bq3ym5HEQm2NKCr3yXDwjc7vTsEThRDnkp2DK9p1uqLR+DHurm/NOTo0KG7HYHU7eppKZj3MyqYuMBf62g==", + "license": "MIT", + "dependencies": { + "@nodelib/fs.stat": "2.0.5", + "run-parallel": "^1.1.9" + }, + "engines": { + "node": ">= 8" + } + }, + "node_modules/@nodelib/fs.stat": { + "version": "2.0.5", + "resolved": "https://registry.npmjs.org/@nodelib/fs.stat/-/fs.stat-2.0.5.tgz", + "integrity": "sha512-RkhPPp2zrqDAQA/2jNhnztcPAlv64XdhIp7a7454A5ovI7Bukxgt7MX7udwAu3zg1DcpPU0rz3VV1SeaqvY4+A==", + "license": "MIT", + "engines": { + "node": ">= 8" + } + }, + "node_modules/@nodelib/fs.walk": { + "version": "1.2.8", + "resolved": "https://registry.npmjs.org/@nodelib/fs.walk/-/fs.walk-1.2.8.tgz", + "integrity": "sha512-oGB+UxlgWcgQkgwo8GcEGwemoTFt3FIO9ababBmaGwXIoBKZ+GTy0pP185beGg7Llih/NSHSV2XAs1lnznocSg==", + "license": "MIT", + "dependencies": { + "@nodelib/fs.scandir": "2.1.5", + "fastq": "^1.6.0" + }, + "engines": { + "node": ">= 8" + } + }, "node_modules/@oslojs/encoding": { "version": "1.1.0", "resolved": "https://registry.npmjs.org/@oslojs/encoding/-/encoding-1.1.0.tgz", @@ -2750,6 +2786,18 @@ "url": "https://github.com/sponsors/wooorm" } }, + "node_modules/binary-extensions": { + "version": "2.3.0", + "resolved": "https://registry.npmjs.org/binary-extensions/-/binary-extensions-2.3.0.tgz", + "integrity": "sha512-Ceh+7ox5qe7LJuLHoY0feh3pHuUDHAcRUeyL2VYghZwfpkNIy/+8Ocg0a3UuSoYzavmylwuLWQOf3hl0jjMMIw==", + "license": "MIT", + "engines": { + "node": ">=8" + }, + "funding": { + "url": "https://github.com/sponsors/sindresorhus" + } + }, "node_modules/boolbase": { "version": "1.0.0", "resolved": "https://registry.npmjs.org/boolbase/-/boolbase-1.0.0.tgz", @@ -2778,6 +2826,18 @@ "url": "https://github.com/sponsors/sindresorhus" } }, + "node_modules/braces": { + "version": "3.0.3", + "resolved": "https://registry.npmjs.org/braces/-/braces-3.0.3.tgz", + "integrity": "sha512-yQbXgO/OSZVD2IsiLlro+7Hf6Q18EJrKSEsdoMzKePKXct3gvD8oLcOQdIzGupr5Fj+EDe8gO/lxc1BzfMpxvA==", + "license": "MIT", + "dependencies": { + "fill-range": "^7.1.1" + }, + "engines": { + "node": ">=8" + } + }, "node_modules/camelcase": { "version": "8.0.0", "resolved": "https://registry.npmjs.org/camelcase/-/camelcase-8.0.0.tgz", @@ -2879,18 +2939,27 @@ } }, "node_modules/chokidar": { - "version": "4.0.3", - "resolved": "https://registry.npmjs.org/chokidar/-/chokidar-4.0.3.tgz", - "integrity": "sha512-Qgzu8kfBvo+cA4962jnP1KkS6Dop5NS6g7R5LFYJr4b8Ub94PPQXUksCw9PvXoeXPRRddRNC5C1JQUR2SMGtnA==", + "version": "3.6.0", + "resolved": "https://registry.npmjs.org/chokidar/-/chokidar-3.6.0.tgz", + "integrity": "sha512-7VT13fmjotKpGipCW9JEQAusEPE+Ei8nl6/g4FBAmIm0GOOLMua9NDDo/DWp0ZAxCr3cPq5ZpBqmPAQgDda2Pw==", "license": "MIT", "dependencies": { - "readdirp": "^4.0.1" + "anymatch": "~3.1.2", + "braces": "~3.0.2", + "glob-parent": "~5.1.2", + "is-binary-path": "~2.1.0", + "is-glob": "~4.0.1", + "normalize-path": "~3.0.0", + "readdirp": "~3.6.0" }, "engines": { - "node": ">= 14.16.0" + "node": ">= 8.10.0" }, "funding": { "url": "https://paulmillr.com/funding/" + }, + "optionalDependencies": { + "fsevents": "~2.3.2" } }, "node_modules/ci-info": { @@ -4190,6 +4259,22 @@ "integrity": "sha512-f3qQ9oQy9j2AhBe/H9VC91wLmKBCCU/gDOnKNAYG5hswO7BLKj09Hc5HYNz9cGI++xlpDCIgDaitVs03ATR84Q==", "license": "MIT" }, + "node_modules/fast-glob": { + "version": "3.3.3", + "resolved": "https://registry.npmjs.org/fast-glob/-/fast-glob-3.3.3.tgz", + "integrity": "sha512-7MptL8U0cqcFdzIzwOTHoilX9x5BrNqye7Z/LuC7kCMRio1EMSyqRK3BEAUD7sXRq4iT4AzTVuZdhgQ2TCvYLg==", + "license": "MIT", + "dependencies": { + "@nodelib/fs.stat": "^2.0.2", + "@nodelib/fs.walk": "^1.2.3", + "glob-parent": "^5.1.2", + "merge2": "^1.3.0", + "micromatch": "^4.0.8" + }, + "engines": { + "node": ">=8.6.0" + } + }, "node_modules/fast-uri": { "version": "3.1.0", "resolved": "https://registry.npmjs.org/fast-uri/-/fast-uri-3.1.0.tgz", @@ -4206,6 +4291,15 @@ ], "license": "BSD-3-Clause" }, + "node_modules/fastq": { + "version": "1.20.1", + "resolved": "https://registry.npmjs.org/fastq/-/fastq-1.20.1.tgz", + "integrity": "sha512-GGToxJ/w1x32s/D2EKND7kTil4n8OVk/9mycTc4VDza13lOvpUZTGX3mFSCtV9ksdGBVzvsyAVLM6mHFThxXxw==", + "license": "ISC", + "dependencies": { + "reusify": "^1.0.4" + } + }, "node_modules/fdir": { "version": "6.5.0", "resolved": "https://registry.npmjs.org/fdir/-/fdir-6.5.0.tgz", @@ -4223,6 +4317,18 @@ } } }, + "node_modules/fill-range": { + "version": "7.1.1", + "resolved": "https://registry.npmjs.org/fill-range/-/fill-range-7.1.1.tgz", + "integrity": "sha512-YsGpe3WHLK8ZYi4tWDg2Jy3ebRz2rXowDxnld4bkQB00cc/1Zw9AWnC0i9ztDJitivtQvaI9KaLyKrc+hBW0yg==", + "license": "MIT", + "dependencies": { + "to-regex-range": "^5.0.1" + }, + "engines": { + "node": ">=8" + } + }, "node_modules/flattie": { "version": "1.1.1", "resolved": "https://registry.npmjs.org/flattie/-/flattie-1.1.1.tgz", @@ -4294,6 +4400,18 @@ "integrity": "sha512-IaOQ9puYtjrkq7Y0Ygl9KDZnrf/aiUJYUpVf89y8kyaxbRG7Y1SrX/jaumrv81vc61+kiMempujsM3Yw7w5qcw==", "license": "ISC" }, + "node_modules/glob-parent": { + "version": "5.1.2", + "resolved": "https://registry.npmjs.org/glob-parent/-/glob-parent-5.1.2.tgz", + "integrity": "sha512-AOIgSQCepiJYwP3ARnGx+5VnTu2HBYdzbGP45eLw1vr3zB3vZLeyed1sC9hnbcOc9/SrMyM5RPQrkGz4aS9Zow==", + "license": "ISC", + "dependencies": { + "is-glob": "^4.0.1" + }, + "engines": { + "node": ">= 6" + } + }, "node_modules/h3": { "version": "1.15.5", "resolved": "https://registry.npmjs.org/h3/-/h3-1.15.5.tgz", @@ -4807,6 +4925,18 @@ "url": "https://github.com/sponsors/wooorm" } }, + "node_modules/is-binary-path": { + "version": "2.1.0", + "resolved": "https://registry.npmjs.org/is-binary-path/-/is-binary-path-2.1.0.tgz", + "integrity": "sha512-ZMERYes6pDydyuGidse7OsHxtbI7WVeUEozgR/g7rd0xUimYNlvZRE/K2MgZTjWy725IfelLeVcEM97mmtRGXw==", + "license": "MIT", + "dependencies": { + "binary-extensions": "^2.0.0" + }, + "engines": { + "node": ">=8" + } + }, "node_modules/is-decimal": { "version": "2.0.1", "resolved": "https://registry.npmjs.org/is-decimal/-/is-decimal-2.0.1.tgz", @@ -4832,6 +4962,15 @@ "url": "https://github.com/sponsors/sindresorhus" } }, + "node_modules/is-extglob": { + "version": "2.1.1", + "resolved": "https://registry.npmjs.org/is-extglob/-/is-extglob-2.1.1.tgz", + "integrity": "sha512-SbKbANkN603Vi4jEZv49LeVJMn4yGwsbzZworEoyEiutsN3nJYdbO36zfhGJ6QEDpOZIFkDtnq5JRxmvl3jsoQ==", + "license": "MIT", + "engines": { + "node": ">=0.10.0" + } + }, "node_modules/is-fullwidth-code-point": { "version": "3.0.0", "resolved": "https://registry.npmjs.org/is-fullwidth-code-point/-/is-fullwidth-code-point-3.0.0.tgz", @@ -4841,6 +4980,18 @@ "node": ">=8" } }, + "node_modules/is-glob": { + "version": "4.0.3", + "resolved": "https://registry.npmjs.org/is-glob/-/is-glob-4.0.3.tgz", + "integrity": "sha512-xelSayHH36ZgE7ZWhli7pW34hNbNl8Ojv5KVmkJD4hBdD3th8Tfk9vYasLM+mXWOZhFkgZfxhLSnrwRr4elSSg==", + "license": "MIT", + "dependencies": { + "is-extglob": "^2.1.1" + }, + "engines": { + "node": ">=0.10.0" + } + }, "node_modules/is-hexadecimal": { "version": "2.0.1", "resolved": "https://registry.npmjs.org/is-hexadecimal/-/is-hexadecimal-2.0.1.tgz", @@ -4869,6 +5020,15 @@ "url": "https://github.com/sponsors/sindresorhus" } }, + "node_modules/is-number": { + "version": "7.0.0", + "resolved": "https://registry.npmjs.org/is-number/-/is-number-7.0.0.tgz", + "integrity": "sha512-41Cifkg6e8TylSpdtTpeLVMqvSBEVzTttHvERD741+pnZ8ANv0004MRL43QKPDlK9cGvNp6NZWZUBlbGXYxxng==", + "license": "MIT", + "engines": { + "node": ">=0.12.0" + } + }, "node_modules/is-plain-obj": { "version": "4.1.0", "resolved": "https://registry.npmjs.org/is-plain-obj/-/is-plain-obj-4.1.0.tgz", @@ -5405,6 +5565,15 @@ "integrity": "sha512-IEn+pegP1aManZuckezWCO+XZQDplx1366JoVhTpMpBB1sPey/SbveZQUosKiKiGYjg1wH4pMlNgXbCiYgihQA==", "license": "CC0-1.0" }, + "node_modules/merge2": { + "version": "1.4.1", + "resolved": "https://registry.npmjs.org/merge2/-/merge2-1.4.1.tgz", + "integrity": "sha512-8q7VEgMJW4J8tcfVPy8g09NcQwZdbwFEqhe/WZkoIzjn/3TGDwtOCYtXGxA3O8tPzpczCCDgv+P2P5y00ZJOOg==", + "license": "MIT", + "engines": { + "node": ">= 8" + } + }, "node_modules/mermaid": { "version": "11.12.3", "resolved": "https://registry.npmjs.org/mermaid/-/mermaid-11.12.3.tgz", @@ -6169,6 +6338,31 @@ ], "license": "MIT" }, + "node_modules/micromatch": { + "version": "4.0.8", + "resolved": "https://registry.npmjs.org/micromatch/-/micromatch-4.0.8.tgz", + "integrity": "sha512-PXwfBhYu0hBCPw8Dn0E+WDYb7af3dSLVWKi3HGv84IdF4TyFoC0ysxFd0Goxw7nSv4T/PzEJQxsYsEiFCKo2BA==", + "license": "MIT", + "dependencies": { + "braces": "^3.0.3", + "picomatch": "^2.3.1" + }, + "engines": { + "node": ">=8.6" + } + }, + "node_modules/micromatch/node_modules/picomatch": { + "version": "2.3.1", + "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-2.3.1.tgz", + "integrity": "sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==", + "license": "MIT", + "engines": { + "node": ">=8.6" + }, + "funding": { + "url": "https://github.com/sponsors/jonschlinkert" + } + }, "node_modules/mlly": { "version": "1.8.0", "resolved": "https://registry.npmjs.org/mlly/-/mlly-1.8.0.tgz", @@ -6621,6 +6815,26 @@ "url": "https://github.com/sponsors/wooorm" } }, + "node_modules/queue-microtask": { + "version": "1.2.3", + "resolved": "https://registry.npmjs.org/queue-microtask/-/queue-microtask-1.2.3.tgz", + "integrity": "sha512-NuaNSa6flKT5JaSYQzJok04JzTL1CA6aGhv5rfLW3PgqA+M2ChpZQnAC8h8i4ZFkBS8X5RqkDBHA7r4hej3K9A==", + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/feross" + }, + { + "type": "patreon", + "url": "https://www.patreon.com/feross" + }, + { + "type": "consulting", + "url": "https://feross.org/support" + } + ], + "license": "MIT" + }, "node_modules/radix3": { "version": "1.1.2", "resolved": "https://registry.npmjs.org/radix3/-/radix3-1.1.2.tgz", @@ -6628,16 +6842,27 @@ "license": "MIT" }, "node_modules/readdirp": { - "version": "4.1.2", - "resolved": "https://registry.npmjs.org/readdirp/-/readdirp-4.1.2.tgz", - "integrity": "sha512-GDhwkLfywWL2s6vEjyhri+eXmfH6j1L7JE27WhqLeYzoh/A3DBaYGEj2H/HFZCn/kMfim73FXxEJTw06WtxQwg==", + "version": "3.6.0", + "resolved": "https://registry.npmjs.org/readdirp/-/readdirp-3.6.0.tgz", + "integrity": "sha512-hOS089on8RduqdbhvQ5Z37A0ESjsqz6qnRcffsMU3495FuTdqSm+7bhJ29JvIOsBDEEnan5DPu9t3To9VRlMzA==", "license": "MIT", + "dependencies": { + "picomatch": "^2.2.1" + }, "engines": { - "node": ">= 14.18.0" + "node": ">=8.10.0" + } + }, + "node_modules/readdirp/node_modules/picomatch": { + "version": "2.3.1", + "resolved": "https://registry.npmjs.org/picomatch/-/picomatch-2.3.1.tgz", + "integrity": "sha512-JU3teHTNjmE2VCGFzuY8EXzCDVwEqB2a8fsIvwaStHhAWJEeVd1o1QD80CU6+ZdEXXSLbSsuLwJjkCBWqRQUVA==", + "license": "MIT", + "engines": { + "node": ">=8.6" }, "funding": { - "type": "individual", - "url": "https://paulmillr.com/funding/" + "url": "https://github.com/sponsors/jonschlinkert" } }, "node_modules/recma-build-jsx": { @@ -7026,6 +7251,16 @@ "url": "https://opencollective.com/unified" } }, + "node_modules/reusify": { + "version": "1.1.0", + "resolved": "https://registry.npmjs.org/reusify/-/reusify-1.1.0.tgz", + "integrity": "sha512-g6QUff04oZpHs0eG5p83rFLhHeV00ug/Yf9nZM6fLeUrPguBTkTQOdpAWWspMh55TZfVQDPaN3NQJfbVRAxdIw==", + "license": "MIT", + "engines": { + "iojs": ">=1.0.0", + "node": ">=0.10.0" + } + }, "node_modules/robust-predicates": { "version": "3.0.2", "resolved": "https://registry.npmjs.org/robust-predicates/-/robust-predicates-3.0.2.tgz", @@ -7088,6 +7323,29 @@ "points-on-path": "^0.2.1" } }, + "node_modules/run-parallel": { + "version": "1.2.0", + "resolved": "https://registry.npmjs.org/run-parallel/-/run-parallel-1.2.0.tgz", + "integrity": "sha512-5l4VyZR86LZ/lDxZTR6jqL8AFE2S0IFLMP26AbjsLVADxHdhB/c0GUsH+y39UfCi3dzz8OlQuPmnaJOMoDHQBA==", + "funding": [ + { + "type": "github", + "url": "https://github.com/sponsors/feross" + }, + { + "type": "patreon", + "url": "https://www.patreon.com/feross" + }, + { + "type": "consulting", + "url": "https://feross.org/support" + } + ], + "license": "MIT", + "dependencies": { + "queue-microtask": "^1.2.2" + } + }, "node_modules/rw": { "version": "1.3.3", "resolved": "https://registry.npmjs.org/rw/-/rw-1.3.3.tgz", @@ -7393,6 +7651,18 @@ "url": "https://github.com/sponsors/SuperchupuDev" } }, + "node_modules/to-regex-range": { + "version": "5.0.1", + "resolved": "https://registry.npmjs.org/to-regex-range/-/to-regex-range-5.0.1.tgz", + "integrity": "sha512-65P7iz6X5yEr1cwcgvQxbbIw7Uk3gOy5dIdtZ4rDveLqhrdJP+Li/Hx6tyK0NEb+2GCyneCMJiGqrADCSNk8sQ==", + "license": "MIT", + "dependencies": { + "is-number": "^7.0.0" + }, + "engines": { + "node": ">=8.0" + } + }, "node_modules/trim-lines": { "version": "3.0.1", "resolved": "https://registry.npmjs.org/trim-lines/-/trim-lines-3.0.1.tgz", diff --git a/docs-site/package.json b/docs-site/package.json index f7f900b0b..b81a983a0 100644 --- a/docs-site/package.json +++ b/docs-site/package.json @@ -10,7 +10,7 @@ "astro": "astro" }, "dependencies": { - "@astrojs/check": "^0.9.6", + "@astrojs/check": "^0.9.2", "@astrojs/starlight": "^0.37.6", "astro": "^5.17.1", "astro-mermaid": "1.1.0", diff --git a/src/docker-manager.test.ts b/src/docker-manager.test.ts index 5b0bf958a..6e4d3cdcc 100644 --- a/src/docker-manager.test.ts +++ b/src/docker-manager.test.ts @@ -529,9 +529,9 @@ describe('docker-manager', () => { // Should NOT include blanket /:/host:rw mount expect(volumes).not.toContain('/:/host:rw'); - // Should include custom mounts - expect(volumes).toContain('/workspace:/workspace:ro'); - expect(volumes).toContain('/data:/data:rw'); + // Should include custom mounts (prefixed with /host for chroot visibility) + expect(volumes).toContain('/workspace:/host/workspace:ro'); + expect(volumes).toContain('/data:/host/data:rw'); // Should still include essential mounts expect(volumes).toContain('/tmp:/tmp:rw'); @@ -549,6 +549,35 @@ describe('docker-manager', () => { expect(volumes.some((v: string) => v.includes('/dev/null'))).toBe(true); }); + it('should handle malformed volume mount without colon as fallback', () => { + const configWithBadMount = { + ...mockConfig, + volumeMounts: ['no-colon-here'] + }; + const result = generateDockerCompose(configWithBadMount, mockNetworkConfig); + const agent = result.services.agent; + const volumes = agent.volumes as string[]; + // Malformed mount should be added as-is (fallback) + expect(volumes).toContain('no-colon-here'); + }); + + it('should forward COPILOT_GITHUB_TOKEN when api-proxy is disabled', () => { + process.env.COPILOT_GITHUB_TOKEN = 'ghp_test_token'; + const configNoProxy = { ...mockConfig, enableApiProxy: false }; + const result = generateDockerCompose(configNoProxy, mockNetworkConfig); + const env = result.services.agent.environment as Record; + expect(env.COPILOT_GITHUB_TOKEN).toBe('ghp_test_token'); + delete process.env.COPILOT_GITHUB_TOKEN; + }); + + it('should forward AWF_ONE_SHOT_TOKEN_DEBUG when set', () => { + process.env.AWF_ONE_SHOT_TOKEN_DEBUG = '1'; + const result = generateDockerCompose(mockConfig, mockNetworkConfig); + const env = result.services.agent.environment as Record; + expect(env.AWF_ONE_SHOT_TOKEN_DEBUG).toBe('1'); + delete process.env.AWF_ONE_SHOT_TOKEN_DEBUG; + }); + it('should use selective mounts by default', () => { diff --git a/src/docker-manager.ts b/src/docker-manager.ts index a3990117f..ee39296fc 100644 --- a/src/docker-manager.ts +++ b/src/docker-manager.ts @@ -440,7 +440,9 @@ export function generateDockerCompose( if (process.env.OPENAI_API_KEY && !config.enableApiProxy) environment.OPENAI_API_KEY = process.env.OPENAI_API_KEY; if (process.env.CODEX_API_KEY && !config.enableApiProxy) environment.CODEX_API_KEY = process.env.CODEX_API_KEY; if (process.env.ANTHROPIC_API_KEY && !config.enableApiProxy) environment.ANTHROPIC_API_KEY = process.env.ANTHROPIC_API_KEY; - // COPILOT_GITHUB_TOKEN is handled separately - gets placeholder when api-proxy enabled + // COPILOT_GITHUB_TOKEN — forward when api-proxy is NOT enabled; when api-proxy IS enabled, + // it gets a placeholder value set earlier (line ~362) for credential isolation + if (process.env.COPILOT_GITHUB_TOKEN && !config.enableApiProxy) environment.COPILOT_GITHUB_TOKEN = process.env.COPILOT_GITHUB_TOKEN; if (process.env.USER) environment.USER = process.env.USER; if (process.env.TERM) environment.TERM = process.env.TERM; if (process.env.XDG_CONFIG_HOME) environment.XDG_CONFIG_HOME = process.env.XDG_CONFIG_HOME; @@ -449,6 +451,11 @@ export function generateDockerCompose( if (process.env.GITHUB_API_URL) environment.GITHUB_API_URL = process.env.GITHUB_API_URL; } + // Forward one-shot-token debug flag if set (used for testing/debugging) + if (process.env.AWF_ONE_SHOT_TOKEN_DEBUG) { + environment.AWF_ONE_SHOT_TOKEN_DEBUG = process.env.AWF_ONE_SHOT_TOKEN_DEBUG; + } + // Additional environment variables from --env flags (these override everything) if (config.additionalEnv) { Object.assign(environment, config.additionalEnv); @@ -741,10 +748,29 @@ export function generateDockerCompose( // ================================================================ // Add custom volume mounts if specified + // In chroot mode (always enabled), the container does `chroot /host`, so paths + // like /data become invisible. We need to prefix the container path with /host + // so that after chroot, /host/data becomes /data from the user's perspective. if (config.volumeMounts && config.volumeMounts.length > 0) { logger.debug(`Adding ${config.volumeMounts.length} custom volume mount(s)`); config.volumeMounts.forEach(mount => { - agentVolumes.push(mount); + // Parse mount format: host_path:container_path[:mode] + const parts = mount.split(':'); + if (parts.length >= 2) { + const hostPath = parts[0]; + const containerPath = parts[1]; + const mode = parts[2] || ''; + // Prefix container path with /host for chroot visibility + const chrootContainerPath = `/host${containerPath}`; + const transformedMount = mode + ? `${hostPath}:${chrootContainerPath}:${mode}` + : `${hostPath}:${chrootContainerPath}`; + logger.debug(`Adding custom volume mount: ${mount} -> ${transformedMount} (chroot-adjusted)`); + agentVolumes.push(transformedMount); + } else { + // Fallback: add as-is if format is unexpected + agentVolumes.push(mount); + } }); } diff --git a/tests/fixtures/stdout-helpers.ts b/tests/fixtures/stdout-helpers.ts new file mode 100644 index 000000000..e334ecd2f --- /dev/null +++ b/tests/fixtures/stdout-helpers.ts @@ -0,0 +1,98 @@ +/** + * Helpers for extracting structured data from stdout that may contain + * Docker build output or other noise preceding the actual command output. + * + * When --build-local is used, Docker build logs are interleaved in stdout + * before the actual curl/command output. These helpers find the relevant + * data by scanning from the end of the output. + */ + +/** + * Extract the last complete JSON object from a string that may contain + * non-JSON content (e.g., Docker build logs) before the JSON payload. + * + * Scans backwards from the end to find the last `}`, then walks backwards + * tracking brace depth to find the matching `{`. + * + * @param output - The full stdout string + * @returns The parsed JSON object, or null if no valid JSON object found + */ +export function extractLastJson(output: string): any | null { + // Find the last closing brace + const lastBrace = output.lastIndexOf('}'); + if (lastBrace === -1) return null; + + // Walk backwards from the last '}' to find the matching '{' + let depth = 0; + for (let i = lastBrace; i >= 0; i--) { + if (output[i] === '}') depth++; + if (output[i] === '{') depth--; + if (depth === 0) { + // Found the matching opening brace + const jsonStr = output.substring(i, lastBrace + 1); + try { + return JSON.parse(jsonStr); + } catch { + // This wasn't valid JSON, keep scanning + // (edge case: unbalanced braces in Docker build output) + continue; + } + } + } + + return null; +} + +/** + * Extract the last line(s) of stdout that look like actual command output + * (i.e., not Docker build step output). + * + * Docker build output lines typically start with patterns like: + * #1 [internal] load ... + * #5 DONE 0.1s + * => [1/5] FROM ... + * + * This returns everything after the last Docker build output line. + * + * @param output - The full stdout string + * @returns The cleaned output with Docker build noise removed + */ +export function extractCommandOutput(output: string): string { + const lines = output.split('\n'); + + // Find the last line that looks like Docker build output or container setup noise. + // Container setup noise includes entrypoint messages, iptables setup, health checks, + // and iptables rule dump lines that appear before the actual user command output. + let lastNoiseLine = -1; + for (let i = 0; i < lines.length; i++) { + const line = lines[i].trim(); + if ( + // Docker buildkit output + (line.startsWith('#') && /^#\d+/.test(line)) || + line.startsWith('=>') || + line.startsWith('DONE') || + line.startsWith('CACHED') || + line.match(/^\[[\d/]+\]/) || + line.startsWith('Sending build context') || + line.startsWith('Successfully built') || + line.startsWith('Successfully tagged') || + // Container entrypoint/setup messages + line.startsWith('[entrypoint]') || + line.startsWith('[iptables]') || + line.startsWith('[health-check]') || + // iptables table dump lines (Chain, pkts/bytes header, rule lines) + line.startsWith('Chain ') || + line.match(/^\s*pkts\s+bytes\s+target/) || + line.match(/^\s*\d+\s+\d+\s+(RETURN|DNAT|DROP|ACCEPT|REJECT|LOG)\b/) + ) { + lastNoiseLine = i; + } + } + + if (lastNoiseLine === -1) { + return output; // No noise detected + } + + // Return everything after the last noise line + return lines.slice(lastNoiseLine + 1).join('\n').trim(); +} diff --git a/tests/integration/api-proxy-observability.test.ts b/tests/integration/api-proxy-observability.test.ts index 83d4ef983..ce69dae44 100644 --- a/tests/integration/api-proxy-observability.test.ts +++ b/tests/integration/api-proxy-observability.test.ts @@ -10,6 +10,7 @@ import { describe, test, expect, beforeAll, afterAll } from '@jest/globals'; import { createRunner, AwfRunner } from '../fixtures/awf-runner'; import { cleanup } from '../fixtures/cleanup'; +import { extractLastJson, extractCommandOutput } from '../fixtures/stdout-helpers'; // The API proxy sidecar is at this fixed IP on the awf-net network const API_PROXY_IP = '172.30.0.30'; @@ -74,7 +75,7 @@ describe('API Proxy Observability', () => { test('should return X-Request-ID header in proxy responses', async () => { // Make a request to the Anthropic proxy and check for x-request-id in response headers const result = await runner.runWithSudo( - `bash -c "curl -s -i -X POST http://${API_PROXY_IP}:10001/v1/messages -H 'Content-Type: application/json' -d '{\"model\":\"test\"}'"`, + `bash -c 'curl -s -i -X POST http://${API_PROXY_IP}:10001/v1/messages -H "Content-Type: application/json" -d "{\\"model\\":\\"test\\"}"'`, { allowDomains: ['api.anthropic.com'], enableApiProxy: true, @@ -96,13 +97,13 @@ describe('API Proxy Observability', () => { // Make a request to the Anthropic proxy, then check /metrics for non-zero counts const script = [ // First, make an API request to generate metrics - `curl -s -X POST http://${API_PROXY_IP}:10001/v1/messages -H 'Content-Type: application/json' -d '{"model":"test"}' > /dev/null`, + `curl -s -X POST http://${API_PROXY_IP}:10001/v1/messages -H "Content-Type: application/json" -d "{\\"model\\":\\"test\\"}" > /dev/null`, // Then fetch metrics `curl -s http://${API_PROXY_IP}:10000/metrics`, ].join(' && '); const result = await runner.runWithSudo( - `bash -c "${script}"`, + `bash -c '${script}'`, { allowDomains: ['api.anthropic.com'], enableApiProxy: true, @@ -122,7 +123,7 @@ describe('API Proxy Observability', () => { test('should include rate_limits in /health when rate limiting is active', async () => { const result = await runner.runWithSudo( - `bash -c "curl -s -X POST http://${API_PROXY_IP}:10001/v1/messages -H 'Content-Type: application/json' -d '{\"model\":\"test\"}' > /dev/null && curl -s http://${API_PROXY_IP}:10000/health"`, + `bash -c 'curl -s -X POST http://${API_PROXY_IP}:10001/v1/messages -H "Content-Type: application/json" -d "{\\"model\\":\\"test\\"}" > /dev/null && curl -s http://${API_PROXY_IP}:10000/health'`, { allowDomains: ['api.anthropic.com'], enableApiProxy: true, @@ -142,7 +143,7 @@ describe('API Proxy Observability', () => { test('should preserve custom X-Request-ID when valid', async () => { const result = await runner.runWithSudo( - `bash -c "curl -s -i -X POST http://${API_PROXY_IP}:10001/v1/messages -H 'Content-Type: application/json' -H 'X-Request-ID: my-custom-trace-abc123' -d '{\"model\":\"test\"}'"`, + `bash -c 'curl -s -i -X POST http://${API_PROXY_IP}:10001/v1/messages -H "Content-Type: application/json" -H "X-Request-ID: my-custom-trace-abc123" -d "{\\"model\\":\\"test\\"}"'`, { allowDomains: ['api.anthropic.com'], enableApiProxy: true, @@ -162,7 +163,7 @@ describe('API Proxy Observability', () => { test('should reject invalid X-Request-ID and generate a new one', async () => { const result = await runner.runWithSudo( - `bash -c "curl -s -i -X POST http://${API_PROXY_IP}:10001/v1/messages -H 'Content-Type: application/json' -H 'X-Request-ID: ' -d '{\"model\":\"test\"}'"`, + `bash -c 'curl -s -i -X POST http://${API_PROXY_IP}:10001/v1/messages -H "Content-Type: application/json" -H "X-Request-ID: " -d "{\\"model\\":\\"test\\"}"'`, { allowDomains: ['api.anthropic.com'], enableApiProxy: true, @@ -176,16 +177,16 @@ describe('API Proxy Observability', () => { ); expect(result).toSucceed(); - const lower = result.stdout.toLowerCase(); - expect(lower).toContain('x-request-id'); - // The injected ID should NOT appear — proxy should have generated a UUID instead - expect(result.stdout).not.toContain('