|
| 1 | +/* |
| 2 | + * Copyright (c) 2025, Oracle and/or its affiliates. All rights reserved. |
| 3 | + * DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. |
| 4 | + * |
| 5 | + * The Universal Permissive License (UPL), Version 1.0 |
| 6 | + * |
| 7 | + * Subject to the condition set forth below, permission is hereby granted to any |
| 8 | + * person obtaining a copy of this software, associated documentation and/or |
| 9 | + * data (collectively the "Software"), free of charge and under any and all |
| 10 | + * copyright rights in the Software, and any and all patent rights owned or |
| 11 | + * freely licensable by each licensor hereunder covering either (i) the |
| 12 | + * unmodified Software as contributed to or provided by such licensor, or (ii) |
| 13 | + * the Larger Works (as defined below), to deal in both |
| 14 | + * |
| 15 | + * (a) the Software, and |
| 16 | + * |
| 17 | + * (b) any piece of software and/or hardware listed in the lrgrwrks.txt file if |
| 18 | + * one is included with the Software each a "Larger Work" to which the Software |
| 19 | + * is contributed by such licensors), |
| 20 | + * |
| 21 | + * without restriction, including without limitation the rights to copy, create |
| 22 | + * derivative works of, display, perform, and distribute the Software and make, |
| 23 | + * use, sell, offer for sale, import, export, have made, and have sold the |
| 24 | + * Software and the Larger Work(s), and to sublicense the foregoing rights on |
| 25 | + * either these or other terms. |
| 26 | + * |
| 27 | + * This license is subject to the following condition: |
| 28 | + * |
| 29 | + * The above copyright notice and either this complete permission notice or at a |
| 30 | + * minimum a reference to the UPL must be included in all copies or substantial |
| 31 | + * portions of the Software. |
| 32 | + * |
| 33 | + * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR |
| 34 | + * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, |
| 35 | + * FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE |
| 36 | + * AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER |
| 37 | + * LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, |
| 38 | + * OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE |
| 39 | + * SOFTWARE. |
| 40 | + */ |
| 41 | +package com.oracle.graal.python.test.integration.advanced; |
| 42 | + |
| 43 | +import static org.junit.Assert.assertEquals; |
| 44 | + |
| 45 | +import java.io.ByteArrayOutputStream; |
| 46 | + |
| 47 | +import org.graalvm.polyglot.Context; |
| 48 | +import org.graalvm.polyglot.SandboxPolicy; |
| 49 | +import org.graalvm.polyglot.Value; |
| 50 | +import org.junit.Assume; |
| 51 | +import org.junit.BeforeClass; |
| 52 | +import org.junit.Test; |
| 53 | + |
| 54 | +public class SandboxPolicyUntrustedTest { |
| 55 | + @BeforeClass |
| 56 | + public static void setupClass() { |
| 57 | + String requestedTest = System.getProperty("test"); |
| 58 | + Assume.assumeTrue(requestedTest != null && requestedTest.equals(SandboxPolicyUntrustedTest.class.getSimpleName())); |
| 59 | + } |
| 60 | + |
| 61 | + private static Value run(String source) { |
| 62 | + ByteArrayOutputStream output = new ByteArrayOutputStream(); |
| 63 | + ByteArrayOutputStream errorOutput = new ByteArrayOutputStream(); |
| 64 | + try (Context context = Context.newBuilder("python") // |
| 65 | + .sandbox(SandboxPolicy.UNTRUSTED) // |
| 66 | + .out(output) // |
| 67 | + .err(errorOutput) // |
| 68 | + .option("engine.MaxIsolateMemory", "1GB") // |
| 69 | + .option("sandbox.MaxHeapMemory", "800MB") // |
| 70 | + .option("sandbox.MaxCPUTime", "10s") // |
| 71 | + .option("sandbox.MaxASTDepth", "100") // |
| 72 | + .option("sandbox.MaxStackFrames", "10") // |
| 73 | + .option("sandbox.MaxThreads", "1") // |
| 74 | + .option("sandbox.MaxOutputStreamSize", "1MB") // |
| 75 | + .option("sandbox.MaxErrorStreamSize", "1MB") // |
| 76 | + .build()) { |
| 77 | + return context.eval("python", source); |
| 78 | + } |
| 79 | + } |
| 80 | + |
| 81 | + @Test |
| 82 | + public void helloworld() { |
| 83 | + assertEquals("hello world", run("'hello world'").asString()); |
| 84 | + } |
| 85 | + |
| 86 | + @Test |
| 87 | + public void canImportBuiltinModules() { |
| 88 | + assertEquals("graalpy", run("import sys; sys.implementation.name").asString()); |
| 89 | + } |
| 90 | + |
| 91 | + @Test |
| 92 | + public void canImportNonBuiltinModules() { |
| 93 | + assertEquals("email", run("import email; email.__name__").asString()); |
| 94 | + } |
| 95 | + |
| 96 | + @Test |
| 97 | + public void doesNotLeakEnvironmentVariables() { |
| 98 | + assertEquals("<empty>", run("import os; os.environ.get('JAVA_HOME', '<empty>')").asString()); |
| 99 | + } |
| 100 | +} |
0 commit comments