mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
test(cloud-agents): pin shell-quoting behavior for install command
Adds three regression cases that fail if a future change drops the shlex.quote() pass on proxy_url, raw_token, or install_script_url. The existing simple-input cases still pass unchanged because shlex.quote returns alnum/colon/slash/dot strings verbatim.
This commit is contained in:
parent
e4cce78b6e
commit
793e769bd5
1 changed files with 23 additions and 0 deletions
|
|
@ -113,6 +113,8 @@ class TestBuildInstallCommand:
|
|||
cmd = build_install_command(
|
||||
proxy_url="https://proxy.example.com", raw_token="TOK"
|
||||
)
|
||||
# All values pass through shlex.quote — simple alnum/`:/.-` strings
|
||||
# come back unquoted, matching the documented one-liner.
|
||||
assert cmd == (
|
||||
"curl -fsS https://litellm.ai/install-worker | sh -s -- "
|
||||
"--proxy https://proxy.example.com --token TOK"
|
||||
|
|
@ -128,6 +130,27 @@ class TestBuildInstallCommand:
|
|||
assert "--proxy https://p" in cmd
|
||||
assert "--token T" in cmd
|
||||
|
||||
def test_proxy_url_with_metacharacters_is_shell_quoted(self):
|
||||
# Defense against header-injection / config bugs that might land a
|
||||
# space, semicolon, or quote in the proxy URL. shlex.quote wraps the
|
||||
# value in single quotes so it can't break out of the install line.
|
||||
cmd = build_install_command(proxy_url="https://h; rm -rf /", raw_token="TOK")
|
||||
assert "'https://h; rm -rf /'" in cmd
|
||||
# Sanity: the dangerous payload must NOT appear unquoted.
|
||||
assert "--proxy https://h; rm -rf /" not in cmd
|
||||
|
||||
def test_raw_token_with_metacharacters_is_shell_quoted(self):
|
||||
cmd = build_install_command(proxy_url="https://p", raw_token="abc def$(whoami)")
|
||||
assert "'abc def$(whoami)'" in cmd
|
||||
|
||||
def test_install_script_url_is_shell_quoted(self):
|
||||
cmd = build_install_command(
|
||||
proxy_url="https://p",
|
||||
raw_token="T",
|
||||
install_script_url="https://hosts space.example/install.sh",
|
||||
)
|
||||
assert "'https://hosts space.example/install.sh'" in cmd
|
||||
|
||||
|
||||
@pytest.fixture(autouse=True)
|
||||
def _no_op_fixture():
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue