Build App (Preview) / compute-version (pull_request) Successful in 3s
Build App (Preview) / create-release (pull_request) Successful in 1s
Build App (Preview) / build-macos (pull_request) Successful in 2m37s
Build App (Preview) / build-linux (pull_request) Successful in 5m30s
Build App (Preview) / build-windows (pull_request) Successful in 5m55s
Build App (Preview) / prune-previews (pull_request) Successful in 3s
Review caught that the device guard was wired to the wrong call. The
daemon does not resolve `--device` at create: verified against Docker
29.7, `docker create --device /dev/does-not-exist` succeeds and prints an
id, and runc only resolves the device — and validates sysctls — when it
builds the container. So on a host with no tun module the create returns
fine and `start` fails, which means the explanation never ran and the
user saw the raw daemon string naming a path they would go looking for on
the wrong machine. The unit tests fed the create-side string straight in,
so they confirmed a function no real failure could reach.
Move the guard onto `start_container`, covering create as well in case a
future daemon checks earlier. It no longer takes `vpn_support_enabled` —
`start_container` has a container id and no project, and nothing else in
Triple-C ever requests a device, so an error naming /dev/net/tun is
unambiguous on its own. The test now uses the daemon's verbatim message
via bollard's real Display format.
Also from review:
* Soften the security claim. Docker does not enable user-namespace
remapping by default, so this is a real CAP_NET_ADMIN in the initial
user namespace with only the network namespace confining it. It
cannot touch host interfaces, but "confers no authority outside the
container" was too strong: within its namespace it can set
promiscuous mode and add addresses, routes and NAT on the shared
docker0 segment, which puts sibling containers — the LiteLLM gateway
among them — within ARP-spoofing reach, and it can flush netfilter
rules sandbox mode may rely on. Said plainly in the code, CLAUDE.md
and HOW-TO-USE.
* Drop Tailscale from the list of clients needing this. Its
--tun=userspace-networking mode needs neither the capability nor the
device, and listing it invites granting NET_ADMIN for nothing.
* Say in the toggle's own hint that changing it recreates the
container, matching how every other recreation-triggering setting is
labelled. The tab's generic "stop the container first" chip does not
tell the user what is about to happen.
* Add RuntimeSection tests: saves on, saves off explicitly rather than
dropping the key, reflects state, is disabled while running, and
carries the recreation warning.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
95 lines
3.0 KiB
TypeScript
95 lines
3.0 KiB
TypeScript
import { describe, it, expect, vi, beforeEach } from "vitest";
|
|
import { render, screen, fireEvent } from "@testing-library/react";
|
|
import RuntimeSection from "./RuntimeSection";
|
|
import type { Project } from "../../../../lib/types";
|
|
|
|
const baseProject: Project = {
|
|
id: "p1",
|
|
name: "api-server",
|
|
paths: [{ host_path: "/src/api", mount_name: "api" }],
|
|
container_id: null,
|
|
status: "stopped",
|
|
backend: "anthropic",
|
|
bedrock_config: null,
|
|
ollama_config: null,
|
|
llamacpp_config: null,
|
|
openai_compatible_config: null,
|
|
allow_docker_access: false,
|
|
sandbox_mode_enabled: true,
|
|
mission_control_enabled: false,
|
|
auth_bridge_enabled: false,
|
|
browser_view_enabled: false,
|
|
vpn_support_enabled: false,
|
|
use_shared_auth_token: true,
|
|
full_permissions: false,
|
|
permission_mode: null,
|
|
ssh_key_path: null,
|
|
ca_cert_path: null,
|
|
git_token: null,
|
|
git_user_name: null,
|
|
git_user_email: null,
|
|
custom_env_vars: [],
|
|
port_mappings: [],
|
|
claude_instructions: null,
|
|
claude_code_settings: null,
|
|
renamed_session_names: {},
|
|
created_at: "2026-01-01T00:00:00Z",
|
|
updated_at: "2026-01-01T00:00:00Z",
|
|
};
|
|
|
|
const VPN = "VPN support";
|
|
|
|
const save = vi.fn().mockResolvedValue(true);
|
|
|
|
function renderSection(over: Partial<Project> = {}, disabled = false) {
|
|
return render(
|
|
<RuntimeSection
|
|
project={{ ...baseProject, ...over }}
|
|
save={save}
|
|
disabled={disabled}
|
|
disabledReason="Container must be stopped to change this setting."
|
|
/>,
|
|
);
|
|
}
|
|
|
|
describe("RuntimeSection — VPN support toggle", () => {
|
|
beforeEach(() => vi.clearAllMocks());
|
|
|
|
it("saves only the VPN flag when switched on", () => {
|
|
renderSection();
|
|
fireEvent.click(screen.getByRole("switch", { name: VPN }));
|
|
expect(save).toHaveBeenCalledWith({ vpn_support_enabled: true });
|
|
});
|
|
|
|
it("saves the flag off again, rather than dropping the key", () => {
|
|
// Off has to be written explicitly: the container carries a
|
|
// `triple-c.vpn-support` label either way, and an absent value would leave
|
|
// the capability granted.
|
|
renderSection({ vpn_support_enabled: true });
|
|
fireEvent.click(screen.getByRole("switch", { name: VPN }));
|
|
expect(save).toHaveBeenCalledWith({ vpn_support_enabled: false });
|
|
});
|
|
|
|
it("reflects the project's current state", () => {
|
|
renderSection({ vpn_support_enabled: true });
|
|
expect(screen.getByRole("switch", { name: VPN })).toBeChecked();
|
|
});
|
|
|
|
it("cannot be changed while the container is running", () => {
|
|
// Capabilities and devices are fixed at creation, so this setting is gated
|
|
// on the container being stopped along with the rest of the tab.
|
|
renderSection({}, true);
|
|
const toggle = screen.getByRole("switch", { name: VPN });
|
|
expect(toggle).toBeDisabled();
|
|
fireEvent.click(toggle);
|
|
expect(save).not.toHaveBeenCalled();
|
|
});
|
|
|
|
it("warns that the change recreates the container", () => {
|
|
renderSection();
|
|
expect(
|
|
screen.getByText(/recreates the container on its next start/i),
|
|
).toBeInTheDocument();
|
|
});
|
|
});
|