From d979c3915e523eee01df83fd949f1c0f89375bc6 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Tue, 8 Sep 2026 08:19:39 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=94=92=20Fix=20missing=20Network=20capabi?= =?UTF-8?q?lity=20check=20in=20std.dns?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- stdlib/src/dns.rs | 15 +++++++++++++-- stdlib/tests/stdlib_tests.rs | 27 +++++++++++++++++++++++++++ 2 files changed, 40 insertions(+), 2 deletions(-) diff --git a/stdlib/src/dns.rs b/stdlib/src/dns.rs index fbde0fa7..b8aa5af6 100644 --- a/stdlib/src/dns.rs +++ b/stdlib/src/dns.rs @@ -4,6 +4,7 @@ use std::cell::RefCell; use std::collections::HashMap; use std::net::ToSocketAddrs; use std::rc::Rc; +use techscript_runtime::context::Capability; use techscript_runtime::{error::RuntimeError, value::RuntimeValue}; impl StdlibRegistry { @@ -16,7 +17,17 @@ impl StdlibRegistry { Rc::new(StdFunction { name: "lookup".to_string(), arity: 1, - callback: |_ctx, args| { + callback: |ctx, args| { + if !ctx.config.capabilities.contains(&Capability::Network) { + return Err(RuntimeError::new( + techscript_runtime::error::RuntimeErrorKind::InvalidOperation( + "Security policy violation: Network capability is denied" + .to_string(), + ), + None, + None, + )); + } let host = match &args[0] { RuntimeValue::Str(s) => s.clone(), _ => { @@ -51,7 +62,7 @@ impl StdlibRegistry { name: "std.dns".to_string(), version: "1.0.0".to_string(), exports, - required_capabilities: Vec::new(), + required_capabilities: vec![Capability::Network], }, ); } diff --git a/stdlib/tests/stdlib_tests.rs b/stdlib/tests/stdlib_tests.rs index f7df969f..273d6a37 100644 --- a/stdlib/tests/stdlib_tests.rs +++ b/stdlib/tests/stdlib_tests.rs @@ -1151,3 +1151,30 @@ fn test_ai_generate_text() { let val = res.unwrap(); assert!(val.as_string().unwrap().contains("Prompt: What is 2+2?")); } + +#[test] +fn test_dns_module_denied() { + let mut registry = StdlibRegistry::new(); + registry.register_dns(); + let dns = registry.get_module("std.dns").unwrap(); + + let mut config = RuntimeConfig::default(); + config.capabilities.clear(); // Ensure Network capability is denied + + let mut ctx = RuntimeContext::new(config); + + let lookup = dns.exports.get("lookup").unwrap(); + let res = lookup.call(&mut ctx, vec![RuntimeValue::Str("localhost".to_string())]); + + assert!(res.is_err()); + if let Err(err) = res { + if let techscript_runtime::error::RuntimeErrorKind::InvalidOperation(msg) = err.kind { + assert_eq!( + msg, + "Security policy violation: Network capability is denied" + ); + } else { + panic!("Expected InvalidOperation error, got {:?}", err.kind); + } + } +}