mirror of
https://github.com/elicpeter/nyx.git
synced 2026-06-12 19:55:14 +02:00
[pitboss/grind] deferred session-0014 (20260516T052512Z-20f8)
This commit is contained in:
parent
a2cc5f7700
commit
6a169f51b8
23 changed files with 737 additions and 29 deletions
36
tests/dynamic_fixtures/stubs_e2e/python/http/vuln/main.py
Normal file
36
tests/dynamic_fixtures/stubs_e2e/python/http/vuln/main.py
Normal file
|
|
@ -0,0 +1,36 @@
|
|||
"""Phase 10 (Track D.3) stub-end-to-end fixture: Python + HTTP.
|
||||
|
||||
The verifier publishes:
|
||||
|
||||
* ``NYX_HTTP_ENDPOINT`` — `http://127.0.0.1:{port}` the HttpStub listens on.
|
||||
* ``NYX_HTTP_LOG`` — companion log path the harness appends attempted
|
||||
outbound calls to so the host HttpStub picks them up on
|
||||
``drain_events()`` even when the request bypasses the on-the-wire
|
||||
listener (DNS-mocked, network-isolated sandbox, pre-flight check).
|
||||
|
||||
This fixture exercises the side-channel path: it records an attempted
|
||||
SSRF call to ``http://169.254.169.254/latest/meta-data/`` through the
|
||||
Python shim helper ``__nyx_stub_http_record`` without issuing the
|
||||
actual network call. The companion test in
|
||||
``tests/stubs_e2e_per_lang.rs`` splices in
|
||||
``crate::dynamic::lang::python::probe_shim`` ahead of this source, runs
|
||||
it with both env vars set, and asserts the stub captured the attempt.
|
||||
"""
|
||||
|
||||
import os
|
||||
|
||||
|
||||
def main():
|
||||
method = "GET"
|
||||
url = "http://169.254.169.254/latest/meta-data/"
|
||||
body = ""
|
||||
# Record the attempted call through the probe shim so the host
|
||||
# HttpStub captures it on the next drain_events() call even when
|
||||
# the harness never reaches the on-the-wire listener.
|
||||
__nyx_stub_http_record(method, url, body, driver="urllib")
|
||||
# Echo so the host can confirm the driver ran end-to-end.
|
||||
print(os.environ.get("NYX_HTTP_ENDPOINT", "no-endpoint"))
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
main()
|
||||
Loading…
Add table
Add a link
Reference in a new issue