test: keep the case-fold tests that drive the production entry points
Drop the docker_environment, hermes_subprocess_env and served-profile copies of the same fold check; the passthrough-registration and local-scrub tests exercise the seams production reads, and the forward_env/extra_args refusal is covered by the collision guard tests already in test_docker_environment.py once the shared helper folds.
This commit is contained in:
@@ -929,32 +929,6 @@ def test_egress_enabled_does_not_reuse_pre_egress_container(monkeypatch):
|
||||
assert run_invocations, "egress-enabled containers require a fresh docker run"
|
||||
|
||||
|
||||
def test_forward_env_collision_matches_case_insensitively():
|
||||
"""docker_forward_env names resolve via os.getenv() on the host, which is
|
||||
case-insensitive on Windows — a case variant of an egress-protected name
|
||||
must still collide, or it injects the real credential past the token swap."""
|
||||
from tools.environments.docker_egress import check_forward_env_collisions
|
||||
|
||||
with pytest.raises(RuntimeError, match="openai_api_key"):
|
||||
check_forward_env_collisions(["openai_api_key"], {"OPENAI_API_KEY"}, enforce=True)
|
||||
# Negative arm: an unrelated lowercase name is not flagged.
|
||||
check_forward_env_collisions(["my_own_key"], {"OPENAI_API_KEY"}, enforce=True)
|
||||
|
||||
|
||||
def test_extra_args_collision_matches_case_insensitively():
|
||||
"""``-e NAME`` resolves NAME in the host env (case-insensitive on Windows),
|
||||
so a variant spelling must collide with the critical set too."""
|
||||
from tools.environments.docker_egress import _extra_args_egress_collisions
|
||||
|
||||
critical = {"OPENAI_API_KEY", "HTTPS_PROXY"}
|
||||
assert _extra_args_egress_collisions(
|
||||
["-e", "openai_api_key=sk-real"], critical) == ["openai_api_key"]
|
||||
assert _extra_args_egress_collisions(
|
||||
["--env=HtTpS_PrOxY=http://evil"], critical) == ["HtTpS_PrOxY"]
|
||||
# Negative arm: unrelated names pass.
|
||||
assert _extra_args_egress_collisions(["-e", "MY_OWN_KEY=x"], critical) == []
|
||||
|
||||
|
||||
def test_reuse_probe_format_is_podman_compatible(monkeypatch):
|
||||
"""Podman does not implement the Docker-only ``{{.Label "key"}}`` template
|
||||
function — a reuse probe using it fails wholesale (``podman ps`` exits
|
||||
|
||||
@@ -77,16 +77,6 @@ class TestStripByDefault:
|
||||
result = _build()
|
||||
assert result.get("PYTHONUTF8") == "1"
|
||||
|
||||
def test_case_variant_keys_stripped_by_default(self):
|
||||
"""Credential names match case-insensitively: on Windows the env block
|
||||
is case-insensitive, so a lowercase-stored ``openai_api_key`` IS the
|
||||
real credential, and both tiers must strip it."""
|
||||
result = _build({"openai_api_key": "sk-lower", "Anthropic_Api_Key": "ant-mixed",
|
||||
"gh_token": "ghp-lower", "telegram_bot_token": "bot-lower"})
|
||||
for var in ("openai_api_key", "Anthropic_Api_Key", "gh_token",
|
||||
"telegram_bot_token"):
|
||||
assert var not in result, f"{var} (case variant) leaked"
|
||||
|
||||
|
||||
class TestInheritCredentials:
|
||||
def test_provider_keys_preserved_when_inheriting(self):
|
||||
@@ -106,15 +96,6 @@ class TestInheritCredentials:
|
||||
for var in _PROVIDER_SAMPLE:
|
||||
assert var in result
|
||||
|
||||
def test_case_variant_provider_keys_preserved_when_inheriting(self):
|
||||
"""inherit_credentials=True keeps provider creds under any casing
|
||||
(the fold widens only the default strip), while Tier-1 variants still
|
||||
strip: a lowercase-stored ``gh_token`` is GH_TOKEN on Windows."""
|
||||
result = _build({"openai_api_key": "sk-lower", "gh_token": "ghp-lower"},
|
||||
inherit_credentials=True)
|
||||
assert result.get("openai_api_key") == "sk-lower"
|
||||
assert "gh_token" not in result
|
||||
|
||||
def test_pythonutf8_set_when_inheriting(self):
|
||||
assert _build(inherit_credentials=True).get("PYTHONUTF8") == "1"
|
||||
|
||||
|
||||
@@ -130,21 +130,3 @@ def test_helper_children_resolve_secrets_through_the_served_profile(mux_homes):
|
||||
seen = _child_view(browser_env)
|
||||
_assert_is_b_env(seen, b, with_secrets=False) # provider tier stays scrubbed for the browser
|
||||
assert seen["FIRECRAWL_API_KEY"] == "b-fc" # the passthrough key is B's, not the launch profile's
|
||||
|
||||
|
||||
def test_case_variant_launch_residue_stripped_for_served_child(mux_homes, monkeypatch):
|
||||
"""On Windows the env block is case-insensitive, so launch residue stored
|
||||
under variant casing (``firecrawl_api_key`` IS FIRECRAWL_API_KEY,
|
||||
``hermes_model`` IS HERMES_MODEL) must not ride into a routed profile's
|
||||
child env — caught by the folded credential scrub and residue strip."""
|
||||
from tools.environments.local import served_profile_child_env
|
||||
|
||||
a, b = mux_homes
|
||||
monkeypatch.setenv("firecrawl_api_key", "a-fc-variant")
|
||||
monkeypatch.setenv("hermes_model", "a-model-variant")
|
||||
|
||||
env = served_profile_child_env(target_home=b)
|
||||
|
||||
assert "firecrawl_api_key" not in env
|
||||
assert "hermes_model" not in env
|
||||
assert env["HERMES_HOME"] == str(b)
|
||||
|
||||
Reference in New Issue
Block a user