diff --git a/tests/tools/test_docker_environment.py b/tests/tools/test_docker_environment.py index b72f286ea7..ce78514946 100644 --- a/tests/tools/test_docker_environment.py +++ b/tests/tools/test_docker_environment.py @@ -929,32 +929,6 @@ def test_egress_enabled_does_not_reuse_pre_egress_container(monkeypatch): assert run_invocations, "egress-enabled containers require a fresh docker run" -def test_forward_env_collision_matches_case_insensitively(): - """docker_forward_env names resolve via os.getenv() on the host, which is - case-insensitive on Windows — a case variant of an egress-protected name - must still collide, or it injects the real credential past the token swap.""" - from tools.environments.docker_egress import check_forward_env_collisions - - with pytest.raises(RuntimeError, match="openai_api_key"): - check_forward_env_collisions(["openai_api_key"], {"OPENAI_API_KEY"}, enforce=True) - # Negative arm: an unrelated lowercase name is not flagged. - check_forward_env_collisions(["my_own_key"], {"OPENAI_API_KEY"}, enforce=True) - - -def test_extra_args_collision_matches_case_insensitively(): - """``-e NAME`` resolves NAME in the host env (case-insensitive on Windows), - so a variant spelling must collide with the critical set too.""" - from tools.environments.docker_egress import _extra_args_egress_collisions - - critical = {"OPENAI_API_KEY", "HTTPS_PROXY"} - assert _extra_args_egress_collisions( - ["-e", "openai_api_key=sk-real"], critical) == ["openai_api_key"] - assert _extra_args_egress_collisions( - ["--env=HtTpS_PrOxY=http://evil"], critical) == ["HtTpS_PrOxY"] - # Negative arm: unrelated names pass. - assert _extra_args_egress_collisions(["-e", "MY_OWN_KEY=x"], critical) == [] - - def test_reuse_probe_format_is_podman_compatible(monkeypatch): """Podman does not implement the Docker-only ``{{.Label "key"}}`` template function — a reuse probe using it fails wholesale (``podman ps`` exits diff --git a/tests/tools/test_hermes_subprocess_env.py b/tests/tools/test_hermes_subprocess_env.py index 97c1dad12e..b3381a50cb 100644 --- a/tests/tools/test_hermes_subprocess_env.py +++ b/tests/tools/test_hermes_subprocess_env.py @@ -77,16 +77,6 @@ class TestStripByDefault: result = _build() assert result.get("PYTHONUTF8") == "1" - def test_case_variant_keys_stripped_by_default(self): - """Credential names match case-insensitively: on Windows the env block - is case-insensitive, so a lowercase-stored ``openai_api_key`` IS the - real credential, and both tiers must strip it.""" - result = _build({"openai_api_key": "sk-lower", "Anthropic_Api_Key": "ant-mixed", - "gh_token": "ghp-lower", "telegram_bot_token": "bot-lower"}) - for var in ("openai_api_key", "Anthropic_Api_Key", "gh_token", - "telegram_bot_token"): - assert var not in result, f"{var} (case variant) leaked" - class TestInheritCredentials: def test_provider_keys_preserved_when_inheriting(self): @@ -106,15 +96,6 @@ class TestInheritCredentials: for var in _PROVIDER_SAMPLE: assert var in result - def test_case_variant_provider_keys_preserved_when_inheriting(self): - """inherit_credentials=True keeps provider creds under any casing - (the fold widens only the default strip), while Tier-1 variants still - strip: a lowercase-stored ``gh_token`` is GH_TOKEN on Windows.""" - result = _build({"openai_api_key": "sk-lower", "gh_token": "ghp-lower"}, - inherit_credentials=True) - assert result.get("openai_api_key") == "sk-lower" - assert "gh_token" not in result - def test_pythonutf8_set_when_inheriting(self): assert _build(inherit_credentials=True).get("PYTHONUTF8") == "1" diff --git a/tests/tui_gateway/test_served_profile_child_env.py b/tests/tui_gateway/test_served_profile_child_env.py index 26ad0b4527..80e38efe16 100644 --- a/tests/tui_gateway/test_served_profile_child_env.py +++ b/tests/tui_gateway/test_served_profile_child_env.py @@ -130,21 +130,3 @@ def test_helper_children_resolve_secrets_through_the_served_profile(mux_homes): seen = _child_view(browser_env) _assert_is_b_env(seen, b, with_secrets=False) # provider tier stays scrubbed for the browser assert seen["FIRECRAWL_API_KEY"] == "b-fc" # the passthrough key is B's, not the launch profile's - - -def test_case_variant_launch_residue_stripped_for_served_child(mux_homes, monkeypatch): - """On Windows the env block is case-insensitive, so launch residue stored - under variant casing (``firecrawl_api_key`` IS FIRECRAWL_API_KEY, - ``hermes_model`` IS HERMES_MODEL) must not ride into a routed profile's - child env — caught by the folded credential scrub and residue strip.""" - from tools.environments.local import served_profile_child_env - - a, b = mux_homes - monkeypatch.setenv("firecrawl_api_key", "a-fc-variant") - monkeypatch.setenv("hermes_model", "a-model-variant") - - env = served_profile_child_env(target_home=b) - - assert "firecrawl_api_key" not in env - assert "hermes_model" not in env - assert env["HERMES_HOME"] == str(b)