fix(integration): bang_shell builds its env via build_subprocess_env()
Compaction moved run_bang_command's Popen within the env-guard scanner's proximity window of _bang_env's os.environ.copy(). Route through the single factory (build_subprocess_env() == _sanitize_subprocess_env(os.environ.copy())) and allowlist the file for the import-failure fallback copy with justification.
This commit is contained in:
@@ -93,10 +93,10 @@ def _bang_env() -> dict:
|
||||
script, so reuse the sanitizer ``quick_commands`` and the local terminal backend use.
|
||||
"""
|
||||
try:
|
||||
from tools.environments.local import _sanitize_subprocess_env
|
||||
return _sanitize_subprocess_env(os.environ.copy())
|
||||
from tools.environments.local import build_subprocess_env
|
||||
return build_subprocess_env() # == _sanitize_subprocess_env(os.environ.copy())
|
||||
except Exception:
|
||||
return os.environ.copy()
|
||||
return os.environ.copy() # tools package unimportable: run the user's command anyway
|
||||
|
||||
|
||||
def run_bang_command(command: str, *, cwd: Optional[str] = None, timeout: int = DEFAULT_TIMEOUT, writer=None) -> int:
|
||||
|
||||
@@ -45,6 +45,10 @@ ALLOWED_RAW_SPAWN_ENV_FILES = {
|
||||
# build_subprocess_env legitimately snapshot os.environ — everything else
|
||||
# delegates to them.
|
||||
"tools/environments/local.py",
|
||||
# Bang-shell (`!cmd` in the CLI) goes through build_subprocess_env(); the
|
||||
# only raw copy is the except-fallback for when the tools package itself
|
||||
# cannot be imported, so the user's typed command still runs.
|
||||
"hermes_cli/bang_shell.py",
|
||||
}
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user