fix(integration): bang_shell builds its env via build_subprocess_env()

Compaction moved run_bang_command's Popen within the env-guard scanner's
proximity window of _bang_env's os.environ.copy(). Route through the single
factory (build_subprocess_env() == _sanitize_subprocess_env(os.environ.copy()))
and allowlist the file for the import-failure fallback copy with justification.
This commit is contained in:
Teknium
2026-09-03 02:07:33 -07:00
parent dc130e54bf
commit 5540860ca6
2 changed files with 7 additions and 3 deletions

View File

@@ -93,10 +93,10 @@ def _bang_env() -> dict:
script, so reuse the sanitizer ``quick_commands`` and the local terminal backend use.
"""
try:
from tools.environments.local import _sanitize_subprocess_env
return _sanitize_subprocess_env(os.environ.copy())
from tools.environments.local import build_subprocess_env
return build_subprocess_env() # == _sanitize_subprocess_env(os.environ.copy())
except Exception:
return os.environ.copy()
return os.environ.copy() # tools package unimportable: run the user's command anyway
def run_bang_command(command: str, *, cwd: Optional[str] = None, timeout: int = DEFAULT_TIMEOUT, writer=None) -> int:

View File

@@ -45,6 +45,10 @@ ALLOWED_RAW_SPAWN_ENV_FILES = {
# build_subprocess_env legitimately snapshot os.environ — everything else
# delegates to them.
"tools/environments/local.py",
# Bang-shell (`!cmd` in the CLI) goes through build_subprocess_env(); the
# only raw copy is the except-fallback for when the tools package itself
# cannot be imported, so the user's typed command still runs.
"hermes_cli/bang_shell.py",
}