From 5540860ca610d6a2cfe3a65e9eb9801def9c1214 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Thu, 3 Sep 2026 02:07:33 -0700 Subject: [PATCH] fix(integration): bang_shell builds its env via build_subprocess_env() Compaction moved run_bang_command's Popen within the env-guard scanner's proximity window of _bang_env's os.environ.copy(). Route through the single factory (build_subprocess_env() == _sanitize_subprocess_env(os.environ.copy())) and allowlist the file for the import-failure fallback copy with justification. --- hermes_cli/bang_shell.py | 6 +++--- tests/agent/test_subprocess_env_guard.py | 4 ++++ 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/hermes_cli/bang_shell.py b/hermes_cli/bang_shell.py index 12128fa637..706f1e149e 100644 --- a/hermes_cli/bang_shell.py +++ b/hermes_cli/bang_shell.py @@ -93,10 +93,10 @@ def _bang_env() -> dict: script, so reuse the sanitizer ``quick_commands`` and the local terminal backend use. """ try: - from tools.environments.local import _sanitize_subprocess_env - return _sanitize_subprocess_env(os.environ.copy()) + from tools.environments.local import build_subprocess_env + return build_subprocess_env() # == _sanitize_subprocess_env(os.environ.copy()) except Exception: - return os.environ.copy() + return os.environ.copy() # tools package unimportable: run the user's command anyway def run_bang_command(command: str, *, cwd: Optional[str] = None, timeout: int = DEFAULT_TIMEOUT, writer=None) -> int: diff --git a/tests/agent/test_subprocess_env_guard.py b/tests/agent/test_subprocess_env_guard.py index 2b79e2dbdb..a904c31995 100644 --- a/tests/agent/test_subprocess_env_guard.py +++ b/tests/agent/test_subprocess_env_guard.py @@ -45,6 +45,10 @@ ALLOWED_RAW_SPAWN_ENV_FILES = { # build_subprocess_env legitimately snapshot os.environ — everything else # delegates to them. "tools/environments/local.py", + # Bang-shell (`!cmd` in the CLI) goes through build_subprocess_env(); the + # only raw copy is the except-fallback for when the tools package itself + # cannot be imported, so the user's typed command still runs. + "hermes_cli/bang_shell.py", }