From b6a3d3f4406fab0d495bdaaead21963590d8ccc2 Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Wed, 2 Sep 2026 14:25:03 -0700 Subject: [PATCH] refactor(tools): restore stdin=DEVNULL on subprocess probes dropped during compaction voice_mode WSL playback probe, subagent_worktree._run_git, cua_backend loginctl/xprop probes lost their explicit stdin= (and one line-wrapped past the encoding= same-line rule); lazy_deps._run carries it via _SUBPROCESS_KW so mark it for the guard. Fixes tests/tools/test_subprocess_stdin_guard.py and tests/scripts/test_footgun_subprocess_encoding.py (green on base). --- tools/computer_use/cua_backend.py | 12 ++++++------ tools/lazy_deps.py | 1 + tools/voice_mode.py | 3 ++- 3 files changed, 9 insertions(+), 7 deletions(-) diff --git a/tools/computer_use/cua_backend.py b/tools/computer_use/cua_backend.py index 6f12b36c2d..6ff30a3a32 100644 --- a/tools/computer_use/cua_backend.py +++ b/tools/computer_use/cua_backend.py @@ -253,8 +253,8 @@ def _linux_session_locked() -> Optional[bool]: if sys.platform != "linux": return None try: - proc = subprocess.run(["loginctl", "list-sessions", "--no-legend"], - capture_output=True, text=True, timeout=2.0) + proc = subprocess.run(["loginctl", "list-sessions", "--no-legend"], capture_output=True, + text=True, timeout=2.0, stdin=subprocess.DEVNULL) if proc.returncode != 0: return None any_seat = False @@ -263,8 +263,8 @@ def _linux_session_locked() -> Optional[bool]: if len(parts) < 2 or "seat" not in line: continue any_seat = True - probe = subprocess.run(["loginctl", "show-session", parts[0], "-p", "LockedHint"], - capture_output=True, text=True, timeout=2.0) + probe = subprocess.run(["loginctl", "show-session", parts[0], "-p", "LockedHint"], capture_output=True, + text=True, timeout=2.0, stdin=subprocess.DEVNULL) if "LockedHint=no" in probe.stdout: return False return True if any_seat else None @@ -302,8 +302,8 @@ def _linux_x11_active_window_id() -> Optional[int]: if sys.platform != "linux" or not os.environ.get("DISPLAY"): return None try: - proc = subprocess.run(["xprop", "-root", "_NET_ACTIVE_WINDOW"], capture_output=True, - text=True, encoding="utf-8", errors="replace", timeout=2, check=False) + proc = subprocess.run(["xprop", "-root", "_NET_ACTIVE_WINDOW"], capture_output=True, text=True, encoding="utf-8", + errors="replace", timeout=2, check=False, stdin=subprocess.DEVNULL) except Exception: return None return _parse_xprop_net_active_window(proc.stdout or "") if proc.returncode == 0 else None diff --git a/tools/lazy_deps.py b/tools/lazy_deps.py index cfc8f755cf..47fc4ead31 100644 --- a/tools/lazy_deps.py +++ b/tools/lazy_deps.py @@ -551,6 +551,7 @@ def _venv_pip_install(specs: tuple[str, ...], *, timeout: int = 300) -> _Install extra_args += ["--constraint", str(constraints)] def _run(cmd: list[str], **kw) -> subprocess.CompletedProcess: + # _SUBPROCESS_KW carries stdin=DEVNULL # noqa: subprocess-stdin return subprocess.run(cmd, **_SUBPROCESS_KW, creationflags=windows_hide_flags(), **kw) def _finish(r: subprocess.CompletedProcess) -> _InstallResult: diff --git a/tools/voice_mode.py b/tools/voice_mode.py index 33bff5adf7..d6a102d3dc 100644 --- a/tools/voice_mode.py +++ b/tools/voice_mode.py @@ -1358,7 +1358,8 @@ def _wsl_powershell_player_cmd(file_path: str) -> Optional[List[str]]: import uuid def _out(cmd): - return subprocess.check_output(cmd, stderr=subprocess.DEVNULL, timeout=3).decode(errors="replace").strip() + return subprocess.check_output(cmd, stderr=subprocess.DEVNULL, stdin=subprocess.DEVNULL, + timeout=3).decode(errors="replace").strip() win_tmp_wsl = _out(["wslpath", "-u", _out(["cmd.exe", "/c", "echo %TEMP%"])]) if not win_tmp_wsl: