Compose the two salvaged approaches (#78065 + #78511): - Keep #78065's terminal-only scrub-path exemption (first-party prefix predicate in _make_run_env / _sanitize_subprocess_env, plain env values never scope-resolved, snapshot exclusion for cross-profile isolation, every non-terminal surface sealed). - Fold #78511's BUZZ_MANAGED_AGENT signal into a context gate instead of an import-time blocklist discard: the blocklist is shared by every scrub surface, so discarding there would leak BUZZ_PRIVATE_KEY into execute_code / hermes_subprocess_env children too. - New gate _buzz_terminal_context_active(): BUZZ_MANAGED_AGENT in the process env (Buzz Desktop buzz-acp harness, #76243) OR the live session's platform is buzz (HERMES_SESSION_PLATFORM ContextVar, concurrency-safe under a multi-session gateway). A Telegram/CLI/cron session on a host that also runs a Buzz gateway does NOT get the signing key in its terminal children (maintainer triage note on #76243: don't expose the key to unrelated shell commands). - Snapshot exclusion stays prefix-only (conservative even when the gate is inactive). - Tests updated for the gate + new negative test (non-Buzz session strips) and positive test (buzz session platform enables carve-out); docs updated accordingly. Closes #78026, closes #76243.
2 lines
11 B
Plaintext
2 lines
11 B
Plaintext
vatevstoil
|