# Conflicts: # apps/desktop/e2e/archived-hidden-session-recoverable.spec.ts # apps/desktop/e2e/bot-chat-message-agent-friendly-name.spec.ts # apps/desktop/e2e/bot-mailbox-unreadable-ticket.spec.ts # apps/desktop/e2e/bot-mode-roster-localized.spec.ts # apps/desktop/e2e/bot-mode-row-click-mirrors-registry.spec.ts # apps/desktop/e2e/bot-mode-tab-shows-bot-name.spec.ts # apps/desktop/e2e/bot-roster-group-row-organisation.spec.ts # apps/desktop/e2e/bot-roster-ignores-infra-dirs.spec.ts # apps/desktop/e2e/bot-roster-timestamp-meta.spec.ts # apps/desktop/e2e/bot-roster-user-sections.spec.ts # apps/desktop/e2e/bot-routines-pane-narrow.spec.ts # apps/desktop/e2e/bot-row-open-recent-session.spec.ts # apps/desktop/e2e/bot-tile-ignores-ambient-composer-model.spec.ts # apps/desktop/e2e/group-composer-auto-grow.spec.ts # apps/desktop/e2e/group-create-gate-remote-roster.spec.ts # apps/desktop/e2e/group-prompt-renamed-primary-handle.spec.ts # apps/desktop/e2e/hosted-room-backend-continuity.spec.ts # apps/desktop/e2e/hosted-room-legacy-store-migration.spec.ts # apps/desktop/e2e/settings-scope-chips-bot-title.spec.ts # apps/desktop/e2e/worktree-branch-status.spec.ts # apps/desktop/electron/backend-probes.test.ts # apps/desktop/electron/connection-apply.test.ts # apps/desktop/electron/desktop-electron-pin.test.ts # apps/desktop/electron/desktop-uninstall.test.ts # apps/desktop/electron/gateway-file-download-transport.test.ts # apps/desktop/electron/gateway-stop-before-update.test.ts # apps/desktop/electron/github-api-auth.test.ts # apps/desktop/electron/registry-primary-profile-scope.test.ts # apps/desktop/electron/update-api-check.test.ts # apps/desktop/electron/update-handoff-marker.test.ts # apps/desktop/electron/venv-blocker-scan.test.ts # apps/desktop/scripts/after-extract.test.mjs # apps/desktop/scripts/local-pack-publish.test.mjs # apps/desktop/scripts/tasks-scroll.test.mjs # apps/desktop/src/app/settings/model-settings.test.tsx # apps/desktop/src/app/updates-overlay.blockers.test.tsx # apps/desktop/src/components/desktop-install-overlay.test.tsx # apps/desktop/src/lib/update-copy.test.ts # scripts/ci/check_os_marker_fakes.py # tests-js/desktop-mac-usage-descriptions.test.ts # tests-js/node-engine-alignment.test.ts # tests/agent/lsp/test_install_and_lint_fixes.py # tests/agent/test_command_token_source.py # tests/agent/test_compression_boundary_hook.py # tests/agent/test_create_openai_client_ssl_verify.py # tests/agent/test_custom_provider_ca_probes.py # tests/agent/test_endpoint_blackhole.py # tests/agent/test_estimator_parity.py # tests/agent/test_in_place_compaction.py # tests/agent/test_moa_loop_mode.py # tests/agent/test_model_metadata.py # tests/agent/test_skill_session_platform_gate.py # tests/agent/test_skill_utils.py # tests/agent/test_ssl_ca_guard.py # tests/computer_use/test_doctor.py # tests/cron/test_codex_execution_paths.py # tests/cron/test_cron_bot_chat_delivery.py # tests/cron/test_cron_script.py # tests/cron/test_media_delivery_parity.py # tests/cron/test_misfire_catchup.py # tests/cron/test_parallel_pool.py # tests/cron/test_recurring_eagain_redispatch.py # tests/gateway/test_choice_picker.py # tests/gateway/test_control_socket_windows_live.py # tests/gateway/test_dingtalk.py # tests/gateway/test_feishu.py # tests/gateway/test_feishu_onboard.py # tests/gateway/test_gateway_shutdown.py # tests/gateway/test_matrix.py # tests/gateway/test_model_command_custom_providers.py # tests/gateway/test_reasoning_command.py # tests/gateway/test_runtime_footer.py # tests/gateway/test_session.py # tests/gateway/test_session_hygiene.py # tests/gateway/test_status.py # tests/gateway/test_teams.py # tests/gateway/test_turn_lease.py # tests/gateway/test_whatsapp_connect.py # tests/hermes_cli/test_approvals_command.py # tests/hermes_cli/test_auth_store_lock_concurrent.py # tests/hermes_cli/test_backup.py # tests/hermes_cli/test_banner_git_state.py # tests/hermes_cli/test_certifi_repair.py # tests/hermes_cli/test_cmd_update.py # tests/hermes_cli/test_compat_manifest_targets.py # tests/hermes_cli/test_computer_use_cli.py # tests/hermes_cli/test_cpr_local_leak.py # tests/hermes_cli/test_dashboard_auth_gate.py # tests/hermes_cli/test_dashboard_procs_kill_grace.py # tests/hermes_cli/test_desktop_lifecycle_windows_live.py # tests/hermes_cli/test_doctor.py # tests/hermes_cli/test_doctor_command_install.py # tests/hermes_cli/test_fleet_config_migration_windows_live.py # tests/hermes_cli/test_gateway.py # tests/hermes_cli/test_gateway_platform_gating.py # tests/hermes_cli/test_gateway_restart_loop.py # tests/hermes_cli/test_gateway_task_probe.py # tests/hermes_cli/test_gateway_wsl.py # tests/hermes_cli/test_gui_command.py # tests/hermes_cli/test_install_cua_driver.py # tests/hermes_cli/test_kanban_db.py # tests/hermes_cli/test_lazy_command_exports.py # tests/hermes_cli/test_lazy_refresh_venv_repair.py # tests/hermes_cli/test_linux_desktop_entry.py # tests/hermes_cli/test_local_runtime.py # tests/hermes_cli/test_local_runtime_updates.py # tests/hermes_cli/test_managed_uv.py # tests/hermes_cli/test_mcp_reload_confirm_gate.py # tests/hermes_cli/test_nous_subscription.py # tests/hermes_cli/test_npm_engine.py # tests/hermes_cli/test_personality_none.py # tests/hermes_cli/test_pet_toggle.py # tests/hermes_cli/test_plan_reconciliation_windows_live.py # tests/hermes_cli/test_plugin_event_bus.py # tests/hermes_cli/test_plugin_manifest_v2.py # tests/hermes_cli/test_plugin_packs.py # tests/hermes_cli/test_plugins_cmd.py # tests/hermes_cli/test_plugins_cmd_enable_disable_nested.py # tests/hermes_cli/test_process_identity.py # tests/hermes_cli/test_profiles.py # tests/hermes_cli/test_profiles_sidebar_cache.py # tests/hermes_cli/test_pty_bridge.py # tests/hermes_cli/test_resolve_turn_limit.py # tests/hermes_cli/test_serve_runtime_inventory.py # tests/hermes_cli/test_session_vacuum_config.py # tests/hermes_cli/test_set_config_value.py # tests/hermes_cli/test_signal_handler_kanban_worker.py # tests/hermes_cli/test_slash_confirm_windows.py # tests/hermes_cli/test_stale_pid_guard.py # tests/hermes_cli/test_startup_fast_guards.py # tests/hermes_cli/test_status.py # tests/hermes_cli/test_telegram_managed_bot.py # tests/hermes_cli/test_tools_config.py # tests/hermes_cli/test_update_apply_shallow_count.py # tests/hermes_cli/test_update_autostash.py # tests/hermes_cli/test_update_concurrent_quarantine.py # tests/hermes_cli/test_update_fetch_failure_classifier.py # tests/hermes_cli/test_update_fleet_probe_resume_token.py # tests/hermes_cli/test_update_handoff_backend_reap.py # tests/hermes_cli/test_update_handoff_desktop_rebuild.py # tests/hermes_cli/test_update_head_moved_gate.py # tests/hermes_cli/test_update_host_obligation.py # tests/hermes_cli/test_update_import_guard.py # tests/hermes_cli/test_update_interrupted_recovery.py # tests/hermes_cli/test_update_inventory.py # tests/hermes_cli/test_update_launchd_unloaded_gateway.py # tests/hermes_cli/test_update_missing_configured_deps.py # tests/hermes_cli/test_update_modified_notice.py # tests/hermes_cli/test_update_multiplex_migration_hook.py # tests/hermes_cli/test_update_no_gateway_restart.py # tests/hermes_cli/test_update_orphan_backend_reap.py # tests/hermes_cli/test_update_parked_branch_guard.py # tests/hermes_cli/test_update_post_pull_syntax_guard.py # tests/hermes_cli/test_update_receipt.py # tests/hermes_cli/test_update_self_lock.py # tests/hermes_cli/test_update_shim_fail_closed.py # tests/hermes_cli/test_update_shim_self_lock.py # tests/hermes_cli/test_update_sqlite_remediation.py # tests/hermes_cli/test_update_stale_dashboard.py # tests/hermes_cli/test_update_stale_virtualenv.py # tests/hermes_cli/test_update_venv_health.py # tests/hermes_cli/test_update_venv_ownership_preflight.py # tests/hermes_cli/test_update_wedged_gateway.py # tests/hermes_cli/test_update_yes_flag.py # tests/hermes_cli/test_update_zip_two_phase.py # tests/hermes_cli/test_urllib_security.py # tests/hermes_cli/test_ux_messages_auth_config.py # tests/hermes_cli/test_ux_messages_startup.py # tests/hermes_cli/test_venv_holder_classifier.py # tests/hermes_cli/test_verify_console_scripts.py # tests/hermes_cli/test_verify_core_dependencies.py # tests/hermes_cli/test_web_server.py # tests/hermes_cli/test_web_server_console_ws.py # tests/hermes_cli/test_web_server_ws_ping.py # tests/hermes_cli/test_web_ui_build.py # tests/hermes_state/test_fts_rebuild_admission.py # tests/hermes_state/test_hermes_state.py # tests/plugins/memory/test_memory_lazy_install.py # tests/plugins/test_google_meet_plugin.py # tests/plugins/test_langfuse_plugin.py # tests/plugins/test_security_guidance_plugin.py # tests/plugins/test_transform_llm_output_hook.py # tests/scripts/desktop_update/test_desktop_update_windows_gateway_flag.py # tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py # tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py # tests/scripts/install/test_install_clone_throttle_fallback.py # tests/scripts/install/test_install_lockfile_churn.py # tests/scripts/install/test_install_no_initial_commit.py # tests/scripts/install/test_install_sh_browser_install.py # tests/scripts/install/test_install_sh_node_prerelease.py # tests/scripts/install/test_install_sh_symlink_stomp.py # tests/scripts/install/test_install_sh_uv_lock_config.py # tests/scripts/install/test_install_unmerged_index.py # tests/scripts/test_contributor_map.py # tests/scripts/test_run_tests_parallel.py # tests/skills/test_competitor_news_monitor_skill.py # tests/skills/test_document_to_action_items_skill.py # tests/skills/test_google_workspace_setup.py # tests/skills/test_google_workspace_setup_deps.py # tests/skills/test_grounded_citations_skill.py # tests/skills/test_ip_as_logo_skill.py # tests/skills/test_live_dashboard_skill.py # tests/skills/test_mcp_oauth_remote_gateway_skill.py # tests/skills/test_office_document_skills.py # tests/skills/test_openclaw_migration.py # tests/skills/test_product_price_monitor_skill.py # tests/skills/test_scrollcraft_skill.py # tests/skills/test_setup_wizard_generator_skill.py # tests/skills/test_weekly_review_planning_skill.py # tests/test_engines_satisfiable.py # tests/test_fast_safe_load.py # tests/test_hermes_bootstrap.py # tests/test_hermes_constants.py # tests/test_hermes_logging.py # tests/test_managed_runtime_resolution.py # tests/test_model_tools_async_bridge.py # tests/test_packaging_build_guard.py # tests/test_packaging_metadata.py # tests/test_yaml_indent_consistency.py # tests/tools/test_approval_timeout_overflow.py # tests/tools/test_base_environment.py # tests/tools/test_bot_mode_dm.py # tests/tools/test_browser_chromium_check.py # tests/tools/test_browser_hardening.py # tests/tools/test_browser_homebrew_paths.py # tests/tools/test_browser_npx_warmup.py # tests/tools/test_browser_orphan_reaper.py # tests/tools/test_browser_real_profile.py # tests/tools/test_browser_use_cli.py # tests/tools/test_clipboard.py # tests/tools/test_code_execution.py # tests/tools/test_code_execution_modes.py # tests/tools/test_code_execution_windows_env.py # tests/tools/test_computer_use.py # tests/tools/test_delegate_liveness_timeout.py # tests/tools/test_execute_code_approval_cluster.py # tests/tools/test_execution_flag_detection.py # tests/tools/test_fal_common.py # tests/tools/test_file_operations.py # tests/tools/test_file_tools.py # tests/tools/test_file_tools_cwd_resolution.py # tests/tools/test_file_tools_live.py # tests/tools/test_lazy_deps.py # tests/tools/test_lazy_deps_durable_target.py # tests/tools/test_lazy_deps_managed.py # tests/tools/test_local_env_blocklist.py # tests/tools/test_local_tempdir.py # tests/tools/test_macos_protected_search.py # tests/tools/test_mcp_npx_cached_bin.py # tests/tools/test_oneshot_completion_linger.py # tests/tools/test_process_registry.py # tests/tools/test_read_file_schema_gating.py # tests/tools/test_skill_improvements.py # tests/tools/test_skills_sync.py # tests/tools/test_termux_api_detection.py # tests/tools/test_tirith_security.py # tests/tools/test_transcription_tools.py # tests/tools/test_tts_streaming.py # tests/tools/test_wake_word.py # tests/tui_gateway/test_compute_host_borrowed_lease.py # tests/tui_gateway/test_compute_host_turn_protocol.py # tests/tui_gateway/test_isolated_orphan_activity.py # tests/tui_gateway/test_protocol.py # tests/tui_gateway/test_slash_worker_profile_home.py # tests/tui_gateway/test_subprocess_encoding.py # tests/tui_gateway/test_tui_gateway_server.py # ui-tui/src/__tests__/terminalParity.test.ts # ui-tui/src/__tests__/termuxComposerLayout.test.ts # ui-tui/src/__tests__/textInputFastEcho.test.ts
518 lines
23 KiB
Python
518 lines
23 KiB
Python
"""Tests for tools.env_passthrough — skill and config env var passthrough."""
|
|
|
|
import os
|
|
import pytest
|
|
import hermes_yaml as yaml
|
|
|
|
from agent import secret_scope as ss
|
|
import tools.env_passthrough as _ep_mod
|
|
from tools.env_passthrough import (
|
|
clear_env_passthrough,
|
|
get_all_passthrough,
|
|
is_env_passthrough,
|
|
register_env_passthrough,
|
|
resolve_passthrough_value,
|
|
)
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _clean_passthrough():
|
|
"""Ensure a clean passthrough state for every test."""
|
|
clear_env_passthrough()
|
|
_ep_mod._config_passthrough.clear()
|
|
ss.set_multiplex_active(False)
|
|
yield
|
|
clear_env_passthrough()
|
|
_ep_mod._config_passthrough.clear()
|
|
ss.set_multiplex_active(False)
|
|
|
|
|
|
class TestSkillScopedPassthrough:
|
|
|
|
|
|
def test_skips_empty(self):
|
|
register_env_passthrough(["", " ", "VALID_KEY"])
|
|
assert is_env_passthrough("VALID_KEY")
|
|
assert not is_env_passthrough("")
|
|
|
|
|
|
class TestConfigPassthrough:
|
|
def test_reads_from_config(self, tmp_path, monkeypatch):
|
|
config = {"terminal": {"env_passthrough": ["MY_CUSTOM_KEY", "ANOTHER_TOKEN"]}}
|
|
config_path = tmp_path / "config.yaml"
|
|
config_path.write_text(yaml.safe_dump(config), encoding="utf-8")
|
|
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
|
_ep_mod._config_passthrough.clear()
|
|
|
|
assert is_env_passthrough("MY_CUSTOM_KEY")
|
|
assert is_env_passthrough("ANOTHER_TOKEN")
|
|
assert not is_env_passthrough("UNRELATED_VAR")
|
|
|
|
|
|
def test_union_of_skill_and_config(self, tmp_path, monkeypatch):
|
|
config = {"terminal": {"env_passthrough": ["CONFIG_KEY"]}}
|
|
config_path = tmp_path / "config.yaml"
|
|
config_path.write_text(yaml.safe_dump(config), encoding="utf-8")
|
|
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
|
_ep_mod._config_passthrough.clear()
|
|
|
|
register_env_passthrough(["SKILL_KEY"])
|
|
all_pt = get_all_passthrough()
|
|
assert "CONFIG_KEY" in all_pt
|
|
assert "SKILL_KEY" in all_pt
|
|
|
|
|
|
class TestProfileScopedResolution:
|
|
def test_active_scope_overrides_process_fallback(self):
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({"SERVICE_TOKEN": "profile-b"})
|
|
try:
|
|
assert resolve_passthrough_value("SERVICE_TOKEN", "profile-a") == "profile-b"
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
|
|
def test_active_scope_does_not_fall_back_to_another_profile(self):
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({})
|
|
try:
|
|
assert resolve_passthrough_value("SERVICE_TOKEN", "profile-a") is None
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
|
|
def test_unscoped_multiplex_read_fails_closed(self):
|
|
ss.set_multiplex_active(True)
|
|
with pytest.raises(ss.UnscopedSecretError):
|
|
resolve_passthrough_value("SERVICE_TOKEN", "profile-a")
|
|
|
|
def test_single_profile_keeps_callers_fallback(self):
|
|
assert resolve_passthrough_value("SERVICE_TOKEN", "profile-a") == "profile-a"
|
|
|
|
def test_active_scope_keeps_explicit_global_override(self, monkeypatch):
|
|
"""Global terminal settings still honor a caller-provided override."""
|
|
monkeypatch.setenv("TERMINAL_CWD", "/default")
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({})
|
|
try:
|
|
assert resolve_passthrough_value("TERMINAL_CWD", "/explicit") == "/explicit"
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
|
|
|
|
class TestExecuteCodeIntegration:
|
|
"""Verify that the passthrough is checked in execute_code's env filtering."""
|
|
|
|
|
|
|
|
def test_execute_code_uses_active_profile_for_passthrough(self, monkeypatch):
|
|
"""The execute_code child must receive the routed profile's value."""
|
|
from tools.code_execution_env import _scrub_child_env
|
|
|
|
register_env_passthrough(["SERVICE_TOKEN"])
|
|
monkeypatch.setenv("SERVICE_TOKEN", "token-for-default")
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({"SERVICE_TOKEN": "token-for-routed-profile"})
|
|
try:
|
|
child_env = _scrub_child_env({"SERVICE_TOKEN": "token-for-default"})
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
ss.set_multiplex_active(False)
|
|
|
|
assert child_env["SERVICE_TOKEN"] == "token-for-routed-profile"
|
|
|
|
def test_execute_code_omits_missing_scoped_passthrough(self, monkeypatch):
|
|
"""A missing routed secret must not leak into the execute_code child."""
|
|
from tools.code_execution_env import _scrub_child_env
|
|
|
|
register_env_passthrough(["SERVICE_TOKEN"])
|
|
monkeypatch.setenv("SERVICE_TOKEN", "token-for-default")
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({})
|
|
try:
|
|
child_env = _scrub_child_env({"SERVICE_TOKEN": "token-for-default"})
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
ss.set_multiplex_active(False)
|
|
|
|
assert "SERVICE_TOKEN" not in child_env
|
|
|
|
def test_execute_code_strips_buzz_vars(self):
|
|
"""BUZZ_* credentials must stay out of the execute_code child even
|
|
though they pass through to terminal children (issue #78026): the
|
|
carve-out is terminal-only.
|
|
|
|
- BUZZ_PRIVATE_KEY matches the KEY secret substring.
|
|
- BUZZ_AUTH_TAG matches the AUTH secret substring.
|
|
- BUZZ_RELAY_URL matches no secret substring but is not on the safe
|
|
prefix allowlist, so it is dropped too.
|
|
"""
|
|
from tools.code_execution_env import _scrub_child_env
|
|
|
|
buzz_vars = {
|
|
"BUZZ_PRIVATE_KEY": "nsec1fake",
|
|
"BUZZ_AUTH_TAG": '["tag","data","kind","sig"]',
|
|
"BUZZ_RELAY_URL": "https://mycommunity.communities.buzz.xyz",
|
|
"PATH": "/usr/bin",
|
|
"HOME": "/home/user",
|
|
}
|
|
child_env = _scrub_child_env(buzz_vars)
|
|
|
|
assert "BUZZ_PRIVATE_KEY" not in child_env
|
|
assert "BUZZ_AUTH_TAG" not in child_env
|
|
assert "BUZZ_RELAY_URL" not in child_env
|
|
assert child_env["PATH"] == "/usr/bin"
|
|
assert child_env["HOME"] == "/home/user"
|
|
|
|
|
|
class TestTerminalIntegration:
|
|
"""Verify that the passthrough is checked in terminal's env sanitizers."""
|
|
|
|
def test_background_terminal_uses_active_profile_for_passthrough(self, monkeypatch):
|
|
"""Background/PTY terminal children must use the routed profile value."""
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
|
|
register_env_passthrough(["SERVICE_TOKEN"])
|
|
monkeypatch.setenv("SERVICE_TOKEN", "token-for-default")
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({"SERVICE_TOKEN": "token-for-routed-profile"})
|
|
try:
|
|
child_env = _sanitize_subprocess_env(
|
|
{"SERVICE_TOKEN": "token-for-default"},
|
|
{"SERVICE_TOKEN": "token-for-default"},
|
|
)
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
ss.set_multiplex_active(False)
|
|
|
|
assert child_env["SERVICE_TOKEN"] == "token-for-routed-profile"
|
|
|
|
def test_background_terminal_omits_missing_scoped_passthrough(self, monkeypatch):
|
|
"""A missing routed secret must not leak into background terminal work."""
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
|
|
register_env_passthrough(["SERVICE_TOKEN"])
|
|
monkeypatch.setenv("SERVICE_TOKEN", "token-for-default")
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({})
|
|
try:
|
|
child_env = _sanitize_subprocess_env({"SERVICE_TOKEN": "token-for-default"})
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
ss.set_multiplex_active(False)
|
|
|
|
assert "SERVICE_TOKEN" not in child_env
|
|
|
|
def test_scope_only_declared_name_reaches_every_local_child(self, monkeypatch):
|
|
"""A routed profile's declared secret lives only in its scope (its .env never enters the
|
|
process env), so it must be added from the scope on every local spawn surface; an
|
|
undeclared scope entry stays out. No scope bound -> byte-identical single-profile env."""
|
|
from tools.code_execution_env import _scrub_child_env
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
|
|
register_env_passthrough(["SERVICE_TOKEN"])
|
|
monkeypatch.delenv("SERVICE_TOKEN", raising=False)
|
|
base = {"PATH": "/usr/bin", "HOME": "/home/user"}
|
|
ss.set_multiplex_active(True)
|
|
token = ss.set_secret_scope({"SERVICE_TOKEN": "token-for-routed-profile",
|
|
"UNDECLARED_TOKEN": "never-forwarded"})
|
|
try:
|
|
terminal_env = _sanitize_subprocess_env(dict(base))
|
|
sandbox_env = _scrub_child_env(dict(base))
|
|
finally:
|
|
ss.reset_secret_scope(token)
|
|
ss.set_multiplex_active(False)
|
|
|
|
for child_env in (terminal_env, sandbox_env):
|
|
assert child_env["SERVICE_TOKEN"] == "token-for-routed-profile"
|
|
assert "UNDECLARED_TOKEN" not in child_env
|
|
assert "SERVICE_TOKEN" not in _sanitize_subprocess_env(dict(base))
|
|
assert "SERVICE_TOKEN" not in _scrub_child_env(dict(base))
|
|
|
|
def test_scope_overlay_failure_is_loud_on_both_local_surfaces(self, monkeypatch):
|
|
"""A scope/config failure while resolving declared scope-only names must raise, not be
|
|
swallowed into a debug log that silently drops the declared secret again (#114209)."""
|
|
import tools.env_passthrough as ep
|
|
from tools.code_execution_env import _scrub_child_env
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
|
|
def _boom(_present):
|
|
raise RuntimeError("scope lookup failed")
|
|
|
|
monkeypatch.setattr(ep, "scoped_passthrough_additions", _boom)
|
|
with pytest.raises(RuntimeError, match="scope lookup failed"):
|
|
_sanitize_subprocess_env({"PATH": "/usr/bin"})
|
|
with pytest.raises(RuntimeError, match="scope lookup failed"):
|
|
_scrub_child_env({"PATH": "/usr/bin"})
|
|
|
|
def test_shared_local_snapshot_re_resolves_current_profile(self, monkeypatch, tmp_path):
|
|
"""A persistent shell snapshot must not retain the previous profile's value."""
|
|
from tools.environments.local import LocalEnvironment
|
|
|
|
register_env_passthrough(["SERVICE_TOKEN"])
|
|
monkeypatch.setenv("SERVICE_TOKEN", "token-for-default")
|
|
ss.set_multiplex_active(True)
|
|
env = None
|
|
token_b = None
|
|
token_c = None
|
|
try:
|
|
token_a = ss.set_secret_scope({"SERVICE_TOKEN": "token-for-profile-a"})
|
|
try:
|
|
env = LocalEnvironment(cwd=str(tmp_path))
|
|
assert env.execute("printf '%s' \"$SERVICE_TOKEN\"")["output"] == "token-for-profile-a"
|
|
finally:
|
|
ss.reset_secret_scope(token_a)
|
|
|
|
token_b = ss.set_secret_scope({"SERVICE_TOKEN": "token-for-profile-b"})
|
|
result = env.execute("printf '%s' \"$SERVICE_TOKEN\"")
|
|
ss.reset_secret_scope(token_b)
|
|
token_b = None
|
|
|
|
token_c = ss.set_secret_scope({})
|
|
missing = env.execute("printf '%s' \"${SERVICE_TOKEN-unset}\"")
|
|
finally:
|
|
if token_b is not None:
|
|
ss.reset_secret_scope(token_b)
|
|
if token_c is not None:
|
|
ss.reset_secret_scope(token_c)
|
|
ss.set_multiplex_active(False)
|
|
if env is not None:
|
|
env.cleanup()
|
|
|
|
assert result["output"] == "token-for-profile-b"
|
|
assert missing["output"] == "unset"
|
|
|
|
def test_blocklisted_var_blocked_by_default(self):
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
from tools.environments.local_env_policy import _HERMES_PROVIDER_ENV_BLOCKLIST
|
|
|
|
# Pick a var we know is in the blocklist
|
|
blocked_var = next(iter(_HERMES_PROVIDER_ENV_BLOCKLIST))
|
|
env = {blocked_var: "secret_value", "PATH": "/usr/bin"}
|
|
result = _sanitize_subprocess_env(env)
|
|
assert blocked_var not in result
|
|
assert "PATH" in result
|
|
|
|
def test_passthrough_cannot_override_provider_blocklist(self):
|
|
"""GHSA-rhgp-j443-p4rf: register_env_passthrough must NOT accept
|
|
Hermes provider credentials — that was the bypass where a skill
|
|
could declare ANTHROPIC_TOKEN / OPENAI_API_KEY as passthrough and
|
|
defeat the execute_code sandbox scrubbing."""
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
from tools.environments.local_env_policy import _HERMES_PROVIDER_ENV_BLOCKLIST
|
|
|
|
blocked_var = next(iter(_HERMES_PROVIDER_ENV_BLOCKLIST))
|
|
# Attempt to register — must be silently refused (logged warning).
|
|
register_env_passthrough([blocked_var])
|
|
|
|
# is_env_passthrough must NOT report it as allowed
|
|
assert not is_env_passthrough(blocked_var)
|
|
|
|
# Sanitizer still strips the var from subprocess env
|
|
env = {blocked_var: "secret_value", "PATH": "/usr/bin"}
|
|
result = _sanitize_subprocess_env(env)
|
|
assert blocked_var not in result
|
|
assert "PATH" in result
|
|
|
|
def test_passthrough_case_variant_of_blocklist_rejected(self):
|
|
"""A case-variant registration (``openai_api_key``) must be refused just
|
|
like the canonical name: the remote-exec env builder resolves each
|
|
registered name via ``os.getenv``, which is case-insensitive on Windows,
|
|
so a variant would tunnel the real ``OPENAI_API_KEY`` value into
|
|
SSH/Docker children: the same GHSA-rhgp-j443-p4rf primitive."""
|
|
for var in ("openai_api_key", "OpenAi_Api_Key", "anthropic_api_key",
|
|
"Aws_Bearer_Token_Bedrock"):
|
|
register_env_passthrough([var])
|
|
assert not is_env_passthrough(var), (
|
|
f"{var} should be refused passthrough registration")
|
|
|
|
def test_passthrough_case_variant_via_config_rejected(self, tmp_path, monkeypatch):
|
|
"""The config-based allowlist (terminal.env_passthrough) must refuse
|
|
case variants of provider credentials on the same filter."""
|
|
config = {"terminal": {"env_passthrough": ["openai_api_key", "MY_OWN_KEY"]}}
|
|
config_path = tmp_path / "config.yaml"
|
|
config_path.write_text(yaml.safe_dump(config), encoding="utf-8")
|
|
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
|
_ep_mod._config_passthrough.clear()
|
|
|
|
assert not is_env_passthrough("openai_api_key")
|
|
assert is_env_passthrough("MY_OWN_KEY")
|
|
|
|
def test_passthrough_case_variant_never_reaches_remote_exec_env(self, monkeypatch):
|
|
"""Even if a case-variant name were present in the registered set, the
|
|
remote env builder must not resolve it: on Windows ``os.getenv`` is
|
|
case-insensitive, so ``openai_api_key`` would carry the real
|
|
``OPENAI_API_KEY`` into SSH/Docker exec envs."""
|
|
from tools.environments import remote_common
|
|
|
|
register_env_passthrough(["openai_api_key"])
|
|
exec_env, _unset = remote_common.resolve_passthrough_env(set())
|
|
assert not any(k.lower() == "openai_api_key" for k in exec_env)
|
|
|
|
# Defense in depth, load-bearing on POSIX too: force the variant into
|
|
# the registered set and set a real env entry under that spelling, so
|
|
# os.getenv() resolves it and only the folded blocklist drops it.
|
|
monkeypatch.setenv("openai_api_key", "sk-variant-value")
|
|
monkeypatch.setenv("MY_OWN_KEY", "own-value")
|
|
monkeypatch.setattr(
|
|
"tools.env_passthrough.get_all_passthrough",
|
|
lambda: {"openai_api_key", "MY_OWN_KEY"})
|
|
exec_env, _unset = remote_common.resolve_passthrough_env(set())
|
|
assert "openai_api_key" not in exec_env
|
|
assert exec_env.get("MY_OWN_KEY") == "own-value"
|
|
|
|
def test_passthrough_case_variant_never_reaches_execute_code_env(self):
|
|
"""The GHSA-rhgp-j443-p4rf path end to end: the variant registration
|
|
is refused, so is_env_passthrough cannot carry the name past the
|
|
execute_code scrub."""
|
|
from tools.code_execution_env import _scrub_child_env
|
|
|
|
register_env_passthrough(["openai_api_key"])
|
|
child_env = _scrub_child_env(
|
|
{"openai_api_key": "sk-real", "PATH": "/usr/bin"},
|
|
is_passthrough=is_env_passthrough, is_windows=False)
|
|
assert "openai_api_key" not in child_env
|
|
assert child_env["PATH"] == "/usr/bin"
|
|
|
|
def test_passthrough_cannot_override_internal_dynamic_secret(self):
|
|
"""A skill must NOT be able to register dynamically-named Hermes
|
|
secrets (AUXILIARY_*_API_KEY / _BASE_URL, GATEWAY_RELAY_* auth) as
|
|
passthrough — they aren't in the static blocklist, so this is the
|
|
defense-in-depth layer that keeps env_passthrough consistent with the
|
|
unconditional strip in the sanitizers."""
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
|
|
for var in (
|
|
"AUXILIARY_VISION_API_KEY",
|
|
"AUXILIARY_VISION_BASE_URL",
|
|
"GATEWAY_RELAY_SECRET",
|
|
"GATEWAY_RELAY_DELIVERY_KEY",
|
|
):
|
|
register_env_passthrough([var])
|
|
assert not is_env_passthrough(var), (
|
|
f"{var} should be refused passthrough registration"
|
|
)
|
|
result = _sanitize_subprocess_env({var: "secret", "PATH": "/usr/bin"})
|
|
assert var not in result
|
|
assert "PATH" in result
|
|
|
|
def test_passthrough_cannot_register_buzz_vars(self, monkeypatch):
|
|
"""GHSA-rhgp-j443-p4rf seal stays intact for the BUZZ_* first-party
|
|
platform credentials: even though they pass through to terminal
|
|
children in a Buzz agent context (issue #78026), env_passthrough
|
|
registration must still refuse them — the carve-out opens NO
|
|
registration path, so a skill cannot expand BUZZ_* exposure to
|
|
execute_code."""
|
|
from tools.environments.local import _sanitize_subprocess_env
|
|
|
|
monkeypatch.setenv("BUZZ_MANAGED_AGENT", "1")
|
|
for var in (
|
|
"BUZZ_PRIVATE_KEY",
|
|
"BUZZ_AUTH_TAG",
|
|
"BUZZ_RELAY_URL",
|
|
):
|
|
register_env_passthrough([var])
|
|
assert not is_env_passthrough(var), (
|
|
f"{var} should be refused passthrough registration"
|
|
)
|
|
# Terminal sanitizer still passes BUZZ_* through to terminal
|
|
# children by the first-party carve-out...
|
|
result = _sanitize_subprocess_env({var: "value", "PATH": "/usr/bin"})
|
|
assert result.get(var) == "value"
|
|
# ...but the execute_code child never sees them.
|
|
from tools.code_execution_env import _scrub_child_env
|
|
|
|
child_env = _scrub_child_env({var: "value", "PATH": "/usr/bin"})
|
|
assert var not in child_env
|
|
|
|
def test_passthrough_allows_auxiliary_non_secret_routing(self):
|
|
"""AUXILIARY_*_PROVIDER / _MODEL and GATEWAY_RELAY routing hints are not
|
|
secrets, so a skill may still register them (they're not protected)."""
|
|
register_env_passthrough([
|
|
"AUXILIARY_VISION_PROVIDER",
|
|
"AUXILIARY_VISION_MODEL",
|
|
"GATEWAY_RELAY_URL",
|
|
])
|
|
assert is_env_passthrough("AUXILIARY_VISION_PROVIDER")
|
|
assert is_env_passthrough("AUXILIARY_VISION_MODEL")
|
|
assert is_env_passthrough("GATEWAY_RELAY_URL")
|
|
|
|
def test_make_run_env_blocklist_override_rejected(self):
|
|
"""_make_run_env must NOT expose a blocklisted var to subprocess env
|
|
even after a skill attempts to register it via passthrough."""
|
|
from tools.environments.local import _make_run_env
|
|
from tools.environments.local_env_policy import _HERMES_PROVIDER_ENV_BLOCKLIST
|
|
|
|
blocked_var = next(iter(_HERMES_PROVIDER_ENV_BLOCKLIST))
|
|
os.environ[blocked_var] = "secret_value"
|
|
try:
|
|
# Without passthrough — blocked
|
|
result_before = _make_run_env({})
|
|
assert blocked_var not in result_before
|
|
|
|
# Skill tries to register it — must be refused, so still blocked
|
|
register_env_passthrough([blocked_var])
|
|
result_after = _make_run_env({})
|
|
assert blocked_var not in result_after
|
|
finally:
|
|
os.environ.pop(blocked_var, None)
|
|
|
|
def test_non_hermes_api_key_still_registerable(self):
|
|
"""Third-party API keys (TENOR_API_KEY, NOTION_TOKEN, etc.) are NOT
|
|
Hermes provider credentials and must still pass through — skills
|
|
that legitimately wrap third-party APIs must keep working."""
|
|
# TENOR_API_KEY is a real example — used by the gif-search skill
|
|
register_env_passthrough(["TENOR_API_KEY"])
|
|
assert is_env_passthrough("TENOR_API_KEY")
|
|
|
|
# Arbitrary skill-specific var
|
|
register_env_passthrough(["MY_SKILL_CUSTOM_CONFIG"])
|
|
assert is_env_passthrough("MY_SKILL_CUSTOM_CONFIG")
|
|
|
|
def test_provider_blocklist_import_failure_fails_closed(self, monkeypatch):
|
|
"""If the dynamic provider blocklist can't be imported, provider
|
|
credentials must be treated as protected and refused passthrough —
|
|
otherwise a skill could tunnel a Hermes credential into the
|
|
execute_code child (regression for #37950 / GHSA-rhgp-j443-p4rf).
|
|
|
|
Verifies the full path: _is_hermes_provider_credential returns True,
|
|
register_env_passthrough refuses the var, and _scrub_child_env keeps
|
|
it out of the child env. A non-Hermes key is also rejected here (the
|
|
fallback is conservative: when we can't tell, we fail closed), which
|
|
is the safe direction.
|
|
"""
|
|
import builtins
|
|
|
|
from tools.code_execution_env import _scrub_child_env
|
|
|
|
real_import = builtins.__import__
|
|
|
|
def fail_local_import(name, *args, **kwargs):
|
|
if name == "tools.environments.local":
|
|
raise ImportError("synthetic blocklist import failure")
|
|
return real_import(name, *args, **kwargs)
|
|
|
|
monkeypatch.setattr(builtins, "__import__", fail_local_import)
|
|
|
|
# Every name is now treated as a protected provider credential.
|
|
assert _ep_mod._is_hermes_provider_credential("OPENAI_API_KEY")
|
|
assert _ep_mod._is_hermes_provider_credential("ANTHROPIC_API_KEY")
|
|
assert _ep_mod._is_hermes_provider_credential("GH_TOKEN")
|
|
|
|
# Registration is refused while the blocklist is unavailable.
|
|
register_env_passthrough(["OPENAI_API_KEY", "ANTHROPIC_API_KEY"])
|
|
assert not is_env_passthrough("OPENAI_API_KEY")
|
|
assert not is_env_passthrough("ANTHROPIC_API_KEY")
|
|
|
|
# And the credential never reaches the execute_code child.
|
|
child_env = _scrub_child_env(
|
|
{
|
|
"OPENAI_API_KEY": "synthetic-secret",
|
|
"ANTHROPIC_API_KEY": "synthetic-secret",
|
|
"PATH": "/usr/bin",
|
|
},
|
|
is_passthrough=is_env_passthrough,
|
|
is_windows=False,
|
|
)
|
|
assert "OPENAI_API_KEY" not in child_env
|
|
assert "ANTHROPIC_API_KEY" not in child_env
|
|
assert child_env["PATH"] == "/usr/bin"
|