d73ff9b0fb
Deploy Site / deploy-vercel (push) Has been cancelled
Deploy Site / deploy-docs (push) Has been cancelled
Docker / shell lint / Lint Dockerfile (hadolint) (push) Has been cancelled
Docker / shell lint / Lint docker/ shell scripts (shellcheck) (push) Has been cancelled
Docker Build and Publish / build-amd64 (push) Has been cancelled
Docker Build and Publish / build-arm64 (push) Has been cancelled
Lint (ruff + ty) / ruff + ty diff (push) Has been cancelled
Lint (ruff + ty) / ruff enforcement (blocking) (push) Has been cancelled
Lint (ruff + ty) / Windows footguns (blocking) (push) Has been cancelled
Nix Lockfile Fix / auto-fix-main (push) Has been cancelled
Nix Lockfile Fix / fix (push) Has been cancelled
Nix / nix (macos-latest) (push) Has been cancelled
Nix / nix (ubuntu-latest) (push) Has been cancelled
OSV-Scanner / Scan lockfiles (push) Has been cancelled
Build Skills Index / build-index (push) Has been cancelled
Tests / test (1) (push) Has been cancelled
Tests / test (2) (push) Has been cancelled
Tests / test (3) (push) Has been cancelled
Tests / test (4) (push) Has been cancelled
Tests / test (5) (push) Has been cancelled
Tests / test (6) (push) Has been cancelled
Tests / e2e (push) Has been cancelled
uv.lock check / uv lock --check (push) Has been cancelled
Docker Build and Publish / merge (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
Tests / save-durations (push) Has been cancelled
31 lines
1.1 KiB
Python
31 lines
1.1 KiB
Python
"""Regression tests for install.sh Python environment sanitization.
|
|
|
|
When install.sh is launched from another Python-driven tool session, inherited
|
|
PYTHONPATH/PYTHONHOME can shadow the freshly installed checkout. The installer
|
|
must sanitize those vars both during installation and at runtime launch.
|
|
"""
|
|
|
|
from pathlib import Path
|
|
|
|
|
|
REPO_ROOT = Path(__file__).resolve().parent.parent
|
|
INSTALL_SH = REPO_ROOT / "scripts" / "install.sh"
|
|
|
|
|
|
def test_install_script_unsets_pythonpath_and_pythonhome_early() -> None:
|
|
text = INSTALL_SH.read_text()
|
|
|
|
# During install, inherited Python env must be sanitized before pip/venv use.
|
|
assert 'unset PYTHONPATH' in text
|
|
assert 'unset PYTHONHOME' in text
|
|
|
|
|
|
def test_hermes_launcher_wrapper_clears_python_env_before_exec() -> None:
|
|
text = INSTALL_SH.read_text()
|
|
|
|
# Wrapper should clear env and forward args untouched to the venv entrypoint.
|
|
assert 'cat > "$command_link_dir/hermes" <<EOF' in text
|
|
assert 'unset PYTHONPATH' in text
|
|
assert 'unset PYTHONHOME' in text
|
|
assert 'exec "$HERMES_BIN" "\\$@"' in text
|