From 9b87e1bfb40a6009ae098debf6ebb026a73d170b Mon Sep 17 00:00:00 2001 From: Ouroboros <311266734+ouroboros-agent@users.noreply.github.com> Date: Thu, 24 Sep 2026 14:22:30 +0300 Subject: [PATCH] test: make the containment-token regressions hold on Windows and under a live container Windows folds environment keys to upper case, so the regression token is spelled upper; the audit spawn allowlist admits the inherited OURO_PROC_CONTAINER_* keys and nothing else; the encoding regression covers PYTHONIOENCODING on the commit-gate env too. --- tests/test_startup_historical_audit_lifecycle.py | 11 +++++++---- tests/test_test_environment.py | 3 ++- 2 files changed, 9 insertions(+), 5 deletions(-) diff --git a/tests/test_startup_historical_audit_lifecycle.py b/tests/test_startup_historical_audit_lifecycle.py index 845118fe3..0e05ac0d2 100644 --- a/tests/test_startup_historical_audit_lifecycle.py +++ b/tests/test_startup_historical_audit_lifecycle.py @@ -196,7 +196,7 @@ def test_the_audit_child_inherits_the_containment_token(tmp_path, monkeypatch): from ouroboros.process_containment import CONTAINMENT_ENV_PREFIX (tmp_path / "logs").mkdir(parents=True, exist_ok=True) - monkeypatch.setenv(CONTAINMENT_ENV_PREFIX + "deadbeef", "1") + monkeypatch.setenv(CONTAINMENT_ENV_PREFIX + "DEADBEEF", "1") # upper: Windows folds env keys monkeypatch.setenv("OUROBOROS_UNRELATED_SECRET", "no") seen: list = [] _patch_spawn(monkeypatch, _FakeChild(), seen=seen) @@ -206,7 +206,7 @@ def test_the_audit_child_inherits_the_containment_token(tmp_path, monkeypatch): _await_terminal(tmp_path, timeout=10) assert len(seen) == 1 env = seen[0][1]["env"] - assert env[CONTAINMENT_ENV_PREFIX + "deadbeef"] == "1" + assert env[CONTAINMENT_ENV_PREFIX + "DEADBEEF"] == "1" assert "OUROBOROS_UNRELATED_SECRET" not in env # the allowlist still holds @@ -307,8 +307,11 @@ def test_the_child_gets_a_dedicated_process_group(tmp_path, monkeypatch): assert kwargs["purpose"] == "startup_historical_audit" assert kwargs["scope"] == "session" assert cmd[1:3] == ["-m", "ouroboros.startup_historical_audit"] - # Only ordinary runtime environment and explicit roots reach the child. - assert set(kwargs["env"]) <= { + # Only ordinary runtime environment, explicit roots and the inherited + # containment token reach the child. + from ouroboros.process_containment import CONTAINMENT_ENV_PREFIX + + assert {key for key in kwargs["env"] if not key.startswith(CONTAINMENT_ENV_PREFIX)} <= { "PATH", "HOME", "USERPROFILE", "SystemRoot", "WINDIR", "TEMP", "TMP", "TMPDIR", "LANG", "LC_ALL", "PYTHONDONTWRITEBYTECODE", "PYTHONPATH", "OUROBOROS_DATA_DIR", "OUROBOROS_REPO_DIR", "OUROBOROS_SETTINGS_PATH", diff --git a/tests/test_test_environment.py b/tests/test_test_environment.py index 2264b9a9e..f8d84054b 100644 --- a/tests/test_test_environment.py +++ b/tests/test_test_environment.py @@ -30,7 +30,8 @@ def test_isolation_keeps_the_platform_default_text_encoding(tmp_path): catches; isolation is about roots, never about the interpreter's encoding.""" env = isolated_environment(tmp_path, REPO, source={}) assert "PYTHONUTF8" not in env and "PYTHONIOENCODING" not in env - assert "PYTHONUTF8" not in _preflight_env(tmp_path / "data", tmp_path / "repo") + gate = _preflight_env(tmp_path / "data", tmp_path / "repo") + assert "PYTHONUTF8" not in gate and "PYTHONIOENCODING" not in gate def test_chromium_download_staging_uses_disposable_temp(tmp_path):