test: make the containment-token regressions hold on Windows and under a live container

Windows folds environment keys to upper case, so the regression token is spelled upper; the audit spawn allowlist admits the inherited OURO_PROC_CONTAINER_* keys and nothing else; the encoding regression covers PYTHONIOENCODING on the commit-gate env too.
This commit is contained in:
Ouroboros 2026-09-24 14:22:30 +03:00
parent 77ce2c6f02
commit 9b87e1bfb4
2 changed files with 9 additions and 5 deletions

View file

@ -196,7 +196,7 @@ def test_the_audit_child_inherits_the_containment_token(tmp_path, monkeypatch):
from ouroboros.process_containment import CONTAINMENT_ENV_PREFIX
(tmp_path / "logs").mkdir(parents=True, exist_ok=True)
monkeypatch.setenv(CONTAINMENT_ENV_PREFIX + "deadbeef", "1")
monkeypatch.setenv(CONTAINMENT_ENV_PREFIX + "DEADBEEF", "1") # upper: Windows folds env keys
monkeypatch.setenv("OUROBOROS_UNRELATED_SECRET", "no")
seen: list = []
_patch_spawn(monkeypatch, _FakeChild(), seen=seen)
@ -206,7 +206,7 @@ def test_the_audit_child_inherits_the_containment_token(tmp_path, monkeypatch):
_await_terminal(tmp_path, timeout=10)
assert len(seen) == 1
env = seen[0][1]["env"]
assert env[CONTAINMENT_ENV_PREFIX + "deadbeef"] == "1"
assert env[CONTAINMENT_ENV_PREFIX + "DEADBEEF"] == "1"
assert "OUROBOROS_UNRELATED_SECRET" not in env # the allowlist still holds
@ -307,8 +307,11 @@ def test_the_child_gets_a_dedicated_process_group(tmp_path, monkeypatch):
assert kwargs["purpose"] == "startup_historical_audit"
assert kwargs["scope"] == "session"
assert cmd[1:3] == ["-m", "ouroboros.startup_historical_audit"]
# Only ordinary runtime environment and explicit roots reach the child.
assert set(kwargs["env"]) <= {
# Only ordinary runtime environment, explicit roots and the inherited
# containment token reach the child.
from ouroboros.process_containment import CONTAINMENT_ENV_PREFIX
assert {key for key in kwargs["env"] if not key.startswith(CONTAINMENT_ENV_PREFIX)} <= {
"PATH", "HOME", "USERPROFILE", "SystemRoot", "WINDIR", "TEMP", "TMP", "TMPDIR",
"LANG", "LC_ALL", "PYTHONDONTWRITEBYTECODE", "PYTHONPATH",
"OUROBOROS_DATA_DIR", "OUROBOROS_REPO_DIR", "OUROBOROS_SETTINGS_PATH",

View file

@ -30,7 +30,8 @@ def test_isolation_keeps_the_platform_default_text_encoding(tmp_path):
catches; isolation is about roots, never about the interpreter's encoding."""
env = isolated_environment(tmp_path, REPO, source={})
assert "PYTHONUTF8" not in env and "PYTHONIOENCODING" not in env
assert "PYTHONUTF8" not in _preflight_env(tmp_path / "data", tmp_path / "repo")
gate = _preflight_env(tmp_path / "data", tmp_path / "repo")
assert "PYTHONUTF8" not in gate and "PYTHONIOENCODING" not in gate
def test_chromium_download_staging_uses_disposable_temp(tmp_path):