From 1f7e81ac553d6427b6513fb21477a596b2042da6 Mon Sep 17 00:00:00 2001 From: Ed_ Date: Fri, 19 Jun 2026 08:14:34 -0400 Subject: [PATCH] fix(sandbox): audit --tests-dir bypass EXCLUDE_DIRS; probe path in regression test --- scripts/audit_test_sandbox_violations.py | 7 ++++--- tests/test_test_sandbox.py | 22 ++++++++++------------ 2 files changed, 14 insertions(+), 15 deletions(-) diff --git a/scripts/audit_test_sandbox_violations.py b/scripts/audit_test_sandbox_violations.py index a5641d97..aa66b099 100644 --- a/scripts/audit_test_sandbox_violations.py +++ b/scripts/audit_test_sandbox_violations.py @@ -48,10 +48,10 @@ PATTERNS = [ EXCLUDE_DIRS = {"artifacts", "logs", "__pycache__", "snapshots"} -def find_violations(tests_dir: Path) -> list[tuple[Path, int, str]]: +def find_violations(tests_dir: Path, apply_excludes: bool = True) -> list[tuple[Path, int, str]]: violations: list[tuple[Path, int, str]] = [] for test_file in tests_dir.rglob("test_*.py"): - if any(excluded in test_file.parts for excluded in EXCLUDE_DIRS): + if apply_excludes and any(excluded in test_file.parts for excluded in EXCLUDE_DIRS): continue try: content = test_file.read_text(encoding="utf-8") @@ -80,7 +80,8 @@ def main() -> int: if not tests_dir.exists(): print(f"Tests dir not found: {tests_dir}", file=sys.stderr) return 1 - violations = find_violations(tests_dir) + apply_excludes = (Path(args.tests_dir).resolve() == repo_root / "tests") + violations = find_violations(tests_dir, apply_excludes=apply_excludes) if args.json: payload = { diff --git a/tests/test_test_sandbox.py b/tests/test_test_sandbox.py index c5833028..c3442bfa 100644 --- a/tests/test_test_sandbox.py +++ b/tests/test_test_sandbox.py @@ -93,21 +93,19 @@ def test_audit_subprocess_bad_dir_exits_one() -> None: def test_sandbox_blocks_writes_outside_tests_dir() -> None: - """A write to /manual_slop.toml raises TEST_SANDBOX_VIOLATION.""" - bad_path = Path(__file__).resolve().parent.parent / "manual_slop.toml" - if bad_path.exists(): - original = bad_path.read_bytes() - existed = True - else: - existed = False - original = b"" + """A write to /manual_slop.toml raises TEST_SANDBOX_VIOLATION. + Per Python's sys.addaudithook contract, raising RuntimeError in the hook + aborts the open() call (the file is NOT created/truncated). + [C: tests/conftest.py:_sandbox_audit_hook]""" + bad_path = Path(__file__).resolve().parent.parent / "_test_sandbox_probe.txt" try: - with pytest.raises(RuntimeError, match="TEST_SANDBOX_VIOLATION"): + with pytest.raises(RuntimeError, match="TEST_SANDBOX"): bad_path.write_text("corrupt", encoding="utf-8") + assert not bad_path.exists(), ( + f"TEST_SANDBOX_VIOLATION: file {bad_path} should NOT have been created" + ) finally: - if existed: - bad_path.write_bytes(original) - elif bad_path.exists(): + if bad_path.exists(): bad_path.unlink()