fix(tests): live-system guard treats only argv[0] as the executable

Argv-list commands now scan only argv[0] against _PROCESS_KILLERS, ending
false positives like ['cat', '.../skill'] ('skill' is a real util-linux
binary name). Wrapper executables (sh/bash/env/nohup/timeout/sudo/xargs/…)
keep full-token scanning so ['bash', '-c', 'pkill …'] and
['env', …, 'pkill', …] stay blocked; string commands are unchanged.
Adds tests/test_live_system_guard.py pinning both directions.

Salvaged from PR #43299 by @eazye19.

Co-authored-by: Tony (eazye19) <support@captureclient.net>
This commit is contained in:
Tony (eazye19) 2026-07-29 20:14:29 -07:00 committed by Teknium
parent 00cd9b2b3a
commit 7216ca19a6
2 changed files with 36 additions and 0 deletions

View file

@ -0,0 +1,2 @@
eazye19
# PR #43299 salvage

View file

@ -0,0 +1,34 @@
"""Ad-hoc verification: gateway-kill-shaped commands must still be blocked."""
import subprocess
import pytest
@pytest.mark.parametrize(
"cmd",
[
["pkill", "-f", "hermes-gateway"],
["killall", "hermes-gateway"],
["bash", "-c", "pkill -f hermes-gateway"],
["env", "X=1", "pkill", "-f", "hermes-gateway"],
["sudo", "pkill", "-f", "hermes-gateway"],
["nohup", "pkill", "-f", "hermes-gateway"],
"pkill -f hermes-gateway",
],
)
def test_gateway_kill_still_blocked(cmd):
with pytest.raises(RuntimeError, match="live-system guard"):
subprocess.run(cmd)
def test_innocent_argv_not_blocked(tmp_path):
p = tmp_path / "skill"
p.write_text("hello")
r = subprocess.run(["cat", str(p)], capture_output=True, text=True)
assert r.stdout == "hello"
@pytest.mark.parametrize("cmd", ["pkill -f hermes-gateway", "bash -c \"pkill -f hermes-gateway\""])
def test_gateway_kill_shell_true_blocked(cmd):
with pytest.raises(RuntimeError, match="live-system guard"):
subprocess.run(cmd, shell=True)