diff --git a/contributors/emails/support@captureclient.net b/contributors/emails/support@captureclient.net new file mode 100644 index 00000000000..af578fe6f75 --- /dev/null +++ b/contributors/emails/support@captureclient.net @@ -0,0 +1,2 @@ +eazye19 +# PR #43299 salvage diff --git a/tests/test_zz_guard_probe_tmp.py b/tests/test_zz_guard_probe_tmp.py new file mode 100644 index 00000000000..63ed7d553e5 --- /dev/null +++ b/tests/test_zz_guard_probe_tmp.py @@ -0,0 +1,34 @@ +"""Ad-hoc verification: gateway-kill-shaped commands must still be blocked.""" +import subprocess + +import pytest + + +@pytest.mark.parametrize( + "cmd", + [ + ["pkill", "-f", "hermes-gateway"], + ["killall", "hermes-gateway"], + ["bash", "-c", "pkill -f hermes-gateway"], + ["env", "X=1", "pkill", "-f", "hermes-gateway"], + ["sudo", "pkill", "-f", "hermes-gateway"], + ["nohup", "pkill", "-f", "hermes-gateway"], + "pkill -f hermes-gateway", + ], +) +def test_gateway_kill_still_blocked(cmd): + with pytest.raises(RuntimeError, match="live-system guard"): + subprocess.run(cmd) + + +def test_innocent_argv_not_blocked(tmp_path): + p = tmp_path / "skill" + p.write_text("hello") + r = subprocess.run(["cat", str(p)], capture_output=True, text=True) + assert r.stdout == "hello" + + +@pytest.mark.parametrize("cmd", ["pkill -f hermes-gateway", "bash -c \"pkill -f hermes-gateway\""]) +def test_gateway_kill_shell_true_blocked(cmd): + with pytest.raises(RuntimeError, match="live-system guard"): + subprocess.run(cmd, shell=True)