test: pin DISABLE_AUTOUPDATER in hermetic env and capture corrupt-seed warning

Both EVALS_HERMETIC branches of buildHermeticEnv now carry
DISABLE_AUTOUPDATER=1 (the allowlist scrubbed the workflow's copy, so every
PTY screen showed the updater's npm-prefix failure). Per-test overrides
still win. The corrupt durations-seed test now captures its expected
warning and restores the console spy.
This commit is contained in:
garrytan committed 2026-09-29 14:22:05 +00:00
1 parent dcaea52800
commit 049fdc315b
4 files changed
+33 -8

No files matched your search

+12 -1
View File
@@ -17,7 +17,7 @@ import { describe, test, expect } from 'bun:test';
import * as fs from 'fs';
import * as path from 'path';
import * as os from 'os';
import { getHermeticDirs, hermeticSkillsConfigDir } from './helpers/hermetic-env';
import { buildHermeticEnv, getHermeticDirs, hermeticSkillsConfigDir } from './helpers/hermetic-env';
const ROOT = path.resolve(import.meta.path, '..', '..');
@@ -87,6 +87,17 @@ describe('hermetic wiring tripwire', () => {
}
});
test('both EVALS_HERMETIC branches pin DISABLE_AUTOUPDATER=1 over the workflow env', () => {
// The allowlist scrubs the workflow's own copy; without this pin every PTY
// screen carries "Auto-update failed: no write permission to npm prefix".
for (const EVALS_HERMETIC of ['1', '0']) {
const base = { PATH: '/usr/bin', EVALS_HERMETIC, DISABLE_AUTOUPDATER: '0' };
expect(buildHermeticEnv(base, {}).DISABLE_AUTOUPDATER, `EVALS_HERMETIC=${EVALS_HERMETIC}`).toBe('1');
expect(buildHermeticEnv(base, {}, { DISABLE_AUTOUPDATER: '0' }).DISABLE_AUTOUPDATER, 'per-test override stays last').toBe('0');
}
expect(read('test/helpers/hermetic-env.ts')).toContain('DISABLE_AUTOUPDATER=1 (pinned in both branches');
});
test('claude runners gate --strict-mcp-config on isHermeticEnabled()', () => {
// Zero MCP servers for hermetic children; EVALS_HERMETIC=0 must restore
// operator MCP along with the operator env (the flag may not be