fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide

AST-driven pass over every subprocess.run/Popen/check_output/check_call/call
with text=True (or universal_newlines=True) and no explicit encoding=:
append encoding='utf-8', errors='replace' at the kwarg site. 136 call
sites across 28 files (cli.py, hermes_cli/main.py, tools_config.py,
environments, computer_use, gateway, scripts, skills helpers, agent/*).

Together with the salvaged #55339/#60741 commits this closes out issue
#53428's bug class; the salvaged #60751 linter rule in
check-windows-footguns.py now enforces it repo-wide (verified: 807 files
scanned, zero findings).
This commit is contained in:
teknium1
2026-07-24 10:05:18 -07:00
committed by Teknium
parent 051217342b
commit d4b867cf9f
28 changed files with 138 additions and 136 deletions
+3 -3
View File
@@ -706,7 +706,7 @@ def iron_proxy_version(binary: Path) -> str:
res = subprocess.run( # noqa: S603
[str(binary), "--version"],
capture_output=True,
text=True,
text=True, encoding="utf-8", errors="replace",
timeout=_RUN_TIMEOUT,
env=minimal_env,
)
@@ -1052,7 +1052,7 @@ def _detect_docker_bridge_ip() -> Optional[str]:
try:
res = subprocess.run( # noqa: S603 — ip is a system binary
["ip", "-4", "-o", "addr", "show", "docker0"],
capture_output=True, text=True, timeout=2,
capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=2,
)
if res.returncode == 0:
for line in res.stdout.splitlines():
@@ -1743,7 +1743,7 @@ def _pid_alive(pid: int) -> bool:
try:
res = subprocess.run( # noqa: S603
["ps", "-p", str(pid), "-o", "comm="],
capture_output=True, text=True, timeout=2,
capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=2,
)
if res.returncode == 0:
comm = (res.stdout or "").strip()