fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide
AST-driven pass over every subprocess.run/Popen/check_output/check_call/call with text=True (or universal_newlines=True) and no explicit encoding=: append encoding='utf-8', errors='replace' at the kwarg site. 136 call sites across 28 files (cli.py, hermes_cli/main.py, tools_config.py, environments, computer_use, gateway, scripts, skills helpers, agent/*). Together with the salvaged #55339/#60741 commits this closes out issue #53428's bug class; the salvaged #60751 linter rule in check-windows-footguns.py now enforces it repo-wide (verified: 807 files scanned, zero findings).
This commit is contained in:
@@ -706,7 +706,7 @@ def iron_proxy_version(binary: Path) -> str:
|
||||
res = subprocess.run( # noqa: S603
|
||||
[str(binary), "--version"],
|
||||
capture_output=True,
|
||||
text=True,
|
||||
text=True, encoding="utf-8", errors="replace",
|
||||
timeout=_RUN_TIMEOUT,
|
||||
env=minimal_env,
|
||||
)
|
||||
@@ -1052,7 +1052,7 @@ def _detect_docker_bridge_ip() -> Optional[str]:
|
||||
try:
|
||||
res = subprocess.run( # noqa: S603 — ip is a system binary
|
||||
["ip", "-4", "-o", "addr", "show", "docker0"],
|
||||
capture_output=True, text=True, timeout=2,
|
||||
capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=2,
|
||||
)
|
||||
if res.returncode == 0:
|
||||
for line in res.stdout.splitlines():
|
||||
@@ -1743,7 +1743,7 @@ def _pid_alive(pid: int) -> bool:
|
||||
try:
|
||||
res = subprocess.run( # noqa: S603
|
||||
["ps", "-p", str(pid), "-o", "comm="],
|
||||
capture_output=True, text=True, timeout=2,
|
||||
capture_output=True, text=True, encoding="utf-8", errors="replace", timeout=2,
|
||||
)
|
||||
if res.returncode == 0:
|
||||
comm = (res.stdout or "").strip()
|
||||
|
||||
Reference in New Issue
Block a user