fix(update): widen UV-env isolation to the sibling dependency-sync sites

The salvaged fix covered the git-path sync; the same raw-os.environ
construction existed at the main update path and the interrupted-install
recovery path. All three now build their uv env via managed_python_env()
(#83914 class — same bug, all sites).

A/B-proven with real uv: poisoned UV_PYTHON/UV_SYSTEM_PYTHON steers the
merge-base construction into the hijacker's interpreter (VERDICT:
HIJACKED); the managed construction installs into the install's venv
(VERDICT: ISOLATED). Compose-checked with #92824's stale-VIRTUAL_ENV pin:
isolation + pin together install into the running interpreter on the
site-packages shape.
This commit is contained in:
Teknium
2026-08-23 02:49:40 -07:00
parent 6ce145f38f
commit fbfdb9312b
+13 -2
View File
@@ -1665,7 +1665,13 @@ def _update_via_zip(args, *, had_desktop_app_before_update: bool = False) -> boo
if not uv_bin:
uv_bin = _ensure_uv_for_termux(pip_cmd)
if uv_bin:
uv_env = {**os.environ, "VIRTUAL_ENV": str(_m().PROJECT_ROOT / "venv")}
# Same third-party UV-env isolation as the main update path (#83914):
# a user-level UV_PYTHON_INSTALL_DIR / UV_PYTHON from unrelated
# software must not steer which interpreter uv resolves here.
from hermes_cli.managed_uv import managed_python_env
uv_env = managed_python_env()
uv_env["VIRTUAL_ENV"] = str(_m().PROJECT_ROOT / "venv")
if _m()._is_termux_env(uv_env):
uv_env.pop("PYTHONPATH", None)
uv_env.pop("PYTHONHOME", None)
@@ -6300,7 +6306,12 @@ def _cmd_update_impl(args, gateway_mode: bool):
check=False,
)
if repair_uv:
repair_env = {**os.environ, "VIRTUAL_ENV": str(_m().PROJECT_ROOT / "venv")}
# Isolated from third-party UV env vars (#83914), same as
# the main-path and git-path dependency syncs.
from hermes_cli.managed_uv import managed_python_env
repair_env = managed_python_env()
repair_env["VIRTUAL_ENV"] = str(_m().PROJECT_ROOT / "venv")
_m()._install_python_dependencies_with_optional_fallback(
[repair_uv, "pip"], env=repair_env, group="all"
)