90e916efc9
Salvage hardening on top of the three cherry-picked contributor commits (#91297 gebilaowang404 + AlexMnrs, #96741 burak33bb, #98826 ayushnangia), closing the remaining unverified-PID kill sites as one class (#98814, #89614): - pid_is_hermes: token-boundary 'hermes' match (no more loose substring false-positives), and an explicit start-time expectation is now honored on POSIX too (a mismatched fingerprint is a recycled PID on any platform). - kill_process_tree: drop the guard on our OWN retained Popen child — a retained handle pins the PID, so the check could only false-refuse. - gateway.status.terminate_pid: POSIX force-kills also refuse when a caller-provided expected_start_time no longer matches. - kill_gateway_processes: re-verify the LIVE cmdline at kill time (the scan-time match is a TOCTOU window). - _reap_unsupervised_gateway_orphans: fingerprint orphans at scan time and require a still-matching identity before the delayed SIGKILL escalation. - whatsapp _kill_port_process: never kill a bare netstat/lsof-scanned PID unless the live process is actually a node bridge (was a stranger-kill). - browser daemon reap/close paths: pass the start-time fingerprint into ProcessRegistry._terminate_host_pid (previously unverified), and the session-close path now runs the same daemon identity verification as the orphan reaper. - tests/hermes_cli/test_taskkill_identity_windows_live.py: live Windows probes (real spawned processes, real psutil ancestry) wired into the on-demand windows-latest wine2e lane. Fixes #98814 Fixes #89614
63 lines
1.9 KiB
YAML
63 lines
1.9 KiB
YAML
name: Windows venv-holder live E2E
|
|
|
|
# ON-DEMAND ONLY (fleet-update #91277, venv-holder consolidation work).
|
|
#
|
|
# Runs the live venv-holder E2E suite on a real windows-latest runner:
|
|
# spawns actual processes with realistic Hermes argv shapes and drives the
|
|
# REAL detection/classification/exemption code against the live process
|
|
# table — the coverage that cannot exist on the Linux lanes and that the
|
|
# maintainer cannot exercise locally before the work reaches main.
|
|
#
|
|
# Deliberately NOT wired to pull_request/main: it fires only on pushes to
|
|
# wine2e/** working branches, so it costs nothing on normal PRs. Delete or
|
|
# keep dormant after the venv-holder work lands.
|
|
|
|
on:
|
|
push:
|
|
branches:
|
|
- "wine2e/**"
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: windows-venv-e2e-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
venv-holder-e2e:
|
|
name: venv-holder live E2E (windows-latest)
|
|
runs-on: windows-latest
|
|
timeout-minutes: 25
|
|
steps:
|
|
- name: Checkout code
|
|
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Install uv
|
|
uses: astral-sh/setup-uv@fac544c07dec837d0ccb6301d7b5580bf5edae39 # 8.2.0
|
|
with:
|
|
version: "0.9.28"
|
|
enable-cache: true
|
|
cache-dependency-glob: |
|
|
pyproject.toml
|
|
uv.lock
|
|
|
|
- name: Set up Python 3.11
|
|
uses: ./.github/actions/retry
|
|
with:
|
|
command: uv python install 3.11
|
|
|
|
- name: Install dependencies
|
|
uses: ./.github/actions/retry
|
|
with:
|
|
command: uv sync --locked --python 3.11 --extra dev
|
|
|
|
- name: Run venv-holder live E2E
|
|
shell: bash
|
|
run: |
|
|
set -uo pipefail
|
|
uv run --no-sync python -m pytest \
|
|
tests/hermes_cli/test_venv_holder_windows_live.py \
|
|
tests/hermes_cli/test_taskkill_identity_windows_live.py \
|
|
-o addopts= -v -p no:cacheprovider
|