chore(runtime): close Wave 3 review nits

This commit is contained in:
Alexandre Teixeira
2026-10-02 23:23:40 +01:00
parent aefdd35d9b
commit 6f2ae056c0
5 changed files with 51 additions and 15 deletions
-4
View File
@@ -404,10 +404,6 @@ def get(job_id: str, *, expected) -> Optional[Dict[str, Any]]:
return rec
def list_for_session(session_id: str) -> List[Dict[str, Any]]:
return [r for r in _load().values() if r.get("session_id") == session_id]
@store_transaction(lambda: _STORE)
def kill(job_id: str, *, expected) -> Optional[Dict[str, Any]]:
"""Terminate a running job's process tree and mark it killed. Returns the
+2
View File
@@ -30,6 +30,8 @@ from src.process_lifecycle import ProcessIdentity, observe
from src.constants import BROWSER_RESOURCES_DIR
PRODUCER_VERSION = "0.35.0"
# Wave 3 session metadata supports only these observed glibc Linux artifacts.
# macOS/Windows and other architectures fail closed before any producer call.
PRODUCER_HASHES = {
"linux-x64": "b7a28c3a43a7008dd02585e2e60c391c08983f7a099149caed63c9f13f57b752",
"linux-arm64": "92cd7d0897837ac648b9a6ab1965c69c5920e0f54df57e4295cdb1143b0541c8",
+1 -11
View File
@@ -1246,8 +1246,6 @@ def _split_bg_marker(content: str):
return False, content
import re as _re
# Variables a legitimate agent bash/python subprocess needs from the host.
# Anything not listed here is never inherited.
_SAFE_SUBPROCESS_VARS = frozenset({
@@ -1267,19 +1265,11 @@ _SAFE_SUBPROCESS_VARS = frozenset({
"LD_LIBRARY_PATH",
})
# Defence-in-depth: reject any allowlisted variable whose *name* matches
# a credential-bearing pattern (e.g. a user who sets PATH_TOKEN=...).
_SENSITIVE_PATTERN = _re.compile(
r"(?:KEY|TOKEN|SECRET|PASSW|AUTH|CREDENTIAL|PRIVATE|DATABASE_URL)",
_re.IGNORECASE,
)
def _agent_subprocess_env() -> dict:
base = {
key: os.environ[key]
for key in _SAFE_SUBPROCESS_VARS
if key in os.environ and not _SENSITIVE_PATTERN.search(key)
if key in os.environ
}
base.setdefault("PATH", os.environ.get("PATH") or os.defpath or "/usr/local/bin:/usr/bin:/bin")
base.setdefault("LANG", "C.UTF-8")