fix(containment): reject resume overrides

Reject containment flags on resumed runs instead of silently discarding them.

DOPS-1172

👽 Directed by Chrispy <chris@akuru.com.au>
Authored by LLM gpt-5.6-sol -- Ranger
This commit is contained in:
👽 Chrispy 2026-09-03 09:59:10 +10:00
parent a1fdb98960
commit 8594b7d0fc
No known key found for this signature in database
2 changed files with 28 additions and 0 deletions

View file

@ -376,6 +376,12 @@ Examples:
"--resume picks up where the prior run left off, including the "
"original target list."
)
if args.workspace_mount or args.read_only_local_targets:
parser.error(
"Cannot combine --resume with --workspace-mount or "
"--read-only-local-targets. Resume restores the original "
"containment configuration."
)
_load_resume_state(args, parser)
agents_path = runtime_state_dir(run_dir_for(args.resume)) / "agents.json"
if not agents_path.exists():

View file

@ -86,6 +86,28 @@ def test_parse_arguments_rejects_resume_with_target_list(
assert "Cannot combine --resume with --target/--target-list" in capsys.readouterr().err
@pytest.mark.parametrize("flag", ["workspace", "read_only"])
def test_parse_arguments_rejects_resume_with_containment_overrides(
tmp_path: Path,
monkeypatch: pytest.MonkeyPatch,
capsys: pytest.CaptureFixture[str],
flag: str,
) -> None:
argv = ["strix", "--resume", "old-run"]
if flag == "workspace":
workspace = tmp_path / "remediation"
workspace.mkdir()
argv.extend(["--workspace-mount", str(workspace)])
else:
argv.append("--read-only-local-targets")
monkeypatch.setattr(sys, "argv", argv)
with pytest.raises(SystemExit):
cli_main.parse_arguments()
assert "Resume restores the original containment configuration" in capsys.readouterr().err
def _write_run_record(runs_dir: Path, run_name: str, record: dict[str, Any]) -> None:
"""Write a resumable run: its record plus the agent snapshot resume needs."""
run_dir = runs_dir / run_name