diff --git a/strix/interface/cli_args.py b/strix/interface/cli_args.py index b0bffec2..b10fd8d3 100644 --- a/strix/interface/cli_args.py +++ b/strix/interface/cli_args.py @@ -376,6 +376,12 @@ Examples: "--resume picks up where the prior run left off, including the " "original target list." ) + if args.workspace_mount or args.read_only_local_targets: + parser.error( + "Cannot combine --resume with --workspace-mount or " + "--read-only-local-targets. Resume restores the original " + "containment configuration." + ) _load_resume_state(args, parser) agents_path = runtime_state_dir(run_dir_for(args.resume)) / "agents.json" if not agents_path.exists(): diff --git a/tests/test_cli_target_list.py b/tests/test_cli_target_list.py index 9c93ea17..e713df18 100644 --- a/tests/test_cli_target_list.py +++ b/tests/test_cli_target_list.py @@ -86,6 +86,28 @@ def test_parse_arguments_rejects_resume_with_target_list( assert "Cannot combine --resume with --target/--target-list" in capsys.readouterr().err +@pytest.mark.parametrize("flag", ["workspace", "read_only"]) +def test_parse_arguments_rejects_resume_with_containment_overrides( + tmp_path: Path, + monkeypatch: pytest.MonkeyPatch, + capsys: pytest.CaptureFixture[str], + flag: str, +) -> None: + argv = ["strix", "--resume", "old-run"] + if flag == "workspace": + workspace = tmp_path / "remediation" + workspace.mkdir() + argv.extend(["--workspace-mount", str(workspace)]) + else: + argv.append("--read-only-local-targets") + monkeypatch.setattr(sys, "argv", argv) + + with pytest.raises(SystemExit): + cli_main.parse_arguments() + + assert "Resume restores the original containment configuration" in capsys.readouterr().err + + def _write_run_record(runs_dir: Path, run_name: str, record: dict[str, Any]) -> None: """Write a resumable run: its record plus the agent snapshot resume needs.""" run_dir = runs_dir / run_name