From 8594b7d0fce65bd7104957f80c8cf03eed5ddcb7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9F=91=BD=20Chrispy?= Date: Thu, 3 Sep 2026 09:59:10 +1000 Subject: [PATCH] fix(containment): reject resume overrides MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Reject containment flags on resumed runs instead of silently discarding them. DOPS-1172 👽 Directed by Chrispy Authored by LLM gpt-5.6-sol -- Ranger --- strix/interface/cli_args.py | 6 ++++++ tests/test_cli_target_list.py | 22 ++++++++++++++++++++++ 2 files changed, 28 insertions(+) diff --git a/strix/interface/cli_args.py b/strix/interface/cli_args.py index b0bffec2..b10fd8d3 100644 --- a/strix/interface/cli_args.py +++ b/strix/interface/cli_args.py @@ -376,6 +376,12 @@ Examples: "--resume picks up where the prior run left off, including the " "original target list." ) + if args.workspace_mount or args.read_only_local_targets: + parser.error( + "Cannot combine --resume with --workspace-mount or " + "--read-only-local-targets. Resume restores the original " + "containment configuration." + ) _load_resume_state(args, parser) agents_path = runtime_state_dir(run_dir_for(args.resume)) / "agents.json" if not agents_path.exists(): diff --git a/tests/test_cli_target_list.py b/tests/test_cli_target_list.py index 9c93ea17..e713df18 100644 --- a/tests/test_cli_target_list.py +++ b/tests/test_cli_target_list.py @@ -86,6 +86,28 @@ def test_parse_arguments_rejects_resume_with_target_list( assert "Cannot combine --resume with --target/--target-list" in capsys.readouterr().err +@pytest.mark.parametrize("flag", ["workspace", "read_only"]) +def test_parse_arguments_rejects_resume_with_containment_overrides( + tmp_path: Path, + monkeypatch: pytest.MonkeyPatch, + capsys: pytest.CaptureFixture[str], + flag: str, +) -> None: + argv = ["strix", "--resume", "old-run"] + if flag == "workspace": + workspace = tmp_path / "remediation" + workspace.mkdir() + argv.extend(["--workspace-mount", str(workspace)]) + else: + argv.append("--read-only-local-targets") + monkeypatch.setattr(sys, "argv", argv) + + with pytest.raises(SystemExit): + cli_main.parse_arguments() + + assert "Resume restores the original containment configuration" in capsys.readouterr().err + + def _write_run_record(runs_dir: Path, run_name: str, record: dict[str, Any]) -> None: """Write a resumable run: its record plus the agent snapshot resume needs.""" run_dir = runs_dir / run_name