Review feedback, both valid.
The control-character fixture caught every OSError, so an unwritable
temp directory or a full disk would have reported these security tests
as skipped instead of failing. It now skips only for errors that mean
the name itself is unrepresentable (EINVAL, EILSEQ, ENAMETOOLONG) and
re-raises everything else.
The mount-policy test derived the protected directory from the
checkout's drive, so a repo cloned to D: would look for D:\Windows,
miss, and skip the branch the test exists to cover. Ask Windows where
it is installed via SYSTEMROOT instead.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
A full run on Windows 11 failed 31 tests, almost all because a fixture
assumed POSIX behaviour or read the developer's own Git configuration
rather than because Strix misbehaved. That noise hides real regressions.
- Resolve git with `shutil.which` instead of `/usr/bin/env git`, and skip
the module when no git is present. This single line accounted for 19 of
the 31 failures.
- Isolate every git subprocess from `GIT_CONFIG_GLOBAL`/`GIT_CONFIG_SYSTEM`
and supply a commit identity, so a global `core.excludesFile`,
`commit.gpgSign`, or `core.hooksPath` cannot change what a test sees.
- Create control-character filenames through a fixture that skips where
the filesystem rejects them, instead of failing to build the fixture.
- Choose the protected system directory for the platform in the mount
policy test. `check_mountable_dir` already handles both families, so on
Windows this now exercises the real policy instead of failing early.
- Assert secret-file permissions through a fixture that keeps the POSIX
0o600 check exact and, on Windows, skips with the reason stated rather
than weakening the assertion. The device-identity test is split so its
identity contract still runs everywhere.
- Pin mypy to `platform = "linux"` so type checking resolves the same
APIs as CI and the container target. This removes the six
`fcntl.flock`/`os.getuid`/`os.getgid` attribute errors reported on
Windows without adding ignores that `warn_unused_ignores` would then
flag on Linux.
Windows now reports 12 failures, all owned elsewhere: #1258 (7-8,
intermittent), #648/#652, #1288, and #1285.
Refs #1259
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix: resolve pre-commit check failures
- Change RuntimeError to TypeError for type validation in report/writer.py
- Update pyupgrade to v3.21.2 for Python 3.14 compatibility
* chore: add pytest test infrastructure
Mirror the layout introduced on feature/438-token_budget: pytest +
pytest-asyncio dev deps, asyncio_mode auto, a tests.* mypy override, and
pytest in the mypy pre-commit hook deps so the tests/ package type-checks.
* feat: add --mount and large-target pre-flight for local repos (#492)
Large local targets were copied into the sandbox file-by-file via the SDK
LocalDir entry, which stalls on big repos and could leave /workspace empty.
- --mount <path> bind-mounts a host directory read-only at /workspace/<subdir>
instead of copying it, bypassing the per-file stream.
- A size pre-flight (STRIX_MAX_LOCAL_COPY_MB, default 1024) fails fast with a
clear message suggesting --mount when a non-mounted local target is too big.
* fix: reject empty --mount paths
An empty or whitespace-only --mount value resolves to the current working
directory and would silently bind-mount it into the sandbox. Reject it.
* fix: dedupe local targets so a dir is never both copied and mounted
If the same directory is passed via --target and --mount (or as duplicate
values), it previously produced two targets — copied AND bind-mounted, and
the copied one could trip the size pre-flight. Dedupe by resolved path,
preferring the bind mount.
* fix: treat non-positive STRIX_MAX_LOCAL_COPY_MB as disabled
Previously a value of 0 (or negative) made every local target count as
oversized, aborting all local scans. Now <= 0 disables the pre-flight.
* fix: log unreadable subtrees during size pre-flight
os.walk silently swallowed directory-listing errors, so a permission-denied
subtree could make a large repo under-count and slip past the pre-flight.
Surface such omissions via an onerror warning.
* docs: document --mount and STRIX_MAX_LOCAL_COPY_MB
Add CLI reference + example for --mount, document the size pre-flight env var,
note the read-only-is-not-a-hard-boundary caveat and that remote repos are not
size-checked, and clarify the backends docstring on when bind mounts apply.
* Update strix/interface/main.py
* Update strix/runtime/docker_client.py
---------