def bridgeabsentenv(tmppath: Path) -> dict:
Root cause. test_install.py's two bare-wrapper tests simulated bridge-absence by (a) copying the wrapper alone to a tmp dir (so search orders 2–3 — same-dir and ../plugin/ — miss), and (b) trusting that the ambient python3 cannot import the pip-installed terminal_jail package, so _find_bridge()'s python-module fallback (search order 4) also misses. That assumption breaks under uv run: uv puts the venv bin/ on PATH, python3 becomes the venv interpreter, search order 4 finds the bridge → the wrapper's interruptor engages → the "bridge not available" warning never appears (test 1 fails) and the firewall blocks the marker command, exiting 126 (test 2 fails).
Fix. TERMINAL_JAIL_BRIDGE is the wrapper's explicit override (search order 1). The wrapper treats an explicit override as authoritative: a missing file is a hard failure (wrapper L82) with no fall-through to order 4. Pin it to a guaranteed-missing path (a unique tmp_path subpath, so it can never exist on any host) in the two tests' env:
# test_install.py
def bridge_absent_env(tmp_path: Path) -> dict:
"""Explicit override = hard failure (wrapper L82, no fall-through to the
python-module search). Pinning a guaranteed-missing path makes
bridge-absence deterministic on every host — ambient python3, the repo
venv, or a fresh `uv run` venv with terminal_jail pip-installed."""
return {"TERMINAL_JAIL_BRIDGE": str(tmp_path / "no-bridge" / "interruptor_bridge.py")}
def test_bare_wrapper_warns_when_bridge_absent(bare_wrapper: Path, tmp_path: Path) -> None:
result = _run(bare_wrapper, "echo hi", env=bridge_absent_env(tmp_path))
assert result.returncode == 0
assert "interruptor bridge not available" in result.stderr
assert "hi" in result.stdout
def test_bare_wrapper_runs_without_firewall_when_bridge_absent(bare_wrapper: Path, tmp_path: Path) -> None:
result = _run(bare_wrapper, "printf 'ran-%s' TERMINAL_JAIL_FORBIDDEN",
env=bridge_absent_env(tmp_path))
assert result.returncode == 0
assert result.stdout.strip() == "ran-TERMINAL_JAIL_FORBIDDEN"
Key points: the pin must be non-empty (an empty TERMINAL_JAIL_BRIDGE is treated as unset and falls through to order 4) and absolute/missing (a path under pytest's unique tmp_path is guaranteed absent, unlike /nonexistent/… which is only conventionally absent). The wrapper's _find_bridge() already provides the required hard-failure semantics:
# wrapper, search order 1 (L82 = the hard-failure return)
if [ -n "${TERMINAL_JAIL_BRIDGE:-}" ]; then
if [ -f "$TERMINAL_JAIL_BRIDGE" ]; then echo "$TERMINAL_JAIL_BRIDGE"; return 0; fi
return 1 # explicit override missing ⇒ hard failure, NO fall-through
fi
# ... orders 2 (same-dir), 3 (../plugin/), 4 (python module import)
The repo wasn't present in this environment (workspace held only `problem.json`), so I built a faithful replica (`/tmp/tj-repro/`: wrapper with the 4-order `_find_bridge()` + L82 hard-failure, a mini pip package `terminal_jail`, and `tests/test_install.py` / `tests/test_install_fixed.py`) and a `uv` venv with the package installed — mirroring a fresh `uv run` clone. Verified with the ambient interpreter (`/usr/bin/python3`, package not importable) and with the venv `bin/` on `PATH` (package importable via `/tmp/tj-repro/uv-venv/lib/python3.14/site-packages/…`). | Scenario | Buggy tests | Fixed tests | |---|---|---| | ambient python3 (no package) — "repo venv" case | **2 passed** | 2 passed | | uv venv bin on PATH (package importable) — "fresh uv clone" case | **2 FAILED** (no warning; rc=126 blocked) | **2 passed** | | hostile ambient: venv PATH + real `TERMINAL_JAIL_BRIDGE` | 2 failed | **2 passed** (pin overrides ambient) | The failing run reproduced the exact reported symptoms: `AssertionError: assert 'interruptor bridge not available' in ''` and `assert 126 == 0` (bridge blocked the `TERMINAL_JAIL_FORBIDDEN` marker). **`_find_bridge()` edge cases** (marker command: rc=126 ⇒ bridge found/blocked; rc=0 + warning ⇒ bridge absent): ``` E1 unset override, pkg importable (buggy-test trigger) -> BRIDGE FOUND (blocked) E2 override=missing path, pkg importable -> BRIDGE ABSENT (hard fail, NO fall-through) E3 override=empty string -> BRIDGE FOUND (treated as unset — pin must be non-empty) E4 override=existing path -> BRIDGE FOUND (override wins) E5 unset override, pkg NOT importable, no plugin sibling -> BRIDGE ABSENT (original repo-venv behaviour) E6 override=missing path, pkg NOT importable -> BRIDGE ABSENT ``` Also confirmed on the real installed wrapper (`/usr/local/lib/terminal-jail/standalone/terminal-jail`): its python-module fallback resolves via the **ambient** `python3`, which is exactly the mechanism the fix neutralizes.
{"model": "deepseek-v4-flash", "problem_class": "python-test-environment-isolation", "result": "passed", "tests": 2}