diff --git a/fleetd/src/test/java/dev/ltms/fleet/session/GitWorktreesTest.java b/fleetd/src/test/java/dev/ltms/fleet/session/GitWorktreesTest.java index 09e266e..971eeb6 100644 --- a/fleetd/src/test/java/dev/ltms/fleet/session/GitWorktreesTest.java +++ b/fleetd/src/test/java/dev/ltms/fleet/session/GitWorktreesTest.java @@ -1809,4 +1809,43 @@ class GitWorktreesTest { + "different count means a helper now bypasses the hermetic factory; route " + "it through gitProcessBuilder or document the new exception here"); } + + /** + * fleetd #369 review round 2. {@link #everyGitSubprocessGoesThroughTheHermeticFactory} counts + * call sites, not behaviour — it catches a NEW helper built the old, leak-prone way, but it + * cannot catch {@link #gitProcessBuilder} itself being gutted: deleting {@code + * pb.environment().putAll(hermeticEnv())} from inside the factory leaves every call site + * unchanged, the count stays 2, and the whole unpoisoned suite stays green — the exact leak + * this ticket fixed would come back silently, with nothing but a human remembering to re-run + * the poison command to catch it. This test instead inspects what the factory actually hands + * to {@link ProcessBuilder#start()}, so it fails the moment the hermetic environment stops + * being applied, on any machine, with no poison needed. + * + *
The property under test: every git subprocess this class starts must run with an
+ * environment that cannot see the operator's real git configuration. A call-site count is a
+ * proxy for that; this is the thing itself.
+ */
+ @Test
+ void gitProcessBuilderCarriesTheFullHermeticEnvironment(@TempDir Path tmp) {
+ Map