Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
52 changes: 37 additions & 15 deletions codex-rs/hooks/src/engine/command_runner.rs
Original file line number Diff line number Diff line change
@@ -1,4 +1,7 @@
use std::collections::HashMap;
#[cfg(not(windows))]
use std::ffi::OsStr;
use std::ffi::OsString;
use std::io::ErrorKind;
use std::path::Path;
use std::process::Stdio;
Expand Down Expand Up @@ -44,6 +47,7 @@ const MAX_CONCURRENT_ASYNC_HOOKS: usize = 8;
#[derive(Clone)]
pub(crate) struct CommandHookRuntime {
shell: CommandShell,
environment: Arc<Vec<(OsString, OsString)>>,
result_sender: Sender<HookCompletedEvent>,
state: Arc<Mutex<CommandHookRuntimeState>>,
output_spiller: HookOutputSpiller,
Expand All @@ -66,11 +70,13 @@ impl Default for CommandHookRuntimeState {
impl CommandHookRuntime {
pub(crate) fn new(
shell: CommandShell,
environment: Arc<Vec<(OsString, OsString)>>,
thread_id: ThreadId,
result_sender: Sender<HookCompletedEvent>,
) -> Self {
Self {
shell,
environment,
result_sender,
state: Arc::new(Mutex::new(CommandHookRuntimeState::default())),
output_spiller: HookOutputSpiller::new(thread_id),
Expand All @@ -86,6 +92,7 @@ impl CommandHookRuntime {
pub(crate) fn reconfigured(&self, shell: CommandShell) -> Self {
Self {
shell,
environment: Arc::clone(&self.environment),
result_sender: self.result_sender.clone(),
state: Arc::clone(&self.state),
output_spiller: self.output_spiller.clone(),
Expand Down Expand Up @@ -195,7 +202,7 @@ pub(crate) async fn run_command(
let started_at = chrono::Utc::now().timestamp();
let started = Instant::now();

let mut command = build_command(&runtime.shell, command, env);
let mut command = build_command(&runtime.shell, command, &runtime.environment, env);
command
.current_dir(cwd)
.stdin(Stdio::piped())
Expand Down Expand Up @@ -372,10 +379,11 @@ fn finish_command_run(
fn build_command(
shell: &CommandShell,
command_line: &str,
environment: &[(OsString, OsString)],
env: &HashMap<String, String>,
) -> Command {
let mut command = if shell.program.is_empty() {
default_shell_command()
default_shell_command(environment)
} else {
Command::new(&shell.program)
};
Expand All @@ -398,27 +406,41 @@ fn build_command(
#[cfg(not(windows))]
command.arg(command_line);
}
// Replay the session snapshot instead of inheriting the live process environment.
command.env_clear();
command.envs(environment.iter().cloned());
command.envs(env);
scrub_non_inheritable_env_vars(command.as_std_mut());
command
}

fn default_shell_command() -> Command {
fn default_shell_command(environment: &[(OsString, OsString)]) -> Command {
#[cfg(windows)]
{
let comspec = std::env::var("COMSPEC").unwrap_or_else(|_| "cmd.exe".to_string());
let mut command = Command::new(comspec);
command.arg("/C");
command
}
let (environment_variable, fallback_program, argument) = ("COMSPEC", "cmd.exe", "/C");

#[cfg(not(windows))]
{
let shell = std::env::var("SHELL").unwrap_or_else(|_| "/bin/sh".to_string());
let mut command = Command::new(shell);
command.arg("-lc");
command
}
let (environment_variable, fallback_program, argument) = ("SHELL", "/bin/sh", "-lc");

let program = environment
.iter()
.find(|(key, _)| {
#[cfg(windows)]
{
key.to_str()
.is_some_and(|key| key.eq_ignore_ascii_case(environment_variable))
}

#[cfg(not(windows))]
{
key == OsStr::new(environment_variable)
}
})
.map(|(_, value)| value.clone())
.unwrap_or_else(|| OsString::from(fallback_program));

let mut command = Command::new(program);
command.arg(argument);
command
}

#[cfg(test)]
Expand Down
139 changes: 135 additions & 4 deletions codex-rs/hooks/src/engine/command_runner_tests.rs
Original file line number Diff line number Diff line change
@@ -1,7 +1,12 @@
use std::collections::HashMap;
use std::ffi::OsStr;
use std::ffi::OsString;
#[cfg(windows)]
use std::fs;
#[cfg(unix)]
use std::os::unix::ffi::OsStringExt;
use std::path::Path;
use std::sync::Arc;
use std::time::Duration;

use async_channel::Receiver;
Expand All @@ -27,6 +32,7 @@ use super::CommandHookRuntime;
use super::CommandShell;
use super::ConfiguredHandler;
use super::MAX_CONCURRENT_ASYNC_HOOKS;
use super::build_command;
use super::run_command;
use crate::events::user_prompt_submit::UserPromptSubmitRequest;

Expand Down Expand Up @@ -74,7 +80,12 @@ async fn cmd_shell_runs_quoted_hook_command_path() {

for shell in shells {
let (result_sender, _result_receiver) = async_channel::unbounded();
let runtime = CommandHookRuntime::new(shell, ThreadId::new(), result_sender);
let runtime = CommandHookRuntime::new(
shell,
Arc::new(std::env::vars_os().collect()),
ThreadId::new(),
result_sender,
);
let result = run_command(&runtime, &handler, &command, &env, "{}", temp.path()).await;

assert_eq!(result.exit_code, Some(0), "stderr: {}", result.stderr);
Expand Down Expand Up @@ -157,22 +168,132 @@ async fn command_hook_does_not_expose_configured_noise_auth_token() {
assert_eq!(result.error, None);
}

#[test]
fn build_command_replays_snapshot_before_hook_overrides_and_scrubbing() {
#[cfg(unix)]
let non_unicode_value = OsString::from_vec(vec![b'v', 0xff]);
let environment = vec![
(
OsString::from("CODEX_HOOK_SNAPSHOT"),
OsString::from("captured"),
),
(
OsString::from("CODEX_HOOK_OVERRIDE"),
OsString::from("captured"),
),
(
OsString::from(CODEX_EXEC_SERVER_NOISE_AUTH_TOKEN_ENV_VAR),
OsString::from("captured-noise-token"),
),
#[cfg(unix)]
(
OsString::from("CODEX_HOOK_NON_UNICODE"),
non_unicode_value.clone(),
),
];
let env = HashMap::from([
("CODEX_HOOK_OVERRIDE".to_string(), "configured".to_string()),
("CODEX_HOOK_SAFE_ENV".to_string(), "visible".to_string()),
(
CODEX_EXEC_SERVER_NOISE_AUTH_TOKEN_ENV_VAR.to_string(),
"configured-noise-token".to_string(),
),
]);
let command = build_command(
&CommandShell {
program: "configured-shell".to_string(),
args: vec!["-c".to_string()],
},
"echo hook-ran",
&environment,
&env,
);

assert_eq!(
configured_environment_value(&command, "CODEX_HOOK_SNAPSHOT"),
Some(Some(OsString::from("captured")))
);
assert_eq!(
configured_environment_value(&command, "CODEX_HOOK_OVERRIDE"),
Some(Some(OsString::from("configured")))
);
assert_eq!(
configured_environment_value(&command, "CODEX_HOOK_SAFE_ENV"),
Some(Some(OsString::from("visible")))
);
assert_eq!(
configured_environment_value(&command, CODEX_EXEC_SERVER_NOISE_AUTH_TOKEN_ENV_VAR),
None
);
#[cfg(unix)]
assert_eq!(
configured_environment_value(&command, "CODEX_HOOK_NON_UNICODE"),
Some(Some(non_unicode_value))
);
}

#[test]
fn fallback_shell_uses_snapshot() {
#[cfg(windows)]
let (name, program) = ("comspec", r"C:\captured\cmd.exe");
#[cfg(not(windows))]
let (name, program) = ("SHELL", "/captured/shell");
let command = build_command(
&CommandShell {
program: String::new(),
args: Vec::new(),
},
"echo hook-ran",
&[(OsString::from(name), OsString::from(program))],
&HashMap::new(),
);

assert_eq!(command.as_std().get_program(), OsStr::new(program));
#[cfg(not(windows))]
assert_eq!(
command
.as_std()
.get_args()
.map(OsStr::to_os_string)
.collect::<Vec<_>>(),
vec![OsString::from("-lc"), OsString::from("echo hook-ran")]
);
}

const ASYNC_HOOK_TEST_TIMEOUT: Duration = Duration::from_secs(30);

fn runtime() -> (CommandHookRuntime, Receiver<HookCompletedEvent>) {
runtime_with_environment(Arc::new(std::env::vars_os().collect()))
}

fn runtime_with_environment(
environment: Arc<Vec<(OsString, OsString)>>,
) -> (CommandHookRuntime, Receiver<HookCompletedEvent>) {
let thread_id = ThreadId::new();
let (result_sender, result_receiver) = async_channel::unbounded();
let runtime = CommandHookRuntime::new(
CommandShell {
program: String::new(),
args: Vec::new(),
},
environment,
thread_id,
result_sender,
);
(runtime, result_receiver)
}

fn configured_environment_value(
command: &tokio::process::Command,
name: &str,
) -> Option<Option<OsString>> {
command
.as_std()
.get_envs()
.find(|(key, _)| *key == OsStr::new(name))
.map(|(_, value)| value.map(OsStr::to_os_string))
}

fn write_handler(temp: &TempDir, source: &str) -> ConfiguredHandler {
let script_path = temp.path().join("async_hook.py");
std::fs::write(&script_path, source).expect("write async test hook");
Expand Down Expand Up @@ -250,20 +371,26 @@ print('{"systemMessage": 123}')
#[tokio::test]
async fn async_hook_result_survives_runtime_reconfiguration() {
let temp = TempDir::new().expect("async test directory");
let (previous, results) = runtime();
let mut environment = std::env::vars_os().collect::<Vec<_>>();
environment.push((
OsString::from("CODEX_HOOK_CAPTURED_ENV"),
OsString::from("captured"),
));
let (previous, results) = runtime_with_environment(Arc::new(environment));
let release_path = temp.path().join("release");
let handler = write_handler(
&temp,
&format!(
r#"import json
import os
from pathlib import Path
import sys
import time

json.load(sys.stdin)
while not Path(r"{}").exists():
time.sleep(0.01)
print("survived reconfiguration")
print(os.environ["CODEX_HOOK_CAPTURED_ENV"])
"#,
release_path.display()
),
Expand All @@ -274,6 +401,10 @@ print("survived reconfiguration")
program: String::new(),
args: Vec::new(),
});
assert!(Arc::ptr_eq(
&previous.environment,
&reconfigured.environment
));
std::fs::write(release_path, "ready").expect("release async hook");

let hook_result = timeout(ASYNC_HOOK_TEST_TIMEOUT, results.recv())
Expand All @@ -284,7 +415,7 @@ print("survived reconfiguration")
hook_result.run.entries,
vec![HookOutputEntry {
kind: HookOutputEntryKind::Context,
text: "survived reconfiguration".to_string(),
text: "captured".to_string(),
}]
);

Expand Down
7 changes: 6 additions & 1 deletion codex-rs/hooks/src/engine/mod_tests.rs
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,12 @@ fn cwd() -> AbsolutePathBuf {

fn command_runtime(shell: CommandShell) -> CommandHookRuntime {
let (result_sender, _result_receiver) = async_channel::unbounded();
CommandHookRuntime::new(shell, ThreadId::new(), result_sender)
CommandHookRuntime::new(
shell,
Arc::new(std::env::vars_os().collect()),
ThreadId::new(),
result_sender,
)
}

pub(crate) fn mcp_executor() -> Arc<dyn HookMcpExecutor> {
Expand Down
Loading
Loading