diff --git a/tests/control_plane/test_agent_preferences.py b/tests/control_plane/test_agent_preferences.py index 621c973410..43d8eab75e 100644 --- a/tests/control_plane/test_agent_preferences.py +++ b/tests/control_plane/test_agent_preferences.py @@ -248,8 +248,8 @@ def dispatch(): @pytest.mark.parametrize("denied_target", ["journal", "namespace"]) def test_permission_denied_hook_is_not_empty_and_recovers(tmp_path, denied_target): import os - if os.geteuid() == 0: - pytest.skip("root bypasses POSIX read permission") + if os.name == "nt" or os.geteuid() == 0: + pytest.skip("mode 000 read denial needs a non-root POSIX host") _, runtime, registry = _write_fixture(tmp_path, required_capability="network") scope = ("--goal-id", GOAL_ID, "--agent-id", AGENT_ID) rc, written = _run_cli(registry, runtime, "semantic-preference", "agent", "remember", *scope, diff --git a/tests/test_contract_scan_unreadable_files.py b/tests/test_contract_scan_unreadable_files.py index e508ea336e..fa22eabf0e 100644 --- a/tests/test_contract_scan_unreadable_files.py +++ b/tests/test_contract_scan_unreadable_files.py @@ -67,7 +67,10 @@ def fail_git_probe(_: Path) -> dict[str, object]: assert payload["scanned_files"] == 1 -@pytest.mark.skipif(os.geteuid() == 0, reason="root reads mode 000 files") +@pytest.mark.skipif( + os.name == "nt" or os.geteuid() == 0, + reason="mode 000 read denial needs a non-root POSIX host", +) def test_scan_public_boundary_reports_unreadable_file(tmp_path: Path) -> None: (tmp_path / "ok.md").write_text("hello\n", encoding="utf-8") locked = tmp_path / "locked.md"