mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Second, deeper pass over tools/gateway/hermes_cli plus first pass over the trees wave 1 missed (acp, acp_adapter, skills, computer_use, docker, dashboard, conformance, monitoring, secret_sources, hermes_state, providers). Same rubric as wave 1 (AGENTS.md test policy); security, alternation/caching invariants, issue-number regressions, and E2E kept. Real test-quality fixes found and rooted out along the way: - tests/tools/test_command_guards.py made real auxiliary-LLM HTTPS calls (DEFAULT_CONFIG smart-approval leaked in) — pinned approval mode=manual via autouse fixture: 17.4s → 0.4s. - test_model_switch_custom_providers.py / test_user_providers_model_switch.py silently probed live provider catalogs (~2s/test) — stubbed cached_provider_model_ids/provider_model_ids/fetch_api_models. - test_telegram_noise_filter.py: 15-platform copy-paste matrix over shared gateway.run logic → 3 representative platforms (55s → 3.9s). - test_gateway_shutdown.py: stop()'s 5s interrupt-deadline loop spun on MagicMock agents — interrupt.side_effect now clears _running_agents (22s → 1.0s). - test_gateway_inactivity_timeout.py poll-harness timings shrunk 3-5x (24s → 1.1s); test_mcp_stability.py backoff/SIGTERM-grace sleeps patched (15.4s → 2.5s); test_async_delegation.py negative-drain wait 5s → 0.5s. - test_telegram_init_deadline.py: loop-block margin restored to 1.0s with rationale comment — the watchdog-dump assertion needs the loop blocked well past deadline+grace under parallel load (flaked once in the 40-worker verification run at a 0.2s margin). Verification: full hermetic suite via scripts/run_tests.sh — 2,438 files, 21,718 tests passed, 0 failed, 293.9s wall. Suite totals vs original baseline: 46,820 → 19,757 test functions (−57.8%), wall 583.5s → 293.9s (−50%), subprocess CPU 13,564s → 11,623s.
84 lines
3.1 KiB
Python
84 lines
3.1 KiB
Python
"""Each standalone config loader (gateway, TUI/desktop, cron) must honor managed scope.
|
|
|
|
These loaders build their own config dict instead of routing through
|
|
hermes_cli.config.load_config, so the managed overlay has to be wired into each.
|
|
This is the regression guard for the whole bug class (a managed display.skin was
|
|
silently ignored by the TUI; the same gap existed in the gateway and cron).
|
|
"""
|
|
import textwrap
|
|
|
|
import pytest
|
|
|
|
|
|
@pytest.fixture
|
|
def homes(tmp_path, monkeypatch):
|
|
home = tmp_path / "home"
|
|
home.mkdir()
|
|
managed = tmp_path / "managed"
|
|
managed.mkdir()
|
|
monkeypatch.setenv("HERMES_HOME", str(home))
|
|
monkeypatch.setenv("HERMES_MANAGED_DIR", str(managed))
|
|
import hermes_cli.config as cfg
|
|
from hermes_cli import managed_scope
|
|
|
|
cfg._LOAD_CONFIG_CACHE.clear()
|
|
cfg._RAW_CONFIG_CACHE.clear()
|
|
managed_scope.invalidate_managed_cache()
|
|
return home, managed
|
|
|
|
|
|
def _seed(home, managed, *, user, mgd):
|
|
(home / "config.yaml").write_text(textwrap.dedent(user), encoding="utf-8")
|
|
(managed / "config.yaml").write_text(textwrap.dedent(mgd), encoding="utf-8")
|
|
import hermes_cli.config as cfg
|
|
from hermes_cli import managed_scope
|
|
|
|
cfg._LOAD_CONFIG_CACHE.clear()
|
|
cfg._RAW_CONFIG_CACHE.clear()
|
|
managed_scope.invalidate_managed_cache()
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_timezone_honors_managed(homes, monkeypatch):
|
|
home, managed = homes
|
|
# hermes_time checks an env override first; ensure it's unset so config wins.
|
|
monkeypatch.delenv("HERMES_TIMEZONE", raising=False)
|
|
monkeypatch.delenv("TZ", raising=False)
|
|
_seed(home, managed, user="timezone: America/New_York\n", mgd="timezone: Asia/Tokyo\n")
|
|
import hermes_time
|
|
|
|
assert hermes_time._resolve_timezone_name() == "Asia/Tokyo"
|
|
|
|
|
|
def test_gateway_env_bridge_honors_managed(homes, monkeypatch):
|
|
"""The gateway config→env bridge must bridge MANAGED values, not user ones.
|
|
|
|
gateway/run.py bridges config.yaml settings into os.environ at startup and on
|
|
every turn (HERMES_TIMEZONE, HERMES_REDACT_SECRETS, HERMES_MAX_ITERATIONS,
|
|
...). A managed value must win at that env layer too — otherwise the bridge
|
|
writes the user's value into the env that the whole process then reads. This
|
|
is the regression that manual verification caught (managed timezone was
|
|
overridden by the user's value via the env bridge).
|
|
|
|
We assert on the managed-overlaid config the bridge consumes (rather than the
|
|
os.environ side effect, which leaks across same-process tests under the
|
|
runner) — the bridge writes whatever this dict carries, so a managed value
|
|
here proves the env var gets the managed value.
|
|
"""
|
|
home, managed = homes
|
|
_seed(home, managed, user="timezone: America/New_York\n", mgd="timezone: Asia/Tokyo\n")
|
|
from hermes_cli import managed_scope
|
|
|
|
managed_scope.invalidate_managed_cache()
|
|
# The bridge loads config.yaml, expands env, then applies this overlay before
|
|
# writing HERMES_TIMEZONE = cfg["timezone"]. Prove the overlay flips the value.
|
|
import yaml
|
|
|
|
raw = yaml.safe_load((home / "config.yaml").read_text())
|
|
bridged = managed_scope.apply_managed_overlay(raw)
|
|
assert bridged.get("timezone") == "Asia/Tokyo"
|