hermes-agent/tests/hermes_cli/test_kanban_worktree_isolation.py
Ahmad 65d42e35d4
Some checks failed
CI / Detect affected areas (push) Waiting to run
CI / Python tests (push) Blocked by required conditions
CI / Python lints (push) Blocked by required conditions
CI / JS & TS checks (push) Blocked by required conditions
CI / Desktop E2E (push) Blocked by required conditions
CI / Docs Site (push) Blocked by required conditions
CI / Deny unrelated histories (push) Blocked by required conditions
CI / Check contributors (push) Blocked by required conditions
CI / Check uv.lock (push) Blocked by required conditions
CI / package-lock.json diff (push) Blocked by required conditions
CI / Lint Docker scripts (push) Blocked by required conditions
CI / Build&Test Docker image (push) Blocked by required conditions
CI / Supply-chain scan (push) Blocked by required conditions
CI / Review label gate (push) Blocked by required conditions
CI / OSV scan (push) Waiting to run
CI / CI review comment (live) (push) Blocked by required conditions
CI / All required checks pass (push) Blocked by required conditions
CI / CI timing report (push) Blocked by required conditions
Deploy Site / deploy-vercel (push) Waiting to run
Deploy Site / deploy-docs (push) Waiting to run
Docker Build, Test, and Publish / build (amd64, type=gha,scope=docker-amd64, type=gha,mode=max,scope=docker-amd64, linux/amd64, ubuntu-latest) (push) Waiting to run
Docker Build, Test, and Publish / build (arm64, type=gha,scope=docker-arm64, type=gha,mode=max,scope=docker-arm64, linux/arm64, ubuntu-24.04-arm) (push) Waiting to run
Docker Build, Test, and Publish / publish (amd64, type=gha,scope=docker-amd64, type=gha,mode=max,scope=docker-amd64, linux/amd64, ubuntu-latest) (push) Blocked by required conditions
Docker Build, Test, and Publish / publish (arm64, type=gha,scope=docker-arm64, type=gha,mode=max,scope=docker-arm64, linux/arm64, ubuntu-24.04-arm) (push) Blocked by required conditions
Docker Build, Test, and Publish / merge (push) Blocked by required conditions
auto-fix lint issues & formatting / Generate eslint --fix patch (push) Waiting to run
auto-fix lint issues & formatting / Apply patch (push) Blocked by required conditions
Build Skills Index / build-index (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
fix(kanban): stop decompose siblings sharing one worktree checkout
Decompose children inherit the root's literal workspace_path (#37172),
so every sibling of a worktree-kind root points at the SAME checkout.
_resolve_worktree_workspace's existing-checkout shortcut then reuses
that directory on whatever branch is currently checked out, ignoring
the task's own branch_name. Net effect: sibling workers — which can be
promoted and dispatched concurrently — run in one directory on the
first sibling's branch, with no lock. Work lands on the wrong task's
branch (provenance corruption) and concurrent siblings trample each
other's index/tree.

Fix, two layers:
- decompose_triage_task: worktree-kind children no longer inherit the
  root's literal path; each child materializes its own
  <repo>/.worktrees/<child-id> at dispatch (dir/scratch inheritance
  unchanged — children legitimately share those).
- _resolve_worktree_workspace: when the requested path is an existing
  checkout of a DIFFERENT branch, fall back to a fresh
  <repo>/.worktrees/<task-id> instead of silently reusing it (heals
  rows that already carry a shared path). Same-branch reuse and the
  no-repo/own-path degenerate cases keep the legacy behaviour.

Tests: tests/hermes_cli/test_kanban_worktree_isolation.py (5); full
test_kanban_db.py + test_kanban_decompose_db.py suites pass unchanged.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-23 09:27:13 -07:00

198 lines
6.5 KiB
Python

"""Per-task worktree isolation for decompose siblings.
Decompose children used to inherit the root's literal ``workspace_path``,
so every sibling of a worktree-kind root pointed at the SAME checkout —
and ``_resolve_worktree_workspace``'s existing-checkout shortcut reused it
on whatever branch was there, letting sibling workers run concurrently in
one directory on one branch (cross-task provenance corruption, no lock).
Two-part fix under test:
- ``decompose_triage_task`` leaves worktree children's ``workspace_path``
unset so each child materializes its own ``<repo>/.worktrees/<child-id>``.
- ``_resolve_worktree_workspace`` falls back to a fresh per-task worktree
when the requested path is occupied by another task's branch (heals
pre-existing rows that still carry a shared path).
"""
from __future__ import annotations
import subprocess
from pathlib import Path
import pytest
from hermes_cli import kanban_db as kb
@pytest.fixture
def kanban_home(tmp_path, monkeypatch):
"""Isolated HERMES_HOME with an empty kanban DB."""
home = tmp_path / ".hermes"
home.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
monkeypatch.setattr(Path, "home", lambda: tmp_path)
kb.init_db()
return home
def _git(cwd: Path, *args: str) -> None:
subprocess.run(
[
"git", "-C", str(cwd),
"-c", "user.name=Test User",
"-c", "user.email=test@example.com",
"-c", "commit.gpgsign=false",
*args,
],
check=True, capture_output=True, text=True,
)
def _make_repo(tmp_path: Path) -> Path:
repo = tmp_path / "repo"
repo.mkdir()
subprocess.run(
["git", "init", "-b", "main", str(repo)],
check=True, capture_output=True, text=True,
)
(repo / "README.md").write_text("base\n", encoding="utf-8")
_git(repo, "add", "README.md")
_git(repo, "commit", "-m", "init")
return repo
def _add_worktree(repo: Path, target: Path, branch: str) -> Path:
_git(repo, "worktree", "add", str(target), "-b", branch, "HEAD")
return target
def test_decompose_worktree_children_get_own_workspace(kanban_home):
with kb.connect() as conn:
root = kb.create_task(conn, title="build the feature", triage=True)
conn.execute(
"UPDATE tasks SET workspace_kind='worktree', "
"workspace_path='/repo/.worktrees/root' WHERE id = ?",
(root,),
)
conn.commit()
child_ids = kb.decompose_triage_task(
conn,
root,
root_assignee="orchestrator",
children=[
{"title": "spec it", "assignee": "alice", "parents": []},
{"title": "implement it", "assignee": "bob", "parents": [0]},
],
author="decomposer",
)
assert child_ids is not None and len(child_ids) == 2
for cid in child_ids:
row = conn.execute(
"SELECT workspace_kind, workspace_path FROM tasks WHERE id = ?",
(cid,),
).fetchone()
assert row["workspace_kind"] == "worktree"
# Each child resolves its own <repo>/.worktrees/<child-id> at
# dispatch; the root's literal path must never be shared.
assert row["workspace_path"] is None
def test_decompose_dir_children_still_inherit_path(kanban_home):
with kb.connect() as conn:
root = kb.create_task(conn, title="ops sweep", triage=True)
conn.execute(
"UPDATE tasks SET workspace_kind='dir', "
"workspace_path='/srv/ops' WHERE id = ?",
(root,),
)
conn.commit()
child_ids = kb.decompose_triage_task(
conn,
root,
root_assignee="orchestrator",
children=[{"title": "child", "assignee": "alice", "parents": []}],
author="decomposer",
)
assert child_ids is not None
row = conn.execute(
"SELECT workspace_kind, workspace_path FROM tasks WHERE id = ?",
(child_ids[0],),
).fetchone()
assert row["workspace_kind"] == "dir"
assert row["workspace_path"] == "/srv/ops"
def test_resolve_worktree_falls_back_when_path_occupied(kanban_home, tmp_path):
repo = _make_repo(tmp_path)
occupied = _add_worktree(repo, repo / ".worktrees" / "sibling", "wt/sibling")
with kb.connect() as conn:
tid = kb.create_task(
conn,
title="second sibling",
workspace_kind="worktree",
workspace_path=str(occupied), # inherited shared/stale path
)
task = kb.get_task(conn, tid)
workspace, branch = kb._resolve_worktree_workspace(task)
assert workspace == (repo / ".worktrees" / tid).resolve()
assert branch == f"wt/{tid}"
# The sibling's checkout is untouched, still on its own branch.
assert (occupied / "README.md").exists()
head = subprocess.run(
["git", "-C", str(occupied), "rev-parse", "--abbrev-ref", "HEAD"],
capture_output=True, text=True, check=True,
).stdout.strip()
assert head == "wt/sibling"
def test_resolve_worktree_same_branch_still_reuses(kanban_home, tmp_path):
repo = _make_repo(tmp_path)
with kb.connect() as conn:
tid = kb.create_task(
conn,
title="returning task",
workspace_kind="worktree",
)
own = _add_worktree(repo, repo / ".worktrees" / tid, f"wt/{tid}")
conn.execute(
"UPDATE tasks SET workspace_path = ? WHERE id = ?",
(str(own), tid),
)
conn.commit()
task = kb.get_task(conn, tid)
workspace, branch = kb._resolve_worktree_workspace(task)
assert workspace == own.resolve()
assert branch == f"wt/{tid}"
def test_resolve_worktree_own_path_on_foreign_branch_keeps_legacy_reuse(
kanban_home, tmp_path
):
repo = _make_repo(tmp_path)
with kb.connect() as conn:
tid = kb.create_task(
conn,
title="foreign-branch checkout",
workspace_kind="worktree",
)
own = _add_worktree(repo, repo / ".worktrees" / tid, "wt/foreign")
conn.execute(
"UPDATE tasks SET workspace_path = ? WHERE id = ?",
(str(own), tid),
)
conn.commit()
task = kb.get_task(conn, tid)
# The fallback target would be the occupied path itself, so the
# legacy reuse applies rather than failing dispatch.
workspace, branch = kb._resolve_worktree_workspace(task)
assert workspace == own.resolve()
assert branch == "wt/foreign"