mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Systematic prune per AGENTS.md test policy, one pass over every major test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli, cron, tui_gateway, honcho/openviking, root-level): - DELETE: source-reading tests (read_text/getsource on prod files), change-detector tests (exact catalog counts, model-name snapshots, config version literals), mock-echo tests (assert a mock returns what it was told), assertion-free/trivial tests, near-duplicate parametrizations (boundaries + one representative kept), async/sync twin duplicates, cosmetic within-file variations. - KEEP (mandatory): security/redaction/approval guards, message-role alternation invariants, prompt-caching/deterministic-call-id invariants, issue-number regression tests (deduped), E2E tests. - 6 test files deleted outright (script-style/no-assert or fully redundant); conftest.py, fakes/, fixtures/ untouched. - tests/acp/conftest.py added: autouse fixture stubs the live models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server tests performed on every session create — test_server.py 147s → 3.4s, and the tests are now genuinely hermetic. - Sleep-based slowness shrunk where safe (codex_ttfb_watchdog, compression_concurrent_fork, etc.); no wall-clock assertion tightened. Verification: full hermetic suite via scripts/run_tests.sh — 2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall (baseline: 583s wall, 13,564s subprocess CPU).
90 lines
3.2 KiB
Python
90 lines
3.2 KiB
Python
"""Tests for the container-context sandbox-mirror guard (#32049 follow-up).
|
|
|
|
Brian's shape-based guard (#32213) catches paths that carry the full
|
|
``…/sandboxes/<backend>/<task>/home/.hermes/…`` prefix. This covers the
|
|
complementary inner-container case: when file tools execute inside Docker,
|
|
the bind-mount strips that prefix and the guard sees plain ``/root/.hermes/…``.
|
|
The root:root ownership on the divergent SOUL.md in #32049 confirms this
|
|
is the primary failure mode.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import pytest
|
|
|
|
|
|
class TestClassifyContainerMirrorTarget:
|
|
|
|
def test_catches_soul_md_with_context(self):
|
|
"""Primary failure mode from #32049: agent writes SOUL.md via container path."""
|
|
from agent.file_safety import classify_container_mirror_target
|
|
|
|
result = classify_container_mirror_target(
|
|
"/root/.hermes/profiles/group1/SOUL.md",
|
|
mirror_prefix="/root/.hermes",
|
|
)
|
|
assert result is not None
|
|
assert result["mirror_root"].replace("\\", "/").endswith("root/.hermes")
|
|
assert result["inner_path"] == "profiles/group1/SOUL.md"
|
|
|
|
@pytest.mark.parametrize("inner", [
|
|
"SOUL.md",
|
|
"memories/MEMORY.md",
|
|
])
|
|
def test_catches_authoritative_profile_files(self, inner):
|
|
from agent.file_safety import classify_container_mirror_target
|
|
|
|
result = classify_container_mirror_target(
|
|
f"/root/.hermes/{inner}",
|
|
mirror_prefix="/root/.hermes",
|
|
)
|
|
assert result is not None
|
|
assert result["inner_path"] == inner
|
|
|
|
|
|
|
|
class TestGetContainerMirrorWarning:
|
|
def test_warning_names_inner_path_and_bypass(self):
|
|
from agent.file_safety import get_container_mirror_warning
|
|
|
|
warn = get_container_mirror_warning(
|
|
"/root/.hermes/profiles/group1/SOUL.md",
|
|
mirror_prefix="/root/.hermes",
|
|
)
|
|
assert warn is not None
|
|
assert "profiles/group1/SOUL.md" in warn
|
|
assert "cross_profile=True" in warn
|
|
|
|
|
|
class TestOrthogonality:
|
|
"""Container-context guard catches what the shape-based guard (#32213) misses."""
|
|
|
|
def test_inner_container_path_caught_by_context_guard(self):
|
|
"""No sandboxes/ segment — shape guard passes, context guard blocks."""
|
|
from agent.file_safety import classify_container_mirror_target
|
|
|
|
path = "/root/.hermes/profiles/group1/SOUL.md"
|
|
|
|
assert classify_container_mirror_target(path) is None # no context
|
|
assert classify_container_mirror_target(path, mirror_prefix="/root/.hermes") is not None
|
|
|
|
|
|
class TestFileToolIntegration:
|
|
"""file_tools must catch the mirror path before creating DockerEnvironment."""
|
|
|
|
def test_guard_uses_current_docker_config_before_env_exists(self, monkeypatch):
|
|
import tools.file_tools as file_tools
|
|
|
|
monkeypatch.setattr(
|
|
file_tools,
|
|
"_get_container_mirror_prefix_for_task",
|
|
lambda task_id: "/root/.hermes",
|
|
)
|
|
|
|
warning = file_tools._check_cross_profile_path(
|
|
"/root/.hermes/profiles/group1/SOUL.md",
|
|
task_id="new-task",
|
|
)
|
|
|
|
assert warning is not None
|
|
assert "Sandbox-mirror write blocked" in warning
|
|
assert "profiles/group1/SOUL.md" in warning
|