hermes-agent/tests/hermes_cli/test_kanban_worktree_isolation.py
Teknium 39975613b1
test: prune wave 2 + speed fixes — 28,106 → 19,757 test functions, suite wall 315s → 294s
Second, deeper pass over tools/gateway/hermes_cli plus first pass over
the trees wave 1 missed (acp, acp_adapter, skills, computer_use, docker,
dashboard, conformance, monitoring, secret_sources, hermes_state,
providers). Same rubric as wave 1 (AGENTS.md test policy); security,
alternation/caching invariants, issue-number regressions, and E2E kept.

Real test-quality fixes found and rooted out along the way:
- tests/tools/test_command_guards.py made real auxiliary-LLM HTTPS calls
  (DEFAULT_CONFIG smart-approval leaked in) — pinned approval
  mode=manual via autouse fixture: 17.4s → 0.4s.
- test_model_switch_custom_providers.py / test_user_providers_model_switch.py
  silently probed live provider catalogs (~2s/test) — stubbed
  cached_provider_model_ids/provider_model_ids/fetch_api_models.
- test_telegram_noise_filter.py: 15-platform copy-paste matrix over
  shared gateway.run logic → 3 representative platforms (55s → 3.9s).
- test_gateway_shutdown.py: stop()'s 5s interrupt-deadline loop spun on
  MagicMock agents — interrupt.side_effect now clears _running_agents
  (22s → 1.0s).
- test_gateway_inactivity_timeout.py poll-harness timings shrunk 3-5x
  (24s → 1.1s); test_mcp_stability.py backoff/SIGTERM-grace sleeps
  patched (15.4s → 2.5s); test_async_delegation.py negative-drain wait
  5s → 0.5s.
- test_telegram_init_deadline.py: loop-block margin restored to 1.0s
  with rationale comment — the watchdog-dump assertion needs the loop
  blocked well past deadline+grace under parallel load (flaked once in
  the 40-worker verification run at a 0.2s margin).

Verification: full hermetic suite via scripts/run_tests.sh —
2,438 files, 21,718 tests passed, 0 failed, 293.9s wall.
Suite totals vs original baseline: 46,820 → 19,757 test functions
(−57.8%), wall 583.5s → 293.9s (−50%), subprocess CPU 13,564s → 11,623s.
2026-07-29 13:39:40 -07:00

130 lines
4.2 KiB
Python

"""Per-task worktree isolation for decompose siblings.
Decompose children used to inherit the root's literal ``workspace_path``,
so every sibling of a worktree-kind root pointed at the SAME checkout —
and ``_resolve_worktree_workspace``'s existing-checkout shortcut reused it
on whatever branch was there, letting sibling workers run concurrently in
one directory on one branch (cross-task provenance corruption, no lock).
Two-part fix under test:
- ``decompose_triage_task`` leaves worktree children's ``workspace_path``
unset so each child materializes its own ``<repo>/.worktrees/<child-id>``.
- ``_resolve_worktree_workspace`` falls back to a fresh per-task worktree
when the requested path is occupied by another task's branch (heals
pre-existing rows that still carry a shared path).
"""
from __future__ import annotations
import subprocess
from pathlib import Path
import pytest
from hermes_cli import kanban_db as kb
@pytest.fixture
def kanban_home(tmp_path, monkeypatch):
"""Isolated HERMES_HOME with an empty kanban DB."""
home = tmp_path / ".hermes"
home.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
monkeypatch.setattr(Path, "home", lambda: tmp_path)
kb.init_db()
return home
def _git(cwd: Path, *args: str) -> None:
subprocess.run(
[
"git", "-C", str(cwd),
"-c", "user.name=Test User",
"-c", "user.email=test@example.com",
"-c", "commit.gpgsign=false",
*args,
],
check=True, capture_output=True, text=True,
)
def _make_repo(tmp_path: Path) -> Path:
repo = tmp_path / "repo"
repo.mkdir()
subprocess.run(
["git", "init", "-b", "main", str(repo)],
check=True, capture_output=True, text=True,
)
(repo / "README.md").write_text("base\n", encoding="utf-8")
_git(repo, "add", "README.md")
_git(repo, "commit", "-m", "init")
return repo
def _add_worktree(repo: Path, target: Path, branch: str) -> Path:
_git(repo, "worktree", "add", str(target), "-b", branch, "HEAD")
return target
def test_decompose_worktree_children_get_own_workspace(kanban_home):
with kb.connect() as conn:
root = kb.create_task(conn, title="build the feature", triage=True)
conn.execute(
"UPDATE tasks SET workspace_kind='worktree', "
"workspace_path='/repo/.worktrees/root' WHERE id = ?",
(root,),
)
conn.commit()
child_ids = kb.decompose_triage_task(
conn,
root,
root_assignee="orchestrator",
children=[
{"title": "spec it", "assignee": "alice", "parents": []},
{"title": "implement it", "assignee": "bob", "parents": [0]},
],
author="decomposer",
)
assert child_ids is not None and len(child_ids) == 2
for cid in child_ids:
row = conn.execute(
"SELECT workspace_kind, workspace_path FROM tasks WHERE id = ?",
(cid,),
).fetchone()
assert row["workspace_kind"] == "worktree"
# Each child resolves its own <repo>/.worktrees/<child-id> at
# dispatch; the root's literal path must never be shared.
assert row["workspace_path"] is None
def test_resolve_worktree_falls_back_when_path_occupied(kanban_home, tmp_path):
repo = _make_repo(tmp_path)
occupied = _add_worktree(repo, repo / ".worktrees" / "sibling", "wt/sibling")
with kb.connect() as conn:
tid = kb.create_task(
conn,
title="second sibling",
workspace_kind="worktree",
workspace_path=str(occupied), # inherited shared/stale path
)
task = kb.get_task(conn, tid)
workspace, branch = kb._resolve_worktree_workspace(task)
assert workspace == (repo / ".worktrees" / tid).resolve()
assert branch == f"wt/{tid}"
# The sibling's checkout is untouched, still on its own branch.
assert (occupied / "README.md").exists()
head = subprocess.run(
["git", "-C", str(occupied), "rev-parse", "--abbrev-ref", "HEAD"],
capture_output=True, text=True, check=True,
).stdout.strip()
assert head == "wt/sibling"