mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Systematic prune per AGENTS.md test policy, one pass over every major test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli, cron, tui_gateway, honcho/openviking, root-level): - DELETE: source-reading tests (read_text/getsource on prod files), change-detector tests (exact catalog counts, model-name snapshots, config version literals), mock-echo tests (assert a mock returns what it was told), assertion-free/trivial tests, near-duplicate parametrizations (boundaries + one representative kept), async/sync twin duplicates, cosmetic within-file variations. - KEEP (mandatory): security/redaction/approval guards, message-role alternation invariants, prompt-caching/deterministic-call-id invariants, issue-number regression tests (deduped), E2E tests. - 6 test files deleted outright (script-style/no-assert or fully redundant); conftest.py, fakes/, fixtures/ untouched. - tests/acp/conftest.py added: autouse fixture stubs the live models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server tests performed on every session create — test_server.py 147s → 3.4s, and the tests are now genuinely hermetic. - Sleep-based slowness shrunk where safe (codex_ttfb_watchdog, compression_concurrent_fork, etc.); no wall-clock assertion tightened. Verification: full hermetic suite via scripts/run_tests.sh — 2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall (baseline: 583s wall, 13,564s subprocess CPU).
105 lines
3.1 KiB
Python
105 lines
3.1 KiB
Python
"""Credential rotation must not carry route-scoped TLS policy."""
|
|
|
|
from types import MethodType, SimpleNamespace
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
from run_agent import AIAgent
|
|
|
|
|
|
def test_credential_rotation_replaces_route_scoped_tls_settings():
|
|
agent = SimpleNamespace(
|
|
api_mode="chat_completions",
|
|
provider="custom",
|
|
model="shared-model",
|
|
api_key="old",
|
|
base_url="https://a.example/v1",
|
|
_client_kwargs={
|
|
"api_key": "old",
|
|
"base_url": "https://a.example/v1",
|
|
"ssl_verify": False,
|
|
"ssl_ca_cert": "/a.pem",
|
|
},
|
|
_apply_client_headers_for_base_url=MagicMock(),
|
|
_replace_primary_openai_client=MagicMock(),
|
|
)
|
|
entry = SimpleNamespace(
|
|
runtime_api_key="new",
|
|
access_token="",
|
|
runtime_base_url="https://b.example/v1",
|
|
base_url="https://b.example/v1",
|
|
)
|
|
config = {
|
|
"custom_providers": [
|
|
{
|
|
"name": "b",
|
|
"base_url": "https://b.example/v1",
|
|
"ssl_verify": True,
|
|
}
|
|
]
|
|
}
|
|
|
|
with patch("hermes_cli.config.load_config_readonly", return_value=config):
|
|
AIAgent._swap_credential(agent, entry)
|
|
|
|
assert agent._client_kwargs["ssl_verify"] is True
|
|
assert "ssl_ca_cert" not in agent._client_kwargs
|
|
agent._replace_primary_openai_client.assert_called_once_with(
|
|
reason="credential_rotation"
|
|
)
|
|
|
|
|
|
def test_credential_rotation_does_not_carry_global_headers_across_routes():
|
|
agent = SimpleNamespace(
|
|
api_mode="chat_completions",
|
|
provider="custom",
|
|
model="shared-model",
|
|
api_key="old",
|
|
base_url="https://a.example/v1",
|
|
_client_kwargs={
|
|
"api_key": "old",
|
|
"base_url": "https://a.example/v1",
|
|
"default_headers": {"Authorization": "old-secret"},
|
|
},
|
|
_replace_primary_openai_client=MagicMock(),
|
|
)
|
|
agent._apply_client_headers_for_base_url = MethodType(
|
|
AIAgent._apply_client_headers_for_base_url,
|
|
agent,
|
|
)
|
|
agent._apply_user_default_headers = MethodType(
|
|
AIAgent._apply_user_default_headers,
|
|
agent,
|
|
)
|
|
entry = SimpleNamespace(
|
|
runtime_api_key="new",
|
|
access_token="",
|
|
runtime_base_url="https://b.example/v1",
|
|
base_url="https://b.example/v1",
|
|
)
|
|
config = {
|
|
"model": {
|
|
"default_headers": {"Authorization": "global-secret"},
|
|
},
|
|
"custom_providers": [
|
|
{
|
|
"name": "b",
|
|
"base_url": "https://b.example/v1",
|
|
"extra_headers": {"X-Route": "b"},
|
|
}
|
|
],
|
|
}
|
|
|
|
with (
|
|
patch("hermes_cli.config.load_config_readonly", return_value=config),
|
|
patch(
|
|
"hermes_cli.config.get_compatible_custom_providers",
|
|
return_value=config["custom_providers"],
|
|
),
|
|
):
|
|
AIAgent._swap_credential(agent, entry)
|
|
|
|
headers = agent._client_kwargs["default_headers"]
|
|
assert "Authorization" not in headers
|
|
assert headers["X-Route"] == "b"
|
|
|
|
|