hermes-agent/tests/hermes_cli/test_managed_scope_config.py
Teknium 6b81590c55
test: prune low-value tests suite-wide (wave 1) — 46,820 → 28,106 test functions
Systematic prune per AGENTS.md test policy, one pass over every major
test tree (gateway, hermes_cli, tools, agent, run_agent, plugins, cli,
cron, tui_gateway, honcho/openviking, root-level):

- DELETE: source-reading tests (read_text/getsource on prod files),
  change-detector tests (exact catalog counts, model-name snapshots,
  config version literals), mock-echo tests (assert a mock returns what
  it was told), assertion-free/trivial tests, near-duplicate
  parametrizations (boundaries + one representative kept), async/sync
  twin duplicates, cosmetic within-file variations.
- KEEP (mandatory): security/redaction/approval guards, message-role
  alternation invariants, prompt-caching/deterministic-call-id
  invariants, issue-number regression tests (deduped), E2E tests.
- 6 test files deleted outright (script-style/no-assert or fully
  redundant); conftest.py, fakes/, fixtures/ untouched.
- tests/acp/conftest.py added: autouse fixture stubs the live
  models.dev/GitHub/Copilot/Anthropic inventory fetches that ACP server
  tests performed on every session create — test_server.py 147s → 3.4s,
  and the tests are now genuinely hermetic.
- Sleep-based slowness shrunk where safe (codex_ttfb_watchdog,
  compression_concurrent_fork, etc.); no wall-clock assertion tightened.

Verification: full hermetic suite via scripts/run_tests.sh —
2439 files, 31,130 tests passed, 0 failed, 0 flaky retries, 315s wall
(baseline: 583s wall, 13,564s subprocess CPU).
2026-07-29 13:10:23 -07:00

66 lines
2.3 KiB
Python

"""Config integration tests — managed scope wins over user config at the leaf."""
import textwrap
import pytest
@pytest.fixture
def homes(tmp_path, monkeypatch):
home = tmp_path / "home"
home.mkdir()
managed = tmp_path / "managed"
managed.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
monkeypatch.setenv("HERMES_MANAGED_DIR", str(managed))
import hermes_cli.config as cfg
from hermes_cli import managed_scope
cfg._LOAD_CONFIG_CACHE.clear()
cfg._RAW_CONFIG_CACHE.clear()
managed_scope.invalidate_managed_cache()
return home, managed
def _write(path, body):
path.write_text(textwrap.dedent(body), encoding="utf-8")
import hermes_cli.config as cfg
from hermes_cli import managed_scope
cfg._LOAD_CONFIG_CACHE.clear()
cfg._RAW_CONFIG_CACHE.clear()
managed_scope.invalidate_managed_cache()
def test_managed_beats_user(homes):
from hermes_cli.config import load_config, cfg_get
home, managed = homes
_write(home / "config.yaml", "model:\n default: user/model\n")
_write(managed / "config.yaml", "model:\n default: managed/model\n")
assert cfg_get(load_config(), "model", "default") == "managed/model"
def test_managed_list_wins_wholesale(homes):
"""D3: a managed list value replaces the user's wholesale."""
from hermes_cli.config import load_config, cfg_get
home, managed = homes
_write(home / "config.yaml", "toolsets:\n enabled: [a, b, c]\n")
_write(managed / "config.yaml", "toolsets:\n enabled: [x]\n")
assert cfg_get(load_config(), "toolsets", "enabled") == ["x"]
def test_user_cannot_shadow_managed_literal_via_envref(homes, monkeypatch):
"""A managed literal must NOT be expandable via a ${VAR} the user controls.
The managed value is a plain literal 'managed/locked' with no ${...}, so a
user-defined env var has nothing to substitute. This asserts the managed
literal survives verbatim regardless of user env, and that managed wins.
"""
from hermes_cli.config import load_config, cfg_get
home, managed = homes
monkeypatch.setenv("EVIL", "user/override")
_write(home / "config.yaml", "model:\n default: ${EVIL}\n")
_write(managed / "config.yaml", "model:\n default: managed/locked\n")
assert cfg_get(load_config(), "model", "default") == "managed/locked"