hermes-agent/tests
teknium1 ed33ebca1d refactor: canonical config loaders for behavioral reads + guarded raw-read primitive (kills the managed-scope/env-expansion drift class)
The disease: ~15 scattered raw yaml.safe_load(config.yaml) reads that
silently miss managed-scope overlay, ${ENV_VAR} expansion, profile-aware
pathing, and root-model normalization. Every new config feature needed an
N-site sweep (incident chain 9cbcc0c9c8732293cf87b0e47a98f91928aa0443). This commit assigns every raw read to an owner and adds a
lint-guard test so the class cannot regrow.

New primitive (additive-only change to hermes_cli/config.py):
  read_user_config_raw(path=None) — reads the user file EXACTLY as
  written; docstring states it is ONLY legal for write-back round-trips
  and raw-file diagnostics. Behavioral reads must use
  load_config()/load_config_readonly().

BEHAVIOR FIXES (class-a sites migrated to a canonical loader — these
previously read values that could DIFFER from the effective config):

  gateway/run.py _try_resolve_fallback_provider → _load_gateway_runtime_config
    keys: fallback_providers/fallback_model (provider, model, base_url,
    api_key). Drift fixed: a managed-pinned fallback chain was ignored;
    an api_key of "${OPENROUTER_API_KEY}" reached the resolver unexpanded.
  gateway/run.py GatewayRunner._load_provider_routing → same loader
    key: provider_routing. Drift fixed: managed-pinned routing prefs and
    ${VAR} templates were ignored.
  gateway/run.py GatewayRunner._load_fallback_model → same loader
    keys: fallback chain. Same drift as above.
  gateway/run.py GatewayRunner._refresh_fallback_model
    keeps the raw primitive (its last-known-good-on-parse-failure contract
    forbids the fail-open loader, which returns {} on a torn write) but now
    applies managed overlay + env expansion inline. Drift fixed: chain
    edits under managed scope / env templates were previously frozen out.
  tui_gateway/server.py _load_cfg (72 behavioral call sites)
    now = raw read + managed overlay (pre-existing) + NEW ${VAR} expansion,
    split from a new _load_cfg_raw() write-back primitive. Drift fixed:
    e.g. custom_prompt: "hello ${VAR}", agent.system_prompt, model,
    api_key/base_url templates reached sessions unexpanded. DEFAULT_CONFIG
    is deliberately NOT merged (callers treat missing keys as unset;
    `_load_cfg() == {}` sentinels and _save_cfg round-trips depend on it).
  tui_gateway/server.py _profile_configured_cwd
    keys: terminal.cwd of a NON-launch profile. Drift fixed: managed
    overlay + ${VAR} expansion now apply (load_config() would resolve the
    wrong profile's home, so the raw primitive + inline pipeline is used).
  plugins/platforms/telegram/adapter.py _reload_dm_topics_from_config
    → load_config_readonly(). keys: platforms.telegram.extra.dm_topics.
    Drift fixed: managed overlay + profile-aware pathing + expansion.
  plugins/memory/holographic _load_plugin_config → load_config_readonly().
    keys: plugins.hermes-memory-store.*. Same drift class.

WRITE-BACK ROUND-TRIPS (class-b: stay raw BY DESIGN via read_user_config_raw;
merging defaults/overlay would pollute the saved user file):
  gateway/slash_commands.py: model persist x2, _save_gateway_config_key,
    memory/skills write_approval toggles
  gateway/platforms/yuanbao.py auto-sethome
  tui_gateway/server.py _write_config_key + all cfg→_save_cfg blocks
    (reasoning show/hide/full/clamp, details_mode[.section], prompt)
    → new _load_cfg_raw()
  plugins/memory/holographic save_config

RAW-FILE DIAGNOSTICS + presence-sensitive bridges (class-c: stay raw,
now via the shared primitive with an explanatory comment):
  hermes_cli/doctor.py x5 (model validation, stale-root-keys, .env drift,
    deprecation sweep, memory-provider probe — the latter two keep their
    inline managed overlay where they had one)
  gateway/run.py _bridge_max_turns_from_config and the module-level
    TERMINAL_*/HERMES_* env bridge (bridging merged defaults would export
    all of DEFAULT_CONFIG into the environment; both keep their inline
    overlay + expansion)
  hermes_cli/send_cmd.py env bridge (same presence-sensitivity)
  hermes_cli/gateway.py multiplex-conflict probe (reads the DEFAULT root's
    config, not the active profile's — load_config is the wrong owner)
  hermes_cli/profiles.py / hermes_cli/web_server.py / tools/wake_word.py
    multi-profile reads (load_config targets only the ACTIVE profile home)
  cron/jobs.py _resolve_default_model_snapshot and cron/scheduler.py
    run_job config read keep their existing inline overlay+expansion but
    now share the primitive (their fail-open + last-value semantics and
    the deliberate no-defaults merge are preserved exactly).

Failure-semantics audit: every migrated site preserves its exact previous
behavior on missing file ({} / early return) and parse failure (raise into
the caller's existing except, warn, last-known-good, or fail-open) —
read_user_config_raw intentionally mirrors bare open()+safe_load semantics
(raises on parse errors, {} only on FileNotFoundError/non-dict root).

Guard: tests/hermes_cli/test_config_read_guard.py scans the tree for
yaml.safe_load within 6 lines of a 'config.yaml' reference outside an
explicit ALLOWLIST (hermes_cli/config.py, gateway/config.py, gateway/run.py
fallback path, hermes_cli/managed_scope.py which reads the MANAGED file,
gateway/readiness.py parse-health probe) and fails on new offenders.

E2E: tests/hermes_cli/test_config_loader_e2e.py runs a subprocess with a
temp HERMES_HOME (config.yaml containing ${E2E_PROMPT_SUFFIX}) plus a
HERMES_MANAGED_DIR overlay pinning agent.reasoning_effort, asserting
tui _load_cfg resolves "hello world"/"high" while _load_cfg_raw +
_save_cfg round-trip the template and user value verbatim with no
managed/default leakage.
2026-07-29 10:53:29 -07:00
..
acp fix(acp): pin the session cwd for slash-command handlers too 2026-07-25 18:06:32 -07:00
acp_adapter feat(surfaces): route busy-input corrections through active-turn redirect 2026-07-22 12:10:58 -05:00
agent test: age the disk L2 entry too in the server-swap redetection test 2026-07-29 10:52:13 -07:00
ci fix(ci): report E2E evidence upload failures (#69901) 2026-07-23 05:45:17 +00:00
cli fix(cli): stop hard-wrapping streamed paragraphs; prefer OSC 52 over SSH 2026-07-29 08:42:16 -07:00
computer_use fix(computer_use): stop the cua-driver child on exit 2026-07-26 03:38:23 -05:00
conformance feat(conformance): vector generator — native renderers as executable spec (#71666) 2026-07-26 16:52:25 +10:00
cron Merge remote-tracking branch 'origin/main' into feat/gateway-health-diagnostics-monitoring 2026-07-29 15:37:14 +00:00
dashboard
docker fix(hermes_cli): heal root-owned logs/gateways on every stage2 boot 2026-07-27 19:19:01 +05:30
e2e test(relay): gate native Anthropic streaming in e2e 2026-07-28 08:25:25 -07:00
fakes
fixtures/plugins/example-dashboard/dashboard
gateway refactor(gateway): shared media-cache mime dispatch for adapter downloads (per-adapter overrides preserve historical mappings) 2026-07-29 10:14:59 -07:00
hermes_cli refactor: canonical config loaders for behavioral reads + guarded raw-read primitive (kills the managed-scope/env-expansion drift class) 2026-07-29 10:53:29 -07:00
hermes_state fix(state): heal alternation at the ACP / CLI-resume / TUI-resume restore sites too 2026-07-17 06:53:38 -07:00
honcho_plugin fix(honcho): default device-code poll interval to 5s when AS omits it 2026-07-24 07:53:12 -07:00
integration
manual
monitoring feat(monitoring): add hermes.gateway.background_delegations (unit/slot count) 2026-07-25 02:30:20 +00:00
openviking_plugin fix(openviking): cool down failed refreshes and publish conn identity atomically 2026-07-24 13:00:53 +05:30
plugins fix(desktop): honest browser-backend readiness + explicit backend activation + full OpenAI TTS voice/model options 2026-07-28 23:52:49 -07:00
providers fix(openrouter): give auxiliary calls the sticky routing key 2026-07-25 22:46:35 -07:00
run_agent test: de-pin aux default literals in provider-parity tests 2026-07-28 18:17:56 -07:00
scripts refactor: remove the claude-marketplace skill source (redundant Marketplace hub tab) 2026-07-28 23:16:27 -07:00
secret_sources feat(secrets): orchestrator-level preserve_existing + profile aliasing (#69058) 2026-07-22 03:20:45 -07:00
skills fix(cli): stop shredding an existing MEMORY.md on hermes import-agent 2026-07-29 16:49:07 +05:30
state fix(compression): recover rotated session lineage 2026-07-24 16:00:34 -07:00
stress
tools refactor: single build_subprocess_env() factory for all child-process spawns (profile + secret-scrub single owner) 2026-07-29 10:14:11 -07:00
tui_gateway test(gateway): change-watcher behavior contracts; align status-snapshot test with 60s cadence 2026-07-28 17:21:58 -05:00
website
__init__.py
conftest.py test: isolate computer-use approval globals between tests 2026-07-29 10:06:27 -07:00
run_interrupt_test.py
test_account_usage.py
test_atomic_replace_symlinks.py
test_audio_playback_guard.py fix(tests): stop the test suite speaking aloud and launching a browser 2026-07-28 14:07:21 -07:00
test_background_review_list_shapes.py
test_background_review_session_isolation.py
test_base_url_hostname.py
test_batch_runner_checkpoint.py
test_bitwarden_secrets.py fix(secrets): unify encrypted-cache fallback with the merged stale-cache path 2026-07-22 04:40:07 -07:00
test_cli_file_drop.py
test_cli_manual_compress.py test(cli): prove /compress type-ahead queue-drain; map contributor email 2026-07-23 07:24:46 -07:00
test_cli_skin_integration.py
test_code_skew.py
test_command_secret_source.py feat(secrets): rework command source as a registered SecretSource — no provider selector 2026-07-22 04:39:28 -07:00
test_conftest_wal_gate.py fix(tests): gate WAL-dependent tests on the linked SQLite's real capability 2026-07-25 07:17:52 -07:00
test_copilot_initiator.py
test_credential_file_permissions.py harden(slack): CDN-allowlist inbound file URLs, DNS-pin token downloads, widen token-file perms warning 2026-07-23 11:44:43 -07:00
test_ctx_halving_fix.py chore: restore test_ctx_halving_fix.py to main 2026-07-14 03:58:54 +05:30
test_delegate_cascade_49148.py
test_dispatch_session_id.py
test_empty_model_fallback.py feat(models): swap Gemini catalog entries to 3.1 Pro + 3.6 Flash; drop retired Qwen models 2026-07-28 10:07:18 -07:00
test_empty_session_hygiene.py
test_env_loader_applied_homes.py fix(secrets): mark _APPLIED_HOMES only after a real fetch attempt (#40597) (#69056) 2026-07-22 03:20:25 -07:00
test_env_loader_op_bootstrap.py
test_env_loader_secret_sources.py test(secrets): match real ApplyReport shape in isolation test 2026-07-22 04:39:17 -07:00
test_evidence_store.py
test_fast_safe_load.py
test_fts_cjk_bigram.py test(state): cover pure-Latin embedded-in-CJK recovery via the cjk index 2026-07-22 10:35:04 -07:00
test_gateway_streaming_nested_config.py fix(gateway): normalize YAML boolean streaming mode and keep enabled a mode-only alias 2026-07-20 05:39:09 -07:00
test_get_tool_definitions_cache_isolation.py
test_hermes_bootstrap.py test(install): add UTF-8 regression guard for skills_sync child path 2026-07-24 17:10:39 -07:00
test_hermes_constants.py fix(dashboard): keep custom themes visible after embedded chat starts (#60601) 2026-07-18 00:34:54 -04:00
test_hermes_home_profile_warning.py
test_hermes_logging.py
test_hermes_state.py fix(sessions): a pinned conversation can't be paged out of the list 2026-07-29 12:00:21 -05:00
test_hermes_state_compression_locks.py fix(compression-lock): reclaim crashed holders instead of stranding the lease 2026-07-25 22:47:07 -07:00
test_hermes_state_readonly_preflight.py fix(state): recover from read-only database files at startup 2026-07-27 17:27:38 -07:00
test_hermes_state_wal_fallback.py fix(state): make the byte-probe guard atomic, path-correct, and fail-closed 2026-07-25 21:44:43 -07:00
test_honcho_client_concurrency.py
test_honcho_client_config.py feat(honcho): make latency-adding paths configurable 2026-07-16 12:48:48 -07:00
test_honcho_session_context.py
test_honcho_startup_fail_open.py fix(ci): make tests, workflows, and attribution reliable under load (#66373) 2026-07-17 20:55:24 +00:00
test_install_autostash_conflict_recovery.py test: add happy-path + no-markers coverage for autostash recovery 2026-07-18 19:18:03 +05:30
test_install_diverged_update.py
test_install_lockfile_churn.py
test_install_macos_launcher.py fix(install): avoid realpath-dependent uv launcher on macOS 2026-07-26 19:30:32 -07:00
test_install_no_initial_commit.py
test_install_ps1_ascii_only.py fix(install): keep install.ps1 pure ASCII so Windows PowerShell 5.1 doesn't misparse it 2026-07-18 18:40:59 -04:00
test_install_ps1_native_stderr_eap.py
test_install_ps1_node_path_for_npm.py
test_install_ps1_python_fallback_venv.py
test_install_ps1_uv_powershell_host.py
test_install_ps1_web_server_syntax_probe.py
test_install_sh_acp_launcher.py fix(install): install a hermes-acp launcher onto PATH 2026-07-28 11:53:12 -07:00
test_install_sh_bootstrap_marker.py fix(install): stamp the bootstrap-complete marker from install.sh too 2026-07-26 16:06:50 -05:00
test_install_sh_browser_install.py
test_install_sh_install_method_stamp.py
test_install_sh_node_global_prefix.py
test_install_sh_pythonpath_sanitization.py
test_install_sh_root_fhs_uv_python_path.py
test_install_sh_setup_wizard_tty_probe.py
test_install_sh_symlink_stomp.py
test_install_sh_termux_network_prereqs.py
test_install_unmerged_index.py
test_ipv4_preference.py
test_iron_proxy.py Reapply "Merge pull request #30179 from NousResearch/feat/iron-proxy" 2026-07-24 09:49:00 -07:00
test_iron_proxy_cli.py Reapply "Merge pull request #30179 from NousResearch/feat/iron-proxy" 2026-07-24 09:49:00 -07:00
test_iron_proxy_e2e.py Reapply "Merge pull request #30179 from NousResearch/feat/iron-proxy" 2026-07-24 09:49:00 -07:00
test_lazy_session_regressions.py fix(desktop): persist @image: refs instead of the vision-enrichment text 2026-07-24 21:20:52 -05:00
test_lint_config.py
test_live_system_guard_self_test.py fix(tests): make the live-system-guard canary fail closed 2026-07-21 12:15:46 +05:30
test_mcp_serve.py
test_mini_swe_runner.py
test_minimax_model_validation.py
test_minimax_oauth.py
test_minisweagent_path.py
test_model_forces_max_completion_tokens.py
test_model_picker_scroll.py
test_model_tools.py Reapply "feat(observability): integrate NeMo Relay runtime and shared metrics" 2026-07-27 21:10:51 -07:00
test_model_tools_async_bridge.py
test_ollama_num_ctx.py
test_onepassword_secrets.py fix(secrets): pass OP_LOAD_DESKTOP_APP_SETTINGS through to the op child env 2026-07-22 03:19:32 -07:00
test_output_cap_parsing.py
test_packaging_build_guard.py rip out brew + pip/PyPI wheel support (#68217) 2026-07-22 16:51:01 -04:00
test_packaging_metadata.py fix(deps): move CVE pins to current fixed versions so update stops downgrading patched envs 2026-07-26 19:29:07 -07:00
test_plugin_skills.py
test_plugin_utils.py
test_process_loop_event_loop_warning.py
test_profile_isolation_runtime.py
test_project_metadata.py Reapply "feat(observability): integrate NeMo Relay runtime and shared metrics" 2026-07-27 21:10:51 -07:00
test_pty_keepalive_ws.py fix(dashboard): scope chat attach tokens by session (#60745) 2026-07-16 19:48:47 -04:00
test_pty_session.py
test_retry_utils.py refactor: single shared Retry-After parser 2026-07-29 10:13:50 -07:00
test_run_tests_parallel.py fix(tests): a run that collects nothing can no longer look green 2026-07-25 07:09:22 -07:00
test_sanitize_tool_error.py
test_search_slow_query_log.py feat(state): messages_fts_cjk — CJK-bigram index on the v23 external-content layout 2026-07-22 07:56:47 -07:00
test_session_db_read_path_split.py fix: follow-up for PR #65541 — track read conns, convert remaining read paths, mark WAL tests 2026-07-28 20:29:44 +05:30
test_session_skill_previews.py fix(sessions): keep the skill body out of session previews 2026-07-26 02:58:20 -05:00
test_session_workspace_binding.py
test_slack_thread_require_mention.py Add Slack thread mention gating 2026-07-22 21:14:44 -07:00
test_slash_worker_watchdog.py test(tui): keep watchdog checks behavior-focused 2026-07-18 04:15:13 -07:00
test_sql_injection.py
test_sqlite_lock_safe_inspection.py fix(state): make the byte-probe guard atomic, path-correct, and fail-closed 2026-07-25 21:44:43 -07:00
test_sqlite_wal_reset_gate.py fix(state): make the byte-probe guard atomic, path-correct, and fail-closed 2026-07-25 21:44:43 -07:00
test_stale_utils_module_import.py
test_state_db_malformed_repair.py perf(state): external-content FTS + tool-row-free trigram index (schema v23) (#65798) 2026-07-22 04:42:50 -07:00
test_subprocess_home_isolation.py
test_telegram_polling_progress_ptb.py test(telegram): gate slots premise assert on runtimes without instance __dict__ 2026-07-14 21:25:44 -07:00
test_termux_all_extra_compat.py
test_timezone.py
test_tini_shim.py test(docker): cover tini -g legacy entrypoint boot path 2026-07-18 01:11:03 -07:00
test_toolset_distributions.py
test_toolsets.py docs(xai): clarify x_search vs xurl routing without schema cross-refs 2026-07-23 21:06:47 -07:00
test_trajectory_compressor.py fix(compaction): skip compression when it can't reduce tokens 2026-07-23 16:21:03 -07:00
test_trajectory_compressor_async.py
test_transform_llm_output_hook.py
test_transform_tool_result_hook.py
test_tui_entry_mcp_owner.py fix(tui): gate the shared-owner MCP discovery wait on the stdio TUI flag 2026-07-21 12:43:27 -07:00
test_tui_gateway_loop_noise.py
test_tui_gateway_queue_on_busy.py fix(delegate): isolate async batches from parent interrupts 2026-07-28 14:20:10 -07:00
test_tui_gateway_server.py fix(voice): full-duplex agent-turn listener — interrupt by voice during generation AND playback 2026-07-29 10:08:53 -07:00
test_tui_gateway_ws.py fix(wake-word): enforce single-owner lifecycle 2026-07-28 07:58:01 -07:00
test_tui_mcp_late_refresh.py
test_utils_truthy_values.py
test_voice_max_recording_seconds.py fix(voice): enforce voice.max_recording_seconds (was dead config) 2026-07-28 11:57:37 -07:00
test_wal_checkpoint_strategy.py fix(state): use PASSIVE checkpoint for periodic WAL flush to prevent B-tree corruption 2026-07-15 04:55:46 -07:00
test_web_server.py fix(web): raise uvicorn WS frame cap for Desktop file.attach 2026-07-28 19:20:14 -05:00
test_web_server_sessiondb_eventloop.py Merge pull request #65893 from NousResearch/bb/salvage-63082-sessiondb-offload 2026-07-16 15:23:32 -04:00
test_windows_subprocess_no_window_flags.py fix(cron): respect the platform-conditional decode design in _run_job_script + taskkill kwarg snapshot 2026-07-24 11:45:57 -07:00
test_yaml_indent_consistency_31999.py
test_yuanbao_integration.py
test_yuanbao_markdown.py
test_yuanbao_pipeline.py
test_yuanbao_proto.py
test_yuanbao_reconnect_set_active.py
test_yuanbao_shutdown.py
test_zeroed_state_db.py fix(state): quarantine lock fails closed when unacquireable (#68805) 2026-07-24 23:06:05 -07:00