From 2dbfd3b4aabcd3ee7c364c08b98d11f9c695455c Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Thu, 3 Sep 2026 09:50:40 -0700 Subject: [PATCH] =?UTF-8?q?review-fix(suppress-audit):=20backup/mcp=5Foaut?= =?UTF-8?q?h/wake=5Fword/run=5Fnotifications=20=E2=80=94=20restore=20BASE?= =?UTF-8?q?=20exception=20semantics?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- gateway/run_notifications.py | 2 +- hermes_cli/backup.py | 36 +++++++++++++++++++++++++----------- tools/mcp_oauth.py | 14 ++++++++------ tools/wake_word.py | 11 ++++++++--- 4 files changed, 42 insertions(+), 21 deletions(-) diff --git a/gateway/run_notifications.py b/gateway/run_notifications.py index 7dc18f0366..1f8be3857e 100644 --- a/gateway/run_notifications.py +++ b/gateway/run_notifications.py @@ -372,7 +372,7 @@ class GatewayNotificationsMixin: chat_id = pending.get("chat_id") session_key = pending.get("session_key") if not (platform_str and chat_id): - return None + continue # BASE: an incomplete marker falls through to the next path, not "unresolved" platform = Platform(platform_str) adapter = self.adapters.get(platform) if not adapter: diff --git a/hermes_cli/backup.py b/hermes_cli/backup.py index 5af0a41f5b..7e564f2d81 100644 --- a/hermes_cli/backup.py +++ b/hermes_cli/backup.py @@ -192,10 +192,17 @@ def _collect_memory_provider_external_paths() -> List[Path]: return [] out: Dict[Path, Path] = {} # resolved -> first declared spelling for raw in declared: - with suppress(Exception): + try: p = Path(raw).expanduser() - if p.exists(): - out.setdefault(p.resolve(), p) + except Exception: + continue + if not p.exists(): + continue + try: + resolved = p.resolve() + except (OSError, ValueError): + continue + out.setdefault(resolved, p) return list(out.values()) @@ -410,11 +417,14 @@ def _foreign_db_holder_pids(db_path: Path) -> Optional[List[int]]: def _canonical(path: str) -> str: return os.path.normcase(os.path.abspath(path.removesuffix(" (deleted)"))) - def _holds_watched(fd_dir: str) -> bool: - for fd in os.listdir(fd_dir): - with suppress(OSError): - if _canonical(os.readlink(f"{fd_dir}/{fd}")) in watched: - return True + def _holds_watched(fds: List[str], fd_dir: str) -> bool: + for fd in fds: + try: + target = os.readlink(f"{fd_dir}/{fd}") + except OSError: + continue + if _canonical(target) in watched: + return True return False canonical_db = _canonical(os.fspath(db_path)) @@ -425,9 +435,13 @@ def _foreign_db_holder_pids(db_path: Path) -> Optional[List[int]]: for pid_str in os.listdir("/proc"): if not pid_str.isdigit() or int(pid_str) == own_pid: continue - with suppress(OSError): - if _holds_watched(f"/proc/{pid_str}/fd"): - pids.append(int(pid_str)) + fd_dir = f"/proc/{pid_str}/fd" + try: + fds = os.listdir(fd_dir) + except OSError: + continue + if _holds_watched(fds, fd_dir): + pids.append(int(pid_str)) except OSError: return None return pids diff --git a/tools/mcp_oauth.py b/tools/mcp_oauth.py index 47cd867670..dbd8917de3 100644 --- a/tools/mcp_oauth.py +++ b/tools/mcp_oauth.py @@ -157,13 +157,15 @@ def _cached_redirect(storage: "HermesTokenStorage | None") -> "tuple[str | None, it gets ``redirect_uri does not match any registered URIs``.""" uri = port = None for raw in (_cached_client_info(storage) or {}).get("redirect_uris") or []: - with contextlib.suppress(TypeError, ValueError): + try: parsed = urlparse(str(raw)) - if uri is None and parsed.scheme == "https" and parsed.netloc: - uri = str(raw) - is_loopback_callback = parsed.scheme == "http" and parsed.path == "/callback" and parsed.hostname in {"127.0.0.1", "localhost"} - if port is None and is_loopback_callback and parsed.port is not None: - port = int(parsed.port) + except (TypeError, ValueError): + continue + if uri is None and parsed.scheme == "https" and parsed.netloc: + uri = str(raw) + is_loopback_callback = parsed.scheme == "http" and parsed.path == "/callback" and parsed.hostname in {"127.0.0.1", "localhost"} + if port is None and is_loopback_callback and parsed.port is not None: + port = int(parsed.port) return uri, port diff --git a/tools/wake_word.py b/tools/wake_word.py index a5ec2589a5..b7dc391a32 100644 --- a/tools/wake_word.py +++ b/tools/wake_word.py @@ -497,8 +497,10 @@ class WakeWordDetector: try: self._audio_q.put_nowait(chunk) except Exception: - with suppress(Exception): # full: drop the oldest frame, then retry once + # Drop oldest on overflow so we stay real-time + with suppress(Exception): self._audio_q.get_nowait() + with suppress(Exception): self._audio_q.put_nowait(chunk) def start(self) -> None: @@ -703,9 +705,12 @@ def _acquire_machine_lock(path: Optional[Path] = None): def _release_machine_lock(handle) -> None: if handle is None: return - with suppress(OSError): + try: _flock(handle, False) - handle.close() + except OSError: + pass + finally: + handle.close() def _teardown_locked(close: Callable[[], None]) -> None: