fix(update): the import-health probe never resolves external secret sources
Port of main's guard into update_cmd_validation: the probe child sets sys.argv to the updater's contract before importing hermes_cli.main, so the startup dotenv load does not run op/bws/command helpers. Tests follow the validation module and the run_completion seam; the unused isolated_update_runtime fixture referenced retired names and goes.
This commit is contained in:
@@ -25,6 +25,10 @@ def _critical_module_import_failures(
|
||||
marker = f"__HERMES_IMPORT_HEALTH_{secrets.token_hex(16)}__"
|
||||
probe = (
|
||||
"import importlib, json, sys\n"
|
||||
# Importing hermes_cli.main runs the startup dotenv load, which pulls external secret
|
||||
# sources (op/bws/command helpers, up to 120s each) unless argv says ``update``. The
|
||||
# probe only checks importability, so it inherits the updater's own argv contract.
|
||||
"sys.argv = ['hermes', 'update']\n"
|
||||
"failures = []\n"
|
||||
"for name in %r:\n"
|
||||
" try:\n"
|
||||
|
||||
Reference in New Issue
Block a user