test(state): trim holder-scope suite to the two behaviour contracts
Keep the two invariant tests from #105428: a genuine second instance whose argv is scoped to another HERMES_HOME is not a holder of our state.db; argv that names our state.db stays flagged. The helper-shape tests were change-detectors on `_argv_scoped_to_other_home` internals. The salvaged commit is re-authored to TaoMasterCoder's GitHub noreply identity: the original `devops@77hub.com` is a shared org address (misconfigured local git, not malice). Refs #107440
This commit is contained in:
@@ -119,25 +119,6 @@ class TestUninspectableHolderInstanceScope:
|
||||
holders = hermes_state_holders.foreign_state_db_holders(db_path)
|
||||
assert holders == []
|
||||
|
||||
def test_other_instance_venv_argv_is_not_a_holder(self, tmp_path, monkeypatch):
|
||||
db_path = tmp_path / "state.db"
|
||||
_install_fake_proc(monkeypatch, tmp_path, unreadable_pids=(222,))
|
||||
_install_fake_argv(monkeypatch, {222: DEMO_VENV_ARGV})
|
||||
|
||||
holders = hermes_state_holders.foreign_state_db_holders(db_path)
|
||||
assert holders == []
|
||||
|
||||
def test_uninspectable_descriptor_other_instance_is_not_a_holder(
|
||||
self, tmp_path, monkeypatch
|
||||
):
|
||||
"""Sibling branch: fd listable but readlink EACCES — same scoping."""
|
||||
db_path = tmp_path / "state.db"
|
||||
_install_fake_proc(monkeypatch, tmp_path, fd_pids=(222,))
|
||||
_install_fake_argv(monkeypatch, {222: DEMO_HOME_ARGV})
|
||||
|
||||
holders = hermes_state_holders.foreign_state_db_holders(db_path)
|
||||
assert holders == []
|
||||
|
||||
def test_argv_referencing_our_db_stays_flagged(self, tmp_path, monkeypatch):
|
||||
"""A (possibly second) instance whose argv names OUR state.db, our
|
||||
sidecars, or our home must still be fail-closed flagged."""
|
||||
@@ -156,115 +137,3 @@ class TestUninspectableHolderInstanceScope:
|
||||
holders = hermes_state_holders.foreign_state_db_holders(db_path)
|
||||
assert [pid for pid, _ in holders] == [222], argv
|
||||
assert holders[0][1].startswith("uninspectable holder:"), argv
|
||||
|
||||
def test_ambiguous_argv_without_absolute_paths_stays_flagged(
|
||||
self, tmp_path, monkeypatch
|
||||
):
|
||||
"""Conservative behavior unchanged: argv with no absolute paths can
|
||||
not disprove the suspicion, so the holder is still reported."""
|
||||
db_path = tmp_path / "state.db"
|
||||
_install_fake_proc(monkeypatch, tmp_path, unreadable_pids=(222,))
|
||||
_install_fake_argv(monkeypatch, {222: AMBIGUOUS_ARGV})
|
||||
|
||||
holders = hermes_state_holders.foreign_state_db_holders(db_path)
|
||||
assert [pid for pid, _ in holders] == [222]
|
||||
assert holders[0][1].startswith("uninspectable holder:")
|
||||
|
||||
def test_uninspectable_descriptor_ambiguous_argv_stays_flagged(
|
||||
self, tmp_path, monkeypatch
|
||||
):
|
||||
db_path = tmp_path / "state.db"
|
||||
_install_fake_proc(monkeypatch, tmp_path, fd_pids=(222,))
|
||||
_install_fake_argv(monkeypatch, {222: AMBIGUOUS_ARGV})
|
||||
|
||||
holders = hermes_state_holders.foreign_state_db_holders(db_path)
|
||||
assert [pid for pid, _ in holders] == [222]
|
||||
assert holders[0][1].startswith("uninspectable descriptor:")
|
||||
|
||||
|
||||
class TestArgvScopedToOtherHome:
|
||||
"""Unit contract for the pure scoping helper."""
|
||||
|
||||
def test_helper_exists_and_is_pure(self, tmp_path):
|
||||
db_path = tmp_path / "state.db"
|
||||
helper = hermes_state_holders._argv_scoped_to_other_home
|
||||
# No /proc access needed: pure function of (argv, db_path).
|
||||
assert helper([], db_path) is False
|
||||
assert helper(["hermes", "gateway"], db_path) is False
|
||||
|
||||
def test_relative_tokens_are_ignored(self, tmp_path):
|
||||
"""A relative-looking 'hermes' token cannot prove instance scope."""
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
["hermes", ".hermes/relative/config.yaml", "gateway"], db_path
|
||||
)
|
||||
is False
|
||||
)
|
||||
|
||||
def test_token_equal_to_our_db_wal_keeps_flag(self, tmp_path):
|
||||
"""A sidecar of OUR db referenced by an other-home binary is still
|
||||
our problem — any reference to ours vetoes the exemption."""
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
["/home/demo/.hermes/hermes-agent/hermes", f"{db_path}-wal"], db_path
|
||||
)
|
||||
is False
|
||||
)
|
||||
|
||||
def test_other_home_and_our_home_tokens_together_keep_flag(self, tmp_path):
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
[
|
||||
"/home/demo/.hermes/hermes-agent/hermes",
|
||||
"--state-dir",
|
||||
str(tmp_path),
|
||||
],
|
||||
db_path,
|
||||
)
|
||||
is False
|
||||
)
|
||||
|
||||
def test_pure_other_home_is_scoped_elsewhere(self, tmp_path):
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
DEMO_HOME_ARGV, db_path
|
||||
)
|
||||
is True
|
||||
)
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
DEMO_VENV_ARGV, db_path
|
||||
)
|
||||
is True
|
||||
)
|
||||
|
||||
def test_other_home_state_db_token_is_scoped_elsewhere(self, tmp_path):
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
["hermes", "vacuum", "/home/demo/.hermes/state.db"], db_path
|
||||
)
|
||||
is True
|
||||
)
|
||||
|
||||
def test_our_db_path_token_keeps_flag(self, tmp_path):
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
["/home/demo/.hermes/hermes-agent/hermes", str(db_path)], db_path
|
||||
)
|
||||
is False
|
||||
)
|
||||
|
||||
def test_our_shm_sidecar_token_keeps_flag(self, tmp_path):
|
||||
db_path = tmp_path / "state.db"
|
||||
assert (
|
||||
hermes_state_holders._argv_scoped_to_other_home(
|
||||
["python3", "run_agent.py", f"{db_path}-shm"], db_path
|
||||
)
|
||||
is False
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user