test(state): trim holder-scope suite to the two behaviour contracts

Keep the two invariant tests from #105428: a genuine second instance
whose argv is scoped to another HERMES_HOME is not a holder of our
state.db; argv that names our state.db stays flagged. The helper-shape
tests were change-detectors on `_argv_scoped_to_other_home` internals.

The salvaged commit is re-authored to TaoMasterCoder's GitHub noreply
identity: the original `devops@77hub.com` is a shared org address
(misconfigured local git, not malice).

Refs #107440
This commit is contained in:
Teknium
2026-09-11 02:12:12 -07:00
parent 085623a11a
commit 902eccae3f

View File

@@ -119,25 +119,6 @@ class TestUninspectableHolderInstanceScope:
holders = hermes_state_holders.foreign_state_db_holders(db_path)
assert holders == []
def test_other_instance_venv_argv_is_not_a_holder(self, tmp_path, monkeypatch):
db_path = tmp_path / "state.db"
_install_fake_proc(monkeypatch, tmp_path, unreadable_pids=(222,))
_install_fake_argv(monkeypatch, {222: DEMO_VENV_ARGV})
holders = hermes_state_holders.foreign_state_db_holders(db_path)
assert holders == []
def test_uninspectable_descriptor_other_instance_is_not_a_holder(
self, tmp_path, monkeypatch
):
"""Sibling branch: fd listable but readlink EACCES — same scoping."""
db_path = tmp_path / "state.db"
_install_fake_proc(monkeypatch, tmp_path, fd_pids=(222,))
_install_fake_argv(monkeypatch, {222: DEMO_HOME_ARGV})
holders = hermes_state_holders.foreign_state_db_holders(db_path)
assert holders == []
def test_argv_referencing_our_db_stays_flagged(self, tmp_path, monkeypatch):
"""A (possibly second) instance whose argv names OUR state.db, our
sidecars, or our home must still be fail-closed flagged."""
@@ -156,115 +137,3 @@ class TestUninspectableHolderInstanceScope:
holders = hermes_state_holders.foreign_state_db_holders(db_path)
assert [pid for pid, _ in holders] == [222], argv
assert holders[0][1].startswith("uninspectable holder:"), argv
def test_ambiguous_argv_without_absolute_paths_stays_flagged(
self, tmp_path, monkeypatch
):
"""Conservative behavior unchanged: argv with no absolute paths can
not disprove the suspicion, so the holder is still reported."""
db_path = tmp_path / "state.db"
_install_fake_proc(monkeypatch, tmp_path, unreadable_pids=(222,))
_install_fake_argv(monkeypatch, {222: AMBIGUOUS_ARGV})
holders = hermes_state_holders.foreign_state_db_holders(db_path)
assert [pid for pid, _ in holders] == [222]
assert holders[0][1].startswith("uninspectable holder:")
def test_uninspectable_descriptor_ambiguous_argv_stays_flagged(
self, tmp_path, monkeypatch
):
db_path = tmp_path / "state.db"
_install_fake_proc(monkeypatch, tmp_path, fd_pids=(222,))
_install_fake_argv(monkeypatch, {222: AMBIGUOUS_ARGV})
holders = hermes_state_holders.foreign_state_db_holders(db_path)
assert [pid for pid, _ in holders] == [222]
assert holders[0][1].startswith("uninspectable descriptor:")
class TestArgvScopedToOtherHome:
"""Unit contract for the pure scoping helper."""
def test_helper_exists_and_is_pure(self, tmp_path):
db_path = tmp_path / "state.db"
helper = hermes_state_holders._argv_scoped_to_other_home
# No /proc access needed: pure function of (argv, db_path).
assert helper([], db_path) is False
assert helper(["hermes", "gateway"], db_path) is False
def test_relative_tokens_are_ignored(self, tmp_path):
"""A relative-looking 'hermes' token cannot prove instance scope."""
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
["hermes", ".hermes/relative/config.yaml", "gateway"], db_path
)
is False
)
def test_token_equal_to_our_db_wal_keeps_flag(self, tmp_path):
"""A sidecar of OUR db referenced by an other-home binary is still
our problem — any reference to ours vetoes the exemption."""
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
["/home/demo/.hermes/hermes-agent/hermes", f"{db_path}-wal"], db_path
)
is False
)
def test_other_home_and_our_home_tokens_together_keep_flag(self, tmp_path):
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
[
"/home/demo/.hermes/hermes-agent/hermes",
"--state-dir",
str(tmp_path),
],
db_path,
)
is False
)
def test_pure_other_home_is_scoped_elsewhere(self, tmp_path):
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
DEMO_HOME_ARGV, db_path
)
is True
)
assert (
hermes_state_holders._argv_scoped_to_other_home(
DEMO_VENV_ARGV, db_path
)
is True
)
def test_other_home_state_db_token_is_scoped_elsewhere(self, tmp_path):
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
["hermes", "vacuum", "/home/demo/.hermes/state.db"], db_path
)
is True
)
def test_our_db_path_token_keeps_flag(self, tmp_path):
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
["/home/demo/.hermes/hermes-agent/hermes", str(db_path)], db_path
)
is False
)
def test_our_shm_sidecar_token_keeps_flag(self, tmp_path):
db_path = tmp_path / "state.db"
assert (
hermes_state_holders._argv_scoped_to_other_home(
["python3", "run_agent.py", f"{db_path}-shm"], db_path
)
is False
)