tests: fold the retired opt-out and the removed rollback out of the mirroring suites

The cron guidance, the eager-activation guard and the launch-env freeze test all encoded
the pre-ruling behaviour: a `false` that disarmed the credential guard, and a "LEGACY
(pre-multiplex topology)" per-profile install the status output no longer offers.
This commit is contained in:
teknium1
2026-09-21 08:00:53 -07:00
committed by Teknium
parent ed703493da
commit 9ac5cea9e0
4 changed files with 18 additions and 13 deletions

View File

@@ -153,7 +153,7 @@ _runtime_status_state: Optional[dict[str, Any]] = None
def _merge_over_on_disk(path: Path, payload: dict[str, Any]) -> dict[str, Any]:
"""Lay the canonical snapshot over whatever is on disk right before writing. Out-of-process
writers (``hermes gateway migrate --standalone`` clearing multiplex-owned status, container_boot
writers (the migration's compensator clearing multiplex-owned status, container_boot
seeding ``desired_state``) stamp this file directly; the gateway's fields win, theirs survive."""
existing = _read_json_file(path)
return {**existing, **payload} if isinstance(existing, dict) else payload

View File

@@ -73,9 +73,12 @@ def test_status_preserves_profile_health_contract(served_root, capsys, monkeypat
assert "hermes --profile default gateway install" in output
assert "sudo hermes --profile default gateway install --system" in output
assert "hermes --profile default gateway run" in output
assert "hermes --profile default gateway restart" in output
# The per-profile service is offered only as the LEGACY second-process topology.
assert "LEGACY (pre-multiplex topology, not recommended)" in output
# Multiplex-only: a per-profile service is not offered at all any more, not even as a
# "legacy" fallback -- the one host gateway is the only topology, and an old per-profile
# install is something to FOLD IN, not something to reinstall.
assert "gateway migrate --multiplex" in output
assert "LEGACY" not in output
assert "hermes gateway install # starts a SECOND gateway" not in output
if mode == "external":
assert "managed scheduler" in output
assert "STALLED" not in output
@@ -143,9 +146,10 @@ def test_standalone_guidance_matches_profile_membership(served_root, monkeypatch
cron_status()
output = capsys.readouterr().out
assert "hermes --profile default gateway install" in output
assert ("hermes --profile default gateway restart" in output) == (home_kind == "named")
# A served/named profile is never told to start a SECOND host process except as LEGACY.
assert ("LEGACY (pre-multiplex topology, not recommended)" in output) == (home_kind == "named")
# A named profile is told the host gateway serves it and how to fold an older per-profile
# install in; it is never offered a second host process, legacy or otherwise.
assert ("gateway migrate --multiplex" in output) == (home_kind == "named")
assert "LEGACY" not in output
@pytest.mark.parametrize("detail", ["unreachable " * 30 + "\nsecret second line", ""])

View File

@@ -23,7 +23,6 @@ def test_boot_time_credential_injection_is_inside_the_frozen_launch_env(tmp_path
# A two-profile host, without touching the live install's profiles/.
monkeypatch.setattr(launch_profile_policy, "_servable_profile_homes",
lambda: {tmp_path / "a", tmp_path / "b"})
monkeypatch.setattr(launch_profile_policy, "_multiplex_disabled_explicitly", lambda: False)
# Stand-ins for the boot steps that follow the old (top-of-function) activation point. A
# provider key injected by the auth gate / keepalive / a lifespan hook is the real case.

View File

@@ -32,16 +32,18 @@ def test_activates_for_a_real_second_profile(two_profile_host):
assert secret_scope.is_multiplex_active()
def test_multiplex_disabled_in_config_is_honoured(two_profile_host, monkeypatch):
"""A host that pinned ``gateway.multiplex_profiles: false`` keeps per-profile gateways AND
per-profile credential semantics; arming the guard there breaks legitimate unscoped reads."""
def test_the_retired_opt_out_no_longer_disarms_the_credential_guard(two_profile_host, monkeypatch):
"""``gateway.multiplex_profiles: false`` is retired as a topology opt-out, so it must not
disarm this guard: a multi-home host that skipped activation because of a stale ``false``
would serve the second profile with the LAUNCH profile's credentials -- the exact fail-open
the guard exists to prevent. The host is multi-profile; that is the whole question."""
(two_profile_host / "config.yaml").write_text("{}\n", encoding="utf-8")
from hermes_cli import config as cfg_mod
monkeypatch.setattr(cfg_mod, "load_config", lambda *a, **k: {"gateway": {"multiplex_profiles": False}})
assert launch_profile_policy.activate_multi_profile_hosting_eagerly() is False
assert not secret_scope.is_multiplex_active()
assert launch_profile_policy.activate_multi_profile_hosting_eagerly() is True
assert secret_scope.is_multiplex_active()
def test_a_crashed_profile_create_shell_is_not_a_second_tenant(two_profile_host):