tests: fold the retired opt-out and the removed rollback out of the mirroring suites
The cron guidance, the eager-activation guard and the launch-env freeze test all encoded the pre-ruling behaviour: a `false` that disarmed the credential guard, and a "LEGACY (pre-multiplex topology)" per-profile install the status output no longer offers.
This commit is contained in:
@@ -153,7 +153,7 @@ _runtime_status_state: Optional[dict[str, Any]] = None
|
||||
|
||||
def _merge_over_on_disk(path: Path, payload: dict[str, Any]) -> dict[str, Any]:
|
||||
"""Lay the canonical snapshot over whatever is on disk right before writing. Out-of-process
|
||||
writers (``hermes gateway migrate --standalone`` clearing multiplex-owned status, container_boot
|
||||
writers (the migration's compensator clearing multiplex-owned status, container_boot
|
||||
seeding ``desired_state``) stamp this file directly; the gateway's fields win, theirs survive."""
|
||||
existing = _read_json_file(path)
|
||||
return {**existing, **payload} if isinstance(existing, dict) else payload
|
||||
|
||||
@@ -73,9 +73,12 @@ def test_status_preserves_profile_health_contract(served_root, capsys, monkeypat
|
||||
assert "hermes --profile default gateway install" in output
|
||||
assert "sudo hermes --profile default gateway install --system" in output
|
||||
assert "hermes --profile default gateway run" in output
|
||||
assert "hermes --profile default gateway restart" in output
|
||||
# The per-profile service is offered only as the LEGACY second-process topology.
|
||||
assert "LEGACY (pre-multiplex topology, not recommended)" in output
|
||||
# Multiplex-only: a per-profile service is not offered at all any more, not even as a
|
||||
# "legacy" fallback -- the one host gateway is the only topology, and an old per-profile
|
||||
# install is something to FOLD IN, not something to reinstall.
|
||||
assert "gateway migrate --multiplex" in output
|
||||
assert "LEGACY" not in output
|
||||
assert "hermes gateway install # starts a SECOND gateway" not in output
|
||||
if mode == "external":
|
||||
assert "managed scheduler" in output
|
||||
assert "STALLED" not in output
|
||||
@@ -143,9 +146,10 @@ def test_standalone_guidance_matches_profile_membership(served_root, monkeypatch
|
||||
cron_status()
|
||||
output = capsys.readouterr().out
|
||||
assert "hermes --profile default gateway install" in output
|
||||
assert ("hermes --profile default gateway restart" in output) == (home_kind == "named")
|
||||
# A served/named profile is never told to start a SECOND host process except as LEGACY.
|
||||
assert ("LEGACY (pre-multiplex topology, not recommended)" in output) == (home_kind == "named")
|
||||
# A named profile is told the host gateway serves it and how to fold an older per-profile
|
||||
# install in; it is never offered a second host process, legacy or otherwise.
|
||||
assert ("gateway migrate --multiplex" in output) == (home_kind == "named")
|
||||
assert "LEGACY" not in output
|
||||
|
||||
|
||||
@pytest.mark.parametrize("detail", ["unreachable " * 30 + "\nsecret second line", ""])
|
||||
|
||||
@@ -23,7 +23,6 @@ def test_boot_time_credential_injection_is_inside_the_frozen_launch_env(tmp_path
|
||||
# A two-profile host, without touching the live install's profiles/.
|
||||
monkeypatch.setattr(launch_profile_policy, "_servable_profile_homes",
|
||||
lambda: {tmp_path / "a", tmp_path / "b"})
|
||||
monkeypatch.setattr(launch_profile_policy, "_multiplex_disabled_explicitly", lambda: False)
|
||||
|
||||
# Stand-ins for the boot steps that follow the old (top-of-function) activation point. A
|
||||
# provider key injected by the auth gate / keepalive / a lifespan hook is the real case.
|
||||
|
||||
@@ -32,16 +32,18 @@ def test_activates_for_a_real_second_profile(two_profile_host):
|
||||
assert secret_scope.is_multiplex_active()
|
||||
|
||||
|
||||
def test_multiplex_disabled_in_config_is_honoured(two_profile_host, monkeypatch):
|
||||
"""A host that pinned ``gateway.multiplex_profiles: false`` keeps per-profile gateways AND
|
||||
per-profile credential semantics; arming the guard there breaks legitimate unscoped reads."""
|
||||
def test_the_retired_opt_out_no_longer_disarms_the_credential_guard(two_profile_host, monkeypatch):
|
||||
"""``gateway.multiplex_profiles: false`` is retired as a topology opt-out, so it must not
|
||||
disarm this guard: a multi-home host that skipped activation because of a stale ``false``
|
||||
would serve the second profile with the LAUNCH profile's credentials -- the exact fail-open
|
||||
the guard exists to prevent. The host is multi-profile; that is the whole question."""
|
||||
(two_profile_host / "config.yaml").write_text("{}\n", encoding="utf-8")
|
||||
from hermes_cli import config as cfg_mod
|
||||
|
||||
monkeypatch.setattr(cfg_mod, "load_config", lambda *a, **k: {"gateway": {"multiplex_profiles": False}})
|
||||
|
||||
assert launch_profile_policy.activate_multi_profile_hosting_eagerly() is False
|
||||
assert not secret_scope.is_multiplex_active()
|
||||
assert launch_profile_policy.activate_multi_profile_hosting_eagerly() is True
|
||||
assert secret_scope.is_multiplex_active()
|
||||
|
||||
|
||||
def test_a_crashed_profile_create_shell_is_not_a_second_tenant(two_profile_host):
|
||||
|
||||
Reference in New Issue
Block a user