From 9ac5cea9e0fabf33bbf4d6f01a6795090f8171d4 Mon Sep 17 00:00:00 2001 From: teknium1 <127238744+teknium1@users.noreply.github.com> Date: Mon, 21 Sep 2026 08:00:53 -0700 Subject: [PATCH] tests: fold the retired opt-out and the removed rollback out of the mirroring suites The cron guidance, the eager-activation guard and the launch-env freeze test all encoded the pre-ruling behaviour: a `false` that disarmed the credential guard, and a "LEGACY (pre-multiplex topology)" per-profile install the status output no longer offers. --- gateway/status.py | 2 +- .../test_cron_satellite_diagnostics.py | 16 ++++++++++------ .../test_web_server_launch_env_freeze.py | 1 - .../test_eager_multiplex_activation.py | 12 +++++++----- 4 files changed, 18 insertions(+), 13 deletions(-) diff --git a/gateway/status.py b/gateway/status.py index 7a24ed0fe8..96c84bb2f3 100644 --- a/gateway/status.py +++ b/gateway/status.py @@ -153,7 +153,7 @@ _runtime_status_state: Optional[dict[str, Any]] = None def _merge_over_on_disk(path: Path, payload: dict[str, Any]) -> dict[str, Any]: """Lay the canonical snapshot over whatever is on disk right before writing. Out-of-process - writers (``hermes gateway migrate --standalone`` clearing multiplex-owned status, container_boot + writers (the migration's compensator clearing multiplex-owned status, container_boot seeding ``desired_state``) stamp this file directly; the gateway's fields win, theirs survive.""" existing = _read_json_file(path) return {**existing, **payload} if isinstance(existing, dict) else payload diff --git a/tests/hermes_cli/test_cron_satellite_diagnostics.py b/tests/hermes_cli/test_cron_satellite_diagnostics.py index f1610c5f1c..685fa0c7fe 100644 --- a/tests/hermes_cli/test_cron_satellite_diagnostics.py +++ b/tests/hermes_cli/test_cron_satellite_diagnostics.py @@ -73,9 +73,12 @@ def test_status_preserves_profile_health_contract(served_root, capsys, monkeypat assert "hermes --profile default gateway install" in output assert "sudo hermes --profile default gateway install --system" in output assert "hermes --profile default gateway run" in output - assert "hermes --profile default gateway restart" in output - # The per-profile service is offered only as the LEGACY second-process topology. - assert "LEGACY (pre-multiplex topology, not recommended)" in output + # Multiplex-only: a per-profile service is not offered at all any more, not even as a + # "legacy" fallback -- the one host gateway is the only topology, and an old per-profile + # install is something to FOLD IN, not something to reinstall. + assert "gateway migrate --multiplex" in output + assert "LEGACY" not in output + assert "hermes gateway install # starts a SECOND gateway" not in output if mode == "external": assert "managed scheduler" in output assert "STALLED" not in output @@ -143,9 +146,10 @@ def test_standalone_guidance_matches_profile_membership(served_root, monkeypatch cron_status() output = capsys.readouterr().out assert "hermes --profile default gateway install" in output - assert ("hermes --profile default gateway restart" in output) == (home_kind == "named") - # A served/named profile is never told to start a SECOND host process except as LEGACY. - assert ("LEGACY (pre-multiplex topology, not recommended)" in output) == (home_kind == "named") + # A named profile is told the host gateway serves it and how to fold an older per-profile + # install in; it is never offered a second host process, legacy or otherwise. + assert ("gateway migrate --multiplex" in output) == (home_kind == "named") + assert "LEGACY" not in output @pytest.mark.parametrize("detail", ["unreachable " * 30 + "\nsecret second line", ""]) diff --git a/tests/hermes_cli/test_web_server_launch_env_freeze.py b/tests/hermes_cli/test_web_server_launch_env_freeze.py index 6f2131d339..7eeb140846 100644 --- a/tests/hermes_cli/test_web_server_launch_env_freeze.py +++ b/tests/hermes_cli/test_web_server_launch_env_freeze.py @@ -23,7 +23,6 @@ def test_boot_time_credential_injection_is_inside_the_frozen_launch_env(tmp_path # A two-profile host, without touching the live install's profiles/. monkeypatch.setattr(launch_profile_policy, "_servable_profile_homes", lambda: {tmp_path / "a", tmp_path / "b"}) - monkeypatch.setattr(launch_profile_policy, "_multiplex_disabled_explicitly", lambda: False) # Stand-ins for the boot steps that follow the old (top-of-function) activation point. A # provider key injected by the auth gate / keepalive / a lifespan hook is the real case. diff --git a/tests/tui_gateway/test_eager_multiplex_activation.py b/tests/tui_gateway/test_eager_multiplex_activation.py index f929ec6381..77fcf6a92b 100644 --- a/tests/tui_gateway/test_eager_multiplex_activation.py +++ b/tests/tui_gateway/test_eager_multiplex_activation.py @@ -32,16 +32,18 @@ def test_activates_for_a_real_second_profile(two_profile_host): assert secret_scope.is_multiplex_active() -def test_multiplex_disabled_in_config_is_honoured(two_profile_host, monkeypatch): - """A host that pinned ``gateway.multiplex_profiles: false`` keeps per-profile gateways AND - per-profile credential semantics; arming the guard there breaks legitimate unscoped reads.""" +def test_the_retired_opt_out_no_longer_disarms_the_credential_guard(two_profile_host, monkeypatch): + """``gateway.multiplex_profiles: false`` is retired as a topology opt-out, so it must not + disarm this guard: a multi-home host that skipped activation because of a stale ``false`` + would serve the second profile with the LAUNCH profile's credentials -- the exact fail-open + the guard exists to prevent. The host is multi-profile; that is the whole question.""" (two_profile_host / "config.yaml").write_text("{}\n", encoding="utf-8") from hermes_cli import config as cfg_mod monkeypatch.setattr(cfg_mod, "load_config", lambda *a, **k: {"gateway": {"multiplex_profiles": False}}) - assert launch_profile_policy.activate_multi_profile_hosting_eagerly() is False - assert not secret_scope.is_multiplex_active() + assert launch_profile_policy.activate_multi_profile_hosting_eagerly() is True + assert secret_scope.is_multiplex_active() def test_a_crashed_profile_create_shell_is_not_a_second_tenant(two_profile_host):