# Conflicts: # apps/desktop/e2e/archived-hidden-session-recoverable.spec.ts # apps/desktop/e2e/bot-chat-message-agent-friendly-name.spec.ts # apps/desktop/e2e/bot-mailbox-unreadable-ticket.spec.ts # apps/desktop/e2e/bot-mode-roster-localized.spec.ts # apps/desktop/e2e/bot-mode-row-click-mirrors-registry.spec.ts # apps/desktop/e2e/bot-mode-tab-shows-bot-name.spec.ts # apps/desktop/e2e/bot-roster-group-row-organisation.spec.ts # apps/desktop/e2e/bot-roster-ignores-infra-dirs.spec.ts # apps/desktop/e2e/bot-roster-timestamp-meta.spec.ts # apps/desktop/e2e/bot-roster-user-sections.spec.ts # apps/desktop/e2e/bot-routines-pane-narrow.spec.ts # apps/desktop/e2e/bot-row-open-recent-session.spec.ts # apps/desktop/e2e/bot-tile-ignores-ambient-composer-model.spec.ts # apps/desktop/e2e/group-composer-auto-grow.spec.ts # apps/desktop/e2e/group-create-gate-remote-roster.spec.ts # apps/desktop/e2e/group-prompt-renamed-primary-handle.spec.ts # apps/desktop/e2e/hosted-room-backend-continuity.spec.ts # apps/desktop/e2e/hosted-room-legacy-store-migration.spec.ts # apps/desktop/e2e/settings-scope-chips-bot-title.spec.ts # apps/desktop/e2e/worktree-branch-status.spec.ts # apps/desktop/electron/backend-probes.test.ts # apps/desktop/electron/connection-apply.test.ts # apps/desktop/electron/desktop-electron-pin.test.ts # apps/desktop/electron/desktop-uninstall.test.ts # apps/desktop/electron/gateway-file-download-transport.test.ts # apps/desktop/electron/gateway-stop-before-update.test.ts # apps/desktop/electron/github-api-auth.test.ts # apps/desktop/electron/registry-primary-profile-scope.test.ts # apps/desktop/electron/update-api-check.test.ts # apps/desktop/electron/update-handoff-marker.test.ts # apps/desktop/electron/venv-blocker-scan.test.ts # apps/desktop/scripts/after-extract.test.mjs # apps/desktop/scripts/local-pack-publish.test.mjs # apps/desktop/scripts/tasks-scroll.test.mjs # apps/desktop/src/app/settings/model-settings.test.tsx # apps/desktop/src/app/updates-overlay.blockers.test.tsx # apps/desktop/src/components/desktop-install-overlay.test.tsx # apps/desktop/src/lib/update-copy.test.ts # scripts/ci/check_os_marker_fakes.py # tests-js/desktop-mac-usage-descriptions.test.ts # tests-js/node-engine-alignment.test.ts # tests/agent/lsp/test_install_and_lint_fixes.py # tests/agent/test_command_token_source.py # tests/agent/test_compression_boundary_hook.py # tests/agent/test_create_openai_client_ssl_verify.py # tests/agent/test_custom_provider_ca_probes.py # tests/agent/test_endpoint_blackhole.py # tests/agent/test_estimator_parity.py # tests/agent/test_in_place_compaction.py # tests/agent/test_moa_loop_mode.py # tests/agent/test_model_metadata.py # tests/agent/test_skill_session_platform_gate.py # tests/agent/test_skill_utils.py # tests/agent/test_ssl_ca_guard.py # tests/computer_use/test_doctor.py # tests/cron/test_codex_execution_paths.py # tests/cron/test_cron_bot_chat_delivery.py # tests/cron/test_cron_script.py # tests/cron/test_media_delivery_parity.py # tests/cron/test_misfire_catchup.py # tests/cron/test_parallel_pool.py # tests/cron/test_recurring_eagain_redispatch.py # tests/gateway/test_choice_picker.py # tests/gateway/test_control_socket_windows_live.py # tests/gateway/test_dingtalk.py # tests/gateway/test_feishu.py # tests/gateway/test_feishu_onboard.py # tests/gateway/test_gateway_shutdown.py # tests/gateway/test_matrix.py # tests/gateway/test_model_command_custom_providers.py # tests/gateway/test_reasoning_command.py # tests/gateway/test_runtime_footer.py # tests/gateway/test_session.py # tests/gateway/test_session_hygiene.py # tests/gateway/test_status.py # tests/gateway/test_teams.py # tests/gateway/test_turn_lease.py # tests/gateway/test_whatsapp_connect.py # tests/hermes_cli/test_approvals_command.py # tests/hermes_cli/test_auth_store_lock_concurrent.py # tests/hermes_cli/test_backup.py # tests/hermes_cli/test_banner_git_state.py # tests/hermes_cli/test_certifi_repair.py # tests/hermes_cli/test_cmd_update.py # tests/hermes_cli/test_compat_manifest_targets.py # tests/hermes_cli/test_computer_use_cli.py # tests/hermes_cli/test_cpr_local_leak.py # tests/hermes_cli/test_dashboard_auth_gate.py # tests/hermes_cli/test_dashboard_procs_kill_grace.py # tests/hermes_cli/test_desktop_lifecycle_windows_live.py # tests/hermes_cli/test_doctor.py # tests/hermes_cli/test_doctor_command_install.py # tests/hermes_cli/test_fleet_config_migration_windows_live.py # tests/hermes_cli/test_gateway.py # tests/hermes_cli/test_gateway_platform_gating.py # tests/hermes_cli/test_gateway_restart_loop.py # tests/hermes_cli/test_gateway_task_probe.py # tests/hermes_cli/test_gateway_wsl.py # tests/hermes_cli/test_gui_command.py # tests/hermes_cli/test_install_cua_driver.py # tests/hermes_cli/test_kanban_db.py # tests/hermes_cli/test_lazy_command_exports.py # tests/hermes_cli/test_lazy_refresh_venv_repair.py # tests/hermes_cli/test_linux_desktop_entry.py # tests/hermes_cli/test_local_runtime.py # tests/hermes_cli/test_local_runtime_updates.py # tests/hermes_cli/test_managed_uv.py # tests/hermes_cli/test_mcp_reload_confirm_gate.py # tests/hermes_cli/test_nous_subscription.py # tests/hermes_cli/test_npm_engine.py # tests/hermes_cli/test_personality_none.py # tests/hermes_cli/test_pet_toggle.py # tests/hermes_cli/test_plan_reconciliation_windows_live.py # tests/hermes_cli/test_plugin_event_bus.py # tests/hermes_cli/test_plugin_manifest_v2.py # tests/hermes_cli/test_plugin_packs.py # tests/hermes_cli/test_plugins_cmd.py # tests/hermes_cli/test_plugins_cmd_enable_disable_nested.py # tests/hermes_cli/test_process_identity.py # tests/hermes_cli/test_profiles.py # tests/hermes_cli/test_profiles_sidebar_cache.py # tests/hermes_cli/test_pty_bridge.py # tests/hermes_cli/test_resolve_turn_limit.py # tests/hermes_cli/test_serve_runtime_inventory.py # tests/hermes_cli/test_session_vacuum_config.py # tests/hermes_cli/test_set_config_value.py # tests/hermes_cli/test_signal_handler_kanban_worker.py # tests/hermes_cli/test_slash_confirm_windows.py # tests/hermes_cli/test_stale_pid_guard.py # tests/hermes_cli/test_startup_fast_guards.py # tests/hermes_cli/test_status.py # tests/hermes_cli/test_telegram_managed_bot.py # tests/hermes_cli/test_tools_config.py # tests/hermes_cli/test_update_apply_shallow_count.py # tests/hermes_cli/test_update_autostash.py # tests/hermes_cli/test_update_concurrent_quarantine.py # tests/hermes_cli/test_update_fetch_failure_classifier.py # tests/hermes_cli/test_update_fleet_probe_resume_token.py # tests/hermes_cli/test_update_handoff_backend_reap.py # tests/hermes_cli/test_update_handoff_desktop_rebuild.py # tests/hermes_cli/test_update_head_moved_gate.py # tests/hermes_cli/test_update_host_obligation.py # tests/hermes_cli/test_update_import_guard.py # tests/hermes_cli/test_update_interrupted_recovery.py # tests/hermes_cli/test_update_inventory.py # tests/hermes_cli/test_update_launchd_unloaded_gateway.py # tests/hermes_cli/test_update_missing_configured_deps.py # tests/hermes_cli/test_update_modified_notice.py # tests/hermes_cli/test_update_multiplex_migration_hook.py # tests/hermes_cli/test_update_no_gateway_restart.py # tests/hermes_cli/test_update_orphan_backend_reap.py # tests/hermes_cli/test_update_parked_branch_guard.py # tests/hermes_cli/test_update_post_pull_syntax_guard.py # tests/hermes_cli/test_update_receipt.py # tests/hermes_cli/test_update_self_lock.py # tests/hermes_cli/test_update_shim_fail_closed.py # tests/hermes_cli/test_update_shim_self_lock.py # tests/hermes_cli/test_update_sqlite_remediation.py # tests/hermes_cli/test_update_stale_dashboard.py # tests/hermes_cli/test_update_stale_virtualenv.py # tests/hermes_cli/test_update_venv_health.py # tests/hermes_cli/test_update_venv_ownership_preflight.py # tests/hermes_cli/test_update_wedged_gateway.py # tests/hermes_cli/test_update_yes_flag.py # tests/hermes_cli/test_update_zip_two_phase.py # tests/hermes_cli/test_urllib_security.py # tests/hermes_cli/test_ux_messages_auth_config.py # tests/hermes_cli/test_ux_messages_startup.py # tests/hermes_cli/test_venv_holder_classifier.py # tests/hermes_cli/test_verify_console_scripts.py # tests/hermes_cli/test_verify_core_dependencies.py # tests/hermes_cli/test_web_server.py # tests/hermes_cli/test_web_server_console_ws.py # tests/hermes_cli/test_web_server_ws_ping.py # tests/hermes_cli/test_web_ui_build.py # tests/hermes_state/test_fts_rebuild_admission.py # tests/hermes_state/test_hermes_state.py # tests/plugins/memory/test_memory_lazy_install.py # tests/plugins/test_google_meet_plugin.py # tests/plugins/test_langfuse_plugin.py # tests/plugins/test_security_guidance_plugin.py # tests/plugins/test_transform_llm_output_hook.py # tests/scripts/desktop_update/test_desktop_update_windows_gateway_flag.py # tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py # tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py # tests/scripts/install/test_install_clone_throttle_fallback.py # tests/scripts/install/test_install_lockfile_churn.py # tests/scripts/install/test_install_no_initial_commit.py # tests/scripts/install/test_install_sh_browser_install.py # tests/scripts/install/test_install_sh_node_prerelease.py # tests/scripts/install/test_install_sh_symlink_stomp.py # tests/scripts/install/test_install_sh_uv_lock_config.py # tests/scripts/install/test_install_unmerged_index.py # tests/scripts/test_contributor_map.py # tests/scripts/test_run_tests_parallel.py # tests/skills/test_competitor_news_monitor_skill.py # tests/skills/test_document_to_action_items_skill.py # tests/skills/test_google_workspace_setup.py # tests/skills/test_google_workspace_setup_deps.py # tests/skills/test_grounded_citations_skill.py # tests/skills/test_ip_as_logo_skill.py # tests/skills/test_live_dashboard_skill.py # tests/skills/test_mcp_oauth_remote_gateway_skill.py # tests/skills/test_office_document_skills.py # tests/skills/test_openclaw_migration.py # tests/skills/test_product_price_monitor_skill.py # tests/skills/test_scrollcraft_skill.py # tests/skills/test_setup_wizard_generator_skill.py # tests/skills/test_weekly_review_planning_skill.py # tests/test_engines_satisfiable.py # tests/test_fast_safe_load.py # tests/test_hermes_bootstrap.py # tests/test_hermes_constants.py # tests/test_hermes_logging.py # tests/test_managed_runtime_resolution.py # tests/test_model_tools_async_bridge.py # tests/test_packaging_build_guard.py # tests/test_packaging_metadata.py # tests/test_yaml_indent_consistency.py # tests/tools/test_approval_timeout_overflow.py # tests/tools/test_base_environment.py # tests/tools/test_bot_mode_dm.py # tests/tools/test_browser_chromium_check.py # tests/tools/test_browser_hardening.py # tests/tools/test_browser_homebrew_paths.py # tests/tools/test_browser_npx_warmup.py # tests/tools/test_browser_orphan_reaper.py # tests/tools/test_browser_real_profile.py # tests/tools/test_browser_use_cli.py # tests/tools/test_clipboard.py # tests/tools/test_code_execution.py # tests/tools/test_code_execution_modes.py # tests/tools/test_code_execution_windows_env.py # tests/tools/test_computer_use.py # tests/tools/test_delegate_liveness_timeout.py # tests/tools/test_execute_code_approval_cluster.py # tests/tools/test_execution_flag_detection.py # tests/tools/test_fal_common.py # tests/tools/test_file_operations.py # tests/tools/test_file_tools.py # tests/tools/test_file_tools_cwd_resolution.py # tests/tools/test_file_tools_live.py # tests/tools/test_lazy_deps.py # tests/tools/test_lazy_deps_durable_target.py # tests/tools/test_lazy_deps_managed.py # tests/tools/test_local_env_blocklist.py # tests/tools/test_local_tempdir.py # tests/tools/test_macos_protected_search.py # tests/tools/test_mcp_npx_cached_bin.py # tests/tools/test_oneshot_completion_linger.py # tests/tools/test_process_registry.py # tests/tools/test_read_file_schema_gating.py # tests/tools/test_skill_improvements.py # tests/tools/test_skills_sync.py # tests/tools/test_termux_api_detection.py # tests/tools/test_tirith_security.py # tests/tools/test_transcription_tools.py # tests/tools/test_tts_streaming.py # tests/tools/test_wake_word.py # tests/tui_gateway/test_compute_host_borrowed_lease.py # tests/tui_gateway/test_compute_host_turn_protocol.py # tests/tui_gateway/test_isolated_orphan_activity.py # tests/tui_gateway/test_protocol.py # tests/tui_gateway/test_slash_worker_profile_home.py # tests/tui_gateway/test_subprocess_encoding.py # tests/tui_gateway/test_tui_gateway_server.py # ui-tui/src/__tests__/terminalParity.test.ts # ui-tui/src/__tests__/termuxComposerLayout.test.ts # ui-tui/src/__tests__/textInputFastEcho.test.ts
420 lines
17 KiB
Python
420 lines
17 KiB
Python
"""Tests for the plugin capability model + consent flow (#64228).
|
|
|
|
Covers: declaration parsing, consent grant/persist, update re-consent on
|
|
added capabilities, fail-closed behavior on missing/corrupt consent state,
|
|
and backward compatibility with the legacy ``allow_*`` gates.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
from types import SimpleNamespace
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
import pytest
|
|
import hermes_yaml as yaml
|
|
|
|
from hermes_cli.plugin_capabilities import (
|
|
CAPABILITY_REGISTRY,
|
|
capability_set_hash,
|
|
consent_hash,
|
|
declared_set_changed,
|
|
granted_capabilities,
|
|
parse_declared_capabilities,
|
|
pending_capabilities,
|
|
plugin_capability_granted,
|
|
record_consent,
|
|
)
|
|
|
|
|
|
@pytest.fixture()
|
|
def hermes_home(tmp_path, monkeypatch):
|
|
"""Point HERMES_HOME at a tmp dir with an empty config.yaml."""
|
|
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
|
(tmp_path / "config.yaml").write_text("{}\n", encoding="utf-8")
|
|
return tmp_path
|
|
|
|
|
|
def _read_cfg(home):
|
|
return yaml.safe_load((home / "config.yaml").read_text(encoding="utf-8")) or {}
|
|
|
|
|
|
# ── Registry sanity ──────────────────────────────────────────────────────────
|
|
|
|
|
|
class TestRegistry:
|
|
def test_every_capability_has_legacy_gate(self):
|
|
for spec in CAPABILITY_REGISTRY.values():
|
|
assert spec.legacy_path, spec.id
|
|
assert spec.description
|
|
|
|
|
|
|
|
# ── Declaration parsing ──────────────────────────────────────────────────────
|
|
|
|
|
|
class TestDeclarationParsing:
|
|
|
|
def test_drops_unknown_ids(self):
|
|
got = parse_declared_capabilities(["tools.override", "root.everything"])
|
|
assert got == ["tools.override"]
|
|
|
|
def test_non_list_ignored(self):
|
|
assert parse_declared_capabilities("tools.override") == []
|
|
assert parse_declared_capabilities({"a": 1}) == []
|
|
assert parse_declared_capabilities(None) == []
|
|
|
|
def test_non_string_entries_ignored(self):
|
|
assert parse_declared_capabilities([1, None, "tools.override"]) == [
|
|
"tools.override"
|
|
]
|
|
|
|
def test_dedup_preserves_order(self):
|
|
got = parse_declared_capabilities(
|
|
["llm.model_override", "tools.override", "llm.model_override"]
|
|
)
|
|
assert got == ["llm.model_override", "tools.override"]
|
|
|
|
def test_manifest_field_lands_on_parsed_manifest(self, tmp_path):
|
|
"""PluginManifest picks up ``capabilities:`` from plugin.yaml."""
|
|
from hermes_cli.plugins import parse_manifest_file
|
|
|
|
plugin_dir = tmp_path / "capplug"
|
|
plugin_dir.mkdir()
|
|
(plugin_dir / "plugin.yaml").write_text(
|
|
"name: capplug\nversion: '1.0'\n"
|
|
"capabilities:\n - tools.override\n - bogus.capability\n",
|
|
encoding="utf-8",
|
|
)
|
|
manifest = parse_manifest_file(
|
|
plugin_dir / "plugin.yaml", plugin_dir, "user", ""
|
|
)
|
|
assert manifest is not None
|
|
assert manifest.capabilities == ["tools.override"]
|
|
|
|
def test_manifest_without_capabilities_field(self, tmp_path):
|
|
from hermes_cli.plugins import parse_manifest_file
|
|
|
|
plugin_dir = tmp_path / "plainplug"
|
|
plugin_dir.mkdir()
|
|
(plugin_dir / "plugin.yaml").write_text(
|
|
"name: plainplug\n", encoding="utf-8"
|
|
)
|
|
manifest = parse_manifest_file(
|
|
plugin_dir / "plugin.yaml", plugin_dir, "user", ""
|
|
)
|
|
assert manifest is not None
|
|
assert manifest.capabilities == []
|
|
|
|
def test_entrypoint_companion_metadata_declares_capabilities_without_import(
|
|
self, monkeypatch
|
|
):
|
|
"""Installed plugins can declare consent metadata in dist entry points."""
|
|
from hermes_cli import plugins as plugins_mod
|
|
from hermes_cli.plugins import PluginManager
|
|
|
|
load = MagicMock(side_effect=AssertionError("plugin code must not be imported"))
|
|
plugin_ep = SimpleNamespace(
|
|
name="thread-namer",
|
|
value="thread_namer.plugin:register",
|
|
group="hermes_agent.plugins",
|
|
dist=SimpleNamespace(
|
|
version="1.2.3",
|
|
metadata={"Summary": "Names gateway threads"},
|
|
),
|
|
load=load,
|
|
)
|
|
capability_ep = SimpleNamespace(
|
|
name="thread-namer.gateway.platform_actions",
|
|
value="thread_namer.plugin:register",
|
|
group="hermes_agent.plugin_capabilities",
|
|
load=load,
|
|
)
|
|
monkeypatch.setattr(
|
|
plugins_mod.importlib.metadata,
|
|
"entry_points",
|
|
lambda: [plugin_ep, capability_ep],
|
|
)
|
|
|
|
manifests = PluginManager()._scan_entry_points()
|
|
|
|
assert len(manifests) == 1
|
|
assert manifests[0].name == "thread-namer"
|
|
assert manifests[0].version == "1.2.3"
|
|
assert manifests[0].description == "Names gateway threads"
|
|
assert manifests[0].capabilities == ["gateway.platform_actions"]
|
|
load.assert_not_called()
|
|
|
|
|
|
# ── Consent grant + persistence ──────────────────────────────────────────────
|
|
|
|
|
|
class TestConsentPersistence:
|
|
def test_record_consent_persists_grant(self, hermes_home):
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
cfg = _read_cfg(hermes_home)
|
|
entry = cfg["plugins"]["entries"]["capplug"]
|
|
assert entry["granted_capabilities"] == ["tools.override"]
|
|
assert entry["capabilities_consent"]["hash"] == capability_set_hash(
|
|
["tools.override"]
|
|
)
|
|
assert entry["capabilities_consent"]["granted_at"]
|
|
# Bridge: legacy key mirrored so existing enforcement sites work.
|
|
assert entry["allow_tool_override"] is True
|
|
|
|
def test_record_consent_mirrors_nested_legacy_key(self, hermes_home):
|
|
record_consent(
|
|
"capplug", ["llm.model_override"], ["llm.model_override"]
|
|
)
|
|
entry = _read_cfg(hermes_home)["plugins"]["entries"]["capplug"]
|
|
assert entry["llm"]["allow_model_override"] is True
|
|
|
|
|
|
def test_grant_is_union_with_previous(self, hermes_home):
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
record_consent(
|
|
"capplug",
|
|
["llm.model_override"],
|
|
["tools.override", "llm.model_override"],
|
|
)
|
|
assert granted_capabilities("capplug") == frozenset(
|
|
{"tools.override", "llm.model_override"}
|
|
)
|
|
|
|
|
|
def test_declined_stays_off(self, hermes_home):
|
|
# No record_consent call — nothing granted.
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
assert pending_capabilities("capplug", ["tools.override"]) == [
|
|
"tools.override"
|
|
]
|
|
|
|
|
|
# ── Update re-consent ────────────────────────────────────────────────────────
|
|
|
|
|
|
class TestUpdateReconsent:
|
|
def test_added_capability_is_pending(self, hermes_home):
|
|
# v1 declared + granted tools.override.
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
# v2 adds llm.model_override.
|
|
declared_v2 = ["tools.override", "llm.model_override"]
|
|
assert pending_capabilities("capplug", declared_v2) == [
|
|
"llm.model_override"
|
|
]
|
|
assert declared_set_changed("capplug", declared_v2) is True
|
|
# The added capability stays ungranted until re-consent.
|
|
assert plugin_capability_granted("capplug", "llm.model_override") is False
|
|
# The previously granted one keeps working.
|
|
assert plugin_capability_granted("capplug", "tools.override") is True
|
|
|
|
def test_unchanged_set_needs_no_reconsent(self, hermes_home):
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
assert pending_capabilities("capplug", ["tools.override"]) == []
|
|
assert declared_set_changed("capplug", ["tools.override"]) is False
|
|
|
|
def test_hash_order_insensitive(self):
|
|
a = capability_set_hash(["tools.override", "llm.model_override"])
|
|
b = capability_set_hash(["llm.model_override", "tools.override"])
|
|
assert a == b
|
|
|
|
def test_no_consent_record_counts_as_changed(self, hermes_home):
|
|
assert declared_set_changed("capplug", ["tools.override"]) is True
|
|
|
|
def test_reconsent_grants_addition(self, hermes_home):
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
declared_v2 = ["tools.override", "llm.model_override"]
|
|
record_consent(
|
|
"capplug", pending_capabilities("capplug", declared_v2), declared_v2
|
|
)
|
|
assert plugin_capability_granted("capplug", "llm.model_override") is True
|
|
assert declared_set_changed("capplug", declared_v2) is False
|
|
|
|
|
|
# ── Fail closed ──────────────────────────────────────────────────────────────
|
|
|
|
|
|
class TestFailClosed:
|
|
def test_missing_config_not_granted(self, tmp_path, monkeypatch):
|
|
monkeypatch.setenv("HERMES_HOME", str(tmp_path / "nonexistent"))
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
assert granted_capabilities("capplug") == frozenset()
|
|
|
|
def test_corrupt_granted_list_not_granted(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n capplug:\n"
|
|
" granted_capabilities: not-a-list\n",
|
|
encoding="utf-8",
|
|
)
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
|
|
def test_corrupt_entry_types_not_granted(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n capplug: 42\n", encoding="utf-8"
|
|
)
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
|
|
def test_unknown_capability_denied(self, hermes_home):
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
assert plugin_capability_granted("capplug", "root.everything") is False
|
|
|
|
def test_unknown_ids_in_granted_list_ignored(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n capplug:\n"
|
|
" granted_capabilities: [root.everything, 42]\n",
|
|
encoding="utf-8",
|
|
)
|
|
assert granted_capabilities("capplug") == frozenset()
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
|
|
def test_corrupt_consent_hash_counts_as_changed(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n capplug:\n"
|
|
" capabilities_consent: broken\n",
|
|
encoding="utf-8",
|
|
)
|
|
assert consent_hash("capplug") is None
|
|
assert declared_set_changed("capplug", ["tools.override"]) is True
|
|
|
|
|
|
# ── Legacy gate backward compat ──────────────────────────────────────────────
|
|
|
|
|
|
class TestLegacyGateCompat:
|
|
def test_legacy_allow_tool_override_still_works(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n oldplug:\n"
|
|
" allow_tool_override: true\n",
|
|
encoding="utf-8",
|
|
)
|
|
assert plugin_capability_granted("oldplug", "tools.override") is True
|
|
|
|
def test_legacy_nested_llm_key_still_works(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n oldplug:\n"
|
|
" llm:\n allow_model_override: true\n",
|
|
encoding="utf-8",
|
|
)
|
|
assert plugin_capability_granted("oldplug", "llm.model_override") is True
|
|
|
|
def test_legacy_false_stays_denied(self, hermes_home):
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n oldplug:\n"
|
|
" allow_tool_override: false\n",
|
|
encoding="utf-8",
|
|
)
|
|
assert plugin_capability_granted("oldplug", "tools.override") is False
|
|
|
|
def test_tool_override_gate_uses_canonical_path(self, hermes_home):
|
|
"""PluginContext._tool_override_allowed honors capability grant."""
|
|
from hermes_cli.plugins import PluginContext, PluginManifest, PluginManager
|
|
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
manifest = PluginManifest(name="capplug", source="user", key="capplug")
|
|
ctx = PluginContext(manifest, PluginManager())
|
|
assert ctx._tool_override_allowed("write_file") is True
|
|
|
|
def test_tool_override_gate_denies_without_grant(self, hermes_home):
|
|
from hermes_cli.plugins import PluginContext, PluginManifest, PluginManager
|
|
|
|
manifest = PluginManifest(name="capplug", source="user", key="capplug")
|
|
ctx = PluginContext(manifest, PluginManager())
|
|
assert ctx._tool_override_allowed("write_file") is False
|
|
|
|
def test_tool_override_gate_legacy_key(self, hermes_home):
|
|
from hermes_cli.plugins import PluginContext, PluginManifest, PluginManager
|
|
|
|
(hermes_home / "config.yaml").write_text(
|
|
"plugins:\n entries:\n oldplug:\n"
|
|
" allow_tool_override: true\n",
|
|
encoding="utf-8",
|
|
)
|
|
manifest = PluginManifest(name="oldplug", source="user", key="oldplug")
|
|
ctx = PluginContext(manifest, PluginManager())
|
|
assert ctx._tool_override_allowed("write_file") is True
|
|
|
|
def test_bundled_plugin_trusted(self, hermes_home):
|
|
from hermes_cli.plugins import PluginContext, PluginManifest, PluginManager
|
|
|
|
manifest = PluginManifest(name="bplug", source="bundled", key="bplug")
|
|
ctx = PluginContext(manifest, PluginManager())
|
|
assert ctx._tool_override_allowed("write_file") is True
|
|
assert ctx.has_capability("tools.override") is True
|
|
|
|
|
|
# ── ctx.has_capability probing ───────────────────────────────────────────────
|
|
|
|
|
|
class TestHasCapability:
|
|
def test_probe_granted(self, hermes_home):
|
|
from hermes_cli.plugins import PluginContext, PluginManifest, PluginManager
|
|
|
|
record_consent("capplug", ["llm.model_override"], ["llm.model_override"])
|
|
manifest = PluginManifest(name="capplug", source="user", key="capplug")
|
|
ctx = PluginContext(manifest, PluginManager())
|
|
assert ctx.has_capability("llm.model_override") is True
|
|
assert ctx.has_capability("tools.override") is False
|
|
assert ctx.has_capability("nonsense.capability") is False
|
|
|
|
|
|
# ── Consent CLI flow ─────────────────────────────────────────────────────────
|
|
|
|
|
|
class TestConsentFlow:
|
|
def _console(self, answers=None, interactive=True):
|
|
console = MagicMock()
|
|
it = iter(answers or [])
|
|
console.input.side_effect = lambda *a, **k: next(it, "")
|
|
return console
|
|
|
|
def test_consent_yes_records_grant(self, hermes_home, monkeypatch):
|
|
from hermes_cli.plugins_cmd import _run_capability_consent
|
|
|
|
console = self._console(["y"])
|
|
with patch("sys.stdin") as stdin, patch("sys.stdout") as stdout:
|
|
stdin.isatty.return_value = True
|
|
stdout.isatty.return_value = True
|
|
granted = _run_capability_consent(
|
|
console, "capplug", ["tools.override"], context="install"
|
|
)
|
|
assert granted is True
|
|
assert plugin_capability_granted("capplug", "tools.override") is True
|
|
|
|
def test_consent_decline_leaves_ungranted(self, hermes_home):
|
|
from hermes_cli.plugins_cmd import _run_capability_consent
|
|
|
|
console = self._console(["n"])
|
|
with patch("sys.stdin") as stdin, patch("sys.stdout") as stdout:
|
|
stdin.isatty.return_value = True
|
|
stdout.isatty.return_value = True
|
|
granted = _run_capability_consent(
|
|
console, "capplug", ["tools.override"], context="install"
|
|
)
|
|
assert granted is False
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
|
|
def test_non_interactive_fails_closed(self, hermes_home):
|
|
from hermes_cli.plugins_cmd import _run_capability_consent
|
|
|
|
console = self._console()
|
|
with patch("sys.stdin") as stdin, patch("sys.stdout") as stdout:
|
|
stdin.isatty.return_value = False
|
|
stdout.isatty.return_value = False
|
|
granted = _run_capability_consent(
|
|
console, "capplug", ["tools.override"], context="install"
|
|
)
|
|
assert granted is False
|
|
assert plugin_capability_granted("capplug", "tools.override") is False
|
|
# No prompt was shown.
|
|
console.input.assert_not_called()
|
|
|
|
def test_already_granted_skips_prompt(self, hermes_home):
|
|
from hermes_cli.plugins_cmd import _run_capability_consent
|
|
|
|
record_consent("capplug", ["tools.override"], ["tools.override"])
|
|
console = self._console()
|
|
granted = _run_capability_consent(
|
|
console, "capplug", ["tools.override"], context="enable"
|
|
)
|
|
assert granted is True
|
|
console.input.assert_not_called()
|