Files
hermes-agent/tests/tools/test_bot_turn_lock.py
ethernet 890bbbda1f Merge remote-tracking branch 'origin/main' into ethie/pm-clean
# Conflicts:
#	apps/desktop/e2e/archived-hidden-session-recoverable.spec.ts
#	apps/desktop/e2e/bot-chat-message-agent-friendly-name.spec.ts
#	apps/desktop/e2e/bot-mailbox-unreadable-ticket.spec.ts
#	apps/desktop/e2e/bot-mode-roster-localized.spec.ts
#	apps/desktop/e2e/bot-mode-row-click-mirrors-registry.spec.ts
#	apps/desktop/e2e/bot-mode-tab-shows-bot-name.spec.ts
#	apps/desktop/e2e/bot-roster-group-row-organisation.spec.ts
#	apps/desktop/e2e/bot-roster-ignores-infra-dirs.spec.ts
#	apps/desktop/e2e/bot-roster-timestamp-meta.spec.ts
#	apps/desktop/e2e/bot-roster-user-sections.spec.ts
#	apps/desktop/e2e/bot-routines-pane-narrow.spec.ts
#	apps/desktop/e2e/bot-row-open-recent-session.spec.ts
#	apps/desktop/e2e/bot-tile-ignores-ambient-composer-model.spec.ts
#	apps/desktop/e2e/group-composer-auto-grow.spec.ts
#	apps/desktop/e2e/group-create-gate-remote-roster.spec.ts
#	apps/desktop/e2e/group-prompt-renamed-primary-handle.spec.ts
#	apps/desktop/e2e/hosted-room-backend-continuity.spec.ts
#	apps/desktop/e2e/hosted-room-legacy-store-migration.spec.ts
#	apps/desktop/e2e/settings-scope-chips-bot-title.spec.ts
#	apps/desktop/e2e/worktree-branch-status.spec.ts
#	apps/desktop/electron/backend-probes.test.ts
#	apps/desktop/electron/connection-apply.test.ts
#	apps/desktop/electron/desktop-electron-pin.test.ts
#	apps/desktop/electron/desktop-uninstall.test.ts
#	apps/desktop/electron/gateway-file-download-transport.test.ts
#	apps/desktop/electron/gateway-stop-before-update.test.ts
#	apps/desktop/electron/github-api-auth.test.ts
#	apps/desktop/electron/registry-primary-profile-scope.test.ts
#	apps/desktop/electron/update-api-check.test.ts
#	apps/desktop/electron/update-handoff-marker.test.ts
#	apps/desktop/electron/venv-blocker-scan.test.ts
#	apps/desktop/scripts/after-extract.test.mjs
#	apps/desktop/scripts/local-pack-publish.test.mjs
#	apps/desktop/scripts/tasks-scroll.test.mjs
#	apps/desktop/src/app/settings/model-settings.test.tsx
#	apps/desktop/src/app/updates-overlay.blockers.test.tsx
#	apps/desktop/src/components/desktop-install-overlay.test.tsx
#	apps/desktop/src/lib/update-copy.test.ts
#	scripts/ci/check_os_marker_fakes.py
#	tests-js/desktop-mac-usage-descriptions.test.ts
#	tests-js/node-engine-alignment.test.ts
#	tests/agent/lsp/test_install_and_lint_fixes.py
#	tests/agent/test_command_token_source.py
#	tests/agent/test_compression_boundary_hook.py
#	tests/agent/test_create_openai_client_ssl_verify.py
#	tests/agent/test_custom_provider_ca_probes.py
#	tests/agent/test_endpoint_blackhole.py
#	tests/agent/test_estimator_parity.py
#	tests/agent/test_in_place_compaction.py
#	tests/agent/test_moa_loop_mode.py
#	tests/agent/test_model_metadata.py
#	tests/agent/test_skill_session_platform_gate.py
#	tests/agent/test_skill_utils.py
#	tests/agent/test_ssl_ca_guard.py
#	tests/computer_use/test_doctor.py
#	tests/cron/test_codex_execution_paths.py
#	tests/cron/test_cron_bot_chat_delivery.py
#	tests/cron/test_cron_script.py
#	tests/cron/test_media_delivery_parity.py
#	tests/cron/test_misfire_catchup.py
#	tests/cron/test_parallel_pool.py
#	tests/cron/test_recurring_eagain_redispatch.py
#	tests/gateway/test_choice_picker.py
#	tests/gateway/test_control_socket_windows_live.py
#	tests/gateway/test_dingtalk.py
#	tests/gateway/test_feishu.py
#	tests/gateway/test_feishu_onboard.py
#	tests/gateway/test_gateway_shutdown.py
#	tests/gateway/test_matrix.py
#	tests/gateway/test_model_command_custom_providers.py
#	tests/gateway/test_reasoning_command.py
#	tests/gateway/test_runtime_footer.py
#	tests/gateway/test_session.py
#	tests/gateway/test_session_hygiene.py
#	tests/gateway/test_status.py
#	tests/gateway/test_teams.py
#	tests/gateway/test_turn_lease.py
#	tests/gateway/test_whatsapp_connect.py
#	tests/hermes_cli/test_approvals_command.py
#	tests/hermes_cli/test_auth_store_lock_concurrent.py
#	tests/hermes_cli/test_backup.py
#	tests/hermes_cli/test_banner_git_state.py
#	tests/hermes_cli/test_certifi_repair.py
#	tests/hermes_cli/test_cmd_update.py
#	tests/hermes_cli/test_compat_manifest_targets.py
#	tests/hermes_cli/test_computer_use_cli.py
#	tests/hermes_cli/test_cpr_local_leak.py
#	tests/hermes_cli/test_dashboard_auth_gate.py
#	tests/hermes_cli/test_dashboard_procs_kill_grace.py
#	tests/hermes_cli/test_desktop_lifecycle_windows_live.py
#	tests/hermes_cli/test_doctor.py
#	tests/hermes_cli/test_doctor_command_install.py
#	tests/hermes_cli/test_fleet_config_migration_windows_live.py
#	tests/hermes_cli/test_gateway.py
#	tests/hermes_cli/test_gateway_platform_gating.py
#	tests/hermes_cli/test_gateway_restart_loop.py
#	tests/hermes_cli/test_gateway_task_probe.py
#	tests/hermes_cli/test_gateway_wsl.py
#	tests/hermes_cli/test_gui_command.py
#	tests/hermes_cli/test_install_cua_driver.py
#	tests/hermes_cli/test_kanban_db.py
#	tests/hermes_cli/test_lazy_command_exports.py
#	tests/hermes_cli/test_lazy_refresh_venv_repair.py
#	tests/hermes_cli/test_linux_desktop_entry.py
#	tests/hermes_cli/test_local_runtime.py
#	tests/hermes_cli/test_local_runtime_updates.py
#	tests/hermes_cli/test_managed_uv.py
#	tests/hermes_cli/test_mcp_reload_confirm_gate.py
#	tests/hermes_cli/test_nous_subscription.py
#	tests/hermes_cli/test_npm_engine.py
#	tests/hermes_cli/test_personality_none.py
#	tests/hermes_cli/test_pet_toggle.py
#	tests/hermes_cli/test_plan_reconciliation_windows_live.py
#	tests/hermes_cli/test_plugin_event_bus.py
#	tests/hermes_cli/test_plugin_manifest_v2.py
#	tests/hermes_cli/test_plugin_packs.py
#	tests/hermes_cli/test_plugins_cmd.py
#	tests/hermes_cli/test_plugins_cmd_enable_disable_nested.py
#	tests/hermes_cli/test_process_identity.py
#	tests/hermes_cli/test_profiles.py
#	tests/hermes_cli/test_profiles_sidebar_cache.py
#	tests/hermes_cli/test_pty_bridge.py
#	tests/hermes_cli/test_resolve_turn_limit.py
#	tests/hermes_cli/test_serve_runtime_inventory.py
#	tests/hermes_cli/test_session_vacuum_config.py
#	tests/hermes_cli/test_set_config_value.py
#	tests/hermes_cli/test_signal_handler_kanban_worker.py
#	tests/hermes_cli/test_slash_confirm_windows.py
#	tests/hermes_cli/test_stale_pid_guard.py
#	tests/hermes_cli/test_startup_fast_guards.py
#	tests/hermes_cli/test_status.py
#	tests/hermes_cli/test_telegram_managed_bot.py
#	tests/hermes_cli/test_tools_config.py
#	tests/hermes_cli/test_update_apply_shallow_count.py
#	tests/hermes_cli/test_update_autostash.py
#	tests/hermes_cli/test_update_concurrent_quarantine.py
#	tests/hermes_cli/test_update_fetch_failure_classifier.py
#	tests/hermes_cli/test_update_fleet_probe_resume_token.py
#	tests/hermes_cli/test_update_handoff_backend_reap.py
#	tests/hermes_cli/test_update_handoff_desktop_rebuild.py
#	tests/hermes_cli/test_update_head_moved_gate.py
#	tests/hermes_cli/test_update_host_obligation.py
#	tests/hermes_cli/test_update_import_guard.py
#	tests/hermes_cli/test_update_interrupted_recovery.py
#	tests/hermes_cli/test_update_inventory.py
#	tests/hermes_cli/test_update_launchd_unloaded_gateway.py
#	tests/hermes_cli/test_update_missing_configured_deps.py
#	tests/hermes_cli/test_update_modified_notice.py
#	tests/hermes_cli/test_update_multiplex_migration_hook.py
#	tests/hermes_cli/test_update_no_gateway_restart.py
#	tests/hermes_cli/test_update_orphan_backend_reap.py
#	tests/hermes_cli/test_update_parked_branch_guard.py
#	tests/hermes_cli/test_update_post_pull_syntax_guard.py
#	tests/hermes_cli/test_update_receipt.py
#	tests/hermes_cli/test_update_self_lock.py
#	tests/hermes_cli/test_update_shim_fail_closed.py
#	tests/hermes_cli/test_update_shim_self_lock.py
#	tests/hermes_cli/test_update_sqlite_remediation.py
#	tests/hermes_cli/test_update_stale_dashboard.py
#	tests/hermes_cli/test_update_stale_virtualenv.py
#	tests/hermes_cli/test_update_venv_health.py
#	tests/hermes_cli/test_update_venv_ownership_preflight.py
#	tests/hermes_cli/test_update_wedged_gateway.py
#	tests/hermes_cli/test_update_yes_flag.py
#	tests/hermes_cli/test_update_zip_two_phase.py
#	tests/hermes_cli/test_urllib_security.py
#	tests/hermes_cli/test_ux_messages_auth_config.py
#	tests/hermes_cli/test_ux_messages_startup.py
#	tests/hermes_cli/test_venv_holder_classifier.py
#	tests/hermes_cli/test_verify_console_scripts.py
#	tests/hermes_cli/test_verify_core_dependencies.py
#	tests/hermes_cli/test_web_server.py
#	tests/hermes_cli/test_web_server_console_ws.py
#	tests/hermes_cli/test_web_server_ws_ping.py
#	tests/hermes_cli/test_web_ui_build.py
#	tests/hermes_state/test_fts_rebuild_admission.py
#	tests/hermes_state/test_hermes_state.py
#	tests/plugins/memory/test_memory_lazy_install.py
#	tests/plugins/test_google_meet_plugin.py
#	tests/plugins/test_langfuse_plugin.py
#	tests/plugins/test_security_guidance_plugin.py
#	tests/plugins/test_transform_llm_output_hook.py
#	tests/scripts/desktop_update/test_desktop_update_windows_gateway_flag.py
#	tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py
#	tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py
#	tests/scripts/install/test_install_clone_throttle_fallback.py
#	tests/scripts/install/test_install_lockfile_churn.py
#	tests/scripts/install/test_install_no_initial_commit.py
#	tests/scripts/install/test_install_sh_browser_install.py
#	tests/scripts/install/test_install_sh_node_prerelease.py
#	tests/scripts/install/test_install_sh_symlink_stomp.py
#	tests/scripts/install/test_install_sh_uv_lock_config.py
#	tests/scripts/install/test_install_unmerged_index.py
#	tests/scripts/test_contributor_map.py
#	tests/scripts/test_run_tests_parallel.py
#	tests/skills/test_competitor_news_monitor_skill.py
#	tests/skills/test_document_to_action_items_skill.py
#	tests/skills/test_google_workspace_setup.py
#	tests/skills/test_google_workspace_setup_deps.py
#	tests/skills/test_grounded_citations_skill.py
#	tests/skills/test_ip_as_logo_skill.py
#	tests/skills/test_live_dashboard_skill.py
#	tests/skills/test_mcp_oauth_remote_gateway_skill.py
#	tests/skills/test_office_document_skills.py
#	tests/skills/test_openclaw_migration.py
#	tests/skills/test_product_price_monitor_skill.py
#	tests/skills/test_scrollcraft_skill.py
#	tests/skills/test_setup_wizard_generator_skill.py
#	tests/skills/test_weekly_review_planning_skill.py
#	tests/test_engines_satisfiable.py
#	tests/test_fast_safe_load.py
#	tests/test_hermes_bootstrap.py
#	tests/test_hermes_constants.py
#	tests/test_hermes_logging.py
#	tests/test_managed_runtime_resolution.py
#	tests/test_model_tools_async_bridge.py
#	tests/test_packaging_build_guard.py
#	tests/test_packaging_metadata.py
#	tests/test_yaml_indent_consistency.py
#	tests/tools/test_approval_timeout_overflow.py
#	tests/tools/test_base_environment.py
#	tests/tools/test_bot_mode_dm.py
#	tests/tools/test_browser_chromium_check.py
#	tests/tools/test_browser_hardening.py
#	tests/tools/test_browser_homebrew_paths.py
#	tests/tools/test_browser_npx_warmup.py
#	tests/tools/test_browser_orphan_reaper.py
#	tests/tools/test_browser_real_profile.py
#	tests/tools/test_browser_use_cli.py
#	tests/tools/test_clipboard.py
#	tests/tools/test_code_execution.py
#	tests/tools/test_code_execution_modes.py
#	tests/tools/test_code_execution_windows_env.py
#	tests/tools/test_computer_use.py
#	tests/tools/test_delegate_liveness_timeout.py
#	tests/tools/test_execute_code_approval_cluster.py
#	tests/tools/test_execution_flag_detection.py
#	tests/tools/test_fal_common.py
#	tests/tools/test_file_operations.py
#	tests/tools/test_file_tools.py
#	tests/tools/test_file_tools_cwd_resolution.py
#	tests/tools/test_file_tools_live.py
#	tests/tools/test_lazy_deps.py
#	tests/tools/test_lazy_deps_durable_target.py
#	tests/tools/test_lazy_deps_managed.py
#	tests/tools/test_local_env_blocklist.py
#	tests/tools/test_local_tempdir.py
#	tests/tools/test_macos_protected_search.py
#	tests/tools/test_mcp_npx_cached_bin.py
#	tests/tools/test_oneshot_completion_linger.py
#	tests/tools/test_process_registry.py
#	tests/tools/test_read_file_schema_gating.py
#	tests/tools/test_skill_improvements.py
#	tests/tools/test_skills_sync.py
#	tests/tools/test_termux_api_detection.py
#	tests/tools/test_tirith_security.py
#	tests/tools/test_transcription_tools.py
#	tests/tools/test_tts_streaming.py
#	tests/tools/test_wake_word.py
#	tests/tui_gateway/test_compute_host_borrowed_lease.py
#	tests/tui_gateway/test_compute_host_turn_protocol.py
#	tests/tui_gateway/test_isolated_orphan_activity.py
#	tests/tui_gateway/test_protocol.py
#	tests/tui_gateway/test_slash_worker_profile_home.py
#	tests/tui_gateway/test_subprocess_encoding.py
#	tests/tui_gateway/test_tui_gateway_server.py
#	ui-tui/src/__tests__/terminalParity.test.ts
#	ui-tui/src/__tests__/termuxComposerLayout.test.ts
#	ui-tui/src/__tests__/textInputFastEcho.test.ts
2026-09-23 07:02:44 -04:00

422 lines
15 KiB
Python

"""Tests: per-profile bot turn lock (#93091 — tools/bot_relay.py).
Two deliveries into the same target profile must serialize on a
cross-process flock; the queued one waits a bounded budget and then fails
with a structured 'target_busy' refusal. Real flock on real (short)
tmp_path lockfiles — flock contends between separate fds even within one
process, so threads exercise the true kernel-lock semantics.
"""
from __future__ import annotations
try:
import fcntl # POSIX-only; on Windows the module is skipped wholesale
except ImportError: # pragma: no cover - Windows
fcntl = None
import json
import os
import subprocess
import sys
import threading
import time
import pytest
pytestmark = pytest.mark.platforms("linux")
from tools import bot_mode_dm, bot_relay
from tools.bot_relay import TurnBusyError, acquire_turn_lock, turn_lock_path
@pytest.fixture
def root(tmp_path):
# Keep the lockfile path SHORT (macOS-safe).
r = tmp_path / "r"
r.mkdir()
return r
def _hold_flock(path, hold_event, release_event):
"""Grab the profile lock on a separate fd, signal, hold until told."""
path.parent.mkdir(parents=True, exist_ok=True)
fd = os.open(path, os.O_RDWR | os.O_CREAT, 0o600)
fcntl.flock(fd, fcntl.LOCK_EX)
hold_event.set()
release_event.wait(timeout=10)
os.close(fd) # close releases the flock — process-death semantics
def test_second_delivery_waits_then_succeeds(root):
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(root, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
# Release shortly after the waiter starts probing.
threading.Timer(0.3, release.set).start()
start = time.monotonic()
with acquire_turn_lock(root, "ops", timeout_seconds=5):
waited = time.monotonic() - start
t.join(timeout=5)
assert waited >= 0.2, "second delivery should have queued behind the holder"
def test_timeout_is_structured_target_busy(root):
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(root, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
try:
with pytest.raises(TurnBusyError) as excinfo:
with acquire_turn_lock(root, "ops", timeout_seconds=0.3):
pass # pragma: no cover — must not acquire
err = excinfo.value
assert err.reason == "target_busy"
assert err.profile == "ops"
assert err.waited_seconds >= 0.3
finally:
release.set()
t.join(timeout=5)
def test_different_profiles_do_not_contend(root):
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(root, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
try:
start = time.monotonic()
with acquire_turn_lock(root, "scout", timeout_seconds=5):
pass
# Upper bound generous for loaded CI runners — the point is only
# that 'scout' never waited the busy 'ops' budget out.
assert time.monotonic() - start < 2.5
finally:
release.set()
t.join(timeout=5)
def test_lock_released_when_holder_fd_closes(root):
"""flock dies with the holder's fd — a crashed turn can't wedge the profile."""
path = turn_lock_path(root, "ops")
path.parent.mkdir(parents=True, exist_ok=True)
fd = os.open(path, os.O_RDWR | os.O_CREAT, 0o600)
fcntl.flock(fd, fcntl.LOCK_EX)
os.close(fd) # simulate holder process death (kernel releases the lock)
with acquire_turn_lock(root, "ops", timeout_seconds=0.5):
pass # acquires immediately — no TurnBusyError
def test_lock_path_is_short_and_sanitized(root):
p = turn_lock_path(root, "we/ird namé" + "x" * 200)
assert p.parent == bot_relay.relay_root(root) / bot_relay.LOCKS_DIR
assert len(p.name) <= 70
assert "/" not in p.name.replace(".lock", "")
def test_turn_wait_seconds_falls_back_to_module_constant(monkeypatch):
def _boom():
raise RuntimeError("no config")
monkeypatch.setattr("hermes_cli.config.load_config", _boom)
assert bot_relay.turn_wait_seconds() == float(bot_relay.TURN_WAIT_SECONDS_FALLBACK)
def test_turn_wait_seconds_reads_config(monkeypatch):
monkeypatch.setattr(
"hermes_cli.config.load_config",
lambda: {"bot_mode": {"turn_wait_seconds": 7}},
)
assert bot_relay.turn_wait_seconds() == 7.0
# ── wiring: local teammate delivery (tools/bot_mode_dm.py) ──────────────────
def test_run_delivery_holds_profile_lock_during_turn(root, tmp_path, monkeypatch):
"""The local `hermes -p <profile>` turn runs UNDER the profile lock."""
home = root / ".hermes"
home.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
dm = tmp_path / "dm.txt"
dm.write_text("hi", encoding="utf-8")
observed = {}
def _fake_run(argv, **kwargs):
# While the turn runs, a second acquire on the same profile must fail.
with pytest.raises(TurnBusyError):
with acquire_turn_lock(home, "ops", timeout_seconds=0.15):
pass # pragma: no cover
observed["argv"] = argv
class _P:
returncode = 0
stdout = ""
stderr = ""
return _P()
monkeypatch.setattr(bot_mode_dm.subprocess, "run", _fake_run)
rc = bot_mode_dm._run_delivery(
["hermes", "-p", "ops", "chat"], str(dm), stdin_file=False
)
assert rc == 0
assert observed["argv"][:3] == ["hermes", "-p", "ops"]
# …and after the turn, the lock is free again.
with acquire_turn_lock(home, "ops", timeout_seconds=0.5):
pass
def test_delivery_main_reports_target_busy_json(root, tmp_path, monkeypatch, capsys):
"""A queued delivery that exceeds its budget surfaces the structured error."""
home = root / ".hermes"
home.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
monkeypatch.setattr(bot_relay, "turn_wait_seconds", lambda: 0.2)
dm = tmp_path / "dm.txt"
dm.write_text("hi", encoding="utf-8")
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(home, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
try:
rc = bot_mode_dm._delivery_main(
["--run-delivery", "query-file", str(dm), "hermes", "-p", "ops", "chat"]
)
assert rc == 1
payload = json.loads(capsys.readouterr().out.strip())
assert payload["reason"] == "target_busy" # #93091 item-1 enum extension
assert "ops" in payload["error"]
finally:
release.set()
t.join(timeout=5)
assert not dm.exists(), "DM plaintext must be reclaimed even on refusal"
def test_peer_stdin_delivery_skips_local_lock(root, tmp_path, monkeypatch):
"""Peer transports run their turn on the remote gateway — no local lock."""
home = root / ".hermes"
home.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
dm = tmp_path / "dm.txt"
dm.write_text("hi", encoding="utf-8")
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(home, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
try:
def _fake_run(argv, **kwargs):
class _P:
returncode = 0
return _P()
monkeypatch.setattr(bot_mode_dm.subprocess, "run", _fake_run)
rc = bot_mode_dm._run_delivery(
["hermes", "peer", "dm", "spark/ops"], str(dm), stdin_file=True
)
assert rc == 0 # did not contend with the held 'ops' lock
finally:
release.set()
t.join(timeout=5)
# ── wiring: relay deliver RPC (tui_gateway/methods_bot_relay.py) ─────────────
def test_local_delivery_command_never_reenters_the_lock():
"""The gateway deliver handler runs local_delivery_command ALREADY holding
the profile lock. That argv must stay a raw hermes CLI invocation:
routing it through the --run-delivery wrapper would make the child hit
_delivery_lock (hermes CLI + '-p'), burn the full wait
budget against its parent's flock, and fail every relay delivery with
target_busy. argv[0] may be a resolved venv path (#93590) — the lock
matcher and this assertion both go by basename."""
from pathlib import Path
argv = bot_relay.local_delivery_command("ops", "/tmp/q.txt")
assert argv[1:3] == ["-p", "ops"]
assert Path(argv[0]).name in ("hermes", "hermes.exe")
assert "--run-delivery" not in argv
assert not any("bot_mode_dm" in part for part in argv)
def test_relay_deliver_returns_target_busy_error(tmp_path, monkeypatch):
import tui_gateway.server as srv
h = tmp_path / "h"
(h / "profiles" / "ops").mkdir(parents=True)
(h / "profiles" / "ops" / "config.yaml").touch() # identity marker: bare dirs are not profiles
monkeypatch.setenv("HERMES_HOME", str(h))
monkeypatch.setattr(bot_relay, "turn_wait_seconds", lambda: 0.2)
spawned = {}
# Deterministic spawn detection: sentinel argv from the exact factory the
# deliver handler uses. A global subprocess.run patch also intercepts
# unrelated gateway-init calls (git rev-parse / ls-remote in CI), so
# never fuzzy-match argv — mark the delivery command itself.
monkeypatch.setattr(
bot_relay, "local_delivery_command", lambda prof, tmp: ["__delivery__", prof]
)
def _fake_run(argv, **kwargs):
argv = list(argv or [])
if argv and argv[0] == "__delivery__":
spawned["argv"] = argv
class _Done:
returncode = 0
stdout = ""
stderr = ""
return _Done()
monkeypatch.setattr("hermes_cli.quiet_single_query.run_reported_turn", _fake_run)
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(h, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
try:
out = srv._methods["bot_relay.deliver"](1, {"profile": "ops", "message": "x"})
assert "error" in out
assert out["error"]["code"] == 5096
assert "target_busy" in out["error"]["message"]
assert out["error"]["data"]["reason"] == "target_busy"
assert not spawned, "turn must not spawn while the profile is busy"
finally:
release.set()
t.join(timeout=5)
def test_relay_deliver_serializes_then_succeeds(tmp_path, monkeypatch):
import tui_gateway.server as srv
h = tmp_path / "h"
(h / "profiles" / "ops").mkdir(parents=True)
(h / "profiles" / "ops" / "config.yaml").touch() # identity marker: bare dirs are not profiles
monkeypatch.setenv("HERMES_HOME", str(h))
monkeypatch.setattr(bot_relay, "turn_wait_seconds", lambda: 5.0)
class _Proc:
returncode = 0
stdout = "pong"
stderr = ""
monkeypatch.setattr("hermes_cli.quiet_single_query.run_reported_turn", lambda *a, **k: _Proc())
held = threading.Event()
release = threading.Event()
t = threading.Thread(
target=_hold_flock, args=(turn_lock_path(h, "ops"), held, release)
)
t.start()
assert held.wait(timeout=5)
threading.Timer(0.3, release.set).start()
start = time.monotonic()
out = srv._methods["bot_relay.deliver"](1, {"profile": "ops", "message": "x"})
t.join(timeout=5)
assert "error" not in out, out
assert out["result"]["reply"] == "pong"
assert time.monotonic() - start >= 0.2, "deliver should have queued"
class _WithReason(RuntimeError):
"""An exception carrying its own ``reason``. ``reason`` is a stdlib attribute on
``ssl.SSLError`` and ``urllib.error.URLError`` too, so a refusal must not forward whatever
it finds there into a channel whose consumers expect a closed vocabulary."""
def __init__(self, reason: str, message: str) -> None:
super().__init__(message)
self.reason = reason
@pytest.mark.parametrize(
("failure", "code", "reason"),
[
(TurnBusyError("ops", 0.2), 5096, "target_busy"),
(subprocess.TimeoutExpired(["hermes"], 600), 5093, "delivery_timeout"),
(RuntimeError("Error code: 401 - invalid api key"), 5094, "provider_auth_or_access"),
(RuntimeError("something nobody has a rule for"), 5094, "unknown"),
(_WithReason("CERTIFICATE_VERIFY_FAILED", "ssl handshake failed"), 5094, "unknown"),
(_WithReason("provider_quota_limit", "quota exhausted"), 5094, "provider_quota_limit"),
],
ids=["busy", "turn-timed-out", "classifiable-failure", "unclassifiable-failure",
"reason-outside-the-vocabulary", "reason-inside-the-vocabulary"],
)
def test_every_relay_refusal_carries_its_typed_reason(tmp_path, monkeypatch, failure, code, reason):
"""`data.reason` is the only channel the Desktop forwards: it reads `error.data.reason` and puts
it in the sender's reply file, and the sender re-classifies from free text otherwise — which can
never produce these codes. A refusal that ships only a JSON-RPC code reaches the sending agent as
`[reason: unknown]`, so it cannot tell "retry shortly" from an auth failure. The turn-failure
branch already did this; these three did not."""
import tui_gateway.server as srv
h = tmp_path / "h"
(h / "profiles" / "ops").mkdir(parents=True)
(h / "profiles" / "ops" / "config.yaml").touch() # identity marker: bare dirs are not profiles
monkeypatch.setenv("HERMES_HOME", str(h))
monkeypatch.setattr(bot_relay, "local_delivery_command", lambda prof, tmp: ["__delivery__", prof])
def _raise(argv, **kwargs):
raise failure
monkeypatch.setattr("hermes_cli.quiet_single_query.run_reported_turn", _raise)
out = srv._methods["bot_relay.deliver"](1, {"profile": "ops", "message": "x"})
assert out["error"]["code"] == code
assert out["error"]["data"]["reason"] == reason
@pytest.mark.parametrize(
("failure", "reason"),
[
(RuntimeError("Error code: 401 - invalid api key"), "provider_auth_or_access"),
(RuntimeError("something nobody has a rule for"), "unknown"),
(_WithReason("CERTIFICATE_VERIFY_FAILED", "ssl handshake failed"), "unknown"),
],
ids=["classifiable-failure", "unclassifiable-failure", "reason-outside-the-vocabulary"],
)
def test_delivery_main_reports_every_failure_as_typed_json(tmp_path, monkeypatch, capsys, failure, reason):
"""The local lane's runner stdout IS the sender's completion notification. A failure other
than target_busy used to reach the sender as stderr prose with no reason, so it could not
tell an auth failure from a transient one; it now rides the same vocabulary as the relay."""
dm = tmp_path / "dm.txt"
dm.write_text("hi", encoding="utf-8")
def _raise(*args, **kwargs):
raise failure
monkeypatch.setattr(bot_mode_dm, "_run_delivery", _raise)
rc = bot_mode_dm._delivery_main(["--run-delivery", "query-file", str(dm), "hermes", "-p", "ops", "chat"])
assert rc == 1
payload = json.loads(capsys.readouterr().out.strip())
assert payload == {"error": str(failure), "reason": reason}