run_agent.py: delete the `# noqa: F401` re-export block (agent.process_bootstrap
OpenAI/_SafeWriter/_get_proxy_*, model_tools get_tool_definitions/
handle_function_call/check_toolset_requirements, FailoverReason,
_qwen_portal_headers/_routermint_headers, session_persistence names,
estimate_request_tokens_rough, ContextCompressor + friends, jittered_backoff,
prompt_builder names, message_sanitization names, tool_dispatch_helpers
names) — 41 names run_agent never used itself — and the `_STREAM_DIAG_HEADERS`
back-compat class alias (no in-tree reader). run_agent now imports only what
it uses (get_toolset_for_tool, is_local_endpoint, coalesce/uniquify tool-call
ids, cleanup_vm/get_active_env from terminal_tool_lifecycle).
agent/*: `_ra().X` late-binds that only reached a re-export now import the
defining module directly (agent_runtime_helpers -> process_bootstrap.OpenAI,
model_tools.handle_function_call, session_persistence._safe_session_filename_component;
agent_init -> model_tools.get_tool_definitions/check_toolset_requirements,
_lazy_headers("agent.client_lifecycle", ...) for qwen/routermint;
system_prompt -> agent.prompt_builder / model_tools directly, dropping its
own _ra() shim and the `_r` parameter threading). `_ra()` stays for
run_agent-resident names (logger, AIAgent, _hermes_home, _set_interrupt, ...).
toolsets.py: remove resolve_multiple_toolsets (shim-only, restored by
34abf954bd); tests/test_toolsets.py pins the same union behavior via
resolve_toolset over each name.
providers/__init__.py: drop the OMIT_TEMPERATURE re-export (no callers via the
package); ProviderProfile stays because __init__ uses it for annotations —
2 tests repointed to providers.base.
agent/iteration_budget.py: drop the "run_agent re-exports the class"
docstring pointer; 4 tests import IterationBudget from its home.
model_tools.py (arg_coercion names), agent/tool_executor.py, and
hermes_cli/cli_session_mixin.py repoints landed via a sibling commit on this
shared worktree.
Callers repointed: gateway/run.py, hermes_cli/cli_chat_turn_mixin.py,
hermes_cli/cli_tui_mixin.py, tui_gateway/session_workdir.py,
agent/transports/codex.py (one-line imports) + comment pointers in
tools/file_state.py, tools/schema_sanitizer.py, scripts/tool_search_livetest.py.
Tests: patch("run_agent.X") / monkeypatch.setattr(run_agent, "X") /
`from run_agent import X` -> defining module across 99 test files.
198 lines
8.6 KiB
Python
198 lines
8.6 KiB
Python
"""Regression coverage for required Codex identity and account headers.
|
|
|
|
The official Codex endpoint must receive Hermes' own harness identity, rather
|
|
than the historical first-party compatibility identity. Live endpoint
|
|
acceptance is a separate smoke test; these tests verify request construction.
|
|
|
|
``_codex_cloudflare_headers`` in ``agent.auxiliary_client`` centralizes the
|
|
header set so the primary chat client (``run_agent.AIAgent.__init__`` +
|
|
``_apply_client_headers_for_base_url``) and the auxiliary client paths
|
|
(``_build_codex_client`` and the ``raw_codex`` branch of ``resolve_provider_client``)
|
|
all emit the same headers.
|
|
|
|
These tests pin:
|
|
- the required Hermes originator
|
|
- the versioned Hermes User-Agent
|
|
- ``ChatGPT-Account-ID`` extraction from the OAuth JWT (canonical casing,
|
|
from codex-rs ``auth.rs``)
|
|
- graceful handling of malformed tokens (drop the account-ID header, don't
|
|
raise)
|
|
- primary-client wiring at both entry points in ``run_agent.py``
|
|
- aux-client wiring at both entry points in ``agent/auxiliary_client.py``
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import base64
|
|
import json
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
from hermes_cli import __version__
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Fixtures
|
|
# ---------------------------------------------------------------------------
|
|
|
|
def _make_codex_jwt(account_id: str = "acct-test-123") -> str:
|
|
"""Build a syntactically valid Codex-style JWT with the account_id claim."""
|
|
def b64url(data: bytes) -> str:
|
|
return base64.urlsafe_b64encode(data).rstrip(b"=").decode()
|
|
header = b64url(b'{"alg":"RS256","typ":"JWT"}')
|
|
claims = {
|
|
"sub": "user-xyz",
|
|
"exp": 9999999999,
|
|
"https://api.openai.com/auth": {
|
|
"chatgpt_account_id": account_id,
|
|
"chatgpt_plan_type": "plus",
|
|
},
|
|
}
|
|
payload = b64url(json.dumps(claims).encode())
|
|
sig = b64url(b"fake-sig")
|
|
return f"{header}.{payload}.{sig}"
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# _codex_cloudflare_headers — the shared helper
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestCodexCloudflareHeaders:
|
|
|
|
def test_user_agent_advertises_hermes_version(self):
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
headers = _codex_cloudflare_headers(_make_codex_jwt())
|
|
assert headers["User-Agent"] == f"HermesAgent/{__version__}"
|
|
assert headers["originator"] == "hermes-agent"
|
|
|
|
|
|
def test_canonical_header_casing(self):
|
|
"""Upstream codex-rs uses PascalCase with trailing -ID. Match exactly."""
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
headers = _codex_cloudflare_headers(_make_codex_jwt())
|
|
assert "ChatGPT-Account-ID" in headers
|
|
# The lowercase/titlecase variants MUST NOT be used — pin to be explicit
|
|
assert "chatgpt-account-id" not in headers
|
|
assert "ChatGPT-Account-Id" not in headers
|
|
|
|
|
|
|
|
def test_jwt_without_chatgpt_account_id_claim(self):
|
|
"""A valid JWT that lacks the account_id claim should still return headers."""
|
|
from agent.auxiliary_client import _codex_cloudflare_headers
|
|
import base64 as _b64, json as _json
|
|
|
|
def b64url(data: bytes) -> str:
|
|
return _b64.urlsafe_b64encode(data).rstrip(b"=").decode()
|
|
payload = b64url(_json.dumps({"sub": "user-xyz", "exp": 9999999999}).encode())
|
|
token = f"{b64url(b'{}')}.{payload}.{b64url(b'sig')}"
|
|
headers = _codex_cloudflare_headers(token)
|
|
assert headers["originator"] == "hermes-agent"
|
|
assert "ChatGPT-Account-ID" not in headers
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Primary chat client wiring (run_agent.AIAgent)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestPrimaryClientWiring:
|
|
|
|
def test_apply_client_headers_on_base_url_change(self):
|
|
"""Credential-rotation / base-url change path must also emit codex headers."""
|
|
from run_agent import AIAgent
|
|
token = _make_codex_jwt("acct-rotation")
|
|
with patch("agent.process_bootstrap.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
agent = AIAgent(
|
|
api_key="placeholder-openrouter-key",
|
|
base_url="https://openrouter.ai/api/v1",
|
|
provider="openrouter",
|
|
model="anthropic/claude-sonnet-4.6",
|
|
quiet_mode=True,
|
|
skip_context_files=True,
|
|
skip_memory=True,
|
|
)
|
|
# Simulate rotation into a Codex credential
|
|
agent._client_kwargs["api_key"] = token
|
|
agent._apply_client_headers_for_base_url(
|
|
"https://chatgpt.com/backend-api/codex"
|
|
)
|
|
headers = agent._client_kwargs.get("default_headers") or {}
|
|
assert headers.get("originator") == "hermes-agent"
|
|
assert headers.get("ChatGPT-Account-ID") == "acct-rotation"
|
|
assert headers.get("User-Agent") == f"HermesAgent/{__version__}"
|
|
|
|
def test_apply_client_headers_clears_codex_headers_off_chatgpt(self):
|
|
"""Switching AWAY from chatgpt.com must drop the codex headers."""
|
|
from run_agent import AIAgent
|
|
token = _make_codex_jwt()
|
|
with patch("agent.process_bootstrap.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
agent = AIAgent(
|
|
api_key=token,
|
|
base_url="https://chatgpt.com/backend-api/codex",
|
|
provider="openai-codex",
|
|
model="gpt-5.4",
|
|
quiet_mode=True,
|
|
skip_context_files=True,
|
|
skip_memory=True,
|
|
)
|
|
# Sanity: headers are set initially
|
|
assert "originator" in (agent._client_kwargs.get("default_headers") or {})
|
|
agent._apply_client_headers_for_base_url(
|
|
"https://api.anthropic.com"
|
|
)
|
|
# default_headers should be popped for anthropic base
|
|
assert "default_headers" not in agent._client_kwargs
|
|
|
|
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Auxiliary client wiring (agent.auxiliary_client)
|
|
# ---------------------------------------------------------------------------
|
|
|
|
class TestAuxiliaryClientWiring:
|
|
def test_build_codex_client_passes_codex_headers(self, monkeypatch):
|
|
"""_build_codex_client builds the OpenAI client used for compression /
|
|
vision / title generation when routed through Codex. Must emit codex
|
|
headers."""
|
|
from agent import auxiliary_client
|
|
token = _make_codex_jwt("acct-aux-try-codex")
|
|
|
|
# Force _select_pool_entry to return "no pool" so we fall through to
|
|
# _read_codex_access_token.
|
|
monkeypatch.setattr(
|
|
auxiliary_client, "_select_pool_entry",
|
|
lambda provider: (False, None),
|
|
)
|
|
monkeypatch.setattr(
|
|
auxiliary_client, "_read_codex_access_token",
|
|
lambda: token,
|
|
)
|
|
with patch("agent.auxiliary_client.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
client, model = auxiliary_client._build_codex_client("gpt-5.4")
|
|
assert client is not None
|
|
headers = mock_openai.call_args.kwargs.get("default_headers") or {}
|
|
assert headers.get("originator") == "hermes-agent"
|
|
assert headers.get("ChatGPT-Account-ID") == "acct-aux-try-codex"
|
|
assert headers.get("User-Agent") == f"HermesAgent/{__version__}"
|
|
|
|
def test_resolve_provider_client_raw_codex_passes_codex_headers(self, monkeypatch):
|
|
"""The ``raw_codex=True`` branch (used by the main agent loop for direct
|
|
responses.stream() access) must also emit codex headers."""
|
|
from agent import auxiliary_client
|
|
token = _make_codex_jwt("acct-aux-raw-codex")
|
|
monkeypatch.setattr(
|
|
auxiliary_client, "_read_codex_access_token",
|
|
lambda: token,
|
|
)
|
|
with patch("agent.auxiliary_client.OpenAI") as mock_openai:
|
|
mock_openai.return_value = MagicMock()
|
|
client, model = auxiliary_client.resolve_provider_client(
|
|
"openai-codex", model="gpt-5.4", raw_codex=True,
|
|
)
|
|
assert client is not None
|
|
headers = mock_openai.call_args.kwargs.get("default_headers") or {}
|
|
assert headers.get("originator") == "hermes-agent"
|
|
assert headers.get("ChatGPT-Account-ID") == "acct-aux-raw-codex"
|
|
assert headers.get("User-Agent") == f"HermesAgent/{__version__}"
|