# Conflicts: # apps/desktop/e2e/archived-hidden-session-recoverable.spec.ts # apps/desktop/e2e/bot-chat-message-agent-friendly-name.spec.ts # apps/desktop/e2e/bot-mailbox-unreadable-ticket.spec.ts # apps/desktop/e2e/bot-mode-roster-localized.spec.ts # apps/desktop/e2e/bot-mode-row-click-mirrors-registry.spec.ts # apps/desktop/e2e/bot-mode-tab-shows-bot-name.spec.ts # apps/desktop/e2e/bot-roster-group-row-organisation.spec.ts # apps/desktop/e2e/bot-roster-ignores-infra-dirs.spec.ts # apps/desktop/e2e/bot-roster-timestamp-meta.spec.ts # apps/desktop/e2e/bot-roster-user-sections.spec.ts # apps/desktop/e2e/bot-routines-pane-narrow.spec.ts # apps/desktop/e2e/bot-row-open-recent-session.spec.ts # apps/desktop/e2e/bot-tile-ignores-ambient-composer-model.spec.ts # apps/desktop/e2e/group-composer-auto-grow.spec.ts # apps/desktop/e2e/group-create-gate-remote-roster.spec.ts # apps/desktop/e2e/group-prompt-renamed-primary-handle.spec.ts # apps/desktop/e2e/hosted-room-backend-continuity.spec.ts # apps/desktop/e2e/hosted-room-legacy-store-migration.spec.ts # apps/desktop/e2e/settings-scope-chips-bot-title.spec.ts # apps/desktop/e2e/worktree-branch-status.spec.ts # apps/desktop/electron/backend-probes.test.ts # apps/desktop/electron/connection-apply.test.ts # apps/desktop/electron/desktop-electron-pin.test.ts # apps/desktop/electron/desktop-uninstall.test.ts # apps/desktop/electron/gateway-file-download-transport.test.ts # apps/desktop/electron/gateway-stop-before-update.test.ts # apps/desktop/electron/github-api-auth.test.ts # apps/desktop/electron/registry-primary-profile-scope.test.ts # apps/desktop/electron/update-api-check.test.ts # apps/desktop/electron/update-handoff-marker.test.ts # apps/desktop/electron/venv-blocker-scan.test.ts # apps/desktop/scripts/after-extract.test.mjs # apps/desktop/scripts/local-pack-publish.test.mjs # apps/desktop/scripts/tasks-scroll.test.mjs # apps/desktop/src/app/settings/model-settings.test.tsx # apps/desktop/src/app/updates-overlay.blockers.test.tsx # apps/desktop/src/components/desktop-install-overlay.test.tsx # apps/desktop/src/lib/update-copy.test.ts # scripts/ci/check_os_marker_fakes.py # tests-js/desktop-mac-usage-descriptions.test.ts # tests-js/node-engine-alignment.test.ts # tests/agent/lsp/test_install_and_lint_fixes.py # tests/agent/test_command_token_source.py # tests/agent/test_compression_boundary_hook.py # tests/agent/test_create_openai_client_ssl_verify.py # tests/agent/test_custom_provider_ca_probes.py # tests/agent/test_endpoint_blackhole.py # tests/agent/test_estimator_parity.py # tests/agent/test_in_place_compaction.py # tests/agent/test_moa_loop_mode.py # tests/agent/test_model_metadata.py # tests/agent/test_skill_session_platform_gate.py # tests/agent/test_skill_utils.py # tests/agent/test_ssl_ca_guard.py # tests/computer_use/test_doctor.py # tests/cron/test_codex_execution_paths.py # tests/cron/test_cron_bot_chat_delivery.py # tests/cron/test_cron_script.py # tests/cron/test_media_delivery_parity.py # tests/cron/test_misfire_catchup.py # tests/cron/test_parallel_pool.py # tests/cron/test_recurring_eagain_redispatch.py # tests/gateway/test_choice_picker.py # tests/gateway/test_control_socket_windows_live.py # tests/gateway/test_dingtalk.py # tests/gateway/test_feishu.py # tests/gateway/test_feishu_onboard.py # tests/gateway/test_gateway_shutdown.py # tests/gateway/test_matrix.py # tests/gateway/test_model_command_custom_providers.py # tests/gateway/test_reasoning_command.py # tests/gateway/test_runtime_footer.py # tests/gateway/test_session.py # tests/gateway/test_session_hygiene.py # tests/gateway/test_status.py # tests/gateway/test_teams.py # tests/gateway/test_turn_lease.py # tests/gateway/test_whatsapp_connect.py # tests/hermes_cli/test_approvals_command.py # tests/hermes_cli/test_auth_store_lock_concurrent.py # tests/hermes_cli/test_backup.py # tests/hermes_cli/test_banner_git_state.py # tests/hermes_cli/test_certifi_repair.py # tests/hermes_cli/test_cmd_update.py # tests/hermes_cli/test_compat_manifest_targets.py # tests/hermes_cli/test_computer_use_cli.py # tests/hermes_cli/test_cpr_local_leak.py # tests/hermes_cli/test_dashboard_auth_gate.py # tests/hermes_cli/test_dashboard_procs_kill_grace.py # tests/hermes_cli/test_desktop_lifecycle_windows_live.py # tests/hermes_cli/test_doctor.py # tests/hermes_cli/test_doctor_command_install.py # tests/hermes_cli/test_fleet_config_migration_windows_live.py # tests/hermes_cli/test_gateway.py # tests/hermes_cli/test_gateway_platform_gating.py # tests/hermes_cli/test_gateway_restart_loop.py # tests/hermes_cli/test_gateway_task_probe.py # tests/hermes_cli/test_gateway_wsl.py # tests/hermes_cli/test_gui_command.py # tests/hermes_cli/test_install_cua_driver.py # tests/hermes_cli/test_kanban_db.py # tests/hermes_cli/test_lazy_command_exports.py # tests/hermes_cli/test_lazy_refresh_venv_repair.py # tests/hermes_cli/test_linux_desktop_entry.py # tests/hermes_cli/test_local_runtime.py # tests/hermes_cli/test_local_runtime_updates.py # tests/hermes_cli/test_managed_uv.py # tests/hermes_cli/test_mcp_reload_confirm_gate.py # tests/hermes_cli/test_nous_subscription.py # tests/hermes_cli/test_npm_engine.py # tests/hermes_cli/test_personality_none.py # tests/hermes_cli/test_pet_toggle.py # tests/hermes_cli/test_plan_reconciliation_windows_live.py # tests/hermes_cli/test_plugin_event_bus.py # tests/hermes_cli/test_plugin_manifest_v2.py # tests/hermes_cli/test_plugin_packs.py # tests/hermes_cli/test_plugins_cmd.py # tests/hermes_cli/test_plugins_cmd_enable_disable_nested.py # tests/hermes_cli/test_process_identity.py # tests/hermes_cli/test_profiles.py # tests/hermes_cli/test_profiles_sidebar_cache.py # tests/hermes_cli/test_pty_bridge.py # tests/hermes_cli/test_resolve_turn_limit.py # tests/hermes_cli/test_serve_runtime_inventory.py # tests/hermes_cli/test_session_vacuum_config.py # tests/hermes_cli/test_set_config_value.py # tests/hermes_cli/test_signal_handler_kanban_worker.py # tests/hermes_cli/test_slash_confirm_windows.py # tests/hermes_cli/test_stale_pid_guard.py # tests/hermes_cli/test_startup_fast_guards.py # tests/hermes_cli/test_status.py # tests/hermes_cli/test_telegram_managed_bot.py # tests/hermes_cli/test_tools_config.py # tests/hermes_cli/test_update_apply_shallow_count.py # tests/hermes_cli/test_update_autostash.py # tests/hermes_cli/test_update_concurrent_quarantine.py # tests/hermes_cli/test_update_fetch_failure_classifier.py # tests/hermes_cli/test_update_fleet_probe_resume_token.py # tests/hermes_cli/test_update_handoff_backend_reap.py # tests/hermes_cli/test_update_handoff_desktop_rebuild.py # tests/hermes_cli/test_update_head_moved_gate.py # tests/hermes_cli/test_update_host_obligation.py # tests/hermes_cli/test_update_import_guard.py # tests/hermes_cli/test_update_interrupted_recovery.py # tests/hermes_cli/test_update_inventory.py # tests/hermes_cli/test_update_launchd_unloaded_gateway.py # tests/hermes_cli/test_update_missing_configured_deps.py # tests/hermes_cli/test_update_modified_notice.py # tests/hermes_cli/test_update_multiplex_migration_hook.py # tests/hermes_cli/test_update_no_gateway_restart.py # tests/hermes_cli/test_update_orphan_backend_reap.py # tests/hermes_cli/test_update_parked_branch_guard.py # tests/hermes_cli/test_update_post_pull_syntax_guard.py # tests/hermes_cli/test_update_receipt.py # tests/hermes_cli/test_update_self_lock.py # tests/hermes_cli/test_update_shim_fail_closed.py # tests/hermes_cli/test_update_shim_self_lock.py # tests/hermes_cli/test_update_sqlite_remediation.py # tests/hermes_cli/test_update_stale_dashboard.py # tests/hermes_cli/test_update_stale_virtualenv.py # tests/hermes_cli/test_update_venv_health.py # tests/hermes_cli/test_update_venv_ownership_preflight.py # tests/hermes_cli/test_update_wedged_gateway.py # tests/hermes_cli/test_update_yes_flag.py # tests/hermes_cli/test_update_zip_two_phase.py # tests/hermes_cli/test_urllib_security.py # tests/hermes_cli/test_ux_messages_auth_config.py # tests/hermes_cli/test_ux_messages_startup.py # tests/hermes_cli/test_venv_holder_classifier.py # tests/hermes_cli/test_verify_console_scripts.py # tests/hermes_cli/test_verify_core_dependencies.py # tests/hermes_cli/test_web_server.py # tests/hermes_cli/test_web_server_console_ws.py # tests/hermes_cli/test_web_server_ws_ping.py # tests/hermes_cli/test_web_ui_build.py # tests/hermes_state/test_fts_rebuild_admission.py # tests/hermes_state/test_hermes_state.py # tests/plugins/memory/test_memory_lazy_install.py # tests/plugins/test_google_meet_plugin.py # tests/plugins/test_langfuse_plugin.py # tests/plugins/test_security_guidance_plugin.py # tests/plugins/test_transform_llm_output_hook.py # tests/scripts/desktop_update/test_desktop_update_windows_gateway_flag.py # tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py # tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py # tests/scripts/install/test_install_clone_throttle_fallback.py # tests/scripts/install/test_install_lockfile_churn.py # tests/scripts/install/test_install_no_initial_commit.py # tests/scripts/install/test_install_sh_browser_install.py # tests/scripts/install/test_install_sh_node_prerelease.py # tests/scripts/install/test_install_sh_symlink_stomp.py # tests/scripts/install/test_install_sh_uv_lock_config.py # tests/scripts/install/test_install_unmerged_index.py # tests/scripts/test_contributor_map.py # tests/scripts/test_run_tests_parallel.py # tests/skills/test_competitor_news_monitor_skill.py # tests/skills/test_document_to_action_items_skill.py # tests/skills/test_google_workspace_setup.py # tests/skills/test_google_workspace_setup_deps.py # tests/skills/test_grounded_citations_skill.py # tests/skills/test_ip_as_logo_skill.py # tests/skills/test_live_dashboard_skill.py # tests/skills/test_mcp_oauth_remote_gateway_skill.py # tests/skills/test_office_document_skills.py # tests/skills/test_openclaw_migration.py # tests/skills/test_product_price_monitor_skill.py # tests/skills/test_scrollcraft_skill.py # tests/skills/test_setup_wizard_generator_skill.py # tests/skills/test_weekly_review_planning_skill.py # tests/test_engines_satisfiable.py # tests/test_fast_safe_load.py # tests/test_hermes_bootstrap.py # tests/test_hermes_constants.py # tests/test_hermes_logging.py # tests/test_managed_runtime_resolution.py # tests/test_model_tools_async_bridge.py # tests/test_packaging_build_guard.py # tests/test_packaging_metadata.py # tests/test_yaml_indent_consistency.py # tests/tools/test_approval_timeout_overflow.py # tests/tools/test_base_environment.py # tests/tools/test_bot_mode_dm.py # tests/tools/test_browser_chromium_check.py # tests/tools/test_browser_hardening.py # tests/tools/test_browser_homebrew_paths.py # tests/tools/test_browser_npx_warmup.py # tests/tools/test_browser_orphan_reaper.py # tests/tools/test_browser_real_profile.py # tests/tools/test_browser_use_cli.py # tests/tools/test_clipboard.py # tests/tools/test_code_execution.py # tests/tools/test_code_execution_modes.py # tests/tools/test_code_execution_windows_env.py # tests/tools/test_computer_use.py # tests/tools/test_delegate_liveness_timeout.py # tests/tools/test_execute_code_approval_cluster.py # tests/tools/test_execution_flag_detection.py # tests/tools/test_fal_common.py # tests/tools/test_file_operations.py # tests/tools/test_file_tools.py # tests/tools/test_file_tools_cwd_resolution.py # tests/tools/test_file_tools_live.py # tests/tools/test_lazy_deps.py # tests/tools/test_lazy_deps_durable_target.py # tests/tools/test_lazy_deps_managed.py # tests/tools/test_local_env_blocklist.py # tests/tools/test_local_tempdir.py # tests/tools/test_macos_protected_search.py # tests/tools/test_mcp_npx_cached_bin.py # tests/tools/test_oneshot_completion_linger.py # tests/tools/test_process_registry.py # tests/tools/test_read_file_schema_gating.py # tests/tools/test_skill_improvements.py # tests/tools/test_skills_sync.py # tests/tools/test_termux_api_detection.py # tests/tools/test_tirith_security.py # tests/tools/test_transcription_tools.py # tests/tools/test_tts_streaming.py # tests/tools/test_wake_word.py # tests/tui_gateway/test_compute_host_borrowed_lease.py # tests/tui_gateway/test_compute_host_turn_protocol.py # tests/tui_gateway/test_isolated_orphan_activity.py # tests/tui_gateway/test_protocol.py # tests/tui_gateway/test_slash_worker_profile_home.py # tests/tui_gateway/test_subprocess_encoding.py # tests/tui_gateway/test_tui_gateway_server.py # ui-tui/src/__tests__/terminalParity.test.ts # ui-tui/src/__tests__/termuxComposerLayout.test.ts # ui-tui/src/__tests__/textInputFastEcho.test.ts
307 lines
12 KiB
Python
307 lines
12 KiB
Python
"""Tests for `!<command>` shell mode in the interactive CLI.
|
|
|
|
Covers bang detection/parsing, that the terminal tool's approval gate is
|
|
invoked for a dangerous command, that non-zero exit codes surface, and the
|
|
load-bearing invariant: a bang command leaves conversation_history
|
|
byte-identical because it never becomes a turn.
|
|
"""
|
|
import builtins
|
|
import copy
|
|
import json
|
|
import os
|
|
from unittest.mock import MagicMock, patch
|
|
|
|
import pytest
|
|
|
|
from hermes_cli.bang_shell import (
|
|
USAGE_HINT,
|
|
bang_shell_enabled,
|
|
is_bang_command,
|
|
parse_bang_command,
|
|
run_bang_command,
|
|
)
|
|
|
|
# ── detection / parsing ────────────────────────────────────────────────────
|
|
|
|
class TestBangDetection:
|
|
@pytest.mark.parametrize("text", [
|
|
"!ls",
|
|
"!git status",
|
|
" !ls -la", # leading whitespace still counts
|
|
"! spaced out", # `!` followed by spaces
|
|
"!!", # double bang
|
|
"!", # bare bang
|
|
])
|
|
def test_leading_bang_is_bang(self, text):
|
|
assert is_bang_command(text) is True
|
|
|
|
@pytest.mark.parametrize("text", [
|
|
"fix the bug!", # trailing `!` in prose
|
|
"echo hi! please", # mid-text `!`
|
|
"run this: !ls", # `!` not at the start
|
|
"/help",
|
|
"hello world",
|
|
"",
|
|
" ",
|
|
None,
|
|
123,
|
|
])
|
|
def test_non_leading_bang_is_not_bang(self, text):
|
|
assert is_bang_command(text) is False
|
|
|
|
@pytest.mark.parametrize("text,expected", [
|
|
("!ls", "ls"),
|
|
("!git status", "git status"),
|
|
(" !ls -la ", "ls -la"),
|
|
("! echo hi", "echo hi"),
|
|
("!!", "!"), # second bang belongs to the command
|
|
("!!ls", "!ls"),
|
|
("!", ""), # bare bang → no command
|
|
("! ", ""),
|
|
("not a bang", ""),
|
|
])
|
|
def test_parse_strips_exactly_one_bang(self, text, expected):
|
|
assert parse_bang_command(text) == expected
|
|
|
|
class TestBangContextGating:
|
|
"""Bang mode is CLI-only — gateway/cron users have their own shells."""
|
|
|
|
def test_enabled_in_plain_cli(self, monkeypatch):
|
|
for var in ("HERMES_GATEWAY_SESSION", "HERMES_CRON_SESSION",
|
|
"HERMES_SESSION_PLATFORM"):
|
|
monkeypatch.delenv(var, raising=False)
|
|
assert bang_shell_enabled() is True
|
|
|
|
@pytest.mark.parametrize("var,value", [
|
|
("HERMES_GATEWAY_SESSION", "1"),
|
|
("HERMES_CRON_SESSION", "true"),
|
|
("HERMES_SESSION_PLATFORM", "discord"),
|
|
])
|
|
def test_disabled_in_non_cli_contexts(self, monkeypatch, var, value):
|
|
for v in ("HERMES_GATEWAY_SESSION", "HERMES_CRON_SESSION",
|
|
"HERMES_SESSION_PLATFORM"):
|
|
monkeypatch.delenv(v, raising=False)
|
|
monkeypatch.setenv(var, value)
|
|
assert bang_shell_enabled() is False
|
|
|
|
# ── execution ──────────────────────────────────────────────────────────────
|
|
|
|
class TestBangExecution:
|
|
@pytest.mark.platforms("linux")
|
|
def test_output_is_streamed_to_writer(self):
|
|
lines = []
|
|
code = run_bang_command("echo bang-one; echo bang-two", writer=lines.append)
|
|
assert code == 0
|
|
assert "bang-one" in lines
|
|
assert "bang-two" in lines
|
|
|
|
@pytest.mark.platforms("linux")
|
|
def test_stderr_is_merged_into_output(self):
|
|
lines = []
|
|
run_bang_command("echo to-stderr >&2", writer=lines.append)
|
|
assert "to-stderr" in lines
|
|
|
|
def test_nonzero_exit_code_is_returned(self):
|
|
lines = []
|
|
code = run_bang_command("exit 42", writer=lines.append)
|
|
assert code == 42
|
|
|
|
@pytest.mark.platforms("linux")
|
|
def test_runs_in_requested_cwd(self, tmp_path):
|
|
lines = []
|
|
code = run_bang_command("pwd", cwd=str(tmp_path), writer=lines.append)
|
|
assert code == 0
|
|
# macOS resolves /tmp through /private, so compare realpaths.
|
|
assert os.path.realpath(lines[-1].strip()) == os.path.realpath(str(tmp_path))
|
|
|
|
def test_missing_cwd_falls_back_without_crashing(self, tmp_path):
|
|
lines = []
|
|
code = run_bang_command(
|
|
"echo ok", cwd=str(tmp_path / "does-not-exist"), writer=lines.append
|
|
)
|
|
assert code == 0
|
|
assert "ok" in lines
|
|
|
|
def test_unavailable_environment_sanitizer_prevents_launch(self):
|
|
lines = []
|
|
real_import = builtins.__import__
|
|
|
|
def block_sanitizer(name, *args, **kwargs):
|
|
if name == "tools.environments.local":
|
|
raise ImportError("environment sanitizer unavailable")
|
|
return real_import(name, *args, **kwargs)
|
|
|
|
with patch("builtins.__import__", block_sanitizer), \
|
|
patch("hermes_cli.bang_shell.subprocess.Popen") as popen:
|
|
code = run_bang_command("echo must-not-run", writer=lines.append)
|
|
|
|
assert code == 127
|
|
popen.assert_not_called()
|
|
assert any("failed to run command" in line for line in lines)
|
|
|
|
# ── CLI handler: approval gate, usage hint, exit codes ─────────────────────
|
|
|
|
def _make_cli(history=None):
|
|
"""Build a HermesCLI shell with only what handle_bang_shell touches."""
|
|
from cli import HermesCLI
|
|
|
|
cli = HermesCLI.__new__(HermesCLI)
|
|
cli.config = {}
|
|
cli.console = MagicMock()
|
|
cli.agent = None
|
|
cli.session_id = "test-session"
|
|
cli.conversation_history = [] if history is None else history
|
|
cli._app = None
|
|
return cli
|
|
|
|
def _printed(cli):
|
|
"""All text the CLI printed, flattened to plain strings."""
|
|
out = []
|
|
for call in cli.console.print.call_args_list:
|
|
if not call.args:
|
|
continue
|
|
arg = call.args[0]
|
|
out.append(getattr(arg, "plain", None) or str(arg))
|
|
return out
|
|
|
|
class TestBangHandlerDispatch:
|
|
def test_non_bang_text_is_not_handled(self):
|
|
cli = _make_cli()
|
|
assert cli.handle_bang_shell("please fix this bug!") is False
|
|
assert cli.handle_bang_shell("/help") is False
|
|
|
|
def test_bare_bang_prints_usage_and_runs_nothing(self):
|
|
cli = _make_cli()
|
|
with patch("hermes_cli.bang_shell.run_bang_command") as runner:
|
|
assert cli.handle_bang_shell("!") is True
|
|
runner.assert_not_called()
|
|
assert any(USAGE_HINT in line for line in _printed(cli))
|
|
|
|
def test_command_output_is_printed(self):
|
|
cli = _make_cli()
|
|
assert cli.handle_bang_shell("!echo hello-bang") is True
|
|
assert any("hello-bang" in line for line in _printed(cli))
|
|
|
|
def test_nonzero_exit_is_surfaced_to_the_user(self):
|
|
cli = _make_cli()
|
|
assert cli.handle_bang_shell("!exit 3") is True
|
|
assert any("exited 3" in line for line in _printed(cli))
|
|
|
|
def test_disabled_context_falls_through(self, monkeypatch):
|
|
"""Gateway sessions must not execute bang commands."""
|
|
cli = _make_cli()
|
|
monkeypatch.setenv("HERMES_GATEWAY_SESSION", "1")
|
|
with patch("hermes_cli.bang_shell.run_bang_command") as runner:
|
|
assert cli.handle_bang_shell("!echo nope") is False
|
|
runner.assert_not_called()
|
|
|
|
class TestBangApprovalGate:
|
|
"""A user-typed command still goes through the terminal tool's gate."""
|
|
|
|
def test_approval_gate_is_invoked_for_a_dangerous_command(self):
|
|
cli = _make_cli()
|
|
gate = MagicMock(return_value={"approved": True, "message": None})
|
|
with patch("tools.terminal_tool._check_all_guards", gate), \
|
|
patch("hermes_cli.bang_shell.run_bang_command", return_value=0):
|
|
cli.handle_bang_shell("!rm -rf ./build")
|
|
|
|
gate.assert_called_once()
|
|
assert gate.call_args.args[0] == "rm -rf ./build"
|
|
|
|
def test_gate_is_invoked_for_every_command_not_just_dangerous_ones(self):
|
|
cli = _make_cli()
|
|
gate = MagicMock(return_value={"approved": True, "message": None})
|
|
with patch("tools.terminal_tool._check_all_guards", gate), \
|
|
patch("hermes_cli.bang_shell.run_bang_command", return_value=0):
|
|
cli.handle_bang_shell("!ls")
|
|
gate.assert_called_once()
|
|
|
|
def test_denied_command_is_not_executed(self):
|
|
cli = _make_cli()
|
|
gate = MagicMock(return_value={
|
|
"approved": False,
|
|
"message": "Command denied: recursive delete",
|
|
})
|
|
with patch("tools.terminal_tool._check_all_guards", gate), \
|
|
patch("hermes_cli.bang_shell.run_bang_command") as runner:
|
|
assert cli.handle_bang_shell("!rm -rf /important") is True
|
|
|
|
runner.assert_not_called()
|
|
assert any("denied" in line.lower() for line in _printed(cli))
|
|
|
|
def test_real_gate_blocks_a_hardline_command(self):
|
|
"""End-to-end through the real approval module — no execution."""
|
|
cli = _make_cli()
|
|
with patch("hermes_cli.bang_shell.run_bang_command") as runner:
|
|
assert cli.handle_bang_shell("!rm -rf /") is True
|
|
runner.assert_not_called()
|
|
|
|
# ── THE load-bearing invariant ─────────────────────────────────────────────
|
|
|
|
_SEED_HISTORY = [
|
|
{"role": "system", "content": "You are Hermes."},
|
|
{"role": "user", "content": "hello"},
|
|
{"role": "assistant", "content": "Hi there."},
|
|
{"role": "user", "content": "list the files"},
|
|
{
|
|
"role": "assistant",
|
|
"content": "",
|
|
"tool_calls": [{
|
|
"id": "call_1",
|
|
"type": "function",
|
|
"function": {"name": "terminal", "arguments": '{"command": "ls"}'},
|
|
}],
|
|
},
|
|
{"role": "tool", "tool_call_id": "call_1", "content": "a.py b.py"},
|
|
]
|
|
|
|
class TestBangLeavesHistoryByteIdentical:
|
|
"""Nothing about a bang command may enter conversation history.
|
|
|
|
This is what makes `!` free (zero tokens, prompt cache untouched) and
|
|
unable to break role alternation. Compared as serialized JSON so an added,
|
|
removed, or mutated message anywhere in the list fails the assertion.
|
|
"""
|
|
|
|
@pytest.mark.parametrize("submission", [
|
|
"!echo history-check", # succeeds
|
|
"!exit 7", # non-zero exit
|
|
"!", # bare bang / usage hint
|
|
"!definitely-not-a-real-binary-xyz", # command not found
|
|
])
|
|
def test_history_is_byte_identical_before_and_after(self, submission):
|
|
cli = _make_cli(history=copy.deepcopy(_SEED_HISTORY))
|
|
before = json.dumps(cli.conversation_history, sort_keys=True)
|
|
|
|
cli.handle_bang_shell(submission)
|
|
|
|
after = json.dumps(cli.conversation_history, sort_keys=True)
|
|
assert after == before, (
|
|
f"bang command {submission!r} mutated conversation history"
|
|
)
|
|
assert len(cli.conversation_history) == len(_SEED_HISTORY)
|
|
|
|
def test_history_unchanged_when_command_is_denied(self):
|
|
cli = _make_cli(history=copy.deepcopy(_SEED_HISTORY))
|
|
before = json.dumps(cli.conversation_history, sort_keys=True)
|
|
|
|
gate = MagicMock(return_value={"approved": False, "message": "nope"})
|
|
with patch("tools.terminal_tool._check_all_guards", gate):
|
|
cli.handle_bang_shell("!rm -rf /important")
|
|
|
|
assert json.dumps(cli.conversation_history, sort_keys=True) == before
|
|
|
|
def test_agent_is_never_invoked(self):
|
|
"""No model turn: the agent object is not touched at all."""
|
|
cli = _make_cli(history=copy.deepcopy(_SEED_HISTORY))
|
|
agent = MagicMock()
|
|
cli.agent = agent
|
|
|
|
cli.handle_bang_shell("!echo no-model-turn")
|
|
|
|
# No chat/steer/run/redirect call of any kind.
|
|
assert agent.mock_calls == []
|
|
assert json.dumps(cli.conversation_history, sort_keys=True) == json.dumps(
|
|
_SEED_HISTORY, sort_keys=True
|
|
)
|