Files
hermes-agent/tests/hermes_cli/test_kanban_write_guard.py
ethernet b897d79ba2 test: the home I/O guard allows metadata reads of the guarded root itself
get_default_hermes_root resolves ~/.hermes to decide whether HERMES_HOME is
a profile of it; os.stat on the root directory reads no user state, only
its contents do. Guard tests that deliberately aim at the real root opt out
with allow_real_home_io, and the spill test no longer accepts a real-home
fallback location.
2026-09-19 02:28:20 -04:00

48 lines
1.5 KiB
Python

"""#69283: kanban write guard prevents tests from writing to real ~/.hermes."""
from __future__ import annotations
import pytest
from hermes_cli import kanban_db
from hermes_cli import kanban_db_connect as kbc
# These probe the kanban guard against the real root on purpose.
pytestmark = pytest.mark.allow_real_home_io
def test_connect_succeeds_under_test_home(tmp_path, monkeypatch):
"""When HERMES_HOME is a temp dir, kanban connect succeeds normally."""
home = tmp_path / "hermes_home"
home.mkdir()
monkeypatch.setenv("HERMES_HOME", str(home))
conn = kbc.connect()
try:
assert str(kanban_db.kanban_db_path()).startswith(str(home))
finally:
conn.close()
def test_connect_raises_when_kanban_home_is_real_root(monkeypatch):
"""When kanban paths resolve to the REAL root, connect raises RuntimeError."""
import tests.conftest as _conftest
monkeypatch.setattr(
kanban_db, "kanban_home", lambda: _conftest._REAL_KANBAN_ROOT
)
monkeypatch.setattr(
kanban_db,
"kanban_db_path",
lambda board=None: _conftest._REAL_KANBAN_ROOT / "kanban.db",
)
with pytest.raises(RuntimeError, match="kanban_write_guard"):
kbc.connect()
def test_connect_raises_for_explicit_db_path_under_real_root():
"""Explicit db_path pointing under the real root is also refused."""
import tests.conftest as _conftest
with pytest.raises(RuntimeError, match="kanban_write_guard"):
kbc.connect(_conftest._REAL_KANBAN_ROOT / "kanban.db")