Files
hermes-agent/tests/hermes_cli/test_update_post_pull_syntax_guard.py
Teknium 39975613b1 test: prune wave 2 + speed fixes — 28,106 → 19,757 test functions, suite wall 315s → 294s
Second, deeper pass over tools/gateway/hermes_cli plus first pass over
the trees wave 1 missed (acp, acp_adapter, skills, computer_use, docker,
dashboard, conformance, monitoring, secret_sources, hermes_state,
providers). Same rubric as wave 1 (AGENTS.md test policy); security,
alternation/caching invariants, issue-number regressions, and E2E kept.

Real test-quality fixes found and rooted out along the way:
- tests/tools/test_command_guards.py made real auxiliary-LLM HTTPS calls
  (DEFAULT_CONFIG smart-approval leaked in) — pinned approval
  mode=manual via autouse fixture: 17.4s → 0.4s.
- test_model_switch_custom_providers.py / test_user_providers_model_switch.py
  silently probed live provider catalogs (~2s/test) — stubbed
  cached_provider_model_ids/provider_model_ids/fetch_api_models.
- test_telegram_noise_filter.py: 15-platform copy-paste matrix over
  shared gateway.run logic → 3 representative platforms (55s → 3.9s).
- test_gateway_shutdown.py: stop()'s 5s interrupt-deadline loop spun on
  MagicMock agents — interrupt.side_effect now clears _running_agents
  (22s → 1.0s).
- test_gateway_inactivity_timeout.py poll-harness timings shrunk 3-5x
  (24s → 1.1s); test_mcp_stability.py backoff/SIGTERM-grace sleeps
  patched (15.4s → 2.5s); test_async_delegation.py negative-drain wait
  5s → 0.5s.
- test_telegram_init_deadline.py: loop-block margin restored to 1.0s
  with rationale comment — the watchdog-dump assertion needs the loop
  blocked well past deadline+grace under parallel load (flaked once in
  the 40-worker verification run at a 0.2s margin).

Verification: full hermetic suite via scripts/run_tests.sh —
2,438 files, 21,718 tests passed, 0 failed, 293.9s wall.
Suite totals vs original baseline: 46,820 → 19,757 test functions
(−57.8%), wall 583.5s → 293.9s (−50%), subprocess CPU 13,564s → 11,623s.
2026-07-29 13:39:40 -07:00

93 lines
3.4 KiB
Python

"""Tests for the post-pull syntax guard in ``hermes update``.
When a bad commit lands on ``main`` with a syntax error in a critical file
(e.g. orphan merge-conflict markers in ``hermes_cli/config.py``), the CLI
becomes unbootable — every ``hermes`` invocation imports those files at
startup. The guard validates them after ``git pull`` and rolls back to the
pre-pull SHA on failure so the user's install stays runnable.
Reference incident: PR #28452 (May 18, 2026) shipped unresolved conflict
markers in ``hermes_cli/config.py``; users who ran ``hermes update`` in
the 7-minute window before #28458 landed could not run any ``hermes``
command afterward.
"""
from __future__ import annotations
from pathlib import Path
from types import SimpleNamespace
from hermes_cli import main as hermes_main
# ---------------------------------------------------------------------------
# _capture_head_sha
# ---------------------------------------------------------------------------
def test_capture_head_sha_returns_stripped_sha(monkeypatch, tmp_path):
def fake_run(cmd, **kwargs):
assert cmd[-2:] == ["rev-parse", "HEAD"]
return SimpleNamespace(stdout="deadbeefcafe\n", returncode=0)
monkeypatch.setattr(hermes_main.subprocess, "run", fake_run)
assert hermes_main._capture_head_sha(["git"], tmp_path) == "deadbeefcafe"
# ---------------------------------------------------------------------------
# _validate_critical_files_syntax
# ---------------------------------------------------------------------------
def _populate_critical_tree(root: Path, *, broken_file: str | None = None) -> None:
"""Create stub files for every entry in ``_UPDATE_CRITICAL_FILES``.
If ``broken_file`` is given, that file gets orphan merge-conflict markers
(the exact failure mode from PR #28452).
"""
broken_payload = (
"x = {\n"
' "a": 1,\n'
"<<<<<<< HEAD\n"
' "b": 2,\n'
"=======\n"
' "c": 0b6d673e7,\n' # invalid binary literal — the actual error users saw
">>>>>>> 0b6d673e7\n"
"}\n"
)
for relpath in hermes_main._UPDATE_CRITICAL_FILES:
path = root / relpath
path.parent.mkdir(parents=True, exist_ok=True)
if relpath == broken_file:
path.write_text(broken_payload)
else:
path.write_text("# stub\n")
def test_validate_critical_files_syntax_tolerates_missing_files(tmp_path):
"""A refactor may legitimately remove one of the critical files — the
guard should skip missing files, not falsely flag the install as broken."""
# Populate everything except hermes_constants.py
for relpath in hermes_main._UPDATE_CRITICAL_FILES:
if relpath == "hermes_constants.py":
continue
path = tmp_path / relpath
path.parent.mkdir(parents=True, exist_ok=True)
path.write_text("# stub\n")
ok, failing_path, error = hermes_main._validate_critical_files_syntax(tmp_path)
assert ok is True
assert failing_path is None
assert error is None
# ---------------------------------------------------------------------------
# Repo invariant — the production tree itself must always pass the guard.
# This catches the case where ``main`` ships a syntax error before the next
# release; if a future ``hermes update`` would brick users, this test fails
# in CI first.
# ---------------------------------------------------------------------------