Under gateway.multiplex_profiles, os.environ holds the DEFAULT profile's .env; a
secondary profile's values exist only in the per-turn secret scope. Every reader
below still read os.environ/os.getenv at call time, so a secondary profile's turn
silently used the default profile's value.
Credentials (F6): FIRECRAWL_API_KEY (read_file hosted OCR), OPENVIKING_API_KEY,
mem0-OSS OPENAI_API_KEY, MODAL_TOKEN_ID/SECRET and BROWSER_USE_API_KEY presence
gates, and the xAI video plugin's os.getenv("XAI_API_KEY") fallback AFTER the
scoped resolver had already missed — the exact fallback-after-miss shape
gateway/AGENTS.md forbids. Deleted, not re-scoped: the resolver is the scope.
Identity / tenant (F7): MEM0_USER_ID/AGENT_ID/HOST/MODE, SUPERMEMORY_CONTAINER_TAG,
RETAINDB_PROJECT, OPENVIKING_ACCOUNT/USER/AGENT (and the whole layered() env
read), HINDSIGHT_BANK_ID/MODE/retain shaping, HERMES_HONCHO_HOST. A raw read
put a secondary profile's memories into the default profile's account/bank/
project/tenant and recalled them back into the default's turns. Each now uses
get_secret with the provider's own per-profile default on a miss.
Endpoints (F8): OPENAI_BASE_URL (aux custom runtime + direct-alias expansion),
XAI_BASE_URL/HERMES_XAI_BASE_URL (aux OAuth), NOUS_INFERENCE_BASE_URL (#65941,
both the aux builder and hermes_cli.auth_nous._nous_inference_env_override),
GATEWAY_PROXY_URL (same UnscopedSecretError-only fallback shape as
GATEWAY_PROXY_KEY three lines below), FIRECRAWL_API_URL, BROWSERBASE_BASE_URL,
SUPERMEMORY/RETAINDB/HONCHO/HINDSIGHT URLs. The keys beside them were already
scoped, so a secondary's key was sent to the default profile's proxy or host.
Targets / display (F11): WEIXIN_HOME_CHANNEL (message posted into the default's
chat), HERMES_LANGUAGE, and agent/i18n's process-wide lru_cache of
display.language — now keyed by HERMES_HOME.
Outbound webhooks: hooks.outbound[].secret_env resolved from os.environ while
the gateway registers each profile's targets inside that profile's scope, so a
secondary's deliveries were signed with the default's secret or left unsigned.
Agent-cache eviction: _spawn_release_thread started a bare threading.Thread, so
commit_memory_session -> provider on_session_end ran with an EMPTY context. The
thread now runs copy_context() and, for the unscoped housekeeping sweep, enters
the owning profile's _profile_runtime_scope resolved from the session key
(agent:<profile>:...). The pressure batch does the same per key.
session_search (#82903): agent/inline_tool_executors.py::_session_search
forwarded every schema argument except `profile`, so a gateway agent could
never select a named profile's store. Forwarded; the ownership-scoping design
in #87779/#87847 is a separate design call and is not attempted here.
Live repro (/tmp/mux_audit/fix-tool-memory-reads/repro.py): 28 FAIL on
origin/main -> 0 FAIL with this change; 10 new invariant tests red on base.
Fixes #82903
Fixes #65941
Fixes #99121
Addresses #87779
Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com>
Co-authored-by: Michael Versluis (Berry) <michael@wve.nl>
68 lines
2.7 KiB
Python
68 lines
2.7 KiB
Python
"""Multiplex invariant: agent-cache eviction commits end-of-session memory under the OWNING profile.
|
|
|
|
``_spawn_release_thread`` used to start a bare ``threading.Thread``; threads begin with an EMPTY
|
|
context, so provider ``on_session_end`` (credentials/home read at call time) ran under the launch
|
|
profile — a secondary's transcript was extracted into the default profile's memory namespace, or
|
|
failed closed (``UnscopedSecretError``) and the memories were lost.
|
|
"""
|
|
from __future__ import annotations
|
|
|
|
import threading
|
|
from pathlib import Path
|
|
from types import SimpleNamespace
|
|
|
|
from agent import secret_scope
|
|
from gateway.config import GatewayConfig
|
|
from gateway.run import GatewayRunner
|
|
from hermes_constants import get_hermes_home
|
|
|
|
|
|
def _runner(profile_homes: dict[str, Path]) -> GatewayRunner:
|
|
runner = GatewayRunner.__new__(GatewayRunner)
|
|
runner.config = GatewayConfig(multiplex_profiles=True)
|
|
runner.session_store = SimpleNamespace(_profile_home_for_key=lambda key: profile_homes.get(key))
|
|
return runner
|
|
|
|
|
|
def _seen_after_release(runner, key, *, wait_scope=None) -> dict:
|
|
seen: dict = {}
|
|
done = threading.Event()
|
|
|
|
def target(agent, k):
|
|
seen["scope"] = secret_scope.current_secret_scope()
|
|
seen["home"] = get_hermes_home()
|
|
done.set()
|
|
|
|
runner._spawn_release_thread(target, (None, key), f"t-{key}", inline_fallback=False, session_key=key)
|
|
assert done.wait(5)
|
|
return seen
|
|
|
|
|
|
def test_unscoped_housekeeping_sweep_enters_the_owning_profile_scope(tmp_path, monkeypatch):
|
|
default_home = tmp_path / ".hermes"
|
|
prof_b = default_home / "profiles" / "b"
|
|
prof_b.mkdir(parents=True)
|
|
(prof_b / ".env").write_text("HINDSIGHT_LLM_API_KEY=key-of-b\n")
|
|
monkeypatch.setenv("HERMES_HOME", str(default_home))
|
|
secret_scope.set_multiplex_active(True)
|
|
try:
|
|
# The housekeeping watcher runs with NO scope installed.
|
|
assert secret_scope.current_secret_scope() is None
|
|
seen = _seen_after_release(_runner({"agent:b:telegram:dm:1": prof_b}), "agent:b:telegram:dm:1")
|
|
finally:
|
|
secret_scope.set_multiplex_active(False)
|
|
assert seen["home"] == prof_b
|
|
assert seen["scope"] and seen["scope"].get("HINDSIGHT_LLM_API_KEY") == "key-of-b"
|
|
|
|
|
|
def test_in_turn_cap_eviction_keeps_the_callers_scope(tmp_path, monkeypatch):
|
|
monkeypatch.setenv("HERMES_HOME", str(tmp_path))
|
|
secret_scope.set_multiplex_active(True)
|
|
token = secret_scope.set_secret_scope({"MARKER": "turn-scope"})
|
|
try:
|
|
seen = _seen_after_release(_runner({}), "agent:main:cli:1")
|
|
finally:
|
|
secret_scope.reset_secret_scope(token)
|
|
secret_scope.set_multiplex_active(False)
|
|
assert seen["scope"] == {"MARKER": "turn-scope"}
|