* fix(update): stop reading gateway identity off the restart watcher's argv (#107002) The detached restart watcher is spawned as `python -c <watcher source> <old_pid> <python> -m hermes_cli.main gateway run`. Its trailing argv is the command it will spawn LATER, but the canonical matchers read identity straight off the joined command line, so the watcher itself was classified as a live `gateway run` process — the documented "never infer process identity from argv substrings" bug class, on the exact surface `hermes update` uses to verify a post-update relaunch. Also budget the post-relaunch liveness poll against the watcher's own deadline: the watcher respawns the gateway only after the PID it was handed exits, so a 30 s window can expire before the relaunch it verifies was scheduled to start. * test(windows-live): run the gateway-ancestor harness parent from a script file A `python -c <src>` parent is an interpreter running inline source and carries no readable Hermes identity, so it is no longer a gateway to any classifier — the harness's own comment already said a realistic gateway argv is not a -c blob. * test(windows-live): share one sleeper SCRIPT across the live process-topology fixtures Four live Windows E2E files stood processes up as `python -c "sleep" <hermes argv tail>`. That shape no longer carries a readable Hermes identity, so the fixtures stopped standing in for the gateways they simulate. One shared sleeper script replaces the -c spelling. * fix(gateway): drop the duplicated _INLINE_SOURCE_FLAG_RE definition The constant was emitted twice around command_line_runs_inline_source. Same pattern both times, so behaviour is unchanged — but one definition is enough. * test(stderr-timestamp): run the gateway-lookalike children from script files Both lookalikes stood a gateway child up as `python -c <src> <gateway tail>`. That shape no longer carries a readable Hermes identity (#107002), so the wrapper correctly stopped treating them as gateway spawns and the tests failed. A `-c` tail is data for a program the inline source may spawn LATER, never the child's own identity — the real wrapper child is `python -m hermes_cli.main gateway run`, which has no `-c`. Running the stand-ins from a real script file restores what the tests mean to assert without depending on the misread. * test(windows-live): restore the tempfile import dropped with the local sleeper helper * test(windows-live): wait on the sleeper SCRIPT name, not its source text The live fixtures proved argv visibility by waiting for `time.sleep(120)` in the spawned process's command line. That string only ever appeared there because the sleeper was spelled `python -c "import time; time.sleep(120)"`; now that it runs from a file the source is in the file, so the probe timed out ("sleeper argv never visible") even though the argv was perfectly visible. Wait on the script name instead, exported as SLEEPER_MARKER next to the script so the probe and the spelling cannot drift apart again. * fix(tests,gateway): keep the live-system guard blocking -c-wrapped gateway spawns The #107002 identity fix made _gateway_command_subcommand return None for 'python -c <src> … -m hermes_cli.main gateway run'. tests/_fixtures/live_system_guard.py shares that matcher, so the autouse guard stopped blocking the detached restart watcher: real gateways leaked out of the e2e run and squatted the webhook port. Add gateway.status.gateway_spawn_intent_subcommand — the spawn-intent mirror of the identity matcher, peeling the inline-source wrapper token-wise and re-running the same canonical matcher on each suffix (still no substring matching) — and point the guard at it. Read-only subcommands stay spawnable. * fix(gateway): make the inline-source option walk value-aware so -X utf8 -c is not read as a gateway The walk that decides whether a command line is an interpreter running inline source (`python -c <src> ...`) treated every token starting with `-` as a flag and the first non-flag token as the end of the option block. CPython options that take a SEPARATE operand (-X/-W/-Q, --check-hash-based-pycs, --jit) break that model: the operand was mistaken for the end of the block, so the walk never reached the -c behind it and the watcher was read as a live gateway again -- exactly the #107002 misclassification, one shape further out. - Reuse the canonical operand sets from hermes_state_holders rather than hand-rolling a second copy (AGENTS.md: parser-derived flag sets). - Walk case-preserving tokens: operand-taking -Q/-W/-X must not be conflated with operand-less -q/-b, so callers no longer lowercase before the walk. - Handle clustered short options precisely (-uc is inline source, -Xc is -X c). - Replace the ad-hoc _INLINE_SOURCE_FLAG_RE rescan in gateway_spawn_intent_subcommand with the index the same walk returns; the regex could not find spellings the walk accepts and would raise StopIteration. Reported by an automated review on PR #121635 and reproduced here. Refs #107002 --------- Co-authored-by: Austin Pickett <austinpickett@users.noreply.github.com>
36 lines
1.6 KiB
Python
36 lines
1.6 KiB
Python
"""Sleeper script used by the live process-topology E2Es to stand in for real Hermes processes.
|
|
|
|
The fixtures spawn ``python <sleeper.py> <argv tail...>``: the tail is inert to the child but
|
|
fully visible to psutil / ``Win32_Process`` cmdline scans, which is what the detection and
|
|
classification code reads.
|
|
|
|
It must NOT be ``python -c "import time; time.sleep(...)" <tail>``. A ``-c`` command line is an
|
|
interpreter running inline source, and the identity matchers deliberately refuse to read the
|
|
trailing argv off one — that tail belongs to a program the inline source may spawn LATER, which is
|
|
how the post-update gateway restart watcher was mistaken for a live gateway (#107002). A ``-c``
|
|
fixture therefore no longer stands in for anything.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import tempfile
|
|
from pathlib import Path
|
|
|
|
_SLEEPER_SOURCE = "import time\ntime.sleep(300)\n"
|
|
_sleeper_script: Path | None = None
|
|
|
|
#: Substring a caller can wait for in the spawned process's *command line* to know the argv is
|
|
#: visible to a cmdline scan. It must name the SCRIPT, not its source text: the source now lives in
|
|
#: a file and never appears in the command line the way a ``-c`` snippet used to.
|
|
SLEEPER_MARKER = "sleeper.py"
|
|
|
|
|
|
def sleeper_script_path() -> str:
|
|
"""Path to the sleeper script, created once per test session."""
|
|
global _sleeper_script
|
|
if _sleeper_script is None:
|
|
path = Path(tempfile.mkdtemp(prefix="hermes-live-sleeper-")) / "sleeper.py"
|
|
path.write_text(_SLEEPER_SOURCE, encoding="utf-8")
|
|
_sleeper_script = path
|
|
return str(_sleeper_script)
|