## What does this PR do? Makes observational CLI commands open `state.db` in read-only mode, so they can inspect a live Hermes installation without participating in writable WAL lifecycle handling. ### Symptom Running `hermes status`, `hermes doctor` without `--fix`, `hermes sessions list`, `hermes sessions stats`, or `hermes insights` while a gateway owns the store could open another writable session handle. The live turn could then lose its WAL generation and stop. ### Impact Users inspecting status or session history during an active turn could lose that in-flight turn and leave the gateway halted until recovery. ### Bug Cause **Trigger:** observational CLI helpers constructed `SessionDB()` with its writable default. **Causal chain:** 1. A live gateway holds the `state.db` WAL generation. 2. A nested observational CLI command opens a second writable handle. 3. Writable-handle close behavior can participate in WAL lifecycle work and retire the generation used by the live writer. **Why it is wrong:** these commands only query state and should not have writer privileges. **Working sibling / contrast:** repair and mutating session commands still use writable access intentionally. **Ruled out:** no state schema, migration, or WAL checkpoint implementation changes are included. ### Fix Routes status, non-fixing doctor state inspection, sessions list/stats, and both insights entrypoints through `SessionDB(read_only=True)`. Repair and mutating paths remain writable, and regression tests cover WAL preservation with a live writer. ## Related Issue Fixes #110173 ## Type of Change - ✅ Bug fix (non-breaking change that fixes an issue) ## Changes Made - `hermes_cli/status.py`, `hermes_cli/doctor_state.py`, and insights helpers — open observational state readers read-only. - `hermes_cli/sessions_cmd.py` — make only `list` and `stats` read-only; retain writable access for mutations. - `tests/hermes_cli/test_observational_sessiondb_modes.py` — verify access modes and a live writer's WAL remains usable. ## How to Test - ✅ `scripts/run_tests.sh tests/hermes_cli/test_observational_sessiondb_modes.py tests/hermes_cli/test_cli_insights_command.py` — 9 passed. - ✅ `scripts/run_tests.sh tests/hermes_cli/test_doctor.py tests/hermes_cli/test_doctor_structural_corruption.py tests/hermes_cli/test_sessions_error_exit_codes.py` — 75 passed; two sandbox-only failures came from blocked host process/symlink operations. - ✅ A live `SessionDB` writer remains able to create and retrieve a session after `sessions stats` reads the store. ## Checklist ### Code - ✅ I've read the Contributing Guide - ✅ My commit messages follow Conventional Commits - ✅ I searched for existing PRs to make sure this isn't a duplicate - ✅ My PR contains only changes related to this fix - ✅ I've run relevant tests locally (see How to Test) - ✅ I've added tests for my changes - ✅ I've tested on my platform: macOS ### Documentation & Housekeeping - ✅ Documentation update: N/A - ✅ `cli-config.yaml.example`: N/A - ✅ `CONTRIBUTING.md` or `AGENTS.md`: N/A - ✅ Cross-platform impact considered - ✅ Tool descriptions/schemas: N/A
138 lines
3.5 KiB
Python
138 lines
3.5 KiB
Python
import json
|
|
import sys
|
|
|
|
from hermes_cli.session_export import export_record_count, render_sessions_export
|
|
from hermes_cli.session_export_html import (
|
|
_generate_messages_html,
|
|
generate_multi_session_html_export,
|
|
)
|
|
|
|
|
|
def _sample_session():
|
|
return {
|
|
"id": "sess-123",
|
|
"source": "cli",
|
|
"model": "test/model",
|
|
"title": "Debug auth flow",
|
|
"started_at": 1700000000,
|
|
"message_count": 5,
|
|
"messages": [
|
|
{
|
|
"id": 1,
|
|
"role": "system",
|
|
"content": "hidden system context",
|
|
"timestamp": 1700000000,
|
|
},
|
|
{
|
|
"id": 2,
|
|
"role": "user",
|
|
"content": "Why is login broken?",
|
|
"timestamp": 1700000001,
|
|
"platform_message_id": "evt-2",
|
|
},
|
|
{
|
|
"id": 3,
|
|
"role": "assistant",
|
|
"content": "I will inspect the auth middleware.",
|
|
"timestamp": 1700000002,
|
|
},
|
|
{
|
|
"id": 4,
|
|
"role": "tool",
|
|
"tool_name": "read_file",
|
|
"content": "def redirect_after_login(): pass",
|
|
"timestamp": 1700000003,
|
|
},
|
|
{
|
|
"id": 5,
|
|
"role": "user",
|
|
"content": [{"type": "text", "text": "Only show me the prompts."}],
|
|
"timestamp": 1700000004,
|
|
},
|
|
],
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_html_export_escapes_tool_call_names():
|
|
payload = '<img src=x onerror="alert(document.domain)">'
|
|
|
|
rendered = _generate_messages_html(
|
|
[
|
|
{
|
|
"role": "assistant",
|
|
"content": "",
|
|
"tool_calls": [
|
|
{
|
|
"id": "call_1",
|
|
"type": "function",
|
|
"function": {"name": payload, "arguments": "<b>x</b>"},
|
|
}
|
|
],
|
|
}
|
|
]
|
|
)
|
|
|
|
assert payload not in rendered
|
|
assert '<img src=x onerror="alert(document.domain)">' in rendered
|
|
assert "<b>x</b>" in rendered
|
|
|
|
|
|
|
|
|
|
def test_export_record_count_switches_unit_for_prompt_only_exports():
|
|
assert export_record_count([_sample_session()]) == (1, "session")
|
|
assert export_record_count([_sample_session()], only="user-prompts") == (
|
|
2,
|
|
"prompt",
|
|
)
|
|
|
|
|
|
def test_sessions_export_cli_prompt_only_stdout(monkeypatch, capsys):
|
|
import hermes_cli.main as main_mod
|
|
import hermes_state
|
|
|
|
captured = {}
|
|
|
|
class FakeDB:
|
|
def resolve_session_id(self, session_id):
|
|
captured["resolved_from"] = session_id
|
|
return "sess-123"
|
|
|
|
def export_session(self, session_id):
|
|
captured["exported"] = session_id
|
|
return _sample_session()
|
|
|
|
def close(self):
|
|
captured["closed"] = True
|
|
|
|
monkeypatch.setattr(hermes_state, "SessionDB", lambda *args, **kwargs: FakeDB())
|
|
monkeypatch.setattr(
|
|
sys,
|
|
"argv",
|
|
["hermes", "sessions", "export", "-", "--session-id", "sess", "--only", "user-prompts"],
|
|
)
|
|
|
|
main_mod.main()
|
|
|
|
output = capsys.readouterr().out
|
|
records = [json.loads(line) for line in output.splitlines()]
|
|
assert [record["text"] for record in records] == [
|
|
"Why is login broken?",
|
|
"Only show me the prompts.",
|
|
]
|
|
assert captured == {
|
|
"resolved_from": "sess",
|
|
"exported": "sess-123",
|
|
"closed": True,
|
|
}
|
|
|
|
|