## What does this PR do? Makes observational CLI commands open `state.db` in read-only mode, so they can inspect a live Hermes installation without participating in writable WAL lifecycle handling. ### Symptom Running `hermes status`, `hermes doctor` without `--fix`, `hermes sessions list`, `hermes sessions stats`, or `hermes insights` while a gateway owns the store could open another writable session handle. The live turn could then lose its WAL generation and stop. ### Impact Users inspecting status or session history during an active turn could lose that in-flight turn and leave the gateway halted until recovery. ### Bug Cause **Trigger:** observational CLI helpers constructed `SessionDB()` with its writable default. **Causal chain:** 1. A live gateway holds the `state.db` WAL generation. 2. A nested observational CLI command opens a second writable handle. 3. Writable-handle close behavior can participate in WAL lifecycle work and retire the generation used by the live writer. **Why it is wrong:** these commands only query state and should not have writer privileges. **Working sibling / contrast:** repair and mutating session commands still use writable access intentionally. **Ruled out:** no state schema, migration, or WAL checkpoint implementation changes are included. ### Fix Routes status, non-fixing doctor state inspection, sessions list/stats, and both insights entrypoints through `SessionDB(read_only=True)`. Repair and mutating paths remain writable, and regression tests cover WAL preservation with a live writer. ## Related Issue Fixes #110173 ## Type of Change - ✅ Bug fix (non-breaking change that fixes an issue) ## Changes Made - `hermes_cli/status.py`, `hermes_cli/doctor_state.py`, and insights helpers — open observational state readers read-only. - `hermes_cli/sessions_cmd.py` — make only `list` and `stats` read-only; retain writable access for mutations. - `tests/hermes_cli/test_observational_sessiondb_modes.py` — verify access modes and a live writer's WAL remains usable. ## How to Test - ✅ `scripts/run_tests.sh tests/hermes_cli/test_observational_sessiondb_modes.py tests/hermes_cli/test_cli_insights_command.py` — 9 passed. - ✅ `scripts/run_tests.sh tests/hermes_cli/test_doctor.py tests/hermes_cli/test_doctor_structural_corruption.py tests/hermes_cli/test_sessions_error_exit_codes.py` — 75 passed; two sandbox-only failures came from blocked host process/symlink operations. - ✅ A live `SessionDB` writer remains able to create and retrieve a session after `sessions stats` reads the store. ## Checklist ### Code - ✅ I've read the Contributing Guide - ✅ My commit messages follow Conventional Commits - ✅ I searched for existing PRs to make sure this isn't a duplicate - ✅ My PR contains only changes related to this fix - ✅ I've run relevant tests locally (see How to Test) - ✅ I've added tests for my changes - ✅ I've tested on my platform: macOS ### Documentation & Housekeeping - ✅ Documentation update: N/A - ✅ `cli-config.yaml.example`: N/A - ✅ `CONTRIBUTING.md` or `AGENTS.md`: N/A - ✅ Cross-platform impact considered - ✅ Tool descriptions/schemas: N/A
131 lines
3.5 KiB
Python
131 lines
3.5 KiB
Python
import sys
|
|
|
|
|
|
def test_sessions_export_md_writes_single_session(monkeypatch, tmp_path, capsys):
|
|
import hermes_cli.main as main_mod
|
|
import hermes_state
|
|
|
|
captured = {}
|
|
|
|
class FakeDB:
|
|
def resolve_session_id(self, session_id):
|
|
captured["resolved_from"] = session_id
|
|
return "20260706_123456_abcd1234"
|
|
|
|
def export_session(self, session_id):
|
|
captured["exported"] = session_id
|
|
return {
|
|
"id": session_id,
|
|
"title": "Export CLI Test",
|
|
"source": "cli",
|
|
"message_count": 1,
|
|
"messages": [{"role": "user", "content": "hello"}],
|
|
}
|
|
|
|
def delete_session(self, *args, **kwargs):
|
|
raise AssertionError("markdown export must not delete sessions")
|
|
|
|
def prune_sessions(self, *args, **kwargs):
|
|
raise AssertionError("markdown export must not prune sessions")
|
|
|
|
def close(self):
|
|
captured["closed"] = True
|
|
|
|
monkeypatch.setattr(hermes_state, "SessionDB", lambda *args, **kwargs: FakeDB())
|
|
monkeypatch.setattr(
|
|
sys,
|
|
"argv",
|
|
[
|
|
"hermes",
|
|
"sessions",
|
|
"export",
|
|
"--format",
|
|
"md",
|
|
"--session-id",
|
|
"20260706_123456",
|
|
str(tmp_path),
|
|
],
|
|
)
|
|
|
|
main_mod.main()
|
|
|
|
output = capsys.readouterr().out
|
|
files = list(tmp_path.glob("*.md"))
|
|
assert len(files) == 1
|
|
text = files[0].read_text(encoding="utf-8")
|
|
assert "# Export CLI Test" in text
|
|
assert "hello" in text
|
|
assert captured == {
|
|
"resolved_from": "20260706_123456",
|
|
"exported": "20260706_123456_abcd1234",
|
|
"closed": True,
|
|
}
|
|
assert "Exported 1 session" in output
|
|
assert "1 message" in output
|
|
assert str(files[0]) in output
|
|
|
|
|
|
def test_sessions_export_redact_scrubs_secrets(monkeypatch, tmp_path):
|
|
"""--redact runs exported content through force-mode secret redaction."""
|
|
import hermes_cli.main as main_mod
|
|
import hermes_state
|
|
|
|
secret = "sk-proj-Zz12345678901234567890123456789012345678"
|
|
|
|
class FakeDB:
|
|
def resolve_session_id(self, session_id):
|
|
return "s1"
|
|
|
|
def export_session(self, session_id):
|
|
return {
|
|
"id": "s1",
|
|
"title": "Redact",
|
|
"messages": [
|
|
{"role": "tool", "name": "terminal", "content": f"api key: {secret}"}
|
|
],
|
|
}
|
|
|
|
def close(self):
|
|
pass
|
|
|
|
monkeypatch.setattr(hermes_state, "SessionDB", lambda *args, **kwargs: FakeDB())
|
|
monkeypatch.setattr(
|
|
sys,
|
|
"argv",
|
|
[
|
|
"hermes", "sessions", "export", "--format", "md",
|
|
"--session-id", "s1", "--redact", str(tmp_path),
|
|
],
|
|
)
|
|
|
|
main_mod.main()
|
|
|
|
text = next(tmp_path.glob("*.md")).read_text(encoding="utf-8")
|
|
assert secret not in text
|
|
assert "api key:" in text
|
|
|
|
|
|
def _trace_fake_db(captured):
|
|
class FakeDB:
|
|
def resolve_session_id(self, session_id):
|
|
return "s1"
|
|
|
|
def get_session(self, session_id):
|
|
return {"id": session_id, "model": "test-model"}
|
|
|
|
def get_messages_as_conversation(self, session_id):
|
|
captured["conv"] = session_id
|
|
return [
|
|
{"role": "user", "content": "hello trace"},
|
|
{"role": "assistant", "content": "hi"},
|
|
]
|
|
|
|
def close(self):
|
|
captured["closed"] = True
|
|
|
|
return FakeDB()
|
|
|
|
|
|
|
|
|