Files
hermes-agent/tests/hermes_cli/test_sessions_export_md_cli.py
KoNit-K b4e22481a8 fix(cli): open observational session stores read-only
## What does this PR do?

Makes observational CLI commands open `state.db` in read-only mode, so they can inspect a live Hermes installation without participating in writable WAL lifecycle handling.

### Symptom

Running `hermes status`, `hermes doctor` without `--fix`, `hermes sessions list`, `hermes sessions stats`, or `hermes insights` while a gateway owns the store could open another writable session handle. The live turn could then lose its WAL generation and stop.

### Impact

Users inspecting status or session history during an active turn could lose that in-flight turn and leave the gateway halted until recovery.

### Bug Cause

**Trigger:** observational CLI helpers constructed `SessionDB()` with its writable default.

**Causal chain:**

1. A live gateway holds the `state.db` WAL generation.
2. A nested observational CLI command opens a second writable handle.
3. Writable-handle close behavior can participate in WAL lifecycle work and retire the generation used by the live writer.

**Why it is wrong:** these commands only query state and should not have writer privileges.

**Working sibling / contrast:** repair and mutating session commands still use writable access intentionally.

**Ruled out:** no state schema, migration, or WAL checkpoint implementation changes are included.

### Fix

Routes status, non-fixing doctor state inspection, sessions list/stats, and both insights entrypoints through `SessionDB(read_only=True)`. Repair and mutating paths remain writable, and regression tests cover WAL preservation with a live writer.

## Related Issue

Fixes #110173

## Type of Change

- ✅ Bug fix (non-breaking change that fixes an issue)

## Changes Made

- `hermes_cli/status.py`, `hermes_cli/doctor_state.py`, and insights helpers — open observational state readers read-only.
- `hermes_cli/sessions_cmd.py` — make only `list` and `stats` read-only; retain writable access for mutations.
- `tests/hermes_cli/test_observational_sessiondb_modes.py` — verify access modes and a live writer's WAL remains usable.

## How to Test

- ✅ `scripts/run_tests.sh tests/hermes_cli/test_observational_sessiondb_modes.py tests/hermes_cli/test_cli_insights_command.py` — 9 passed.
- ✅ `scripts/run_tests.sh tests/hermes_cli/test_doctor.py tests/hermes_cli/test_doctor_structural_corruption.py tests/hermes_cli/test_sessions_error_exit_codes.py` — 75 passed; two sandbox-only failures came from blocked host process/symlink operations.
- ✅ A live `SessionDB` writer remains able to create and retrieve a session after `sessions stats` reads the store.

## Checklist

### Code

- ✅ I've read the Contributing Guide
- ✅ My commit messages follow Conventional Commits
- ✅ I searched for existing PRs to make sure this isn't a duplicate
- ✅ My PR contains only changes related to this fix
- ✅ I've run relevant tests locally (see How to Test)
- ✅ I've added tests for my changes
- ✅ I've tested on my platform: macOS

### Documentation & Housekeeping

- ✅ Documentation update: N/A
- ✅ `cli-config.yaml.example`: N/A
- ✅ `CONTRIBUTING.md` or `AGENTS.md`: N/A
- ✅ Cross-platform impact considered
- ✅ Tool descriptions/schemas: N/A
2026-09-15 12:51:27 +05:30

131 lines
3.5 KiB
Python

import sys
def test_sessions_export_md_writes_single_session(monkeypatch, tmp_path, capsys):
import hermes_cli.main as main_mod
import hermes_state
captured = {}
class FakeDB:
def resolve_session_id(self, session_id):
captured["resolved_from"] = session_id
return "20260706_123456_abcd1234"
def export_session(self, session_id):
captured["exported"] = session_id
return {
"id": session_id,
"title": "Export CLI Test",
"source": "cli",
"message_count": 1,
"messages": [{"role": "user", "content": "hello"}],
}
def delete_session(self, *args, **kwargs):
raise AssertionError("markdown export must not delete sessions")
def prune_sessions(self, *args, **kwargs):
raise AssertionError("markdown export must not prune sessions")
def close(self):
captured["closed"] = True
monkeypatch.setattr(hermes_state, "SessionDB", lambda *args, **kwargs: FakeDB())
monkeypatch.setattr(
sys,
"argv",
[
"hermes",
"sessions",
"export",
"--format",
"md",
"--session-id",
"20260706_123456",
str(tmp_path),
],
)
main_mod.main()
output = capsys.readouterr().out
files = list(tmp_path.glob("*.md"))
assert len(files) == 1
text = files[0].read_text(encoding="utf-8")
assert "# Export CLI Test" in text
assert "hello" in text
assert captured == {
"resolved_from": "20260706_123456",
"exported": "20260706_123456_abcd1234",
"closed": True,
}
assert "Exported 1 session" in output
assert "1 message" in output
assert str(files[0]) in output
def test_sessions_export_redact_scrubs_secrets(monkeypatch, tmp_path):
"""--redact runs exported content through force-mode secret redaction."""
import hermes_cli.main as main_mod
import hermes_state
secret = "sk-proj-Zz12345678901234567890123456789012345678"
class FakeDB:
def resolve_session_id(self, session_id):
return "s1"
def export_session(self, session_id):
return {
"id": "s1",
"title": "Redact",
"messages": [
{"role": "tool", "name": "terminal", "content": f"api key: {secret}"}
],
}
def close(self):
pass
monkeypatch.setattr(hermes_state, "SessionDB", lambda *args, **kwargs: FakeDB())
monkeypatch.setattr(
sys,
"argv",
[
"hermes", "sessions", "export", "--format", "md",
"--session-id", "s1", "--redact", str(tmp_path),
],
)
main_mod.main()
text = next(tmp_path.glob("*.md")).read_text(encoding="utf-8")
assert secret not in text
assert "api key:" in text
def _trace_fake_db(captured):
class FakeDB:
def resolve_session_id(self, session_id):
return "s1"
def get_session(self, session_id):
return {"id": session_id, "model": "test-model"}
def get_messages_as_conversation(self, session_id):
captured["conv"] = session_id
return [
{"role": "user", "content": "hello trace"},
{"role": "assistant", "content": "hi"},
]
def close(self):
captured["closed"] = True
return FakeDB()