Files
hermes-agent/hermes_cli/toolset_validation.py
phihu ccd32a9f0b fix(config): warn when a platform_toolsets entry is an empty list
validate_platform_toolsets() accumulated a single valid_count across every
platform, so the "zero valid toolsets" safety net was suppressed as soon as any
one platform carried a valid toolset. A platform wiped to [] — the active one,
typically cli — therefore produced no warning at all.

resolve_enabled_toolsets() honours that empty list verbatim ([] is a list, so
the platform-default fallback is skipped), leaving the agent with zero tool
schemas. The model then has nothing to call and emits the tool call as
assistant text with finish_reason=stop: no error, no warning, no log entry.
That is the silent-failure mode this module was written to prevent (#38798).

Note the asymmetry this leaves intact: a malformed *string* value is not a list,
so it falls back to the platform default and fails open (#78103); an empty list
fails closed. The fail-closed resolution is deliberate (the explicit_empty_
selection contract in tools_config.py, and #82010 wants it persistable), so this
only adds the missing warning and does not change resolution semantics.

Fixes #89050

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 10:08:31 -07:00

93 lines
4.0 KiB
Python

"""Validation for the ``platform_toolsets`` config section.
Pure, side-effect-free helpers so the logic is unit-testable without importing
the tool registry or launching Hermes (mirrors the decoupled-helper pattern used
elsewhere in the CLI).
Motivated by #38798: a config migration silently rewrote the valid toolset name
``hermes-cli`` to the non-existent ``hermes``. ``resolve_toolset('hermes')``
returns an empty list, so every tool silently disappeared with no error, warning,
or log entry — the agent degraded to text-only replies and the cause took
significant debugging to find. Surfacing invalid toolset names (and the
zero-tools end state) loudly turns that silent failure into an actionable one.
"""
from typing import Callable, List
def validate_platform_toolsets(
platform_toolsets: object,
is_valid_toolset: Callable[[str], bool],
) -> List[str]:
"""Return human-readable warnings for a ``platform_toolsets`` mapping.
Two failure modes are reported:
1. A toolset name that ``is_valid_toolset`` rejects — usually a corrupted or
renamed entry. When ``hermes-<platform>`` would have been valid (the exact
#38798 shape, where ``cli`` held ``hermes`` instead of ``hermes-cli``),
the warning includes that as a suggestion.
2. The mapping is non-empty but resolves to *zero* valid toolsets, so the
agent would start with no tools at all.
3. A platform is configured with an *empty* toolset list. Checked
per-platform because the global zero-valid-toolsets net in (2) is
suppressed as soon as any other platform carries a valid toolset.
``is_valid_toolset`` is injected (normally :func:`toolsets.validate_toolset`)
so this function performs no imports or I/O and is testable in isolation.
Args:
platform_toolsets: The raw ``platform_toolsets`` value from config. Only
``dict`` values carry toolset entries; anything else yields no
warnings (nothing to validate).
is_valid_toolset: Predicate returning ``True`` for a known toolset name.
Returns:
A list of warning strings (empty when everything is valid).
"""
warnings: List[str] = []
if not isinstance(platform_toolsets, dict) or not platform_toolsets:
return warnings
valid_count = 0
for platform, raw in platform_toolsets.items():
# An explicitly-empty list is honoured verbatim by
# ``resolve_enabled_toolsets()``: ``[]`` *is* a list, so the
# platform-default fallback is skipped and the platform starts with zero
# tools. That is the intended contract for a deliberate opt-out, but it
# reads identically to an accidental wipe, and the global ``valid_count``
# below cannot catch it — any *other* populated platform pushes the count
# above zero and suppresses the safety net. Report it per-platform so the
# zero-tools end state is never silent.
if isinstance(raw, list) and not raw:
warnings.append(
f"platform '{platform}' is configured with an empty toolset "
f"list — the agent will have no tools on this platform. "
f"Run `hermes tools` to reconfigure."
)
continue
names = raw if isinstance(raw, list) else [raw]
for name in names:
if not isinstance(name, str) or not name:
continue
if is_valid_toolset(name):
valid_count += 1
continue
suggestion = f"hermes-{platform}"
hint = (
f" — did you mean '{suggestion}'?"
if is_valid_toolset(suggestion)
else ""
)
warnings.append(
f"platform '{platform}' references unknown toolset "
f"'{name}'{hint}"
)
if valid_count == 0:
warnings.append(
"platform_toolsets resolves to zero valid toolsets — the agent will "
"have no tools. Run `hermes tools` to reconfigure."
)
return warnings