# Conflicts: # AGENTS.md # acp_adapter/edit_approval.py # acp_adapter/server.py # agent/agent_init.py # agent/anthropic_adapter.py # agent/anthropic_credentials.py # agent/auxiliary_client.py # agent/azure_identity_adapter.py # agent/bedrock_adapter.py # agent/browser_registry.py # agent/chat_completion_helpers.py # agent/coding_context.py # agent/context_references.py # agent/conversation_loop.py # agent/copilot_acp_client.py # agent/credits_tracker.py # agent/curator.py # agent/curator_backup.py # agent/deadline.py # agent/display.py # agent/errors.py # agent/estop.py # agent/i18n.py # agent/image_gen_registry.py # agent/image_routing.py # agent/learning_graph.py # agent/learning_mutations.py # agent/lsp/servers.py # agent/model_metadata.py # agent/models_dev.py # agent/monitoring/gateway_health_export.py # agent/monitoring/otlp_exporter.py # agent/pet/store.py # agent/process_bootstrap.py # agent/prompt_builder.py # agent/proxy_sources/iron_proxy.py # agent/secret_sources/_cache.py # agent/secret_sources/bitwarden.py # agent/secret_sources/registry.py # agent/shell_hooks.py # agent/skill_bundles.py # agent/skill_commands.py # agent/skill_utils.py # agent/ssl_guard.py # agent/ssl_verify.py # agent/system_prompt.py # agent/terminal_env_registry.py # agent/trace_upload.py # agent/transcription_registry.py # agent/tts_registry.py # agent/verify/environment.py # agent/vertex_adapter.py # agent/video_gen_registry.py # agent/web_search_registry.py # cli.py # cron/jobs.py # cron/scheduler.py # gateway/agent_cache_pressure.py # gateway/cgroup_cleanup.py # gateway/channel_directory.py # gateway/config.py # gateway/control_socket.py # gateway/dead_targets.py # gateway/drain_control.py # gateway/hooks.py # gateway/kanban_watchers.py # gateway/lifecycle_ledger.py # gateway/mirror.py # gateway/pairing.py # gateway/platform_registry.py # gateway/platforms/helpers.py # gateway/platforms/weixin.py # gateway/readiness.py # gateway/restart_loop_guard.py # gateway/rich_sent_store.py # gateway/run.py # gateway/session.py # gateway/shutdown_flush.py # gateway/shutdown_forensics.py # gateway/slash_commands.py # gateway/status.py # gateway/sticker_cache.py # gateway/whatsapp_identity.py # hermes_bootstrap.py # hermes_cli/_early_recovery.py # hermes_cli/_install_repair.py # hermes_cli/_startup_fast.py # hermes_cli/_subprocess_compat.py # hermes_cli/agent_plugins.py # hermes_cli/auth.py # hermes_cli/backup.py # hermes_cli/banner.py # hermes_cli/browser_connect.py # hermes_cli/build_info.py # hermes_cli/cli_agent_setup_mixin.py # hermes_cli/cli_commands_mixin.py # hermes_cli/codex_models.py # hermes_cli/config.py # hermes_cli/config_defaults.py # hermes_cli/config_migrations.py # hermes_cli/container_boot.py # hermes_cli/dashboard_auth/registry.py # hermes_cli/debug.py # hermes_cli/dep_ensure.py # hermes_cli/doctor.py # hermes_cli/doctor_live.py # hermes_cli/dump.py # hermes_cli/env_loader.py # hermes_cli/foreign_sessions.py # hermes_cli/gateway.py # hermes_cli/gateway_windows.py # hermes_cli/gui_uninstall.py # hermes_cli/image_provenance.py # hermes_cli/install_identity.py # hermes_cli/kanban.py # hermes_cli/kanban_db.py # hermes_cli/linux_desktop_entry.py # hermes_cli/local_runtime/binaries.py # hermes_cli/local_runtime/endpoint.py # hermes_cli/local_runtime/growth.py # hermes_cli/local_runtime/supervisor.py # hermes_cli/logs.py # hermes_cli/macos_tcc_anchor.py # hermes_cli/main.py # hermes_cli/memory_setup.py # hermes_cli/model_catalog.py # hermes_cli/models.py # hermes_cli/nous_subscription.py # hermes_cli/npm_engine.py # hermes_cli/plugin_index.py # hermes_cli/plugins.py # hermes_cli/plugins_cmd.py # hermes_cli/profile_distribution.py # hermes_cli/profiles.py # hermes_cli/prompt_size.py # hermes_cli/psutil_android.py # hermes_cli/runtime_repair.py # hermes_cli/security_advisories.py # hermes_cli/security_audit.py # hermes_cli/security_audit_startup.py # hermes_cli/service_manager.py # hermes_cli/session_export_md.py # hermes_cli/setup.py # hermes_cli/skills_hub.py # hermes_cli/slack_cli.py # hermes_cli/status.py # hermes_cli/subcommands/gateway.py # hermes_cli/subcommands/uninstall.py # hermes_cli/tools_config.py # hermes_cli/uninstall.py # hermes_cli/update_cmd.py # hermes_cli/update_contract.py # hermes_cli/update_inventory.py # hermes_cli/update_lock.py # hermes_cli/update_receipt.py # hermes_cli/urllib_security.py # hermes_cli/web_routers/local_models.py # hermes_cli/web_routers/profiles.py # hermes_cli/web_routers/skills.py # hermes_cli/web_server.py # hermes_constants.py # hermes_state.py # plugins/disk-cleanup/__init__.py # plugins/disk-cleanup/disk_cleanup.py # plugins/google_meet/node/registry.py # plugins/google_meet/node/server.py # plugins/google_meet/process_manager.py # plugins/google_meet/realtime/openai_client.py # plugins/hermes-achievements/dashboard/plugin_api.py # plugins/memory/hindsight/__init__.py # plugins/memory/honcho/__init__.py # plugins/memory/honcho/cli.py # plugins/memory/honcho/client.py # plugins/memory/honcho/oauth.py # plugins/memory/honcho/session.py # plugins/memory/mem0/__init__.py # plugins/memory/mem0/_setup.py # plugins/memory/openviking/__init__.py # plugins/memory/retaindb/__init__.py # plugins/memory/supermemory/__init__.py # plugins/platforms/a2a/protocol.py # plugins/platforms/dingtalk/adapter.py # plugins/platforms/discord/adapter.py # plugins/platforms/feishu/adapter.py # plugins/platforms/google_chat/adapter.py # plugins/platforms/matrix/adapter.py # plugins/platforms/photon/adapter.py # plugins/platforms/photon/auth.py # plugins/platforms/photon/cli.py # plugins/platforms/slack/adapter.py # plugins/platforms/teams/adapter.py # plugins/platforms/telegram/adapter.py # plugins/platforms/wecom/callback_adapter.py # plugins/platforms/whatsapp/adapter.py # plugins/teams_pipeline/store.py # plugins/video_gen/fal/__init__.py # plugins/web/ddgs/provider.py # plugins/web/exa/provider.py # plugins/web/firecrawl/provider.py # plugins/web/parallel/provider.py # tests/agent/test_ssl_ca_guard.py # tests/hermes_cli/test_certifi_repair.py # tests/hermes_cli/test_cmd_update.py # tests/hermes_cli/test_cmd_update_apt.py # tests/hermes_cli/test_dashboard_unified_launch.py # tests/hermes_cli/test_dep_ensure.py # tests/hermes_cli/test_doctor.py # tests/hermes_cli/test_doctor_live.py # tests/hermes_cli/test_gui_command.py # tests/hermes_cli/test_kanban_boards.py # tests/hermes_cli/test_kanban_db.py # tests/hermes_cli/test_lazy_refresh_venv_repair.py # tests/hermes_cli/test_memory_setup_provider_arg.py # tests/hermes_cli/test_nous_subscription.py # tests/hermes_cli/test_pip_install_detection.py # tests/hermes_cli/test_profile_export_credentials.py # tests/hermes_cli/test_psutil_android_extract.py # tests/hermes_cli/test_status.py # tests/hermes_cli/test_tui_npm_install.py # tests/hermes_cli/test_update_fleet_restart_pending.py # tests/hermes_cli/test_update_head_moved_gate.py # tests/hermes_cli/test_update_interrupted_recovery.py # tests/hermes_cli/test_web_server.py # tests/hermes_cli/test_web_ui_build.py # tests/test_hermes_logging.py # tests/test_managed_runtime_resolution.py # tests/tools/test_browser_chromium_autoinstall.py # tests/tools/test_browser_chromium_check.py # tests/tools/test_browser_homebrew_paths.py # tests/tools/test_browser_lightpanda.py # tests/tools/test_browser_npx_warmup.py # tests/tools/test_browser_open_timeout.py # tests/tools/test_browser_orphan_reaper.py # tests/tools/test_browser_real_profile.py # tests/tools/test_browser_suspect_recycle.py # tests/tools/test_find_shell.py # tests/tools/test_local_env_blocklist.py # tests/tools/test_macos_protected_search.py # tests/tui_gateway/test_compute_host.py # tools/approval.py # tools/blueprints.py # tools/bot_mode_dm.py # tools/bot_mode_probe.py # tools/bot_relay.py # tools/browser_tool.py # tools/browser_use_cli.py # tools/checkpoint_manager.py # tools/code_execution_tool.py # tools/code_kernel.py # tools/computer_use/cua_backend.py # tools/cronjob_tools.py # tools/discord_tool.py # tools/environments/base.py # tools/environments/daytona.py # tools/environments/local.py # tools/environments/modal.py # tools/environments/vercel_sandbox.py # tools/fal_common.py # tools/file_operations.py # tools/lazy_deps.py # tools/mcp_tool.py # tools/neutts_synth.py # tools/process_registry.py # tools/read_extract.py # tools/registry.py # tools/skill_ledger.py # tools/skill_linter.py # tools/skill_manager_tool.py # tools/skill_usage.py # tools/skills_ast_audit.py # tools/skills_guard.py # tools/skills_hub.py # tools/skills_sync.py # tools/skills_sync_client.py # tools/skills_tool.py # tools/terminal_scope.py # tools/terminal_tool.py # tools/tirith_security.py # tools/transcription_tools.py # tools/tts_tool.py # tools/vision_tools.py # tools/voice_mode.py # tools/wake_word.py # tools/web_result_cache.py # tools/website_policy.py # tools/working_diff.py # tools/write_approval.py # tui_gateway/entry.py # tui_gateway/methods_tools.py # tui_gateway/server.py
219 lines
9.1 KiB
Python
219 lines
9.1 KiB
Python
"""Tests for _find_shell — user-login-shell preference on POSIX.
|
|
|
|
Regression tests for #42203: on macOS, ``_find_shell`` used to return
|
|
``/bin/bash`` (bash 3.2) which silently swallowed background commands
|
|
when ``~/.bash_profile`` contained ``exec /bin/zsh -l``.
|
|
"""
|
|
|
|
import os
|
|
import platform
|
|
import subprocess
|
|
from unittest.mock import patch
|
|
|
|
import pytest
|
|
|
|
from tools.environments.local import _find_bash, _find_shell
|
|
|
|
|
|
class TestFindShellPrefersUserShell:
|
|
"""_find_shell should prefer $SHELL over bash on POSIX."""
|
|
|
|
@pytest.mark.platforms("linux")
|
|
def test_returns_shell_env_when_set_and_exists(self, tmp_path):
|
|
"""When $SHELL points to an existing allowlisted executable, _find_shell returns it."""
|
|
fake_zsh = tmp_path / "zsh"
|
|
fake_zsh.touch()
|
|
fake_zsh.chmod(0o755)
|
|
with patch.dict(os.environ, {"SHELL": str(fake_zsh)}):
|
|
assert _find_shell() == str(fake_zsh)
|
|
|
|
def test_falls_back_when_shell_not_executable(self, tmp_path):
|
|
"""$SHELL exists but lacks the execute bit -> fall back to _find_bash
|
|
(returning it would fail at spawn time)."""
|
|
fake = tmp_path / "zsh"
|
|
fake.touch()
|
|
fake.chmod(0o644) # not executable
|
|
with patch.dict(os.environ, {"SHELL": str(fake)}):
|
|
assert _find_shell() == _find_bash()
|
|
|
|
def test_falls_back_for_incompatible_shell_fish(self, tmp_path):
|
|
"""#42203 regression: $SHELL=fish must NOT be returned — spawn_local's
|
|
`-lic` / `set +m` syntax breaks fish, which would trade the bash-3.2
|
|
swallow for a parse error on every background command. Fall back to bash."""
|
|
fake_fish = tmp_path / "fish"
|
|
fake_fish.touch()
|
|
fake_fish.chmod(0o755)
|
|
with patch.dict(os.environ, {"SHELL": str(fake_fish)}):
|
|
assert _find_shell() == _find_bash()
|
|
|
|
|
|
@pytest.mark.platforms("linux")
|
|
def test_honours_allowlisted_bash_and_dash(self, tmp_path):
|
|
"""Every allowlisted POSIX-sh-family shell is honoured."""
|
|
for name in ("bash", "dash", "sh", "ksh"):
|
|
fake = tmp_path / name
|
|
fake.touch()
|
|
fake.chmod(0o755)
|
|
with patch.dict(os.environ, {"SHELL": str(fake)}):
|
|
assert _find_shell() == str(fake), name
|
|
|
|
|
|
def test_falls_back_to_find_bash_when_shell_empty(self):
|
|
"""When $SHELL is empty string, _find_shell delegates."""
|
|
with patch.dict(os.environ, {"SHELL": ""}):
|
|
assert _find_shell() == _find_bash()
|
|
|
|
|
|
class TestFindShellWindowsBehavior:
|
|
"""On Windows, _find_shell always delegates to _find_bash."""
|
|
|
|
@pytest.mark.platforms("windows")
|
|
def test_windows_ignores_shell_env(self):
|
|
"""On Windows, $SHELL is ignored — _find_shell delegates to _find_bash.
|
|
|
|
Windows-only: faking ``_IS_WINDOWS`` selected the branch but left
|
|
``_find_bash`` resolving a POSIX bash, so the equality proved nothing
|
|
about Git-Bash resolution on the real host.
|
|
"""
|
|
# Even if SHELL is set, it should be ignored on Windows
|
|
with patch.dict(os.environ, {"SHELL": "/usr/bin/zsh"}):
|
|
result = _find_shell()
|
|
assert result == _find_bash()
|
|
|
|
|
|
class TestFindShellReturnsString:
|
|
"""_find_shell must return a string, never None."""
|
|
|
|
def test_returns_string(self):
|
|
"""_find_shell always returns a non-empty string on any platform."""
|
|
result = _find_shell()
|
|
assert isinstance(result, str)
|
|
assert len(result) > 0
|
|
|
|
|
|
class TestFindBashUnchanged:
|
|
"""_find_bash should be unaffected by the _find_shell change."""
|
|
|
|
def test_find_bash_still_prefers_bash(self):
|
|
"""_find_bash still returns bash (not $SHELL) on POSIX."""
|
|
result = _find_bash()
|
|
# On any system, _find_bash should return something containing "bash"
|
|
# or fall back to $SHELL or /bin/sh — but it should NOT prefer $SHELL
|
|
# over bash the way _find_shell does.
|
|
assert isinstance(result, str)
|
|
assert len(result) > 0
|
|
|
|
|
|
class TestFindBashCollapsedToPmShell:
|
|
"""_find_bash is now a thin wrapper over pm.shell(); the Windows
|
|
candidate ladder (HERMES_GIT_BASH_PATH → %LOCALAPPDATA%\\hermes\\git →
|
|
Program Files) and the ASLR diagnostic were deleted — the store is the
|
|
authority on bundled bash."""
|
|
|
|
@pytest.mark.platforms("windows")
|
|
def test_delegates_to_pm_shell(self, monkeypatch):
|
|
"""_find_bash returns whatever pm.shell() resolves (store bash or
|
|
provisioned PATH)."""
|
|
import tools.environments.local as local_mod
|
|
from tools.environments import local_gitbash_probe as gitbash_probe
|
|
|
|
monkeypatch.setattr(
|
|
"pm.shell.bash", lambda: r"C:\store\tools\git-x\usr\bin\bash.exe"
|
|
)
|
|
assert _find_bash() == r"C:\store\tools\git-x\usr\bin\bash.exe"
|
|
gitbash_probe._bash_starts_cache.clear()
|
|
|
|
def test_raises_when_pm_shell_finds_nothing(self, monkeypatch):
|
|
"""A store with no bash (and no PATH bash) surfaces a clear error
|
|
pointing at `hermes pm install` instead of hunting locations."""
|
|
import tools.environments.local as local_mod
|
|
from tools.environments import local_gitbash_probe as gitbash_probe
|
|
|
|
monkeypatch.setattr("pm.shell.bash", lambda: None)
|
|
with pytest.raises(RuntimeError) as exc_info:
|
|
local_mod._find_bash()
|
|
assert "No shell found" in str(exc_info.value)
|
|
assert "hermes pm install" in str(exc_info.value)
|
|
|
|
|
|
|
|
@pytest.mark.platforms("macos")
|
|
@pytest.mark.skipif(
|
|
not os.path.isfile("/bin/bash"),
|
|
reason="reproduces the macOS system-bash-3.2 login-shell swallow",
|
|
)
|
|
class TestMacosLoginShellSwallowRegression:
|
|
"""E2E regression for #42203: the actual failure is that system bash 3.2,
|
|
invoked as a login shell (`-lic`) with stdin=/dev/null and a
|
|
~/.bash_profile that `exec`s zsh, silently swallows the command (exit 0,
|
|
no output, no side effects). Prove (a) the bug exists with /bin/bash and
|
|
(b) the zsh path _find_shell prefers does NOT swallow."""
|
|
|
|
def _spawn_like_registry(self, shell, command, home, tmp_path):
|
|
import subprocess
|
|
env = dict(os.environ)
|
|
env["HOME"] = str(home)
|
|
# Mirror process_registry.spawn_local: [shell, "-lic", "set +m; <cmd>"]
|
|
# with stdin redirected to /dev/null.
|
|
return subprocess.run(
|
|
[shell, "-lic", f"set +m; {command}"],
|
|
stdin=subprocess.DEVNULL,
|
|
capture_output=True,
|
|
text=True,
|
|
env=env,
|
|
)
|
|
|
|
def test_system_bash_swallows_but_zsh_does_not(self, tmp_path):
|
|
# A .bash_profile that exec's zsh — the reported macOS shape.
|
|
home = tmp_path / "home"
|
|
home.mkdir()
|
|
(home / ".bash_profile").write_text("exec /bin/zsh -l\n")
|
|
|
|
# Use /bin/zsh explicitly rather than $SHELL. The reported bug is
|
|
# specifically "system bash 3.2 swallows, zsh does not", and $SHELL is
|
|
# not zsh everywhere this runs: GitHub's macOS runner exports
|
|
# SHELL=/bin/bash, which silently turned the control arm into a SECOND
|
|
# bash arm. It then swallowed (correctly, per the bug!) and the
|
|
# assertion read as "the fix path is broken" when nothing was broken.
|
|
# /bin/zsh is the macOS default login shell since Catalina and is
|
|
# present on every supported version.
|
|
zsh = "/bin/zsh"
|
|
if not os.path.isfile(zsh):
|
|
pytest.skip("no zsh available")
|
|
|
|
marker_bash = tmp_path / "bash_ran"
|
|
marker_zsh = tmp_path / "zsh_ran"
|
|
|
|
# /bin/bash login shell: command is swallowed (file NOT created).
|
|
self._spawn_like_registry("/bin/bash", f"echo x > {marker_bash}", home, tmp_path)
|
|
# zsh (what _find_shell prefers when $SHELL is zsh): command runs.
|
|
self._spawn_like_registry(zsh, f"echo x > {marker_zsh}", home, tmp_path)
|
|
|
|
# The FIX path (zsh) must run the command.
|
|
assert marker_zsh.exists(), "zsh path must run the command"
|
|
|
|
# Differential: when /bin/bash is the swallow-prone 3.x (macOS system
|
|
# bash), the login-shell invocation must demonstrably FAIL to run the
|
|
# command — that's the bug this PR routes around. Only assert the
|
|
# negative when we've confirmed a 3.x bash, so the test stays valid on
|
|
# boxes/CI with a newer /bin/bash that doesn't swallow.
|
|
ver = subprocess.run(
|
|
["/bin/bash", "--version"], capture_output=True, text=True
|
|
).stdout
|
|
if "version 3." in ver:
|
|
assert not marker_bash.exists(), (
|
|
"system bash 3.x login shell should swallow the command "
|
|
"(the #42203 bug); _find_shell routes around it by preferring zsh"
|
|
)
|
|
|
|
def test_find_shell_selects_working_shell_on_this_box(self, tmp_path):
|
|
"""_find_shell's choice must actually execute a background-style
|
|
command (regression against returning a swallow-prone shell)."""
|
|
shell = _find_shell()
|
|
marker = tmp_path / "ok_marker"
|
|
subprocess.run(
|
|
[shell, "-lic", f"set +m; echo ok > {marker}"],
|
|
stdin=subprocess.DEVNULL, capture_output=True, text=True,
|
|
)
|
|
assert marker.exists(), f"_find_shell()={shell} swallowed the command"
|