Files
hermes-agent/tests/tools/test_multiplex_tool_credential_scope.py
Teknium a9838c2100 fix(multiplex): tool and memory-provider env reads stay inside the routed profile
Under gateway.multiplex_profiles, os.environ holds the DEFAULT profile's .env; a
secondary profile's values exist only in the per-turn secret scope. Every reader
below still read os.environ/os.getenv at call time, so a secondary profile's turn
silently used the default profile's value.

Credentials (F6): FIRECRAWL_API_KEY (read_file hosted OCR), OPENVIKING_API_KEY,
mem0-OSS OPENAI_API_KEY, MODAL_TOKEN_ID/SECRET and BROWSER_USE_API_KEY presence
gates, and the xAI video plugin's os.getenv("XAI_API_KEY") fallback AFTER the
scoped resolver had already missed — the exact fallback-after-miss shape
gateway/AGENTS.md forbids. Deleted, not re-scoped: the resolver is the scope.

Identity / tenant (F7): MEM0_USER_ID/AGENT_ID/HOST/MODE, SUPERMEMORY_CONTAINER_TAG,
RETAINDB_PROJECT, OPENVIKING_ACCOUNT/USER/AGENT (and the whole layered() env
read), HINDSIGHT_BANK_ID/MODE/retain shaping, HERMES_HONCHO_HOST. A raw read
put a secondary profile's memories into the default profile's account/bank/
project/tenant and recalled them back into the default's turns. Each now uses
get_secret with the provider's own per-profile default on a miss.

Endpoints (F8): OPENAI_BASE_URL (aux custom runtime + direct-alias expansion),
XAI_BASE_URL/HERMES_XAI_BASE_URL (aux OAuth), NOUS_INFERENCE_BASE_URL (#65941,
both the aux builder and hermes_cli.auth_nous._nous_inference_env_override),
GATEWAY_PROXY_URL (same UnscopedSecretError-only fallback shape as
GATEWAY_PROXY_KEY three lines below), FIRECRAWL_API_URL, BROWSERBASE_BASE_URL,
SUPERMEMORY/RETAINDB/HONCHO/HINDSIGHT URLs. The keys beside them were already
scoped, so a secondary's key was sent to the default profile's proxy or host.

Targets / display (F11): WEIXIN_HOME_CHANNEL (message posted into the default's
chat), HERMES_LANGUAGE, and agent/i18n's process-wide lru_cache of
display.language — now keyed by HERMES_HOME.

Outbound webhooks: hooks.outbound[].secret_env resolved from os.environ while
the gateway registers each profile's targets inside that profile's scope, so a
secondary's deliveries were signed with the default's secret or left unsigned.

Agent-cache eviction: _spawn_release_thread started a bare threading.Thread, so
commit_memory_session -> provider on_session_end ran with an EMPTY context. The
thread now runs copy_context() and, for the unscoped housekeeping sweep, enters
the owning profile's _profile_runtime_scope resolved from the session key
(agent:<profile>:...). The pressure batch does the same per key.

session_search (#82903): agent/inline_tool_executors.py::_session_search
forwarded every schema argument except `profile`, so a gateway agent could
never select a named profile's store. Forwarded; the ownership-scoping design
in #87779/#87847 is a separate design call and is not attempted here.

Live repro (/tmp/mux_audit/fix-tool-memory-reads/repro.py): 28 FAIL on
origin/main -> 0 FAIL with this change; 10 new invariant tests red on base.

Fixes #82903
Fixes #65941
Fixes #99121
Addresses #87779
Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com>
Co-authored-by: Michael Versluis (Berry) <michael@wve.nl>
2026-09-11 15:26:46 -07:00

57 lines
2.3 KiB
Python

"""Multiplex invariant: tool-side profile credentials / targets never leak from the default profile.
Under ``gateway.multiplex_profiles`` ``os.environ`` holds the DEFAULT profile's ``.env``; a secondary
profile's turn runs with a secret scope that may not define a var at all. Every reader below must
then see "unset", never the default profile's value (`agent/secret_scope.py::get_secret` contract).
"""
from __future__ import annotations
import pytest
from agent import secret_scope
@pytest.fixture
def secondary_scope(monkeypatch):
"""Multiplex ON with a secondary profile's (empty) secret scope installed."""
secret_scope.set_multiplex_active(True)
token = secret_scope.set_secret_scope({})
try:
yield
finally:
secret_scope.reset_secret_scope(token)
secret_scope.set_multiplex_active(False)
def test_scoped_tool_credential_gates_ignore_default_profile_environ(monkeypatch, secondary_scope, tmp_path):
from tools import browser_use_cli, read_extract, tool_backend_helpers
monkeypatch.setenv("FIRECRAWL_API_KEY", "fc-default")
monkeypatch.setenv("MODAL_TOKEN_ID", "id-default")
monkeypatch.setenv("MODAL_TOKEN_SECRET", "secret-default")
monkeypatch.setenv("BROWSER_USE_API_KEY", "bu-default")
monkeypatch.setattr(tool_backend_helpers.Path, "home", lambda: tmp_path) # no ~/.modal.toml
enabled, api_key, _ = read_extract._hosted_ocr_config()
assert (enabled, api_key) == (False, None)
assert tool_backend_helpers.has_direct_modal_credentials() is False
assert browser_use_cli.is_legacy_browser_use_cloud_config({"cloud_provider": "browser-use"}) is False
def test_weixin_home_channel_resolves_from_profile_scope_not_environ(monkeypatch, secondary_scope):
from tools import send_message_tool
class _NoHome:
def get_home_channel(self, platform):
return None
monkeypatch.setenv("WEIXIN_HOME_CHANNEL", "wx-default-chat")
chat_id, err = send_message_tool._home_chat_id(_NoHome(), None, "weixin")
assert chat_id is None and err
# The secondary's own .env value is honoured.
token = secret_scope.set_secret_scope({"WEIXIN_HOME_CHANNEL": "wx-secondary-chat"})
try:
assert send_message_tool._home_chat_id(_NoHome(), None, "weixin") == ("wx-secondary-chat", None)
finally:
secret_scope.reset_secret_scope(token)