Files
hermes-agent/tests/test_resource_limits.py
ethernet e8fcb007b9 Merge remote-tracking branch 'upstream/main' into ethie/pm-clean
# Conflicts:
#	AGENTS.md
#	acp_adapter/edit_approval.py
#	acp_adapter/server.py
#	agent/agent_init.py
#	agent/anthropic_adapter.py
#	agent/anthropic_credentials.py
#	agent/auxiliary_client.py
#	agent/azure_identity_adapter.py
#	agent/bedrock_adapter.py
#	agent/browser_registry.py
#	agent/chat_completion_helpers.py
#	agent/coding_context.py
#	agent/context_references.py
#	agent/conversation_loop.py
#	agent/copilot_acp_client.py
#	agent/credits_tracker.py
#	agent/curator.py
#	agent/curator_backup.py
#	agent/deadline.py
#	agent/display.py
#	agent/errors.py
#	agent/estop.py
#	agent/i18n.py
#	agent/image_gen_registry.py
#	agent/image_routing.py
#	agent/learning_graph.py
#	agent/learning_mutations.py
#	agent/lsp/servers.py
#	agent/model_metadata.py
#	agent/models_dev.py
#	agent/monitoring/gateway_health_export.py
#	agent/monitoring/otlp_exporter.py
#	agent/pet/store.py
#	agent/process_bootstrap.py
#	agent/prompt_builder.py
#	agent/proxy_sources/iron_proxy.py
#	agent/secret_sources/_cache.py
#	agent/secret_sources/bitwarden.py
#	agent/secret_sources/registry.py
#	agent/shell_hooks.py
#	agent/skill_bundles.py
#	agent/skill_commands.py
#	agent/skill_utils.py
#	agent/ssl_guard.py
#	agent/ssl_verify.py
#	agent/system_prompt.py
#	agent/terminal_env_registry.py
#	agent/trace_upload.py
#	agent/transcription_registry.py
#	agent/tts_registry.py
#	agent/verify/environment.py
#	agent/vertex_adapter.py
#	agent/video_gen_registry.py
#	agent/web_search_registry.py
#	cli.py
#	cron/jobs.py
#	cron/scheduler.py
#	gateway/agent_cache_pressure.py
#	gateway/cgroup_cleanup.py
#	gateway/channel_directory.py
#	gateway/config.py
#	gateway/control_socket.py
#	gateway/dead_targets.py
#	gateway/drain_control.py
#	gateway/hooks.py
#	gateway/kanban_watchers.py
#	gateway/lifecycle_ledger.py
#	gateway/mirror.py
#	gateway/pairing.py
#	gateway/platform_registry.py
#	gateway/platforms/helpers.py
#	gateway/platforms/weixin.py
#	gateway/readiness.py
#	gateway/restart_loop_guard.py
#	gateway/rich_sent_store.py
#	gateway/run.py
#	gateway/session.py
#	gateway/shutdown_flush.py
#	gateway/shutdown_forensics.py
#	gateway/slash_commands.py
#	gateway/status.py
#	gateway/sticker_cache.py
#	gateway/whatsapp_identity.py
#	hermes_bootstrap.py
#	hermes_cli/_early_recovery.py
#	hermes_cli/_install_repair.py
#	hermes_cli/_startup_fast.py
#	hermes_cli/_subprocess_compat.py
#	hermes_cli/agent_plugins.py
#	hermes_cli/auth.py
#	hermes_cli/backup.py
#	hermes_cli/banner.py
#	hermes_cli/browser_connect.py
#	hermes_cli/build_info.py
#	hermes_cli/cli_agent_setup_mixin.py
#	hermes_cli/cli_commands_mixin.py
#	hermes_cli/codex_models.py
#	hermes_cli/config.py
#	hermes_cli/config_defaults.py
#	hermes_cli/config_migrations.py
#	hermes_cli/container_boot.py
#	hermes_cli/dashboard_auth/registry.py
#	hermes_cli/debug.py
#	hermes_cli/dep_ensure.py
#	hermes_cli/doctor.py
#	hermes_cli/doctor_live.py
#	hermes_cli/dump.py
#	hermes_cli/env_loader.py
#	hermes_cli/foreign_sessions.py
#	hermes_cli/gateway.py
#	hermes_cli/gateway_windows.py
#	hermes_cli/gui_uninstall.py
#	hermes_cli/image_provenance.py
#	hermes_cli/install_identity.py
#	hermes_cli/kanban.py
#	hermes_cli/kanban_db.py
#	hermes_cli/linux_desktop_entry.py
#	hermes_cli/local_runtime/binaries.py
#	hermes_cli/local_runtime/endpoint.py
#	hermes_cli/local_runtime/growth.py
#	hermes_cli/local_runtime/supervisor.py
#	hermes_cli/logs.py
#	hermes_cli/macos_tcc_anchor.py
#	hermes_cli/main.py
#	hermes_cli/memory_setup.py
#	hermes_cli/model_catalog.py
#	hermes_cli/models.py
#	hermes_cli/nous_subscription.py
#	hermes_cli/npm_engine.py
#	hermes_cli/plugin_index.py
#	hermes_cli/plugins.py
#	hermes_cli/plugins_cmd.py
#	hermes_cli/profile_distribution.py
#	hermes_cli/profiles.py
#	hermes_cli/prompt_size.py
#	hermes_cli/psutil_android.py
#	hermes_cli/runtime_repair.py
#	hermes_cli/security_advisories.py
#	hermes_cli/security_audit.py
#	hermes_cli/security_audit_startup.py
#	hermes_cli/service_manager.py
#	hermes_cli/session_export_md.py
#	hermes_cli/setup.py
#	hermes_cli/skills_hub.py
#	hermes_cli/slack_cli.py
#	hermes_cli/status.py
#	hermes_cli/subcommands/gateway.py
#	hermes_cli/subcommands/uninstall.py
#	hermes_cli/tools_config.py
#	hermes_cli/uninstall.py
#	hermes_cli/update_cmd.py
#	hermes_cli/update_contract.py
#	hermes_cli/update_inventory.py
#	hermes_cli/update_lock.py
#	hermes_cli/update_receipt.py
#	hermes_cli/urllib_security.py
#	hermes_cli/web_routers/local_models.py
#	hermes_cli/web_routers/profiles.py
#	hermes_cli/web_routers/skills.py
#	hermes_cli/web_server.py
#	hermes_constants.py
#	hermes_state.py
#	plugins/disk-cleanup/__init__.py
#	plugins/disk-cleanup/disk_cleanup.py
#	plugins/google_meet/node/registry.py
#	plugins/google_meet/node/server.py
#	plugins/google_meet/process_manager.py
#	plugins/google_meet/realtime/openai_client.py
#	plugins/hermes-achievements/dashboard/plugin_api.py
#	plugins/memory/hindsight/__init__.py
#	plugins/memory/honcho/__init__.py
#	plugins/memory/honcho/cli.py
#	plugins/memory/honcho/client.py
#	plugins/memory/honcho/oauth.py
#	plugins/memory/honcho/session.py
#	plugins/memory/mem0/__init__.py
#	plugins/memory/mem0/_setup.py
#	plugins/memory/openviking/__init__.py
#	plugins/memory/retaindb/__init__.py
#	plugins/memory/supermemory/__init__.py
#	plugins/platforms/a2a/protocol.py
#	plugins/platforms/dingtalk/adapter.py
#	plugins/platforms/discord/adapter.py
#	plugins/platforms/feishu/adapter.py
#	plugins/platforms/google_chat/adapter.py
#	plugins/platforms/matrix/adapter.py
#	plugins/platforms/photon/adapter.py
#	plugins/platforms/photon/auth.py
#	plugins/platforms/photon/cli.py
#	plugins/platforms/slack/adapter.py
#	plugins/platforms/teams/adapter.py
#	plugins/platforms/telegram/adapter.py
#	plugins/platforms/wecom/callback_adapter.py
#	plugins/platforms/whatsapp/adapter.py
#	plugins/teams_pipeline/store.py
#	plugins/video_gen/fal/__init__.py
#	plugins/web/ddgs/provider.py
#	plugins/web/exa/provider.py
#	plugins/web/firecrawl/provider.py
#	plugins/web/parallel/provider.py
#	tests/agent/test_ssl_ca_guard.py
#	tests/hermes_cli/test_certifi_repair.py
#	tests/hermes_cli/test_cmd_update.py
#	tests/hermes_cli/test_cmd_update_apt.py
#	tests/hermes_cli/test_dashboard_unified_launch.py
#	tests/hermes_cli/test_dep_ensure.py
#	tests/hermes_cli/test_doctor.py
#	tests/hermes_cli/test_doctor_live.py
#	tests/hermes_cli/test_gui_command.py
#	tests/hermes_cli/test_kanban_boards.py
#	tests/hermes_cli/test_kanban_db.py
#	tests/hermes_cli/test_lazy_refresh_venv_repair.py
#	tests/hermes_cli/test_memory_setup_provider_arg.py
#	tests/hermes_cli/test_nous_subscription.py
#	tests/hermes_cli/test_pip_install_detection.py
#	tests/hermes_cli/test_profile_export_credentials.py
#	tests/hermes_cli/test_psutil_android_extract.py
#	tests/hermes_cli/test_status.py
#	tests/hermes_cli/test_tui_npm_install.py
#	tests/hermes_cli/test_update_fleet_restart_pending.py
#	tests/hermes_cli/test_update_head_moved_gate.py
#	tests/hermes_cli/test_update_interrupted_recovery.py
#	tests/hermes_cli/test_web_server.py
#	tests/hermes_cli/test_web_ui_build.py
#	tests/test_hermes_logging.py
#	tests/test_managed_runtime_resolution.py
#	tests/tools/test_browser_chromium_autoinstall.py
#	tests/tools/test_browser_chromium_check.py
#	tests/tools/test_browser_homebrew_paths.py
#	tests/tools/test_browser_lightpanda.py
#	tests/tools/test_browser_npx_warmup.py
#	tests/tools/test_browser_open_timeout.py
#	tests/tools/test_browser_orphan_reaper.py
#	tests/tools/test_browser_real_profile.py
#	tests/tools/test_browser_suspect_recycle.py
#	tests/tools/test_find_shell.py
#	tests/tools/test_local_env_blocklist.py
#	tests/tools/test_macos_protected_search.py
#	tests/tui_gateway/test_compute_host.py
#	tools/approval.py
#	tools/blueprints.py
#	tools/bot_mode_dm.py
#	tools/bot_mode_probe.py
#	tools/bot_relay.py
#	tools/browser_tool.py
#	tools/browser_use_cli.py
#	tools/checkpoint_manager.py
#	tools/code_execution_tool.py
#	tools/code_kernel.py
#	tools/computer_use/cua_backend.py
#	tools/cronjob_tools.py
#	tools/discord_tool.py
#	tools/environments/base.py
#	tools/environments/daytona.py
#	tools/environments/local.py
#	tools/environments/modal.py
#	tools/environments/vercel_sandbox.py
#	tools/fal_common.py
#	tools/file_operations.py
#	tools/lazy_deps.py
#	tools/mcp_tool.py
#	tools/neutts_synth.py
#	tools/process_registry.py
#	tools/read_extract.py
#	tools/registry.py
#	tools/skill_ledger.py
#	tools/skill_linter.py
#	tools/skill_manager_tool.py
#	tools/skill_usage.py
#	tools/skills_ast_audit.py
#	tools/skills_guard.py
#	tools/skills_hub.py
#	tools/skills_sync.py
#	tools/skills_sync_client.py
#	tools/skills_tool.py
#	tools/terminal_scope.py
#	tools/terminal_tool.py
#	tools/tirith_security.py
#	tools/transcription_tools.py
#	tools/tts_tool.py
#	tools/vision_tools.py
#	tools/voice_mode.py
#	tools/wake_word.py
#	tools/web_result_cache.py
#	tools/website_policy.py
#	tools/working_diff.py
#	tools/write_approval.py
#	tui_gateway/entry.py
#	tui_gateway/methods_tools.py
#	tui_gateway/server.py
2026-09-04 13:03:39 -04:00

357 lines
11 KiB
Python

"""Tests for configurable RLIMIT_NOFILE startup handling."""
from __future__ import annotations
from pathlib import Path
import subprocess
import sys
import textwrap
from types import SimpleNamespace
import pytest
from hermes_cli import resource_limits
from hermes_cli import dashboard_procs
from hermes_cli import main_dashboard
class _FakeResource:
RLIMIT_NOFILE = 7
RLIM_INFINITY = 2**63 - 1
def __init__(self, soft: int, hard: int) -> None:
self.limits = (soft, hard)
self.set_calls: list[tuple[int, tuple[int, int]]] = []
def getrlimit(self, resource: int) -> tuple[int, int]:
assert resource == self.RLIMIT_NOFILE
return self.limits
def setrlimit(self, resource: int, limits: tuple[int, int]) -> None:
assert resource == self.RLIMIT_NOFILE
self.set_calls.append((resource, limits))
self.limits = limits
def test_real_config_loader_reads_runtime_nofile_setting(monkeypatch, tmp_path):
"""The helper uses the canonical config loader, not a second YAML parser."""
home = tmp_path / ".hermes"
home.mkdir()
(home / "config.yaml").write_text(
"runtime:\n nofile_soft_limit: 2048\n",
encoding="utf-8",
)
fake_resource = _FakeResource(soft=256, hard=4096)
monkeypatch.setenv("HERMES_HOME", str(home))
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit() is True
assert fake_resource.set_calls == [
(fake_resource.RLIMIT_NOFILE, (2048, 4096)),
]
def test_default_is_clamped_to_hard_limit(monkeypatch):
fake_resource = _FakeResource(soft=256, hard=1024)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit({}) is True
assert fake_resource.limits == (1024, 1024)
def test_finite_soft_limit_raises_when_hard_limit_is_infinite(monkeypatch):
fake_resource = _FakeResource(soft=256, hard=_FakeResource.RLIM_INFINITY)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit({}) is True
assert fake_resource.set_calls == [
(
fake_resource.RLIMIT_NOFILE,
(4096, fake_resource.RLIM_INFINITY),
),
]
def test_never_lowers_an_already_higher_soft_limit(monkeypatch):
fake_resource = _FakeResource(soft=8192, hard=16384)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit(
{"runtime": {"nofile_soft_limit": 4096}}
) is False
assert fake_resource.set_calls == []
assert fake_resource.limits == (8192, 16384)
@pytest.mark.parametrize("disabled", [0, False, None])
def test_explicit_values_disable(monkeypatch, disabled):
fake_resource = _FakeResource(soft=256, hard=4096)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit(
{"runtime": {"nofile_soft_limit": disabled}}
) is False
assert fake_resource.set_calls == []
def test_unsupported_platform_is_a_safe_noop(monkeypatch):
monkeypatch.setattr(resource_limits, "_resource", None)
assert resource_limits.apply_nofile_soft_limit({}) is False
def test_fresh_process_import_without_posix_resource_is_a_safe_noop():
code = textwrap.dedent(
"""
import importlib.util
import pathlib
import sys
sys.modules["resource"] = None
module_path = pathlib.Path(sys.argv[1])
spec = importlib.util.spec_from_file_location(
"hermes_cli._resource_limits_without_posix_resource",
module_path,
)
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)
assert module._resource is None
assert module.apply_nofile_soft_limit({}) is False
"""
)
subprocess.run(
[sys.executable, "-c", code, resource_limits.__file__],
check=True,
cwd=Path(resource_limits.__file__).resolve().parents[1],
capture_output=True,
text=True,
)
@pytest.mark.parametrize("invalid", [True, -1, 4096.0, "4096", object()])
def test_invalid_values_are_safe_noops(monkeypatch, invalid):
fake_resource = _FakeResource(soft=256, hard=4096)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit(
{"runtime": {"nofile_soft_limit": invalid}}
) is False
assert fake_resource.set_calls == []
def test_setrlimit_denial_is_a_safe_noop(monkeypatch):
class _DeniedResource(_FakeResource):
def setrlimit(self, resource: int, limits: tuple[int, int]) -> None:
raise PermissionError("simulated EPERM")
fake_resource = _DeniedResource(soft=256, hard=4096)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit({}) is False
assert fake_resource.limits == (256, 4096)
def test_getrlimit_failure_is_a_safe_noop(monkeypatch):
class _BrokenResource(_FakeResource):
def getrlimit(self, resource: int) -> tuple[int, int]:
raise OSError("simulated getrlimit failure")
fake_resource = _BrokenResource(soft=256, hard=4096)
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit({}) is False
assert fake_resource.set_calls == []
def test_never_lowers_an_unlimited_soft_limit(monkeypatch):
fake_resource = _FakeResource(soft=-1, hard=-1)
fake_resource.RLIM_INFINITY = -1
monkeypatch.setattr(resource_limits, "_resource", fake_resource)
assert resource_limits.apply_nofile_soft_limit({}) is False
assert fake_resource.set_calls == []
assert fake_resource.limits == (-1, -1)
@pytest.mark.anyio
async def test_gateway_startup_applies_limit_before_gateway_initialization(monkeypatch):
import gateway.code_skew
import gateway.run as gateway_run
calls: list[str] = []
monkeypatch.setattr(
resource_limits,
"apply_nofile_soft_limit",
lambda: calls.append("limit"),
)
class _StopStartup(Exception):
pass
def stop_after_limit():
calls.append("gateway-init")
raise _StopStartup
monkeypatch.setattr(gateway.code_skew, "record_boot_fingerprint", stop_after_limit)
with pytest.raises(_StopStartup):
await gateway_run.start_gateway()
assert calls == ["limit", "gateway-init"]
def test_serve_startup_applies_limit_before_web_server(monkeypatch):
from hermes_cli import main as cli_main
import hermes_cli.main_web_build as main_web_build
import hermes_cli.plugins
import hermes_cli.web_server
# cmd_dashboard(headless_backend=True) exports HERMES_SERVE_HEADLESS=1 into
# this process's environment (main.py serve path). Touch the key through
# monkeypatch FIRST so teardown restores the pre-test state — otherwise the
# leaked flag flips later web-server tests (mount_spa) into the headless
# 404 path.
monkeypatch.setenv("HERMES_SERVE_HEADLESS", "0")
calls: list[str] = []
monkeypatch.setattr(
resource_limits,
"apply_nofile_soft_limit",
lambda: calls.append("limit"),
)
monkeypatch.setattr(cli_main, "_sync_bundled_skills_quietly", lambda: None)
monkeypatch.setattr(cli_main, "_build_web_ui", lambda *args, **kwargs: True)
monkeypatch.setattr(main_web_build, "_build_web_ui", lambda *args, **kwargs: True)
monkeypatch.setattr(cli_main, "_maybe_setup_dashboard_auth_interactively", lambda args: None)
monkeypatch.setattr(hermes_cli.plugins, "discover_plugins", lambda: None)
monkeypatch.setattr(
hermes_cli.web_server,
"start_server",
lambda **kwargs: calls.append("server"),
)
args = SimpleNamespace(
status=False,
stop=False,
headless_backend=True,
ssh_owner_nonce=None,
ssh_session_token_file=None,
host="127.0.0.1",
port=0,
no_open=True,
insecure=False,
open_profile="",
isolated=True,
skip_build=False,
)
cli_main.cmd_dashboard(args)
assert calls == ["limit", "server"]
@pytest.mark.platforms("linux")
def test_named_profile_reroute_defers_limit_to_final_process(monkeypatch, tmp_path):
"""The launcher profile must not leak its limit across machine re-exec."""
from hermes_cli import main as cli_main
import hermes_cli.profiles
import hermes_constants
from tools.environments import local as local_environment
calls: list[str] = []
exec_call: dict[str, object] = {}
monkeypatch.delenv("HERMES_DESKTOP", raising=False)
monkeypatch.setattr(
resource_limits,
"apply_nofile_soft_limit",
lambda: calls.append("limit"),
)
monkeypatch.setattr(
hermes_cli.profiles,
"get_active_profile_name",
lambda: "worker",
)
monkeypatch.setattr(main_dashboard, "_dashboard_listening", lambda *args: False)
monkeypatch.setattr(
local_environment,
"build_subprocess_env",
lambda **kwargs: {},
)
monkeypatch.setattr(
hermes_constants,
"get_default_hermes_root",
lambda: tmp_path,
)
class _ExecCalled(Exception):
pass
def stop_at_exec(executable, argv, env):
exec_call.update(executable=executable, argv=argv, env=env)
raise _ExecCalled
monkeypatch.setattr(cli_main.os, "execvpe", stop_at_exec)
args = SimpleNamespace(
status=False,
stop=False,
headless_backend=True,
ssh_owner_nonce=None,
ssh_session_token_file=None,
host="127.0.0.1",
port=0,
no_open=True,
insecure=False,
open_profile="",
isolated=False,
skip_build=False,
)
with pytest.raises(_ExecCalled):
cli_main.cmd_dashboard(args)
assert calls == []
assert exec_call["argv"][1:5] == ["-m", "hermes_cli.main", "-p", "default"]
assert exec_call["env"]["HERMES_HOME"] == str(tmp_path)
@pytest.mark.parametrize("lifecycle_flag", ["status", "stop"])
def test_dashboard_lifecycle_flags_skip_limit_adjustment(monkeypatch, lifecycle_flag):
"""Informational/stop-only commands must not mutate process limits."""
from hermes_cli import main as cli_main
import hermes_cli.main_dashboard as hermes_cli_main_dashboard
calls: list[str] = []
monkeypatch.setattr(
resource_limits,
"apply_nofile_soft_limit",
lambda: calls.append("limit"),
)
monkeypatch.setattr(dashboard_procs, "_scan_dashboard_processes", lambda: [])
monkeypatch.setattr(cli_main, "_find_stale_dashboard_pids", lambda: [])
monkeypatch.setattr(hermes_cli_main_dashboard, "_find_stale_dashboard_pids", lambda: [])
args = SimpleNamespace(
status=lifecycle_flag == "status",
stop=lifecycle_flag == "stop",
headless_backend=False,
ssh_owner_nonce=None,
ssh_session_token_file=None,
host="127.0.0.1",
port=0,
no_open=True,
insecure=False,
open_profile="",
isolated=False,
skip_build=False,
)
with pytest.raises(SystemExit):
cli_main.cmd_dashboard(args)
assert calls == []