91 lines
3.1 KiB
Python
91 lines
3.1 KiB
Python
"""End-to-end credential isolation proof for multiplex mode (Workstream A).
|
|
|
|
These exercise the REAL resolution path (runtime_provider, secret scope, MCP
|
|
interpolation) rather than mocking it, proving the property that matters: two
|
|
profiles with different keys never see each other's, and an unscoped read in
|
|
multiplex mode fails closed instead of leaking.
|
|
"""
|
|
import pytest
|
|
|
|
from pathlib import Path
|
|
|
|
from agent import secret_scope as ss
|
|
|
|
|
|
@pytest.fixture(autouse=True)
|
|
def _reset(monkeypatch):
|
|
ss.set_multiplex_active(False)
|
|
yield
|
|
ss.set_multiplex_active(False)
|
|
|
|
|
|
class TestRuntimeProviderUsesScope:
|
|
"""hermes_cli.runtime_provider._getenv resolves through the secret scope."""
|
|
|
|
|
|
def test_getenv_two_profiles_isolated(self, monkeypatch):
|
|
from hermes_cli.runtime_provider import _getenv
|
|
ss.set_multiplex_active(True)
|
|
|
|
tok_a = ss.set_secret_scope({"OPENAI_API_KEY": "sk-A"})
|
|
try:
|
|
assert _getenv("OPENAI_API_KEY") == "sk-A"
|
|
finally:
|
|
ss.reset_secret_scope(tok_a)
|
|
|
|
tok_b = ss.set_secret_scope({"OPENAI_API_KEY": "sk-B"})
|
|
try:
|
|
assert _getenv("OPENAI_API_KEY") == "sk-B"
|
|
finally:
|
|
ss.reset_secret_scope(tok_b)
|
|
|
|
|
|
class TestMcpInterpolationUsesScope:
|
|
"""MCP config ${VAR} interpolation resolves through the secret scope."""
|
|
|
|
def test_interpolation_reads_scope(self, monkeypatch):
|
|
from tools.mcp_tool import _interpolate_env_vars
|
|
monkeypatch.setenv("MY_MCP_TOKEN", "global-token")
|
|
ss.set_multiplex_active(True)
|
|
tok = ss.set_secret_scope({"MY_MCP_TOKEN": "profile-token"})
|
|
try:
|
|
cfg = {"env": {"TOKEN": "${MY_MCP_TOKEN}"}}
|
|
assert _interpolate_env_vars(cfg) == {"env": {"TOKEN": "profile-token"}}
|
|
finally:
|
|
ss.reset_secret_scope(tok)
|
|
|
|
|
|
class TestProfilePathResolutionUnderMultiplexScope:
|
|
"""Profile-scoped paths must follow the per-turn _profile_runtime_scope.
|
|
|
|
The multiplexed gateway (gateway.multiplex_profiles) serves every profile
|
|
from ONE process, scoping each inbound turn with _profile_runtime_scope —
|
|
the same in-process-many-profiles topology as the desktop tui_gateway. The
|
|
profile-isolation fixes (per-call path resolution + thread context
|
|
propagation) must therefore hold under THIS scope too, not just desktop.
|
|
This is the regression guard proving reachability is not desktop-only.
|
|
"""
|
|
|
|
def _profiles(self, tmp_path):
|
|
prof_a = tmp_path / "profA"
|
|
prof_b = tmp_path / "profB"
|
|
for p in (prof_a, prof_b):
|
|
(p / "skills").mkdir(parents=True, exist_ok=True)
|
|
(p / "state").mkdir(parents=True, exist_ok=True)
|
|
return prof_a, prof_b
|
|
|
|
def test_skills_dir_follows_multiplex_scope(self, tmp_path):
|
|
from gateway.run import _profile_runtime_scope
|
|
import tools.skills_hub as sh
|
|
|
|
prof_a, prof_b = self._profiles(tmp_path)
|
|
with _profile_runtime_scope(prof_a):
|
|
a_seen = Path(sh.SKILLS_DIR)
|
|
with _profile_runtime_scope(prof_b):
|
|
b_seen = Path(sh.SKILLS_DIR)
|
|
|
|
assert a_seen == prof_a / "skills"
|
|
assert b_seen == prof_b / "skills"
|
|
|
|
|