test: align delegated-child env tests with retained board routing

The descendant fence now keeps HERMES_KANBAN_DB/BOARD/WORKSPACE so a
fenced child can still read the board it belongs to; only worker identity
(TASK, RUN_ID, CLAIM_LOCK) is scrubbed. Three pre-existing tests still
asserted the DB var was dropped and went red on CI.
This commit is contained in:
Teknium
2026-09-07 06:31:19 -07:00
parent b578261584
commit 64950092d5
3 changed files with 9 additions and 6 deletions
@@ -168,9 +168,10 @@ def test_delegate_child_execute_code_env_bridges_contextvar_and_scrubs_kanban(
assert env["HERMES_DELEGATED_CHILD_CONTEXT"] == "1"
assert "HERMES_KANBAN_TASK" not in env
assert "HERMES_KANBAN_RUN_ID" not in env
assert "HERMES_KANBAN_DB" not in env
assert "HERMES_KANBAN_WORKSPACE" not in env
assert "HERMES_KANBAN_CLAIM_LOCK" not in env
# Board location and workspace routing ride along with the fence marker.
assert env["HERMES_KANBAN_DB"] == str(home / "kanban.db")
assert env["HERMES_KANBAN_WORKSPACE"] == str(tmp_path / "parent-workspace")
def test_delegate_child_kanban_cli_cannot_delete_parent_board(
@@ -464,7 +464,7 @@ def test_env_scrub_hermes_allowlist_and_secret_blocks():
"HERMES_DELEGATED_CHILD_CONTEXT": "1",
# other HERMES_* → dropped (broad prefix removed)
"HERMES_BASE_URL": "https://x", "HERMES_INTERACTIVE": "1",
"HERMES_KANBAN_DB": "postgres://u:p@h/db",
"HERMES_KANBAN_TASK": "t_parent",
# secret substrings (incl. new DSN/WEBHOOK) → dropped
"SENTRY_DSN": "https://a@s.io/1", "SLACK_WEBHOOK": "https://h/x",
"OPENAI_API_KEY": "sk", "GITHUB_TOKEN": "ghp",
@@ -479,7 +479,7 @@ def test_env_scrub_hermes_allowlist_and_secret_blocks():
):
assert kept in out, f"{kept} should be kept"
for dropped in (
"HERMES_BASE_URL", "HERMES_INTERACTIVE", "HERMES_KANBAN_DB",
"HERMES_BASE_URL", "HERMES_INTERACTIVE", "HERMES_KANBAN_TASK",
"SENTRY_DSN", "SLACK_WEBHOOK", "OPENAI_API_KEY", "GITHUB_TOKEN",
"RANDOM_X",
):
+4 -2
View File
@@ -169,10 +169,12 @@ class TestDelegatedChildMarker:
env = hermes_subprocess_env(inherit_credentials=True)
assert env["HERMES_DELEGATED_CHILD_CONTEXT"] == "1"
# Worker identity is scrubbed; board location and workspace routing survive so the
# fenced descendant can still read the board it belongs to.
assert "HERMES_KANBAN_TASK" not in env
assert "HERMES_KANBAN_RUN_ID" not in env
assert "HERMES_KANBAN_DB" not in env
assert "HERMES_KANBAN_WORKSPACE" not in env
assert env["HERMES_KANBAN_DB"] == "/tmp/parent-kanban.db"
assert env["HERMES_KANBAN_WORKSPACE"] == "/tmp/parent-workspace"
assert env["MY_APP_VAR"] == "keep-me"