From 64950092d53cfe842f35faa2f43b5cef03be59fa Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Mon, 7 Sep 2026 06:31:19 -0700 Subject: [PATCH] test: align delegated-child env tests with retained board routing The descendant fence now keeps HERMES_KANBAN_DB/BOARD/WORKSPACE so a fenced child can still read the board it belongs to; only worker identity (TASK, RUN_ID, CLAIM_LOCK) is scrubbed. Three pre-existing tests still asserted the DB var was dropped and went red on CI. --- tests/tools/test_delegate_kanban_isolation.py | 5 +++-- tests/tools/test_execute_code_approval_cluster.py | 4 ++-- tests/tools/test_hermes_subprocess_env.py | 6 ++++-- 3 files changed, 9 insertions(+), 6 deletions(-) diff --git a/tests/tools/test_delegate_kanban_isolation.py b/tests/tools/test_delegate_kanban_isolation.py index 27d45ddcc0..a248590c18 100644 --- a/tests/tools/test_delegate_kanban_isolation.py +++ b/tests/tools/test_delegate_kanban_isolation.py @@ -168,9 +168,10 @@ def test_delegate_child_execute_code_env_bridges_contextvar_and_scrubs_kanban( assert env["HERMES_DELEGATED_CHILD_CONTEXT"] == "1" assert "HERMES_KANBAN_TASK" not in env assert "HERMES_KANBAN_RUN_ID" not in env - assert "HERMES_KANBAN_DB" not in env - assert "HERMES_KANBAN_WORKSPACE" not in env assert "HERMES_KANBAN_CLAIM_LOCK" not in env + # Board location and workspace routing ride along with the fence marker. + assert env["HERMES_KANBAN_DB"] == str(home / "kanban.db") + assert env["HERMES_KANBAN_WORKSPACE"] == str(tmp_path / "parent-workspace") def test_delegate_child_kanban_cli_cannot_delete_parent_board( diff --git a/tests/tools/test_execute_code_approval_cluster.py b/tests/tools/test_execute_code_approval_cluster.py index a5664b1faf..a14a807aac 100644 --- a/tests/tools/test_execute_code_approval_cluster.py +++ b/tests/tools/test_execute_code_approval_cluster.py @@ -464,7 +464,7 @@ def test_env_scrub_hermes_allowlist_and_secret_blocks(): "HERMES_DELEGATED_CHILD_CONTEXT": "1", # other HERMES_* → dropped (broad prefix removed) "HERMES_BASE_URL": "https://x", "HERMES_INTERACTIVE": "1", - "HERMES_KANBAN_DB": "postgres://u:p@h/db", + "HERMES_KANBAN_TASK": "t_parent", # secret substrings (incl. new DSN/WEBHOOK) → dropped "SENTRY_DSN": "https://a@s.io/1", "SLACK_WEBHOOK": "https://h/x", "OPENAI_API_KEY": "sk", "GITHUB_TOKEN": "ghp", @@ -479,7 +479,7 @@ def test_env_scrub_hermes_allowlist_and_secret_blocks(): ): assert kept in out, f"{kept} should be kept" for dropped in ( - "HERMES_BASE_URL", "HERMES_INTERACTIVE", "HERMES_KANBAN_DB", + "HERMES_BASE_URL", "HERMES_INTERACTIVE", "HERMES_KANBAN_TASK", "SENTRY_DSN", "SLACK_WEBHOOK", "OPENAI_API_KEY", "GITHUB_TOKEN", "RANDOM_X", ): diff --git a/tests/tools/test_hermes_subprocess_env.py b/tests/tools/test_hermes_subprocess_env.py index 00ff0f5c9a..bac2c5d5e7 100644 --- a/tests/tools/test_hermes_subprocess_env.py +++ b/tests/tools/test_hermes_subprocess_env.py @@ -169,10 +169,12 @@ class TestDelegatedChildMarker: env = hermes_subprocess_env(inherit_credentials=True) assert env["HERMES_DELEGATED_CHILD_CONTEXT"] == "1" + # Worker identity is scrubbed; board location and workspace routing survive so the + # fenced descendant can still read the board it belongs to. assert "HERMES_KANBAN_TASK" not in env assert "HERMES_KANBAN_RUN_ID" not in env - assert "HERMES_KANBAN_DB" not in env - assert "HERMES_KANBAN_WORKSPACE" not in env + assert env["HERMES_KANBAN_DB"] == "/tmp/parent-kanban.db" + assert env["HERMES_KANBAN_WORKSPACE"] == "/tmp/parent-workspace" assert env["MY_APP_VAR"] == "keep-me"