test(approval): keep two invariants for unattended allowlist keys; document rule keys

Drop the session-only negative (session grants were never consulted on the unattended
path, so it pins pre-existing behaviour rather than the fix). Keep the permanent-key
positive and the Tirith-not-bypassed negative. Docs: command_allowlist rule keys are
honored in cron/-q/unattended sessions.
This commit is contained in:
teknium1
2026-09-14 17:47:34 -07:00
committed by Teknium
parent 05e7e89175
commit 6f87575009
2 changed files with 8 additions and 20 deletions
-20
View File
@@ -283,26 +283,6 @@ class TestCronDenyModeAllGuards:
assert result["approved"] is True
def test_session_pattern_key_does_not_allow_command_in_cron_deny(self, monkeypatch):
"""A session-only approval must not become standing authority for unattended work."""
monkeypatch.delenv("HERMES_CRON_SESSION", raising=False)
monkeypatch.delenv("HERMES_INTERACTIVE", raising=False)
monkeypatch.delenv("HERMES_GATEWAY_SESSION", raising=False)
monkeypatch.delenv("HERMES_EXEC_ASK", raising=False)
monkeypatch.delenv("HERMES_YOLO_MODE", raising=False)
approval_module.approve_session("test-session", "script execution via heredoc")
from unittest.mock import patch as mock_patch
tokens = set_session_vars(session_key="test-session", cron_session="1")
try:
with mock_patch("tools.approval_context._get_cron_approval_mode", return_value="deny"):
result = check_all_command_guards("python3 - <<'PY'\nprint('ok')\nPY", "local")
finally:
clear_session_vars(tokens)
assert result["approved"] is False
assert "BLOCKED" in result["message"]
def test_pattern_key_allowlist_does_not_bypass_tirith_in_cron_deny(self, monkeypatch):
"""Approving one dangerous pattern must not suppress an independent Tirith finding."""
monkeypatch.setenv("HERMES_CRON_SESSION", "1")
+8
View File
@@ -267,6 +267,14 @@ command_allowlist:
These patterns are loaded at startup and silently approved in all future sessions.
Entries can be exact command text, a shell-style glob (`podman *`), or a
dangerous-pattern rule key such as `script execution via heredoc` (the key shown
in the approval prompt). Rule keys are honored on every surface, including
unattended ones: a cron job, `hermes chat -q` run or webhook session under
`cron_mode`/`single_query_mode`/`unattended_mode: deny` still runs a command whose
detected rule key is in `command_allowlist`, while Tirith content-security
findings on the same command continue to block it.
The setting must be a list of strings. Legacy installs that stored a list as a
quoted YAML/JSON string recover that list at load time and log a warning to
re-save it with `hermes config edit`. Other malformed values are ignored with