Files
hermes-agent/tests/hermes_cli/test_update_interrupted_recovery.py
T
Halldrix 19cff89300 fix(update): complete pending core install before any native import (self-lock loop fix)
Reviewer egilewski found the original defer was circular (#83590 comment):
the self-lock preflight wrote .update-incomplete and exited, but the next
launch only ran the full recovery AFTER main.py's third-party imports —
so a healthy venv's probes made the early pass a no-op, main.py imported
cryptography eagerly, the .pyd got mapped again, and the deferred install
re-hit the exact self-lock it was meant to escape.

Close the loop by making the marker guarantee the install runs BEFORE any
native extension can be imported:

- hermes_cli/_install_repair.py (new, stdlib-only): single source of truth
  for the core .[all] reinstall — ensurepip bootstrap, uv-pip/pip
  resolution with VIRTUAL_ENV, Termux env stripping, Windows hermes*.exe
  quarantine, per-extra fallback ladder, and fd1→fd2 routing for acp
  safety.  Deliberately free of managed_uv/hermes_constants imports so it
  stays importable in the corrupted-venv state it exists to repair.
- hermes_cli/_early_recovery.py: recover_if_needed now completes a pending
  .update-incomplete install BEFORE the import probes, on every launch
  that sees the marker (unless argv is update).  Success clears the
  marker; failure bumps an attempts counter inside the marker body and
  keeps it.  A 3-attempt ceiling stops a persistently-failing install
  from reinstall-hammering every launch (hermes acp included) — past the
  ceiling the late post-import recovery takes over with its manual
  recovery instructions.  Single-flight lock shared with the late path.
- hermes_cli/main.py: _recover_core_update_marker_locked delegates the
  install to the shared executor (no duplicated logic); ensure_uv stays
  in the late path so a venv whose uv vanished mid-update still
  bootstraps it.
- tests: 7 new regressions — the reviewer's exact case (marker + healthy
  venv → install runs while sys.modules has no cryptography), failure
  keeps marker + increments attempts, retry ceiling, lazy marker does
  not trigger core install (#58004 invariant), argv-update skip, and
  corrupt/missing marker bodies.  The key test was sabotage-verified:
  removing the pre-import branch makes it fail with zero install calls,
  while a lone-lazy-marker test still passes; restoring the branch makes
  it pass again.

Refs #83569
2026-08-14 22:03:56 -07:00

111 lines
3.3 KiB
Python

"""Tests for interrupted-install self-heal (the ``.update-incomplete`` marker).
Covers the breadcrumb lifecycle and the launch-time recovery guard added so a
``hermes update`` killed mid-install (Ctrl-C, terminal close, WSL OOM) gets
finished automatically on the next launch instead of leaving a half-built venv.
"""
from __future__ import annotations
from pathlib import Path
import hermes_cli.main as m
def test_marker_round_trip(tmp_path, monkeypatch):
monkeypatch.setattr(m, "PROJECT_ROOT", tmp_path)
marker = m._update_marker_path()
assert marker == tmp_path / ".update-incomplete"
assert not marker.exists()
m._write_update_incomplete_marker()
assert marker.exists()
body = marker.read_text()
assert "started=" in body
assert "pid=" in body
m._clear_update_incomplete_marker()
assert not marker.exists()
def _stub_install_env(monkeypatch, m, seen):
"""Common stubs so recovery's install path is inert and observable."""
class R:
returncode = 0
monkeypatch.setattr(m.subprocess, "run", lambda *a, **k: R())
monkeypatch.setattr(m, "_is_termux_env", lambda *a, **k: False)
monkeypatch.setattr("hermes_cli.managed_uv.ensure_uv", lambda: None)
# The install executor moved to hermes_cli._install_repair (shared between
# the pre-import early pass and this late recovery path) — stub WHERE it
# is executed, not the legacy main.py wrapper it replaced.
import hermes_cli._install_repair as ir
monkeypatch.setattr(
ir, "run_core_install", lambda _root: seen.__setitem__("install", True)
)
def test_recovery_self_lock_does_not_clear_core_marker_via_import_probes(
tmp_path, monkeypatch
):
# ``.update-incomplete`` is the generic core-install marker. Healthy
# lazy-refresh import probes alone must NOT clear it and skip full
# reinstall — a missing dep outside the 7-probe set would look healthy
# (#58004 review blocker).
monkeypatch.setattr(m, "PROJECT_ROOT", tmp_path)
(tmp_path / "pyproject.toml").write_text("[project]\nname='x'\n")
m._write_update_incomplete_marker()
scripts_dir = tmp_path / "venv" / "Scripts"
scripts_dir.mkdir(parents=True)
shim = scripts_dir / "hermes.exe"
shim.write_text("")
monkeypatch.setattr(m, "_is_windows", lambda: True)
monkeypatch.setattr(m, "_venv_scripts_dir", lambda: scripts_dir)
monkeypatch.setattr(m, "_hermes_exe_shims", lambda d: [shim])
monkeypatch.setattr(
m,
"_default_venv_install_target",
lambda: (["uv", "pip"], {"VIRTUAL_ENV": str(tmp_path / "venv")}),
)
monkeypatch.setattr(
m, "_repair_venv_via_import_probes", lambda *a, **k: "healthy"
)
class FakeProc:
def __init__(self, exe_path):
self._exe = exe_path
def exe(self):
return self._exe
def parents(self):
return [FakeProc(str(shim))]
monkeypatch.setattr("psutil.Process", lambda: FakeProc(sys_executable_path()))
seen = {"install": False}
_stub_install_env(monkeypatch, m, seen)
m._recover_from_interrupted_install()
assert seen["install"] is True, "core marker still requires full reinstall"
assert not m._update_marker_path().exists(), "cleared only after full reinstall"
def sys_executable_path():
import sys
return sys.executable