Files
hermes-agent/tests/gateway/test_stale_platform_lock_retryable.py
T
Shannon Sands c127d0c3b1 fix(gateway): attribute scoped credential lock conflicts to the owning profile (OOF-3)
Scoped credential locks (Telegram bot token, Discord bot token, etc.) are
machine-global, but the conflict error only reported the holder's PID:

    Telegram bot token already in use (PID 559). Stop the other gateway first.

On multi-profile hosts (e.g. hosted instances running 13 profiles), a bare
PID gives the operator no way to tell WHICH profile owns the credential —
the exact failure mode observed on zerocool-9781, where the 'default'
profile was misconfigured with the same bot token as 'lead-gen-outreach'
and logged an unattributable conflict every ~5 minutes (4,602 rows).

Fix:
- acquire_scoped_lock() now stamps a 'profile' label on lock records,
  inferred from the process HERMES_HOME (<root>/profiles/<name> layouts,
  'default' for the root home). Omitted when not inferable.
- New scoped_lock_owner_label() resolves the owning profile from a lock
  record: prefers the explicit field, falls back to inferring from the
  persisted hermes_home for locks written before the field existed.
  Labels are validated against the profile-id grammar before use (lock
  files are plain JSON on disk and the label flows into log lines and a
  suggested CLI command).
- _acquire_platform_lock() conflict message now names the owning profile
  and gives the correct remedy:

    Telegram bot token already in use by the 'lead-gen-outreach' profile
    gateway (PID 559). Stop that gateway first
    (hermes --profile lead-gen-outreach gateway stop).

  Records with no attribution signal keep the original PID-only wording.

Testing:
- New TestScopedLockOwnerLabel suite covering label inference (named,
  Docker, root/default, unknown layouts), grammar validation, explicit-
  field preference, hermes_home fallback, and legacy/malformed records.
- acquire_scoped_lock tests for profile stamping and omission.
- Adapter-level tests for profile-attributed, legacy-home-inferred, and
  PID-only conflict messages.
- 76/76 targeted gateway tests pass; broad gateway suite failures are
  baseline-identical (verified via git stash comparison). Ruff clean.
2026-08-16 20:32:09 -07:00

185 lines
6.1 KiB
Python

"""Regression tests for platform-lock acquire behavior.
#54167 — stale platform lock must be retryable.
When a gateway process is killed (SIGKILL, crash) during Telegram
initialization, the scoped lock file survives. On next startup,
``acquire_scoped_lock()`` detects the stale lock and deletes it, but may
still return ``(False, existing_dict)`` to the caller (e.g. if the
unlink fails due to permissions, or a race condition lets another
process grab the lock first).
``_acquire_platform_lock()`` must mark such failures as **retryable**
so the reconnect watcher can retry after a delay — not permanently kill
the platform.
#65176 — a live gateway token conflict may attempt one-shot takeover only
during the initial connect of an explicit ``gateway run --replace`` startup.
``gateway run --replace`` only kills same-HERMES_HOME PID-file holders.
A normal start or reconnect must retain the retryable conflict behavior and
must never evict the active holder.
"""
from typing import Any, Dict
from unittest.mock import MagicMock, patch
import pytest
from gateway.platforms.base import BasePlatformAdapter
from gateway.run import GatewayRunner
class _StubAdapter(BasePlatformAdapter):
"""Minimal concrete subclass for testing _acquire_platform_lock."""
platform = MagicMock(value="telegram")
async def connect(self, *, is_reconnect: bool = False) -> bool:
return True
async def disconnect(self) -> None:
pass
async def send(self, *args: Any, **kwargs: Any) -> None:
pass
async def get_chat_info(self, chat_id: str) -> Dict[str, Any]:
return {}
@pytest.fixture()
def adapter():
"""Create a stub adapter with __init__ bypassed."""
obj = _StubAdapter.__new__(_StubAdapter)
obj._running = True
obj._fatal_error_code = None
obj._fatal_error_message = None
obj._fatal_error_retryable = True
obj._fatal_error_handler = None
obj._platform_lock_scope = None
obj._platform_lock_identity = None
obj._platform_lock_takeover_allowed = False
obj._platform_lock_takeover_attempted = False
obj._status_write_logged = None
return obj
def test_stale_lock_failure_is_retryable(adapter):
"""Lock failure must be retryable, not permanently fatal (#54167)."""
with patch(
"gateway.status.acquire_scoped_lock",
return_value=(False, {"pid": 99999, "start_time": "2026-01-01T00:00:00Z"}),
), patch.object(adapter, "_write_runtime_status_safe"):
result = adapter._acquire_platform_lock(
"telegram-bot-token", "test-token", "Telegram bot token"
)
assert result is False
assert adapter._fatal_error_retryable is True
assert adapter._fatal_error_code == "telegram-bot-token_lock"
def test_explicit_replace_takeover_reacquires_lock_once(adapter):
"""Initial explicit --replace may hand off and re-acquire once (#65176)."""
existing = {
"pid": 4242,
"kind": "hermes-gateway",
"argv": ["hermes", "gateway", "run"],
"start_time": 123,
}
acquire = MagicMock(side_effect=[(False, existing), (True, None)])
adapter._platform_lock_takeover_allowed = True
with patch("gateway.status.acquire_scoped_lock", acquire), patch(
"gateway.status.take_over_scoped_lock_holder",
return_value=4242,
) as takeover, patch.object(
adapter, "_write_runtime_status_safe"
):
result = adapter._acquire_platform_lock(
"telegram-bot-token", "test-token", "Telegram bot token"
)
assert result is True
assert adapter._platform_lock_takeover_allowed is False
assert adapter._platform_lock_takeover_attempted is True
takeover.assert_called_once_with(existing)
assert acquire.call_count == 2
def test_lock_conflict_names_owning_profile(adapter):
"""OOF-3: cross-profile conflicts must name the owning profile, not just a PID."""
existing = {
"pid": 559,
"start_time": 123,
"profile": "lead-gen-outreach",
"hermes_home": "/opt/data/profiles/lead-gen-outreach",
}
with patch(
"gateway.status.acquire_scoped_lock",
return_value=(False, existing),
), patch.object(adapter, "_write_runtime_status_safe"):
result = adapter._acquire_platform_lock(
"telegram-bot-token",
"test-token",
"Telegram bot token",
)
assert result is False
assert adapter._fatal_error_message == (
"Telegram bot token already in use by the "
"'lead-gen-outreach' profile gateway (PID 559). "
"Stop that gateway first "
"(hermes --profile lead-gen-outreach gateway stop)."
)
assert adapter._fatal_error_retryable is True
assert adapter._fatal_error_code == "telegram-bot-token_lock"
def test_lock_conflict_infers_profile_from_legacy_hermes_home(adapter):
"""Locks written before the profile field existed still attribute via hermes_home."""
existing = {
"pid": 559,
"start_time": 123,
"hermes_home": "/opt/data/profiles/lead-gen-outreach",
}
with patch(
"gateway.status.acquire_scoped_lock",
return_value=(False, existing),
), patch.object(adapter, "_write_runtime_status_safe"):
result = adapter._acquire_platform_lock(
"telegram-bot-token",
"test-token",
"Telegram bot token",
)
assert result is False
assert "'lead-gen-outreach' profile gateway (PID 559)" in (
adapter._fatal_error_message
)
def test_lock_conflict_keeps_pid_only_wording_for_legacy_record(adapter):
"""Records with no attribution signal retain the original PID-only message."""
existing = {
"pid": 99999,
"start_time": 123,
}
with patch(
"gateway.status.acquire_scoped_lock",
return_value=(False, existing),
), patch.object(adapter, "_write_runtime_status_safe"):
result = adapter._acquire_platform_lock(
"telegram-bot-token",
"test-token",
"Telegram bot token",
)
assert result is False
assert adapter._fatal_error_message == (
"Telegram bot token already in use (PID 99999). "
"Stop the other gateway first."
)