e0ef0eb9c3
* feat(connections): manage_connections covers local MCP servers; setup_mcp leaves the schema
One model tool now connects the user to apps of both kinds. A target
`{"name": "linear", "mcp": true}` is a locally configured MCP server;
`install` / `enable` / `authorize` are its verbs. Bare strings and
`{"name": ...}` stay managed connectors and that leg is unchanged.
MCP targets run through one backend-owned connection operation
(tools/connections_tool_operation.py): created with a server-side
deadline from the new config key `connections.wait_timeout_seconds`
(default 120, floor 5, no ceiling), per-target state, and exactly-once
settlement (all resolved / Continue / deadline / interrupt). Unresolved
targets freeze as `not_connected` with the settle reason.
Why the fold works now: the approval card is reached through
`agent.connection_callback` via the agent-level inline executor table,
which is the only path that carries a GUI callback. Registry dispatch
(every non-GUI surface) settles MCP targets as `unavailable` with the
`hermes mcp install / login` hint; managed targets in the same call
are unaffected.
`setup_mcp` is removed from every advertised toolset and from the
deferral list; an inline-table shim keeps calls from conversations
opened before this change dispatching (prompt-cache protection).
`_LEGACY_TOOL_ALIASES` is not the mechanism: inline tools bypass it.
Gateway: `mcp.setup.request/respond` are replaced by
`connection.request/respond/expire` (no wire compat; desktop ships
with this). The bridge waits exactly the operation's deadline. The
`session.resume` snapshot gains `pending_connection` so a reopened
window restores the card with the original deadline.
`manage_connections` joins `_SEQUENTIAL_DEADLINE_EXEMPT_TOOLS`: the
operation owns its wait; the 420s guard must not report `tool_timeout`
while the card is live.
The portal `check_fn` on the tool is dropped in favour of a
handler-level gate on the managed leg, so signed-out sessions can still
approve local MCPs.
* wip(desktop): connection.request store, resume restore, card routing for MCP targets
Renderer half of the setup_mcp fold, first slice: connection-request store
(mirrors clarify), connection.request/expire handling, pending_connection
resume restore, mcpTargets() + isCardTool(name, args) so MCP-target
manage_connections calls classify as cards. Not yet: the card component
rewrite (mcp-setup-tool.tsx), mcp-directory.ts removal, vitest, docs.
Does not typecheck until the card rewrite lands.
* fix(config): hermes update turns on the connections toolset for saved toolset lists
`hermes tools` writes an explicit `platform_toolsets.<platform>` list, and the
resolver reads absence from that list as "unchecked". The `connections`
toolset (#106842) shipped after most users last saved, so `manage_connections`
is stripped from the schema on every install that ever opened the picker.
The Nous entitlement gate never runs; the agent reports the tool as missing.
Migration 44 -> 45 (renumbered when folded into #109517; main was already at 44) appends `connections` to each explicit per-platform list
that lacks it and records the offer in `known_builtin_toolsets` where that
record exists, so a later uncheck reads as a decline. It skips: platforms
whose record already holds `connections` (the user saw the checkbox and left
it off), bare composite lists ([hermes-cli]) that already inherit it, platforms
where the toolset is not allowed, and any config whose `agent.disabled_toolsets`
names `connections` (Blank Slate, `hermes tools --disable`), because the
resolver subtracts that list last and the enable would never take effect.
The explicit-list test is the resolver's own: any configurable or plugin key.
`hermes update` runs migrations post-pull for the active profile and every
sibling, so one update is enough. Fresh installs and composite users were
never affected.
* refactor: anti-slop pass on the desktop slice; shorten added comments
Parse connection.request at the boundary with a typed wire interface instead of
unknown + typeof; mcpTargets reuses connectorText; comments cut to one or two
lines. slop-ratchet: no net-new findings in 13 touched files.
* feat(desktop): the MCP approval card answers manage_connections; MCP Directory removed
The existing card (mcp-setup-tool.tsx) now reads the connection-request store,
renders for manage_connections calls with mcp:true targets, answers through
connection.respond with a per-target outcome, and no longer calls reload.mcp
after Install; the new server's tools arrive on the between-turns refresh.
A settled operation renders the first target's frozen state.
session.resume restores a pending card with its original deadline on both the
activate and cold-resume paths.
lib/mcp-directory.ts is deleted along with its two fallback branches
(suggestion provider, card install). The catalog was already primary in both;
a catalog miss now yields no suggestion / a notInCatalog error. The GitHub
never-suggest test is rewritten on catalog-shaped data.
vitest: connection-request store (6), suggestion provider, clarify restore.
slop-ratchet: no net-new findings in 19 touched files.
* chore: drop __pycache__ files swept in by an over-broad git add
* fix(desktop): correlate the connection.request row with the model's tool call by reason
The synthetic row from connection.request and the tool.start row carried
different ids and no shared match value (op_id is not in the model's args),
so the card mounted twice. reason is the arg both sides carry.
* docs: manage_connections covers local MCP servers; connections.wait_timeout_seconds
* fix(connections): settle reason derives from target state, never from the renderer
A card that answers one of two targets and claims all_resolved must settle as
continue with the other target not_connected; found live with a two-target call.
* fix(desktop): a pending connection card re-arms on resume and activate
The store entry was restored but the transcript row was not, so navigating
away and back (or reloading) lost the card while the backend kept waiting.
restorePendingClarifyToolCall's core is generalized to any blocking tool
name and both resume paths project the connection row through it.
Verified live: card restored after navigate-away and after a full renderer
reload, deadline_at unchanged, approve settles connected.
* style: literal wording in added comments, docstrings and docs
* fix: shared gateway-event contract and config-schema category for the connection events
connection.request/expire replace mcp.setup.* in apps/shared gateway-events
(json list, BACKEND_EVENT_NAMES, GatewayEventMap) so the renderer's event
union includes them and the tui_gateway contract test passes. The new
`connections` config section folds into the agent tab like the other
single-field sections.
* style: import order (perfectionist) in the desktop and shared files this PR touches
* chore: retrigger CI (zero-job dispatch failure, auto-heal)
124 lines
4.8 KiB
Python
124 lines
4.8 KiB
Python
"""GUI capability follows the SESSION's client, not the backend's process env.
|
|
|
|
The desktop app is a client. It can drive a backend that Electron spawned
|
|
locally, one reached over SSH, one behind a plain URL+token, or Hermes Cloud —
|
|
and only the first two run with ``HERMES_DESKTOP=1`` in their environment.
|
|
Gating the pane/browser/reaction tools on that env var therefore stripped every
|
|
one of them from URL and cloud gateways, while the same backend still told the
|
|
model "You are chatting inside the Hermes desktop app".
|
|
|
|
These tests pin the contract that replaced it: eligibility is resolved from the
|
|
session's own ``source`` (``session.create``'s ``source: 'desktop'``), so the
|
|
answer is identical on every connection topology.
|
|
"""
|
|
|
|
import pytest
|
|
|
|
import tui_gateway.server as server
|
|
from toolsets import TOOLSETS, resolve_toolset
|
|
|
|
GUI_TOOLS = {
|
|
"annotate_preview",
|
|
"desktop_preview",
|
|
"drive_preview",
|
|
"close_terminal",
|
|
"focus_pane",
|
|
"read_terminal",
|
|
"read_window_below",
|
|
"react_to_message",
|
|
"show_tip",
|
|
"gui_tour",
|
|
}
|
|
|
|
|
|
@pytest.fixture
|
|
def no_desktop_env(monkeypatch):
|
|
"""A backend nobody told about the desktop — i.e. every remote gateway."""
|
|
monkeypatch.delenv("HERMES_DESKTOP", raising=False)
|
|
monkeypatch.delenv("HERMES_DESKTOP_TERMINAL", raising=False)
|
|
monkeypatch.delenv("HERMES_TUI_TOOLSETS", raising=False)
|
|
return monkeypatch
|
|
|
|
|
|
class TestDesktopUiToolset:
|
|
def test_holds_exactly_the_gui_affordances(self):
|
|
# apply_layout registers into desktop_ui via the registry (not the
|
|
# static toolsets.py list), so force discovery first — otherwise the
|
|
# result depends on which earlier test imported tool modules
|
|
# (pre-existing ordering flake, surfaced by the #97979 test sweep).
|
|
from tools.registry import discover_builtin_tools
|
|
discover_builtin_tools()
|
|
assert set(resolve_toolset("desktop_ui")) == GUI_TOOLS | {"apply_layout"}
|
|
|
|
def test_stays_off_the_core_tool_list(self):
|
|
"""Core ships on every API call — a GUI-only tool must not be there."""
|
|
from toolsets import _HERMES_CORE_TOOLS
|
|
|
|
assert GUI_TOOLS.isdisjoint(_HERMES_CORE_TOOLS)
|
|
|
|
def test_no_platform_bundle_carries_it(self):
|
|
"""Messaging/CLI bundles must not pick these up by listing them."""
|
|
for name, spec in TOOLSETS.items():
|
|
if name == "desktop_ui":
|
|
continue
|
|
assert GUI_TOOLS.isdisjoint(set(spec.get("tools") or ())), name
|
|
|
|
|
|
class TestSurfaceResolution:
|
|
def test_desktop_session_gets_them_with_no_desktop_env(self, no_desktop_env):
|
|
"""THE regression: a desktop client on a remote/cloud backend."""
|
|
assert "desktop_ui" in server._gui_surface_toolsets("desktop")
|
|
|
|
def test_tui_session_does_not(self, no_desktop_env):
|
|
assert "desktop_ui" not in server._gui_surface_toolsets("tui")
|
|
|
|
def test_desktop_env_alone_does_not_grant_them(self, no_desktop_env):
|
|
"""A desktop-spawned backend serving a TUI session stays clean.
|
|
|
|
The embedded terminal pane runs `hermes --tui` against this same
|
|
backend; env-keyed gating handed it GUI tools it cannot answer.
|
|
"""
|
|
no_desktop_env.setenv("HERMES_DESKTOP", "1")
|
|
assert "desktop_ui" not in server._gui_surface_toolsets("tui")
|
|
|
|
def test_project_tools_ride_on_every_gui_surface(self, no_desktop_env):
|
|
for platform in ("desktop", "tui"):
|
|
assert "project" in server._gui_surface_toolsets(platform)
|
|
|
|
|
|
class TestResolverPlumbing:
|
|
def test_posture_path_folds_in_the_session_surface(self, no_desktop_env):
|
|
"""Focus-mode returns early — the surface toolsets must survive it."""
|
|
import agent.coding_context as cc
|
|
|
|
no_desktop_env.setattr(cc, "coding_selection", lambda **_: ["coding"])
|
|
|
|
assert server._load_enabled_toolsets("desktop") == [
|
|
"coding",
|
|
"desktop_ui",
|
|
"project",
|
|
]
|
|
assert server._load_enabled_toolsets("tui") == ["coding", "project"]
|
|
|
|
def test_config_path_folds_in_the_session_surface(self, no_desktop_env):
|
|
import agent.coding_context as cc
|
|
import hermes_cli.config as config_mod
|
|
|
|
no_desktop_env.setattr(cc, "coding_selection", lambda **_: None)
|
|
no_desktop_env.setattr(
|
|
config_mod, "load_config", lambda: {"platform_toolsets": {"cli": ["memory"]}}
|
|
)
|
|
|
|
desktop = server._load_enabled_toolsets("desktop")
|
|
tui = server._load_enabled_toolsets("tui")
|
|
|
|
assert desktop is not None and tui is not None
|
|
assert "desktop_ui" in desktop
|
|
assert "desktop_ui" not in tui
|
|
|
|
def test_explicit_env_pin_still_wins(self, no_desktop_env):
|
|
"""HERMES_TUI_TOOLSETS is an operator override; surface can't re-add."""
|
|
no_desktop_env.setenv("HERMES_TUI_TOOLSETS", "web,memory")
|
|
|
|
assert server._load_enabled_toolsets("desktop") == ["web", "memory"]
|