Skip to content

test(cli): the title-resume-hint gate could not see naive quoting - #892

Merged
Kyzcreig merged 1 commit into
mainfrom
daedalus-opus/t_e484ec2d-hint-roundtrip
Sep 23, 2026
Merged

Kyzcreig merged 1 commit into
mainfrom
daedalus-opus/t_e484ec2d-hint-roundtrip

Conversation

@Kyzcreig

@Kyzcreig Kyzcreig commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

tests/cli/test_exit_summary_resume_hint.py gates cli.py:17984, and its
only fixture title was "My Cool Session" — no apostrophe, so
shlex.quote(t) and a naive hand-rolled f"'{t}'" emit BYTE-IDENTICAL
output for it. The test therefore could not tell correct quoting from
naive quoting, and mutant M9 (naive single quotes at that site) survived
the whole file. M9 is a real defect: real bash REFUSES
hermes -c 'don't' with "unexpected EOF while looking for matching ''". The class is already gated at the twin site (main.py:2003) by tests/hermes_cli/test_cli_hint.py's quo'te` parametrization — this was a
missing discriminator, not a missing gate.

Replaced the literal-spelling assertion with a ROUND-TRIP oracle
mirroring the twin's: drive the real print site, hand the printed line to
a real /bin/bash (NUL-delimited), and require the argv back to equal
["hermes", "-c", <title>, "-p", "dev"]. Parametrized over 12 titles
including the apostrophe discriminator, expansion/substitution, control
operators, and globbing (with a hostile_cwd so the globs can actually
hit). A round trip cannot go stale when the site's quoting style changes
— which is exactly what caused t_0c5ac29a.

VERIFIED (worktree at fda1503; .venv/bin/python -P 3.11.15,
PYTHONPATH=, HERMES_HOME=/tmp/te484-home, -p no:randomly;
every mutant ast.parse'd VALID-PYTHON, every restore cmp'd
byte-identical):
M0 control -> 16 passed GREEN
M9 naive single -> 1 failed, 15 passed KILLED [quo'te]
M8a pre-#889 double -> 4 failed, 12 passed KILLED
M8b bare/unwired -> 12 failed, 4 passed KILLED
cli.py untouched (git status: test file only). ruff 0.15.10 clean.
tests/cli + tests/hermes_cli/test_cli_hint.py: 1 failed, 1561 passed —
the failure is INHERITED (test_resume_quiet_stderr, 1 failed/1433 passed
on the same worktree stashed clean; passes 4/4 in isolation).

Stacked on #889 (daedalus-opus/t_c9e1a012-hint-shell): hint_value at
cli.py:17984 exists only on that branch.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

@Kyzcreig

Copy link
Copy Markdown
Collaborator Author

apollo/merge-pass 2026-09-23: rebased onto current main (clean, own commits only, no content change) so CI runs against the post-#915 main; landing via fleet-merge on the FR-pause lane once green.

tests/cli/test_exit_summary_resume_hint.py gates cli.py:17984, and its
only fixture title was "My Cool Session" — no apostrophe, so
shlex.quote(t) and a naive hand-rolled f"'{t}'" emit BYTE-IDENTICAL
output for it. The test therefore could not tell correct quoting from
naive quoting, and mutant M9 (naive single quotes at that site) survived
the whole file. M9 is a real defect: real bash REFUSES
`hermes -c 'don't'` with "unexpected EOF while looking for matching `''".
The class is already gated at the twin site (main.py:2003) by
tests/hermes_cli/test_cli_hint.py's `quo'te` parametrization — this was a
missing discriminator, not a missing gate.

Replaced the literal-spelling assertion with a ROUND-TRIP oracle
mirroring the twin's: drive the real print site, hand the printed line to
a real /bin/bash (NUL-delimited), and require the argv back to equal
["hermes", "-c", <title>, "-p", "dev"]. Parametrized over 12 titles
including the apostrophe discriminator, expansion/substitution, control
operators, and globbing (with a hostile_cwd so the globs can actually
hit). A round trip cannot go stale when the site's quoting style changes
— which is exactly what caused t_0c5ac29a.

VERIFIED (worktree at fda1503; .venv/bin/python -P 3.11.15,
PYTHONPATH=<worktree>, HERMES_HOME=/tmp/te484-home, -p no:randomly;
every mutant ast.parse'd VALID-PYTHON, every restore cmp'd
byte-identical):
  M0 control          -> 16 passed                    GREEN
  M9 naive single     -> 1 failed, 15 passed          KILLED [quo'te]
  M8a pre-#889 double -> 4 failed, 12 passed          KILLED
  M8b bare/unwired    -> 12 failed, 4 passed          KILLED
cli.py untouched (git status: test file only). ruff 0.15.10 clean.
tests/cli + tests/hermes_cli/test_cli_hint.py: 1 failed, 1561 passed —
the failure is INHERITED (test_resume_quiet_stderr, 1 failed/1433 passed
on the same worktree stashed clean; passes 4/4 in isolation).

Stacked on #889 (daedalus-opus/t_c9e1a012-hint-shell): hint_value at
cli.py:17984 exists only on that branch.
@Kyzcreig
Kyzcreig force-pushed the daedalus-opus/t_e484ec2d-hint-roundtrip branch from 8c69c76 to 216b536 Compare September 23, 2026 10:53
@Kyzcreig

Copy link
Copy Markdown
Collaborator Author

🤖 merged-by: apollo · lane: fr-pause-0922 · gate: BYPASS: FR PAUSED by Ace ruling 2026-09-22 (state/fleetreview-pause-20260922.md); t_e484ec2d approved · why: argus approved; 16 hint tests pass; 37 checks green, clean; CI green; Apollo merge pass 2026-09-22

@Kyzcreig
Kyzcreig added this pull request to the merge queue Sep 23, 2026
Merged via the queue into main with commit f90c14c Sep 23, 2026
54 checks passed
@Kyzcreig
Kyzcreig deleted the daedalus-opus/t_e484ec2d-hint-roundtrip branch September 23, 2026 11:13
Kyzcreig added a commit that referenced this pull request Sep 23, 2026
…hooser

Every fixture in both resume-hint round-trip gates carried exactly ONE hostile
shell feature -- "quo'te" apostrophe, "$HOME" expansion, "`id`" substitution,
"a b" splitting. That vocabulary cannot distinguish a correct quoter from one
that merely SELECTS a quote style by scanning for an apostrophe, because such a
quoter is byte-correct on every single-feature token: it emits '$HOME' for the
expansion-only case and "quo'te" for the apostrophe-only case, and bash hands
both back unchanged.

Python's repr() is exactly that quoter, and it is a real defect: it picks
double quotes for the apostrophe, and double quotes do not stop expansion, so
a possessive session title EXECUTES when pasted --

    "Ace's $(id)"  binds  Ace's uid=502(...)
    "it's `id`"    binds  it's uid=502(...)
    "don't $HOME"  binds  don't /Users/<user>

Measured before this commit, the repr mutation SURVIVES both gates: 16 passed
at cli.py:17984 and 117 passed at hermes_cli/main.py:2003. Adding fixtures that
combine an apostrophe WITH an expansion kills it at both sites -- 4 failed and
3 failed respectively -- on exactly those combined ids and no others.

Added to both vocabularies rather than one, because drift between the twin
fixture lists is what produced t_0c5ac29a and t_e484ec2d.

Verified (~/.hermes/hermes-agent/.venv/bin/python -P, PYTHONPATH=<worktree>,
HERMES_HOME=<fresh mktemp>, -p no:randomly; every mutant ast.parse()d, every
restore sha256-compared):

  M15-repr           cli.py:17984         4 failed, 18 passed    KILLED
  M15b-repr-SIBLING  main.py:2003         3 failed, 132 passed   KILLED
  M9-naive-single                         5 failed, 17 passed    KILLED
  M8a-pre889-double                       8 failed, 14 passed    KILLED
  M8b-bare                               18 failed,  4 passed    KILLED
  M14-quote-if-space                     11 failed, 11 passed    KILLED
  M16-drop-profile-flag                  18 failed,  4 passed    KILLED
  M17-unwire                             18 failed,  4 passed    KILLED
  controls                               22 passed / 135 passed  GREEN

Class sweep at the choke point every listed consumer delegates to: mutating
hermes_cli/cli_hint.py itself to repr() is KILLED in both halves --
hint_value 8 failed, hint_arg 10 failed, both 18 failed.

Test-only. No production file is modified; cli.py, hermes_cli/main.py and
hermes_cli/cli_hint.py are byte-identical after the battery.

Card: t_f5323218 (found by Argus reviewing PR #892)
(cherry picked from commit cdc50ea)
@Kyzcreig Kyzcreig added the fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent) label Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

fleetreview:post-merge Ask FleetReview to review this MERGED pull (merge commit vs first parent)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant