Repository navigation
fix(gateway): scope resolve_proxy_url()'s platform_env_var read by multiplex profile - #104279
nftpoetrist wants to merge 1 commit into
Conversation
…ltiplex profile resolve_proxy_url() read platform_env_var (TELEGRAM_PROXY, DISCORD_PROXY, MATTERMOST_PROXY, MATRIX_PROXY) via raw os.environ.get() — a shared chokepoint used by 7+ adapters. Under a secondary multiplex profile, os.environ holds the default profile's YAML-to-env bridge output, so a secondary profile with its own (different or absent) proxy config would silently borrow the default profile's proxy, or vice versa — and proxy URLs can embed credentials (http://user:pass@host). Fix: read platform_env_var through gateway.platforms._shared's get_scoped_secret(), which is scope-aware (profile's own scope first, falling back to os.environ only when unscoped/default-profile) and already used by 10+ other adapters for the same class of setting. The generic HTTPS_PROXY/HTTP_PROXY/ALL_PROXY fallback stays a raw env read — those are OS/system-level network settings, not a per-profile Hermes concept. This closes a gap PR NousResearch#100448 explicitly deferred ("proxy_url is deliberately NOT scoped here ... left for a dedicated fix to that shared helper").
PR #104279 — fix(gateway): scope resolve_proxy_url()'s platform_env_var read by multiplex profileCorrect application of the #72348 scoping pattern to the shared proxy chokepoint: per-platform proxy vars can embed credentials, so a secondary profile must read its own Non-blocking observations:
Verdict: looks good to merge. |
|
Landed on |
Problem
gateway/platforms/base.py::resolve_proxy_url(platform_env_var, target_hosts)is a shared chokepoint used by Telegram, Discord, Mattermost, Matrix, SMS, and Slack (tools/send_message_senders.py,plugins/platforms/{telegram,discord,mattermost,matrix,sms,slack}/adapter.py,plugins/platforms/telegram/telegram_network.py) to resolve each adapter's proxy URL. It readplatform_env_var(e.g.TELEGRAM_PROXY,DISCORD_PROXY) via rawos.environ.get().Under a secondary multiplex profile,
os.environholds the default profile's YAML-to-env bridge output — a secondary profile with its own (different or absent) proxy configuration would silently borrow the default profile's proxy, or the reverse. Proxy URLs can embed credentials (http://user:pass@host), so this is a credential/routing scoping gap, not just a config-value one.This gap was already identified and explicitly deferred in this account's own PR #100448:
This PR is that dedicated fix.
Fix
platform_env_varis now read throughgateway.platforms._shared.get_scoped_secret()— the same scope-aware helper (profile's own secret scope first, falling back toos.environonly when unscoped/default-profile) already used by 10+ other adapters for this exact class of setting.The generic
HTTPS_PROXY/HTTP_PROXY/ALL_PROXYfallback (used when noplatform_env_varis configured andgateway.trust_envis true) is left as a raw env read — those are OS/system-level network settings, not a per-profile Hermes concept, and scoping them would be a behavior change without a corresponding per-profile convention to back it.Testing
TestResolveProxyUrlMultiplexScopeclass intests/gateway/test_gateway_trust_env.py(3 tests): a scoped secondary profile uses its ownDISCORD_PROXY, a scoped profile with no own value does not borrow the default profile's env value (fails closed toNone), and a single-profile/unscoped control confirms the legacy env read is unchanged.None); the control test correctly passes either way.tests/gateway/test_gateway_trust_env.py+test_proxy_mode.py+test_telegram_closewait_limits_31599.py+test_telegram_polling_progress.py+tests/tools/test_send_message_telegram_proxy.py+test_slack.py+test_mattermost.py+ alltest_matrix*.py: all green, no regressions.tests/gateway/test_discord_send.pyshowed 3 failures in a combined run with the Slack/Discord/Mattermost suites — confirmed via mutation-verify (identical failures with the fix reverted) and isolated runs (all pass alone) that this is a pre-existing test-order-pollution artifact in this test file, completely unrelated to this change.Scope note
Discord/Telegram/Mattermost/Matrix/SMS/Slack all call through this one function — fixing it here closes the gap for every caller at once rather than patching each adapter's own proxy resolution individually.