Repository navigation
Conversation
…home's plugin keys _save_platform_tools writes plugin toolset names into platform_toolsets.<platform> and records them in known_plugin_toolsets.<platform>, and hermes_cli/plugins_cmd.py writes the same pair when a plugin is enabled. A key has to belong to the home the config is being written FOR: previously the caller's process-wide plugin registry decided, so a save made for home B by a process whose own home had plugin X stamped X's toolset into B, and every later run in B warned "Unknown toolsets: <x>". Per-home plugin managers are what keep the two apart; these tests lock that in. Red on the code before the keyed per-home manager (4e1b2e4^), green after.
nca7777
marked this pull request as ready for review
September 23, 2026 19:47
Author
|
Evidence (all run from a worktree of
No production file is touched by this branch, so there is nothing to regression-review beyond the test file itself. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Locks in the invariant that a
platform_toolsetssave for ONE home can only carry plugin toolsetkeys THAT home can resolve — never the keys of whatever home the calling process happens to have its
plugins loaded from. Tests only; no behaviour change.
hermes_cli/tools_config.py::_save_platform_toolswrites plugin toolset names intoplatform_toolsets.<platform>and records them inknown_plugin_toolsets.<platform>, andhermes_cli/tools_config.py::_get_platform_toolsauto-enables a plugin key that is not yet "known"for that platform.
hermes_cli/plugins_cmd.py::_toggle_plugin_toolset(the plugin enable path)writes the same pair. In all three the keys come from
_get_plugin_toolset_keys().If those keys are resolved from the caller's process-wide plugin registry instead of the home the
config is being written for, one save stamps a foreign name into another home's list — after which
every run in that home logs
Warning: Unknown toolsets: <x>, because a home with no<home>/plugins/<x>can never resolve the name. That is the shape of a real fleet-wide drift here: one write put two
community plugins' toolset keys into 60 homes'
clilists (byte-identical, together with theirplugins.enabledentries), 50 of which never had those plugin directories, so those homes warned onevery CLI/gateway run for five days.
Per-home plugin managers (keyed by the resolved Hermes home, #4e1b2e43) are what keeps the two apart
today, so this PR is the regression fence rather than a fix: the same code that leaked before that
change must fail these tests, and does.
Related Issue
No issue filed; opening the tests directly so the invariant has an owner in CI. Related review queue
(not duplicates): #109844 (
fix(config): stop flagging declared plugin toolsets as unknown) is theREAD side in
toolset_validation, and #88003 / #55801 are warning-suppression discussions — none ofthem assert anything about which home's plugin keys get WRITTEN.
Type of Change
Changes Made
tests/hermes_cli/test_platform_toolsets_plugin_key_scope.py(new, 2 tests):test_save_for_another_home_does_not_stamp_the_callers_plugin_toolset— home A is the processhome and has a real (synthetic) directory plugin registering toolset
probe_ts; home B has thesame config and no plugin dir. Warm the site under A (assert the key is live there — the positive
control), then run the resolve-then-save path the dashboard toggle and
hermes toolsuse underB: neither B's
platform_toolsetsnor B'sknown_plugin_toolsetsmay name the key. Finalassertion: the same save for A does keep the key, so the negative isn't vacuous.
test_enabling_a_plugin_does_not_stamp_it_into_a_home_without_it— the plugin-enable writer(
plugins_cmd.dashboard_set_agent_plugin_enabled) under home B must refuse (not installed) andleave B's
plugins.enabledandplatform_toolsetsuntouched.config.yaml, real directory-plugin discovery, realset_hermes_home_overridescope switch (the same seam a multiplexed dashboard uses).How to Test
scripts/run_tests.sh tests/hermes_cli/test_platform_toolsets_plugin_key_scope.py -q→ 2 passed.scripts/run_tests.sh tests/hermes_cli/test_tools_config.py tests/hermes_cli/test_platform_toolsets_plugin_key_scope.py tests/plugins/ -q→
144 files, 1895 tests passed, 0 failed, 6 skipped.Red-on-defect proof: the first test run against the code immediately before the keyed per-home
plugin manager (
4e1b2e43^, i.e.22af80bcfd) fails with(that tree:
git worktree add --detach <dir> 4e1b2e43^, copy the test file in, run it — 1 failed,1 passed). On this branch: 2 passed.
Checklist
scripts/run_tests.sh