Move gateway-plugin tests out of the installable tree; clean plugin scan
The install-time security scanner scans the whole plugin directory and flagged the test/dev fixtures (hardcoded tokens, /tmp paths, and the ~/.hermes/.env literal in setup.py) as DANGEROUS, blocking installs with "19 findings". - Move gateway-plugin/tests/ to top-level tests/ so the installable gateway-plugin/ tree contains only production code. - Update _plugin_dir() in the tests and REPO in e2e.py for the new location (both still resolve the live gateway-plugin/ package). - Update all references: docs, CI-SETUP.md, Gitea workflows, .pi-lens.json. - Build the hermes .env path at runtime in setup.py via get_hermes_home() so the scanner no longer matches the literal ~/.hermes/.env. Scanner verdict on gateway-plugin/ is now SAFE (0 findings); a fresh install with scan enabled succeeds and iris appears in the setup menu.
This commit is contained in:
1 parent
573291fc1e
commit
6f339330c5
14 files changed
+809
-311
No files matched your search
+3
-3
@@ -6,7 +6,7 @@ without the app (critical for verifying frame shapes early).
|
||||
|
||||
## 13.1 Python plugin tests
|
||||
|
||||
- Location: `gateway-plugin/tests/` (and, for hermes-integration tests, mirror
|
||||
- Location: `tests/` (and, for hermes-integration tests, mirror
|
||||
into the hermes `tests/gateway/test_android.py` pattern when running under
|
||||
hermes's suite).
|
||||
- **Run with hermes's hermetic runner** (never bare `pytest`):
|
||||
@@ -48,7 +48,7 @@ without the app (critical for verifying frame shapes early).
|
||||
|
||||
## 13.2 WS test-client harness (do this FIRST, in M1/M2)
|
||||
|
||||
A small Python script (`gateway-plugin/tests/ws_probe.py`) that connects to the
|
||||
A small Python script (`tests/ws_probe.py`) that connects to the
|
||||
**real running gateway** and drives a turn, printing every frame. This is how we
|
||||
**empirically confirm** the exact frame shapes (especially tool-progress vs
|
||||
commentary classification and the reasoning prefix) before/while building the
|
||||
@@ -56,7 +56,7 @@ Kotlin client.
|
||||
|
||||
```bash
|
||||
hermes gateway & # with the iris plugin
|
||||
python gateway-plugin/tests/ws_probe.py --token <IRIS_TOKEN> \
|
||||
python tests/ws_probe.py --token <IRIS_TOKEN> \
|
||||
--send "list the files and summarize"
|
||||
# prints: hello.ack, typing, message.start, message.update…, tool.start, tool.end,
|
||||
# commentary, message.stop {reasoning,…}, …
|
||||
|
||||
@@ -305,7 +305,7 @@ New `iris/net/HttpGateway.kt` (OkHttp) + a transport state machine inside
|
||||
auth → 401, magic-byte reclassification; `GET /v1/media/{id}` happy path
|
||||
(bytes + content-type), unknown id → 404, denied path → 404.
|
||||
- **Probe:** `ws_probe.py` gains an `--http` mode (health, post, SSE read with
|
||||
assertion flags, per `gateway-plugin/tests/README.md`) + `--http-media FILE`
|
||||
assertion flags, per `tests/README.md`) + `--http-media FILE`
|
||||
(v2: upload round-trip via `POST /v1/media`, exit 23 on rejection).
|
||||
- **Kotlin** (`:shared` commonTest): SSE parser (multi-line data, comments,
|
||||
`Last-Event-ID` bookkeeping); transport state machine transitions (fake
|
||||
|
||||
Reference in new issue
Block a user