2026-03-14 06:04:39 -07:00
|
|
|
import importlib
|
2026-03-13 22:00:36 -07:00
|
|
|
import logging
|
|
|
|
|
|
2026-03-14 06:04:39 -07:00
|
|
|
terminal_tool_module = importlib.import_module("tools.terminal_tool")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def _clear_terminal_env(monkeypatch):
|
|
|
|
|
"""Remove terminal env vars that could affect requirements checks."""
|
|
|
|
|
keys = [
|
|
|
|
|
"TERMINAL_ENV",
|
2026-03-26 15:27:27 -07:00
|
|
|
"TERMINAL_MODAL_MODE",
|
2026-03-14 06:04:39 -07:00
|
|
|
"TERMINAL_SSH_HOST",
|
|
|
|
|
"TERMINAL_SSH_USER",
|
|
|
|
|
"MODAL_TOKEN_ID",
|
2026-03-26 15:27:27 -07:00
|
|
|
"MODAL_TOKEN_SECRET",
|
2026-03-14 06:04:39 -07:00
|
|
|
"HOME",
|
|
|
|
|
"USERPROFILE",
|
|
|
|
|
]
|
|
|
|
|
for key in keys:
|
|
|
|
|
monkeypatch.delenv(key, raising=False)
|
feat: ungate Tool Gateway — subscription-based access with per-tool opt-in
Replace the HERMES_ENABLE_NOUS_MANAGED_TOOLS env-var feature flag with
subscription-based detection. The Tool Gateway is now available to any
paid Nous subscriber without needing a hidden env var.
Core changes:
- managed_nous_tools_enabled() checks get_nous_auth_status() +
check_nous_free_tier() instead of an env var
- New use_gateway config flag per tool section (web, tts, browser,
image_gen) records explicit user opt-in and overrides direct API
keys at runtime
- New prefers_gateway(section) shared helper in tool_backend_helpers.py
used by all 4 tool runtimes (web, tts, image gen, browser)
UX flow:
- hermes model: after Nous login/model selection, shows a curses
prompt listing all gateway-eligible tools with current status.
User chooses to enable all, enable only unconfigured tools, or skip.
Defaults to Enable for new users, Skip when direct keys exist.
- hermes tools: provider selection now manages use_gateway flag —
selecting Nous Subscription sets it, selecting any other provider
clears it
- hermes status: renamed section to Nous Tool Gateway, added
free-tier upgrade nudge for logged-in free users
- curses_radiolist: new description parameter for multi-line context
that survives the screen clear
Runtime behavior:
- Each tool runtime (web_tools, tts_tool, image_generation_tool,
browser_use) checks prefers_gateway() before falling back to
direct env-var credentials
- get_nous_subscription_features() respects use_gateway flags,
suppressing direct credential detection when the user opted in
Removed:
- HERMES_ENABLE_NOUS_MANAGED_TOOLS env var and all references
- apply_nous_provider_defaults() silent TTS auto-set
- get_nous_subscription_explainer_lines() static text
- Override env var warnings (use_gateway handles this properly now)
2026-04-16 01:59:51 -04:00
|
|
|
# Default: no Nous subscription — patch both the terminal_tool local
|
|
|
|
|
# binding and tool_backend_helpers (used by resolve_modal_backend_state).
|
|
|
|
|
monkeypatch.setattr(terminal_tool_module, "managed_nous_tools_enabled", lambda: False)
|
|
|
|
|
import tools.tool_backend_helpers as _tbh
|
|
|
|
|
monkeypatch.setattr(_tbh, "managed_nous_tools_enabled", lambda: False)
|
2026-03-13 22:00:36 -07:00
|
|
|
|
|
|
|
|
|
refactor: remove mini-swe-agent dependency — inline Docker/Modal backends (#2804)
Drop the mini-swe-agent git submodule. All terminal backends now use
hermes-agent's own environment implementations directly.
Docker backend:
- Inline the `docker run -d` container startup (was 15 lines in
minisweagent's DockerEnvironment). Our wrapper already handled
execute(), cleanup(), security hardening, volumes, and resource limits.
Modal backend:
- Import swe-rex's ModalDeployment directly instead of going through
minisweagent's 90-line passthrough wrapper.
- Bake the _AsyncWorker pattern (from environments/patches.py) directly
into ModalEnvironment for Atropos compatibility without monkey-patching.
Cleanup:
- Remove minisweagent_path.py (submodule path resolution helper)
- Remove submodule init/install from install.sh and setup-hermes.sh
- Remove mini-swe-agent from .gitmodules
- environments/patches.py is now a no-op (kept for backward compat)
- terminal_tool.py no longer does sys.path hacking for minisweagent
- mini_swe_runner.py guards imports (optional, for RL training only)
- Update all affected tests to mock the new direct subprocess calls
- Update README.md, CONTRIBUTING.md
No functionality change — all Docker, Modal, local, SSH, Singularity,
and Daytona backends behave identically. 6093 tests pass.
2026-03-24 07:30:25 -07:00
|
|
|
def test_local_terminal_requirements(monkeypatch, caplog):
|
|
|
|
|
"""Local backend uses Hermes' own LocalEnvironment wrapper."""
|
2026-03-14 06:04:39 -07:00
|
|
|
_clear_terminal_env(monkeypatch)
|
2026-03-13 22:00:36 -07:00
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "local")
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
2026-03-14 06:04:39 -07:00
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
2026-03-13 22:00:36 -07:00
|
|
|
|
|
|
|
|
assert ok is True
|
|
|
|
|
assert "Terminal requirements check failed" not in caplog.text
|
2026-03-14 06:04:39 -07:00
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_unknown_terminal_env_logs_error_and_returns_false(monkeypatch, caplog):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
|
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "unknown-backend")
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
|
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
|
|
|
|
|
|
|
|
|
assert ok is False
|
|
|
|
|
assert any(
|
|
|
|
|
"Unknown TERMINAL_ENV 'unknown-backend'" in record.getMessage()
|
|
|
|
|
for record in caplog.records
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_ssh_backend_without_host_or_user_logs_and_returns_false(monkeypatch, caplog):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
|
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "ssh")
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
|
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
|
|
|
|
|
|
|
|
|
assert ok is False
|
|
|
|
|
assert any(
|
|
|
|
|
"SSH backend selected but TERMINAL_SSH_HOST and TERMINAL_SSH_USER" in record.getMessage()
|
|
|
|
|
for record in caplog.records
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_modal_backend_without_token_or_config_logs_specific_error(monkeypatch, caplog, tmp_path):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
|
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "modal")
|
|
|
|
|
monkeypatch.setenv("HOME", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("USERPROFILE", str(tmp_path))
|
2026-03-26 15:27:27 -07:00
|
|
|
monkeypatch.setattr(terminal_tool_module, "is_managed_tool_gateway_ready", lambda _vendor: False)
|
2026-03-14 06:04:39 -07:00
|
|
|
monkeypatch.setattr(terminal_tool_module.importlib.util, "find_spec", lambda _name: object())
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
|
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
|
|
|
|
|
|
|
|
|
assert ok is False
|
|
|
|
|
assert any(
|
2026-03-30 13:28:10 +09:00
|
|
|
"Modal backend selected but no direct Modal credentials/config was found" in record.getMessage()
|
2026-03-26 15:27:27 -07:00
|
|
|
for record in caplog.records
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
def test_modal_backend_with_managed_gateway_does_not_require_direct_creds_or_minisweagent(monkeypatch, tmp_path):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
feat: ungate Tool Gateway — subscription-based access with per-tool opt-in
Replace the HERMES_ENABLE_NOUS_MANAGED_TOOLS env-var feature flag with
subscription-based detection. The Tool Gateway is now available to any
paid Nous subscriber without needing a hidden env var.
Core changes:
- managed_nous_tools_enabled() checks get_nous_auth_status() +
check_nous_free_tier() instead of an env var
- New use_gateway config flag per tool section (web, tts, browser,
image_gen) records explicit user opt-in and overrides direct API
keys at runtime
- New prefers_gateway(section) shared helper in tool_backend_helpers.py
used by all 4 tool runtimes (web, tts, image gen, browser)
UX flow:
- hermes model: after Nous login/model selection, shows a curses
prompt listing all gateway-eligible tools with current status.
User chooses to enable all, enable only unconfigured tools, or skip.
Defaults to Enable for new users, Skip when direct keys exist.
- hermes tools: provider selection now manages use_gateway flag —
selecting Nous Subscription sets it, selecting any other provider
clears it
- hermes status: renamed section to Nous Tool Gateway, added
free-tier upgrade nudge for logged-in free users
- curses_radiolist: new description parameter for multi-line context
that survives the screen clear
Runtime behavior:
- Each tool runtime (web_tools, tts_tool, image_generation_tool,
browser_use) checks prefers_gateway() before falling back to
direct env-var credentials
- get_nous_subscription_features() respects use_gateway flags,
suppressing direct credential detection when the user opted in
Removed:
- HERMES_ENABLE_NOUS_MANAGED_TOOLS env var and all references
- apply_nous_provider_defaults() silent TTS auto-set
- get_nous_subscription_explainer_lines() static text
- Override env var warnings (use_gateway handles this properly now)
2026-04-16 01:59:51 -04:00
|
|
|
monkeypatch.setattr(terminal_tool_module, "managed_nous_tools_enabled", lambda: True)
|
|
|
|
|
import tools.tool_backend_helpers as _tbh
|
|
|
|
|
monkeypatch.setattr(_tbh, "managed_nous_tools_enabled", lambda: True)
|
2026-03-26 15:27:27 -07:00
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "modal")
|
|
|
|
|
monkeypatch.setenv("HOME", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("USERPROFILE", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("TERMINAL_MODAL_MODE", "managed")
|
|
|
|
|
monkeypatch.setattr(terminal_tool_module, "is_managed_tool_gateway_ready", lambda _vendor: True)
|
|
|
|
|
monkeypatch.setattr(
|
|
|
|
|
terminal_tool_module.importlib.util,
|
|
|
|
|
"find_spec",
|
|
|
|
|
lambda _name: (_ for _ in ()).throw(AssertionError("should not be called")),
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
assert terminal_tool_module.check_terminal_requirements() is True
|
|
|
|
|
|
|
|
|
|
|
2026-03-31 08:48:54 +09:00
|
|
|
def test_modal_backend_auto_mode_prefers_managed_gateway_over_direct_creds(monkeypatch, tmp_path):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
feat: ungate Tool Gateway — subscription-based access with per-tool opt-in
Replace the HERMES_ENABLE_NOUS_MANAGED_TOOLS env-var feature flag with
subscription-based detection. The Tool Gateway is now available to any
paid Nous subscriber without needing a hidden env var.
Core changes:
- managed_nous_tools_enabled() checks get_nous_auth_status() +
check_nous_free_tier() instead of an env var
- New use_gateway config flag per tool section (web, tts, browser,
image_gen) records explicit user opt-in and overrides direct API
keys at runtime
- New prefers_gateway(section) shared helper in tool_backend_helpers.py
used by all 4 tool runtimes (web, tts, image gen, browser)
UX flow:
- hermes model: after Nous login/model selection, shows a curses
prompt listing all gateway-eligible tools with current status.
User chooses to enable all, enable only unconfigured tools, or skip.
Defaults to Enable for new users, Skip when direct keys exist.
- hermes tools: provider selection now manages use_gateway flag —
selecting Nous Subscription sets it, selecting any other provider
clears it
- hermes status: renamed section to Nous Tool Gateway, added
free-tier upgrade nudge for logged-in free users
- curses_radiolist: new description parameter for multi-line context
that survives the screen clear
Runtime behavior:
- Each tool runtime (web_tools, tts_tool, image_generation_tool,
browser_use) checks prefers_gateway() before falling back to
direct env-var credentials
- get_nous_subscription_features() respects use_gateway flags,
suppressing direct credential detection when the user opted in
Removed:
- HERMES_ENABLE_NOUS_MANAGED_TOOLS env var and all references
- apply_nous_provider_defaults() silent TTS auto-set
- get_nous_subscription_explainer_lines() static text
- Override env var warnings (use_gateway handles this properly now)
2026-04-16 01:59:51 -04:00
|
|
|
monkeypatch.setattr(terminal_tool_module, "managed_nous_tools_enabled", lambda: True)
|
|
|
|
|
import tools.tool_backend_helpers as _tbh
|
|
|
|
|
monkeypatch.setattr(_tbh, "managed_nous_tools_enabled", lambda: True)
|
2026-03-31 08:48:54 +09:00
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "modal")
|
|
|
|
|
monkeypatch.setenv("MODAL_TOKEN_ID", "tok-id")
|
|
|
|
|
monkeypatch.setenv("MODAL_TOKEN_SECRET", "tok-secret")
|
|
|
|
|
monkeypatch.setenv("HOME", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("USERPROFILE", str(tmp_path))
|
|
|
|
|
monkeypatch.setattr(terminal_tool_module, "is_managed_tool_gateway_ready", lambda _vendor: True)
|
|
|
|
|
monkeypatch.setattr(
|
|
|
|
|
terminal_tool_module.importlib.util,
|
|
|
|
|
"find_spec",
|
|
|
|
|
lambda _name: (_ for _ in ()).throw(AssertionError("should not be called")),
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
assert terminal_tool_module.check_terminal_requirements() is True
|
|
|
|
|
|
|
|
|
|
|
2026-03-26 15:27:27 -07:00
|
|
|
def test_modal_backend_direct_mode_does_not_fall_back_to_managed(monkeypatch, caplog, tmp_path):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
|
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "modal")
|
|
|
|
|
monkeypatch.setenv("TERMINAL_MODAL_MODE", "direct")
|
|
|
|
|
monkeypatch.setenv("HOME", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("USERPROFILE", str(tmp_path))
|
|
|
|
|
monkeypatch.setattr(terminal_tool_module, "is_managed_tool_gateway_ready", lambda _vendor: True)
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
|
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
|
|
|
|
|
|
|
|
|
assert ok is False
|
|
|
|
|
assert any(
|
|
|
|
|
"TERMINAL_MODAL_MODE=direct" in record.getMessage()
|
2026-03-14 06:04:39 -07:00
|
|
|
for record in caplog.records
|
|
|
|
|
)
|
2026-03-30 13:28:10 +09:00
|
|
|
|
|
|
|
|
|
2026-03-31 08:48:54 +09:00
|
|
|
def test_modal_backend_managed_mode_does_not_fall_back_to_direct(monkeypatch, caplog, tmp_path):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
|
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "modal")
|
|
|
|
|
monkeypatch.setenv("TERMINAL_MODAL_MODE", "managed")
|
|
|
|
|
monkeypatch.setenv("MODAL_TOKEN_ID", "tok-id")
|
|
|
|
|
monkeypatch.setenv("MODAL_TOKEN_SECRET", "tok-secret")
|
|
|
|
|
monkeypatch.setenv("HOME", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("USERPROFILE", str(tmp_path))
|
|
|
|
|
monkeypatch.setattr(terminal_tool_module, "is_managed_tool_gateway_ready", lambda _vendor: False)
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
|
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
|
|
|
|
|
|
|
|
|
assert ok is False
|
|
|
|
|
assert any(
|
feat: ungate Tool Gateway — subscription-based access with per-tool opt-in
Replace the HERMES_ENABLE_NOUS_MANAGED_TOOLS env-var feature flag with
subscription-based detection. The Tool Gateway is now available to any
paid Nous subscriber without needing a hidden env var.
Core changes:
- managed_nous_tools_enabled() checks get_nous_auth_status() +
check_nous_free_tier() instead of an env var
- New use_gateway config flag per tool section (web, tts, browser,
image_gen) records explicit user opt-in and overrides direct API
keys at runtime
- New prefers_gateway(section) shared helper in tool_backend_helpers.py
used by all 4 tool runtimes (web, tts, image gen, browser)
UX flow:
- hermes model: after Nous login/model selection, shows a curses
prompt listing all gateway-eligible tools with current status.
User chooses to enable all, enable only unconfigured tools, or skip.
Defaults to Enable for new users, Skip when direct keys exist.
- hermes tools: provider selection now manages use_gateway flag —
selecting Nous Subscription sets it, selecting any other provider
clears it
- hermes status: renamed section to Nous Tool Gateway, added
free-tier upgrade nudge for logged-in free users
- curses_radiolist: new description parameter for multi-line context
that survives the screen clear
Runtime behavior:
- Each tool runtime (web_tools, tts_tool, image_generation_tool,
browser_use) checks prefers_gateway() before falling back to
direct env-var credentials
- get_nous_subscription_features() respects use_gateway flags,
suppressing direct credential detection when the user opted in
Removed:
- HERMES_ENABLE_NOUS_MANAGED_TOOLS env var and all references
- apply_nous_provider_defaults() silent TTS auto-set
- get_nous_subscription_explainer_lines() static text
- Override env var warnings (use_gateway handles this properly now)
2026-04-16 01:59:51 -04:00
|
|
|
"paid Nous subscription is required" in record.getMessage()
|
2026-03-31 08:48:54 +09:00
|
|
|
for record in caplog.records
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
2026-03-30 13:28:10 +09:00
|
|
|
def test_modal_backend_managed_mode_without_feature_flag_logs_clear_error(monkeypatch, caplog, tmp_path):
|
|
|
|
|
_clear_terminal_env(monkeypatch)
|
|
|
|
|
monkeypatch.setenv("TERMINAL_ENV", "modal")
|
|
|
|
|
monkeypatch.setenv("TERMINAL_MODAL_MODE", "managed")
|
|
|
|
|
monkeypatch.setenv("HOME", str(tmp_path))
|
|
|
|
|
monkeypatch.setenv("USERPROFILE", str(tmp_path))
|
|
|
|
|
monkeypatch.setattr(terminal_tool_module, "is_managed_tool_gateway_ready", lambda _vendor: False)
|
|
|
|
|
|
|
|
|
|
with caplog.at_level(logging.ERROR):
|
|
|
|
|
ok = terminal_tool_module.check_terminal_requirements()
|
|
|
|
|
|
|
|
|
|
assert ok is False
|
|
|
|
|
assert any(
|
feat: ungate Tool Gateway — subscription-based access with per-tool opt-in
Replace the HERMES_ENABLE_NOUS_MANAGED_TOOLS env-var feature flag with
subscription-based detection. The Tool Gateway is now available to any
paid Nous subscriber without needing a hidden env var.
Core changes:
- managed_nous_tools_enabled() checks get_nous_auth_status() +
check_nous_free_tier() instead of an env var
- New use_gateway config flag per tool section (web, tts, browser,
image_gen) records explicit user opt-in and overrides direct API
keys at runtime
- New prefers_gateway(section) shared helper in tool_backend_helpers.py
used by all 4 tool runtimes (web, tts, image gen, browser)
UX flow:
- hermes model: after Nous login/model selection, shows a curses
prompt listing all gateway-eligible tools with current status.
User chooses to enable all, enable only unconfigured tools, or skip.
Defaults to Enable for new users, Skip when direct keys exist.
- hermes tools: provider selection now manages use_gateway flag —
selecting Nous Subscription sets it, selecting any other provider
clears it
- hermes status: renamed section to Nous Tool Gateway, added
free-tier upgrade nudge for logged-in free users
- curses_radiolist: new description parameter for multi-line context
that survives the screen clear
Runtime behavior:
- Each tool runtime (web_tools, tts_tool, image_generation_tool,
browser_use) checks prefers_gateway() before falling back to
direct env-var credentials
- get_nous_subscription_features() respects use_gateway flags,
suppressing direct credential detection when the user opted in
Removed:
- HERMES_ENABLE_NOUS_MANAGED_TOOLS env var and all references
- apply_nous_provider_defaults() silent TTS auto-set
- get_nous_subscription_explainer_lines() static text
- Override env var warnings (use_gateway handles this properly now)
2026-04-16 01:59:51 -04:00
|
|
|
"paid Nous subscription is required" in record.getMessage()
|
2026-03-30 13:28:10 +09:00
|
|
|
for record in caplog.records
|
|
|
|
|
)
|