Files
nousresearch--hermes-agent/tests/agent/test_auxiliary_client_ssl_verify.py
wehub-resource-sync b4fbd6fe9f
Deploy Site / deploy-vercel (push) Has been skipped
Deploy Site / deploy-docs (push) Has been skipped
Build Skills Index / build-index (push) Has been skipped
CI / Deny unrelated histories (push) Has been skipped
CI / Detect affected areas (push) Successful in 27m35s
CI / OSV scan (push) Failing after 4s
CI / Build&Test Docker image (push) Successful in 9s
CI / Supply-chain scan (push) Has been skipped
CI / Lint Docker scripts (push) Failing after 5m13s
CI / Check contributors (push) Failing after 12m8s
CI / Docs Site (push) Failing after 12m8s
CI / TypeScript (push) Failing after 12m8s
CI / Python lints (push) Failing after 12m9s
CI / Python tests (push) Failing after 12m9s
CI / Check uv.lock (push) Failing after 23m22s
CI / CI timing report (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
CI / All required checks pass (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 11:56:03 +08:00

80 lines
3.1 KiB
Python

"""Regression: auxiliary-client keepalive httpx client must honor custom CA bundles.
The main OpenAI client resolves per-provider ``ssl_ca_cert`` / ``ssl_verify`` and
``HERMES_CA_BUNDLE`` via ``agent.ssl_verify.resolve_httpx_verify``. Auxiliary calls
(compression, vision, web_extract, title generation, session_search) build their own
keepalive client through ``agent.process_bootstrap.build_keepalive_http_client`` and must
apply the same TLS settings — otherwise an HTTPS custom_providers endpoint signed by a
private CA works for chat but fails ``APIConnectionError`` on every auxiliary task.
"""
import ssl
import certifi
import httpx
import pytest
from agent.process_bootstrap import build_keepalive_http_client
_CA_ENV_VARS = ("HERMES_CA_BUNDLE", "SSL_CERT_FILE", "REQUESTS_CA_BUNDLE", "HTTPS_PROXY")
@pytest.fixture
def clean_tls_env(monkeypatch):
for var in _CA_ENV_VARS:
monkeypatch.delenv(var, raising=False)
def test_build_keepalive_http_client_forwards_verify_context(clean_tls_env):
ctx = ssl.create_default_context(cafile=certifi.where())
client = build_keepalive_http_client("https://ollama.example.com/v1", verify=ctx)
assert isinstance(client, httpx.Client)
assert client._transport._pool._ssl_context is ctx
def test_build_keepalive_http_client_verify_false_disables_hostname_check(clean_tls_env):
client = build_keepalive_http_client("https://ollama.example.com/v1", verify=False)
assert isinstance(client, httpx.Client)
assert client._transport._pool._ssl_context.check_hostname is False
def test_build_keepalive_http_client_default_verify_true(clean_tls_env):
client = build_keepalive_http_client("https://ollama.example.com/v1")
assert isinstance(client, httpx.Client)
def test_resolve_aux_verify_uses_per_provider_ssl_ca_cert(clean_tls_env, monkeypatch):
"""_resolve_aux_verify should mirror the main-client resolution for a matched base_url."""
import hermes_cli.config as cfg
from agent import auxiliary_client
# get_custom_provider_tls_settings is imported inside the function from
# hermes_cli.config, so patch it at the source module.
monkeypatch.setattr(
cfg,
"get_custom_provider_tls_settings",
lambda *a, **k: {"ssl_ca_cert": certifi.where()},
)
verify = auxiliary_client._resolve_aux_verify("https://ollama.example.com/v1")
assert isinstance(verify, ssl.SSLContext)
def test_resolve_aux_verify_ssl_verify_false(clean_tls_env, monkeypatch):
import hermes_cli.config as cfg
from agent import auxiliary_client
monkeypatch.setattr(
cfg,
"get_custom_provider_tls_settings",
lambda *a, **k: {"ssl_verify": False},
)
assert auxiliary_client._resolve_aux_verify("https://ollama.example.com/v1") is False
def test_resolve_aux_verify_no_match_defaults_true(clean_tls_env, monkeypatch):
import hermes_cli.config as cfg
from agent import auxiliary_client
monkeypatch.setattr(cfg, "get_custom_provider_tls_settings", lambda *a, **k: {})
assert auxiliary_client._resolve_aux_verify("https://openrouter.ai/api/v1") is True