headroom/tests/test_plugins_hermes_retrieve.py
jimu 058bcedab8
feat(plugins): Hermes agent headroom_retrieve plugin (#824)
## Summary

Implements the Hermes-side retrieval plugin proposed in #796 (as invited
— thanks for the quick response!).

When Hermes routes traffic through `headroom proxy`, compressed markers
are a one-way street: Hermes registers its own tools, so it never gets
the `headroom_retrieve` CCR tool that Claude Code receives via MCP
injection. In practice the model either re-runs the original command or
— observed in the wild — treats `ccr:abc123` as a file path and tries to
`cat` it.

This plugin uses Hermes's user-plugin system (`~/.hermes/plugins/`) to
register a native `headroom_retrieve` tool that calls the proxy's `POST
/v1/retrieve` endpoint.

## What's included

- `plugins/hermes/headroom_retrieve/` — `plugin.yaml` + `__init__.py`
(single-file, httpx, ~100 lines)
- `plugins/hermes/README.md` — install steps and proxy-side
recommendations

## Design notes

- **Both marker formats covered**: Kompress emits `[N items compressed
... hash=KEY]`, SmartCrusher's opaque-blob walker emits
`<<ccr:HASH[,KIND,SIZE]>>`. The tool description teaches both and
explicitly says markers are NOT file paths; the handler normalizes
whole-marker input (`<<ccr:abc,base64,4.5KB>>` → `abc`).
- **Re-compression loop guard**: retrieved originals travel back through
the proxy on the next request and get re-compressed into a fresh marker,
looping forever. README documents
`HEADROOM_EXCLUDE_TOOLS=read_file,headroom_retrieve` as the fix (Hermes
tool names don't match `DEFAULT_EXCLUDE_TOOLS`, which targets Claude
Code's `Read`/`Grep`/...).
- **Actionable failure modes**: 404 (TTL expired / proxy restarted) and
connection-refused both return guidance to re-run the original command
rather than retry.

## Relationship to existing PRs

Complementary to #707 / #556 (`headroom wrap hermes`, proxy-side): those
launch/route Hermes through the proxy; this gives the agent the
retrieval capability once it's routed. Notably #707 disables CCR tool
injection in Hermes mode precisely because Hermes must register its own
tool — this plugin is that registration.

## Testing

Running in production on macOS (headroom 0.23.0, pipx) and Linux
(0.22.4, systemd) for a day. Verified: fresh-marker retrieval roundtrip,
whole-marker hash normalization (6 input shapes), expired-hash 404
messaging, proxy-down messaging, and end-to-end via live Hermes sessions
(fresh ≥500B `read_file` returns original with the documented exclude
config).

Closes #796

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: akb4q <zhunyunjiang@gmail.com>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 18:43:10 -05:00

183 lines
5.6 KiB
Python

"""Tests for the Hermes headroom_retrieve plugin (plugins/hermes/).
The plugin targets the Hermes Agent runtime, which provides a
``tools.registry`` module. That module does not exist inside the headroom
codebase, so these tests stub it before loading the plugin file directly
via importlib.
"""
from __future__ import annotations
import importlib.util
import json
import sys
import types
from pathlib import Path
from typing import Any
import httpx
import pytest
PLUGIN_PATH = (
Path(__file__).resolve().parent.parent
/ "plugins"
/ "hermes"
/ "headroom_retrieve"
/ "__init__.py"
)
def _load_plugin() -> types.ModuleType:
"""Load the plugin file with a stubbed Hermes ``tools.registry``."""
registry = types.ModuleType("tools.registry")
registry.tool_error = lambda msg: json.dumps({"error": msg}) # type: ignore[attr-defined]
registry.tool_result = lambda data: json.dumps({"result": data}) # type: ignore[attr-defined]
tools_pkg = types.ModuleType("tools")
tools_pkg.registry = registry # type: ignore[attr-defined]
sys.modules.setdefault("tools", tools_pkg)
sys.modules["tools.registry"] = registry
spec = importlib.util.spec_from_file_location("hermes_headroom_retrieve", PLUGIN_PATH)
assert spec is not None and spec.loader is not None
module = importlib.util.module_from_spec(spec)
spec.loader.exec_module(module)
return module
class _FakeResponse:
def __init__(self, status_code: int, payload: dict[str, Any] | None = None) -> None:
self.status_code = status_code
self._payload = payload or {}
self.text = json.dumps(self._payload)
def json(self) -> dict[str, Any]:
return self._payload
@pytest.fixture()
def plugin() -> types.ModuleType:
return _load_plugin()
@pytest.mark.parametrize(
("raw", "expected"),
[
("abc123", "abc123"),
("ccr:abc123", "abc123"),
("<<ccr:abc123>>", "abc123"),
("<<ccr:abc123,base64,4.5KB>>", "abc123"),
("hash=abc123", "abc123"),
(" <<ccr:abc123>> ", "abc123"),
],
)
def test_handler_normalizes_marker_shapes_to_bare_hash(
plugin: types.ModuleType, monkeypatch: pytest.MonkeyPatch, raw: str, expected: str
) -> None:
# Arrange
seen: dict[str, Any] = {}
def fake_post(url: str, json: dict[str, Any], timeout: int) -> _FakeResponse: # noqa: A002
seen["payload"] = json
return _FakeResponse(200, {"original_content": "data", "original_tokens": 1})
monkeypatch.setattr(plugin.httpx, "post", fake_post)
# Act
plugin._handle_headroom_retrieve({"hash": raw})
# Assert
assert seen["payload"]["hash"] == expected
def test_handler_passes_optional_query_through(
plugin: types.ModuleType, monkeypatch: pytest.MonkeyPatch
) -> None:
# Arrange
seen: dict[str, Any] = {}
def fake_post(url: str, json: dict[str, Any], timeout: int) -> _FakeResponse: # noqa: A002
seen["payload"] = json
return _FakeResponse(200, {"original_content": "data"})
monkeypatch.setattr(plugin.httpx, "post", fake_post)
# Act
plugin._handle_headroom_retrieve({"hash": "abc123", "query": "error lines"})
# Assert
assert seen["payload"] == {"hash": "abc123", "query": "error lines"}
def test_handler_returns_original_content_on_200(
plugin: types.ModuleType, monkeypatch: pytest.MonkeyPatch
) -> None:
# Arrange
payload = {"original_content": "full text", "original_tokens": 42, "tool_name": "read_file"}
monkeypatch.setattr(plugin.httpx, "post", lambda *a, **kw: _FakeResponse(200, payload))
# Act
out = json.loads(plugin._handle_headroom_retrieve({"hash": "abc123"}))
# Assert
assert out["result"]["original_content"] == "full text"
assert out["result"]["original_tokens"] == 42
assert out["result"]["tool_name"] == "read_file"
def test_handler_reports_expired_entry_on_404(
plugin: types.ModuleType, monkeypatch: pytest.MonkeyPatch
) -> None:
# Arrange
monkeypatch.setattr(plugin.httpx, "post", lambda *a, **kw: _FakeResponse(404))
# Act
out = json.loads(plugin._handle_headroom_retrieve({"hash": "deadbeef"}))
# Assert: actionable message, not a bare error
assert "expired" in out["error"]
assert "re-run" in out["error"].lower()
def test_handler_reports_unreachable_proxy_on_connection_error(
plugin: types.ModuleType, monkeypatch: pytest.MonkeyPatch
) -> None:
# Arrange
def raise_connect_error(*a: Any, **kw: Any) -> None:
raise httpx.ConnectError("connection refused")
monkeypatch.setattr(plugin.httpx, "post", raise_connect_error)
# Act
out = json.loads(plugin._handle_headroom_retrieve({"hash": "abc123"}))
# Assert
assert "unreachable" in out["error"]
def test_handler_rejects_empty_hash(plugin: types.ModuleType) -> None:
# Act
out = json.loads(plugin._handle_headroom_retrieve({"hash": " "}))
# Assert
assert "required" in out["error"]
def test_register_exposes_tool_with_marker_aware_schema(plugin: types.ModuleType) -> None:
# Arrange
registered: dict[str, Any] = {}
class FakeCtx:
def register_tool(self, **kwargs: Any) -> None:
registered.update(kwargs)
# Act
plugin.register(FakeCtx())
# Assert
assert registered["name"] == "headroom_retrieve"
assert registered["toolset"] == "headroom"
assert registered["schema"]["parameters"]["required"] == ["hash"]
# The description must teach both marker formats so the model recognizes them.
description = registered["schema"]["description"]
assert "<<ccr:" in description
assert "hash=" in description