Skip to content

fix(hermes): guard pruner flags against missing parameters and unhandled shifts - #6794

Open
vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/hermes-slash-worker-option-args
Open

vaibhavsrv wants to merge 1 commit into
Osmantic:public-betafrom
vaibhavsrv:fix/hermes-slash-worker-option-args

Conversation

@vaibhavsrv

Copy link
Copy Markdown
Contributor

Why this matters

In ods/scripts/prune-hermes-slash-workers.sh, option flags requiring values (--max-count, --max-age-seconds, --container) read $2 and execute shift 2 under set -euo pipefail without checking if an argument was provided. Passing any of these options as the trailing argument crashes the script with an unhandled exit code 1 and completely empty standard error, giving operators no diagnostic feedback. Furthermore, passing an option without a value immediately before another flag (e.g., --container --force or --max-count --dry-run) causes the parser to swallow the subsequent flag into the option parameter; in the --container --force case, this runs Docker commands against an invalid container name, suppresses --force, prints an unrecognized option warning from grep, and emits a false-positive [PASS] no Hermes slash workers found with exit code 0.

This change introduces pre-shift parameter presence and option-flag validation across --max-count, --max-age-seconds, and --container. If an argument is missing, empty, or starts with a hyphen indicating another option flag, the script outputs a clear diagnostic ([FAIL] <option> requires an argument), displays usage information, and exits cleanly with usage status 1. Valid arguments, dry-run mode, and worker process filtering contracts remain untouched.

Validation

  • Baseline reproduction: Running bash ods/scripts/prune-hermes-slash-workers.sh --container on unpatched code terminated with unhandled status 1 and empty stderr; passing bash ods/scripts/prune-hermes-slash-workers.sh --container --force silently swallowed --force into CONTAINER and produced a false-positive exit 0.
  • Post-fix verification: Running python3 ods/tests/test_prune_hermes_slash_workers_options.py confirms that missing trailing options, empty argument values, and option flag hijacking are rejected with exit code 1 and informative diagnostics, while valid arguments dispatch cleanly.
  • Telemetry statement: "Hermes worker suites: 19 passed (15 existing behavioral, 4 options regression). New-test PyCompile, ShellCheck, and diff checks pass; new regressions wired into Linux CI."

Overlap check

Risk / AI disclosure

AI-assisted investigation, implementation and CLI regressions. This strengthens a CLI check, not runtime admission. Independent human review and platform/runtime qualification remain gates. No running configuration, deployment or upstream merge changed.

Follow-up integration evidence

Composed with #6770 at 6c455ba without conflicts. Production and test diffs passed together; update dry-run checks remain intact.
Backlog composition was local-only (production/test diffs, excluding workflow/Makefile wiring); it is not an upstream merge or independent human approval. Declared live-review gates remain open.

@vaibhavsrv vaibhavsrv changed the title fix(hermes): reject missing option arguments in slash worker pruner fix(hermes): guard pruner flags against missing parameters and unhandled shifts Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant