docs: fix stale packaging/SSL/PHOTON references

- desktop.md: dist:win is MSIX-only, not NSIS+MSI
- BUILDING.md: sign-nested-chromium is LIVE (after-pack.mjs wires it), not dead
- pyproject: lazy_deps.py comment -> pm
- photon docs: drop dead PHOTON_NODE_BIN rows (adapter is pm-store-first);
  restore PHOTON_MENTION_PATTERNS row my earlier edit wrongly removed
- urllib_security/models docstrings: SSL_CERT_FILE/certifi fallback ->
  platform trust store (post truststore port)
This commit is contained in:
ethernet
2026-09-04 02:08:39 -04:00
parent fdafef44a5
commit 9c80d20f8b
7 changed files with 12 additions and 11 deletions

View File

@@ -104,9 +104,10 @@ in sync with app-builder-lib when electron-builder bumps.
The macOS build signs and notarizes with electron-builder's builtin
notarization when the `APPLE_ID` / `APPLE_APP_SPECIFIC_PASSWORD` /
`APPLE_TEAM_ID` secrets are present. The `sign-nested-chromium` path is dead
(the browser ships in the payload; nested signing is handled by the
electron-builder signing pass).
`APPLE_TEAM_ID` secrets are present. The `sign-nested-chromium` path signs
the payload's nested Chromium Mach-O binaries (see `sign-nested-chromium.mjs`,
wired from `after-pack.mjs`); the outer app bundle is signed by the
electron-builder signing pass.
## Local build

View File

@@ -51,9 +51,10 @@ def _custom_provider_ssl_context(base_url: str):
Mirrors the httpx/requests TLS resolution so the urllib ``/models``
discovery probe honors a provider's ``ssl_ca_cert`` / ``ssl_verify``
instead of falling back to the process-wide ``SSL_CERT_FILE`` / certifi
bundle. Returns None when no per-provider TLS override applies, so the
caller keeps urllib's default policy for public/unconfigured endpoints.
instead of falling back to the process-wide platform trust store
(``agent.ssl_verify.install_truststore``). Returns None when no
per-provider TLS override applies, so the caller keeps urllib's default
policy for public/unconfigured endpoints.
"""
if not base_url:
return None

View File

@@ -164,7 +164,8 @@ def open_credentialed_url(
``ssl_context`` (an ``ssl.SSLContext``) overrides the HTTPS handler's TLS
policy for this request only. It is used to honor a custom provider's
``ssl_ca_cert`` / ``ssl_verify`` on the ``/models`` discovery path, which
otherwise falls back to the process-wide ``SSL_CERT_FILE`` / certifi bundle.
otherwise falls back to the process-wide platform trust store
(``agent.ssl_verify.install_truststore``).
"""
if opener_factory is None:
opener = _secure_opener_from_installed_policy(

View File

@@ -359,7 +359,7 @@ acp = ["agent-client-protocol==0.9.0"]
# 2.4.6 release (Mini Shai-Hulud worm); 2.4.6 was removed from PyPI and the
# project is serving clean releases again (2.4.7 2026-05-25, 2.4.8 2026-05-28).
# Like other opt-in TTS/STT backends, this is lazy-installed via
# tools/lazy_deps.py (stt.mistral / tts.mistral) at first use — deliberately
# pm (stt.mistral / tts.mistral) at first use — deliberately
# NOT re-added to [all] so a future quarantined release can't break fresh
# installs (see [all] policy comment below).
mistral = ["mistralai==2.4.8"]

View File

@@ -701,7 +701,6 @@ Connect Hermes to [Photon](https://photon.codes/) / Spectrum (iMessage and other
| `PHOTON_TELEMETRY` | Enable Spectrum SDK telemetry in the sidecar (`true`/`false`, default `false`; toggle with `hermes photon telemetry on|off`). |
| `PHOTON_SIDECAR_PORT` | Loopback port for the Node sidecar control + inbound channel (default `8789`). |
| `PHOTON_SIDECAR_AUTOSTART` | Spawn the Node sidecar on connect (`true`/`false`, default `true`). |
| `PHOTON_NODE_BIN` | Path to the node binary (default: `shutil.which('node')`). |
| `PHOTON_DASHBOARD_HOST` | Photon Dashboard API host (default `https://app.photon.codes`). |
| `PHOTON_SPECTRUM_HOST` | Photon Spectrum API host (default `https://spectrum.photon.codes`). |

View File

@@ -532,7 +532,7 @@ Build installers:
```bash
npm run dist:mac # DMG + zip
npm run dist:win # NSIS + MSI
npm run dist:win # MSIX
npm run dist:linux # AppImage + deb + rpm
npm run pack # unpacked app under release/ (no installer)
```

View File

@@ -241,7 +241,6 @@ Common issues:
| `PHOTON_PROJECT_SECRET` | from `.env` | Project secret; set by setup |
| `PHOTON_SIDECAR_PORT` | `8789` | Loopback port for the sidecar control + inbound channel |
| `PHOTON_SIDECAR_AUTOSTART`| `true` | Whether the adapter spawns the sidecar |
| `PHOTON_NODE_BIN` | `which node` | Override the Node binary path |
| `PHOTON_HOME_CHANNEL` | (unset) | Default space id for cron / notifications |
| `PHOTON_HOME_CHANNEL_NAME`| (unset) | Human label for the home channel |
| `PHOTON_ALLOWED_USERS` | (unset) | Comma-separated E.164 allowlist |