From 9c80d20f8bdfffa6b052a188481a050b76497102 Mon Sep 17 00:00:00 2001 From: ethernet Date: Fri, 4 Sep 2026 02:08:39 -0400 Subject: [PATCH] docs: fix stale packaging/SSL/PHOTON references - desktop.md: dist:win is MSIX-only, not NSIS+MSI - BUILDING.md: sign-nested-chromium is LIVE (after-pack.mjs wires it), not dead - pyproject: lazy_deps.py comment -> pm - photon docs: drop dead PHOTON_NODE_BIN rows (adapter is pm-store-first); restore PHOTON_MENTION_PATTERNS row my earlier edit wrongly removed - urllib_security/models docstrings: SSL_CERT_FILE/certifi fallback -> platform trust store (post truststore port) --- apps/desktop/BUILDING.md | 7 ++++--- hermes_cli/models.py | 7 ++++--- hermes_cli/urllib_security.py | 3 ++- pyproject.toml | 2 +- website/docs/reference/environment-variables.md | 1 - website/docs/user-guide/desktop.md | 2 +- website/docs/user-guide/messaging/photon.md | 1 - 7 files changed, 12 insertions(+), 11 deletions(-) diff --git a/apps/desktop/BUILDING.md b/apps/desktop/BUILDING.md index 52a260e72e..07b3925b15 100644 --- a/apps/desktop/BUILDING.md +++ b/apps/desktop/BUILDING.md @@ -104,9 +104,10 @@ in sync with app-builder-lib when electron-builder bumps. The macOS build signs and notarizes with electron-builder's builtin notarization when the `APPLE_ID` / `APPLE_APP_SPECIFIC_PASSWORD` / -`APPLE_TEAM_ID` secrets are present. The `sign-nested-chromium` path is dead -(the browser ships in the payload; nested signing is handled by the -electron-builder signing pass). +`APPLE_TEAM_ID` secrets are present. The `sign-nested-chromium` path signs +the payload's nested Chromium Mach-O binaries (see `sign-nested-chromium.mjs`, +wired from `after-pack.mjs`); the outer app bundle is signed by the +electron-builder signing pass. ## Local build diff --git a/hermes_cli/models.py b/hermes_cli/models.py index 42070a455b..0d561d1b6c 100644 --- a/hermes_cli/models.py +++ b/hermes_cli/models.py @@ -51,9 +51,10 @@ def _custom_provider_ssl_context(base_url: str): Mirrors the httpx/requests TLS resolution so the urllib ``/models`` discovery probe honors a provider's ``ssl_ca_cert`` / ``ssl_verify`` - instead of falling back to the process-wide ``SSL_CERT_FILE`` / certifi - bundle. Returns None when no per-provider TLS override applies, so the - caller keeps urllib's default policy for public/unconfigured endpoints. + instead of falling back to the process-wide platform trust store + (``agent.ssl_verify.install_truststore``). Returns None when no + per-provider TLS override applies, so the caller keeps urllib's default + policy for public/unconfigured endpoints. """ if not base_url: return None diff --git a/hermes_cli/urllib_security.py b/hermes_cli/urllib_security.py index 6ab076ce08..147d9cb3fe 100644 --- a/hermes_cli/urllib_security.py +++ b/hermes_cli/urllib_security.py @@ -164,7 +164,8 @@ def open_credentialed_url( ``ssl_context`` (an ``ssl.SSLContext``) overrides the HTTPS handler's TLS policy for this request only. It is used to honor a custom provider's ``ssl_ca_cert`` / ``ssl_verify`` on the ``/models`` discovery path, which - otherwise falls back to the process-wide ``SSL_CERT_FILE`` / certifi bundle. + otherwise falls back to the process-wide platform trust store + (``agent.ssl_verify.install_truststore``). """ if opener_factory is None: opener = _secure_opener_from_installed_policy( diff --git a/pyproject.toml b/pyproject.toml index 1ded38470d..076f34c50a 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -359,7 +359,7 @@ acp = ["agent-client-protocol==0.9.0"] # 2.4.6 release (Mini Shai-Hulud worm); 2.4.6 was removed from PyPI and the # project is serving clean releases again (2.4.7 2026-05-25, 2.4.8 2026-05-28). # Like other opt-in TTS/STT backends, this is lazy-installed via -# tools/lazy_deps.py (stt.mistral / tts.mistral) at first use — deliberately +# pm (stt.mistral / tts.mistral) at first use — deliberately # NOT re-added to [all] so a future quarantined release can't break fresh # installs (see [all] policy comment below). mistral = ["mistralai==2.4.8"] diff --git a/website/docs/reference/environment-variables.md b/website/docs/reference/environment-variables.md index d79bda4892..4c87009a64 100644 --- a/website/docs/reference/environment-variables.md +++ b/website/docs/reference/environment-variables.md @@ -701,7 +701,6 @@ Connect Hermes to [Photon](https://photon.codes/) / Spectrum (iMessage and other | `PHOTON_TELEMETRY` | Enable Spectrum SDK telemetry in the sidecar (`true`/`false`, default `false`; toggle with `hermes photon telemetry on|off`). | | `PHOTON_SIDECAR_PORT` | Loopback port for the Node sidecar control + inbound channel (default `8789`). | | `PHOTON_SIDECAR_AUTOSTART` | Spawn the Node sidecar on connect (`true`/`false`, default `true`). | -| `PHOTON_NODE_BIN` | Path to the node binary (default: `shutil.which('node')`). | | `PHOTON_DASHBOARD_HOST` | Photon Dashboard API host (default `https://app.photon.codes`). | | `PHOTON_SPECTRUM_HOST` | Photon Spectrum API host (default `https://spectrum.photon.codes`). | diff --git a/website/docs/user-guide/desktop.md b/website/docs/user-guide/desktop.md index b1b81df9c4..09cd4b3f11 100644 --- a/website/docs/user-guide/desktop.md +++ b/website/docs/user-guide/desktop.md @@ -532,7 +532,7 @@ Build installers: ```bash npm run dist:mac # DMG + zip -npm run dist:win # NSIS + MSI +npm run dist:win # MSIX npm run dist:linux # AppImage + deb + rpm npm run pack # unpacked app under release/ (no installer) ``` diff --git a/website/docs/user-guide/messaging/photon.md b/website/docs/user-guide/messaging/photon.md index 04e79d5d44..39184922c8 100644 --- a/website/docs/user-guide/messaging/photon.md +++ b/website/docs/user-guide/messaging/photon.md @@ -241,7 +241,6 @@ Common issues: | `PHOTON_PROJECT_SECRET` | from `.env` | Project secret; set by setup | | `PHOTON_SIDECAR_PORT` | `8789` | Loopback port for the sidecar control + inbound channel | | `PHOTON_SIDECAR_AUTOSTART`| `true` | Whether the adapter spawns the sidecar | -| `PHOTON_NODE_BIN` | `which node` | Override the Node binary path | | `PHOTON_HOME_CHANNEL` | (unset) | Default space id for cron / notifications | | `PHOTON_HOME_CHANNEL_NAME`| (unset) | Human label for the home channel | | `PHOTON_ALLOWED_USERS` | (unset) | Comma-separated E.164 allowlist |