Merge remote-tracking branch 'origin/main' into ethie/pm-clean

Resolved toward the branch: PM provisions uv/python (main's install.ps1 uv-shim
salvage + its test and workflow steps dropped), the shim re-exec stays retired,
package.json carries no electron-builder block (afterExtract identity stamp wired
into electron-builder.config.cjs instead; after-pack.mjs keeps signing only),
Desktop workspace-deps helpers stay retired. Main's scratch-dir bootstrap
(export_scratch_tmp_env) is taken and re-run after profile resolution.
This commit is contained in:
ethernet
2026-09-19 22:57:07 -04:00
698 changed files with 18472 additions and 2011 deletions

View File

@@ -11,7 +11,7 @@ gh run view <RUN_ID> --log-failed
# With curl — download and extract
curl -sL -H "Authorization: token $GITHUB_TOKEN" \
https://api.github.com/repos/$GH_OWNER/$GH_REPO/actions/runs/<RUN_ID>/logs \
-o /tmp/ci-logs.zip && unzip -o /tmp/ci-logs.zip -d /tmp/ci-logs
-o ~/.hermes/cache/scratch/ci-logs.zip && unzip -o ~/.hermes/cache/scratch/ci-logs.zip -d ~/.hermes/cache/scratch/ci-logs
```
## Common Failure Patterns

View File

@@ -232,8 +232,8 @@ RUN_ID=<run_id>
curl -s -L \
-H "Authorization: token $GITHUB_TOKEN" \
https://api.github.com/repos/$OWNER/$REPO/actions/runs/$RUN_ID/logs \
-o /tmp/ci-logs.zip
cd /tmp && unzip -o ci-logs.zip -d ci-logs && cat ci-logs/*.txt
-o ~/.hermes/cache/scratch/ci-logs.zip
cd ~/.hermes/cache/scratch && unzip -o ci-logs.zip -d ci-logs && cat ci-logs/*.txt
```
### Step 2: Fix and Push

View File

@@ -432,8 +432,8 @@ RUN_ID=<run_id>
curl -s -L \
-H "Authorization: token $GITHUB_TOKEN" \
https://api.github.com/repos/$OWNER/$REPO/actions/runs/$RUN_ID/logs \
-o /tmp/ci-logs.zip
cd /tmp && unzip -o ci-logs.zip -d ci-logs
-o ~/.hermes/cache/scratch/ci-logs.zip
cd ~/.hermes/cache/scratch && unzip -o ci-logs.zip -d ci-logs
# Re-run a failed workflow
curl -s -X POST \

View File

@@ -101,6 +101,7 @@ Bad: `Use when a user asks to monitor named competitors or companies for product
| `osascript`, `defaults`, `pmset` | `[macos]` |
| `apt`/`systemctl`/`/proc` | `[linux]` |
<!-- no-tmp: ok — names the anti-pattern skill authors must avoid -->
POSIX-only signals to search for in `scripts/`: `fcntl`, `termios`, `pty`, `os.fork`, `os.killpg`, `signal.SIGKILL`, `os.kill(pid, 0)` liveness checks, hardcoded `/tmp` `/proc` `/etc`. Default posture: fix cross-platform first (`tempfile.gettempdir()`, `pathlib.Path`, `psutil.pid_exists`); gate narrower only when the dependency is genuinely platform-bound, and say why in `## Pitfalls`.
## Size Limits

View File

@@ -122,10 +122,10 @@ When there is no port, or you must not disturb the user's window:
```bash
cd apps/desktop
HERMES_HOME=/tmp/cdp-probe-home \
HERMES_HOME=$HOME/.hermes/cache/scratch/cdp-probe-home \
HERMES_DESKTOP_DEV_SERVER=http://127.0.0.1:5174 \
HERMES_DESKTOP_CDP_PORT=9333 \
npx electron . --user-data-dir=/tmp/cdp-probe-userdata
npx electron . --user-data-dir=$HOME/.hermes/cache/scratch/cdp-probe-userdata
```
The separate `--user-data-dir` dodges Electron's single-instance lock, so it

View File

@@ -111,7 +111,7 @@ npm i -g chrome-remote-interface # or project-local
node --inspect-brk=9229 target.js &
```
Driver script (save as `/tmp/cdp-debug.js`):
Driver script (save as `~/.hermes/cache/scratch/cdp-debug.js`):
```javascript
const CDP = require('chrome-remote-interface');
@@ -164,14 +164,14 @@ const CDP = require('chrome-remote-interface');
Run it:
```bash
node /tmp/cdp-debug.js
node ~/.hermes/cache/scratch/cdp-debug.js
```
Hermes-specific note: `chrome-remote-interface` is NOT in `ui-tui/package.json`. Install it to a throwaway location if you don't want to dirty the project:
```bash
mkdir -p /tmp/cdp-tools && cd /tmp/cdp-tools && npm i chrome-remote-interface
NODE_PATH=/tmp/cdp-tools/node_modules node /tmp/cdp-debug.js
mkdir -p ~/.hermes/cache/scratch/cdp-tools && cd ~/.hermes/cache/scratch/cdp-tools && npm i chrome-remote-interface
NODE_PATH=~/.hermes/cache/scratch/cdp-tools/node_modules node ~/.hermes/cache/scratch/cdp-debug.js
```
## Debugging Hermes ui-tui
@@ -246,8 +246,8 @@ await client.Profiler.enable();
await client.Profiler.start();
await new Promise(r => setTimeout(r, 5000));
const { profile } = await client.Profiler.stop();
require('fs').writeFileSync('/tmp/cpu.cpuprofile', JSON.stringify(profile));
// Open /tmp/cpu.cpuprofile in Chrome DevTools → Performance tab
require('fs').writeFileSync('~/.hermes/cache/scratch/cpu.cpuprofile', JSON.stringify(profile));
// Open ~/.hermes/cache/scratch/cpu.cpuprofile in Chrome DevTools → Performance tab
```
```javascript
@@ -256,7 +256,7 @@ await client.HeapProfiler.enable();
const chunks = [];
client.HeapProfiler.addHeapSnapshotChunk(({ chunk }) => chunks.push(chunk));
await client.HeapProfiler.takeHeapSnapshot({ reportProgress: false });
require('fs').writeFileSync('/tmp/heap.heapsnapshot', chunks.join(''));
require('fs').writeFileSync('~/.hermes/cache/scratch/heap.heapsnapshot', chunks.join(''));
```
## Common Pitfalls

View File

@@ -213,7 +213,7 @@ The easiest terminal-side DAP client is VS Code CLI or a small script. From insi
**Option 1: `debugpy`'s own CLI REPL** — not an official feature, but a tiny DAP client script:
```python
# /tmp/dap_client.py
# ~/.hermes/cache/scratch/dap_client.py
import socket, json, itertools, time, sys
HOST, PORT = "127.0.0.1", 5678

View File

@@ -1,7 +1,7 @@
---
name: requesting-code-review
description: "Pre-commit review: security scan, quality gates, auto-fix."
version: 2.0.0
version: 2.1.0
author: Hermes Agent (adapted from obra/superpowers + MorAlekss)
license: MIT
platforms: [linux, macos, windows]
@@ -124,6 +124,11 @@ Quick scan before dispatching the reviewer:
## Step 5 — Independent reviewer subagent
**Interactive sessions only.** In a one-shot run (`hermes chat -q`, `--oneshot`, a
benchmark harness) there is no one to hand the verdict to and a fresh subagent re-pays
the whole system prompt plus a repo re-read: skip Steps 5 and 7, apply the Step 4
checklist to the diff yourself, run the tests, and go to Step 8.
Call `delegate_task` directly — it is NOT available inside execute_code or scripts.
The reviewer gets ONLY the diff and static scan results. No shared context with
@@ -193,7 +198,7 @@ Suggestions (non-blocking): [list]
## Step 7 — Auto-fix loop
**Maximum 2 fix-and-reverify cycles.**
**Maximum 2 fix-and-reverify cycles. Interactive sessions only (see Step 5).**
Spawn a THIRD agent context — not you (the implementer), not the reviewer.
It fixes ONLY the reported issues: