hermes_cli.runtime_paths (venv generations, selection, activation) moves to
pm.environments, and gains venv_bin_dir / venv_python / project_python. Every
in-tree caller asks pm for an interpreter now; pm no longer reaches back into
hermes_cli for its own environment layout (pm.packages, pm.extras, pm.ensure,
pm.paths imported hermes_cli.runtime_paths). The three open-coded
"Scripts/python.exe or bin/python" ladders in pm collapse onto venv_python.
hermes_constants.venv_python_path / venv_bin_dir and hermes_cli.runtime_paths
stay as frozen-updater-surface shims only (tests/compat/old_updater_surface.json).
To keep the boot path light, pm/__init__ resolves its facade lazily (PEP 562)
and pm.registry loads the built-in package definitions on first read instead of
at import: `import hermes_bootstrap` now loads pm + pm.environments only (25ms,
was 37ms with the eager facade dragging in the downloader). The stripped-payload
fixtures that ship only pre-import files keep working for the same reason.
Also restores two frozen-surface re-exports the F401 sweep dropped
(banner._github_compare_behind, cua_backend.resolve_cua_driver_cmd).
The PATH shim failed after a *successful* app-driven upgrade:
hermes: dependency environment has no site-packages:
.../environments/27eb6e8b.../venv/lib/python3.11/site-packages; run `hermes pm repair`
PM had just built that environment with CPython 3.14.7 (uv: "Using CPython
3.14.7", "Installed 104 packages"), while the shim ran 3.11 -- so
site_packages() composed lib/python3.11/... inside a 3.14 venv, found no tree,
and activate_dependencies() raised, since a published generation makes a missing
tree fatal (it is only tolerated when the runtime-facts file is absent).
An upgrade can legitimately rebuild the dependency environment with a different
Python than the launcher that imports it, so the tree must be dated from the venv
itself: pyvenv.cfg's `version`, falling back to the lib/python* directory, and
only then to this interpreter (Windows keeps Lib/site-packages). Verified: the
old formula names lib/python3.14/site-packages for a 3.9 venv (absent);
venv_python_version is host-independent and the file is 7/7 green, red on base.
Dependency acquisition during packaging left native wheels and packager
inputs outside the pre-build cache save. Compose PM and existing providers
into a preparation phase, then require builds to consume admitted inputs.
Share native preparation with PM Bundle. Keep path-bound environments and
signing outputs separate from reusable caches. Use read-only cache tokens
for commit builds and preserve the one-command local build path.
Verify pinned tools through PM, probe PTYs under the prepared Electron,
and supply dmgbuild through a build-only PM package. Resolve bundled tool
stores from their payload manifest so relocation preserves discovery.
Validation: focused Python and JS tests, checkJs, Ruff, Windows checks,
anti-slop, cache relocation, and network-denied Linux AppImage builds.
Relocated runtime smoke passed with NixOS host libraries supplied.
Native Windows/macOS signing and live GitHub cache behavior remain untested.