dc11e3b3bc made scripts/releases/versioning.py import the new sibling
scripts/releases/semver.py. Three fixtures hand-copy a file list of that
package into a temp tree, so importing versioning there now dies with
`ModuleNotFoundError: No module named 'scripts.releases.semver'`
(JS & TS checks: channel-build-version.test.ts MSIX manifest case; the
same import chain runs in test_source_build_env.py and
test_commit_stamp_identity.py via distance -> versioning).
Copy the package as a tree, like the fixtures already do for pm/, so the
next intra-package import cannot silently break them again.
Runtime identity resolved through hermes_cli.__version__ (a static 0.0.0
on source installs, rewritten by release stamping) leaked v0.0.0 into
About, /api/health, User-Agents, and plugin compat, and source updates
showed "couldn't reach update server" because identity and channel
authority disagreed with the checkout.
Now: get_version_info() resolves install stamp -> live git -> unknown,
never pyproject metadata, never a package constant. Source checkouts
derive identity from their reachable release tag; the completion tail of
every successful install/update/historical takeover atomically rewrites
install-stamp.json with that identity; a stale source stamp whose commit
no longer matches HEAD defers to live git. ACP/TUI use derived_version
for display and base_version for protocol fields; all ~44 runtime
__version__ consumers migrated; hermes_cli.__version__ and generated
_version.py are gone; release stamping only touches the native manifests
external builders consume (nix/tauri/cargo) and passes release identity
straight into write_install_stamp.py; pyproject.toml stays inert 0.0.0.
Desktop no longer synthesizes a competing install-stamp.json: the
checkout owns its stamp, and desktop-bootstrap classification keys on
the bootstrap-complete marker. verify-bootstrap-version-stamp.py now
cross-checks the checkout's stamp (baseVersion + commit == HEAD).
Validation: 31-file focused suite green (version identity, stamping,
adoption, providers, gateway, acp/tui runtime identity, api server via
extras env, release graph); desktop tsc + 25 vitest green; real-repo
probe: base=unknown derived=git.0635606.dirty source=git on this
checkout; clean-env imports resolve entirely from this tree; windows
footgun + compat-pointer scans clean.
Under both pwsh 7.6 and Windows PowerShell 5.1 on the lane `& python.exe ...` returns with
$LASTEXITCODE unset and no side effect while Start-Process sees a real exit code — the shape
PowerShell gives a non-console image. Narrate what the venv launcher is and whether the base
interpreter it points at behaves, so the next red run names the cause.
- test_source_build_env: the pwsh probe dumps the env through a script file, not
`-c 'import json, ...'` — pwsh 7.6 on the Windows lane re-quotes native argv and the
venv launcher receives a truncated -c body (`import` → SyntaxError, no stamp). Drop the
spawn-path diagnostics that answered that question. On nt prefer Windows PowerShell,
the shell install-e2e-windows-run.yml actually drives the asset with.
- test_update_fleet_completion: the obligation is host-scoped now; assert through
`_fleet_restart_obligation_armed()`, not the legacy per-home marker path.
- gateway-contract.generated.ts: regenerated (main's `npm run fix` sweep stripped the
eslint-disable line the generator emits).
On the Windows lane `& python ...` under pwsh 7.6.5 returns $?=True with $LASTEXITCODE unset and
no side effect: the child is not started. Exercise the three spawn paths so the next run says which
of them reach the interpreter.
The Windows lane runs the scriptblock (every narration line prints) but $LASTEXITCODE stays
unset after `& $env:PROBE_PYTHON`: the native call itself produced nothing. Log path existence,
run a bare child first, and print $? and the stamp presence right after the call.
- test_source_launcher_publication: launchd ProgramArguments are `/usr/bin/osascript -e` since #71206;
on Linux exec the child argv the script would spawn (minus the shell redirection tail).
- test_source_build_env: pwsh 7.6.5 on the Windows lane exits 0 without running the child; the probe
now traps any terminating error (exit 97 + stack) and narrates each step to stderr.
The Windows lane runs the -File probe to exit 0 with no stamp and no output. Log the shell,
PowerShell version and inputs to stderr, close stdin, and include the return code so the next
red run explains itself.
- test_source_build_env: Windows PowerShell 5.1 runs a multi-line -Command argument only up to
the first line break and exits 0; the probe is a -File script now (the child never ran, hence
the empty stamp).
- test_plugins_cmd_enable_disable_nested: `enable` no longer prompts for or writes an undeclared
allow_tool_override grant (09bcf17801); the test asserts that and uses --no-allow-tool-override
for the persisted False.
- test_stage_only: the directory hold opens with FILE_LIST_DIRECTORY, not access 0 — a
zero-access handle does not oppose the rename the repin performs.
- desktop-update/windows.ps1: the legacy-install retry re-sends the identical request
(--force included); the contract test compares both attempts.
- test_mint_launchers: the bootstrap imports hermes_cli.venv_sync/steward before
prepare_launch can return early for a fixture repo; copy them into the tree.
- test_source_build_env: when the pwsh child writes no stamp, fail with the child's
stdout/stderr instead of a bare FileNotFoundError (the Windows lane hides the cause).
Production:
- agent/bedrock_adapter.py, agent/vertex_adapter.py: pm.ensure_import ran at
module import. In any process that imports these modules without a committed
PM selection (CI's build_environment test venv, a fresh checkout) that sync
rebuilt the dependency environment mid-process and replaced sys.path with a
generation missing the caller's own packages (anthropic, aiohttp vanished).
The extra is now ensured at first client build / credential request.
- plugins/platforms/matrix/adapter.py: a complete install needs no
ensure_and_bind round trip; only a partial one syncs.
- tools/browser_tool.py: drop the facade's duplicate warm_agent_browser_npx_cache
shim; the compat pointer already resolves to browser_tool_install.
Test harness:
- tests/home_io_guard.py: PATH-entry probes (shutil.which) and the running
interpreter's own installation (stdlib reads, realpath ancestry, fixture
symlinks into it) are not Hermes state; a patched Path.expanduser must not
crash the guard. run_tests.sh no longer filters PATH — the guard owns it.
- tests/tui_gateway/conftest.py: import hermes_bootstrap before any file opens
a MagicMock hermes_constants window (6 files exited the process at boot).
- tests/hermes_cli/conftest.py probe_root: scratch checkouts the import guard
probes need hermes_bootstrap.py (the launcher imports it).
- tests/pm/_fixtures.py stage_host_python: a copied relocatable python needs
its stdlib beside it (No module named 'encodings' on CI).
- tests/install/e2e-assets/smoke-env.mjs: dependency-free env shaping so the
source-build-env probe runs under bare node (main deleted the Playwright
entry it was imported through).
- adapt main's new tests to branch seams (model_metadata_http, launch
completion tail, CI toolchain exports uv after python, source_launch
hermes_cli stub, systemd_notify single marker).
- build_update_products builds only the frontends the checkout carries; a
python-only slice (the installer's acceptance fixture) publishes commands
and runs maintenance without asking PM for node.
- stderr_timestamp.py is a launcher boot file copied into published
commands; it inlines the EX_CONFIG code instead of importing gateway.restart.
- Tests: the stamp-writer slice gains hermes_cli/release_channels.py and
pm/paths.py (the modules update_channel now imports); the source-launch
fixture records the source_completion hand-off (--finish-update) instead
of building products; the stdlib recovery probe blocks PM's engine
modules, not the pm.environments boot leaf; the memory-provider restart
test selects a generation the running interpreter has not activated;
the warm-path installer stage is `products`.
hermes_cli.runtime_paths (venv generations, selection, activation) moves to
pm.environments, and gains venv_bin_dir / venv_python / project_python. Every
in-tree caller asks pm for an interpreter now; pm no longer reaches back into
hermes_cli for its own environment layout (pm.packages, pm.extras, pm.ensure,
pm.paths imported hermes_cli.runtime_paths). The three open-coded
"Scripts/python.exe or bin/python" ladders in pm collapse onto venv_python.
hermes_constants.venv_python_path / venv_bin_dir and hermes_cli.runtime_paths
stay as frozen-updater-surface shims only (tests/compat/old_updater_surface.json).
To keep the boot path light, pm/__init__ resolves its facade lazily (PEP 562)
and pm.registry loads the built-in package definitions on first read instead of
at import: `import hermes_bootstrap` now loads pm + pm.environments only (25ms,
was 37ms with the eager facade dragging in the downloader). The stripped-payload
fixtures that ship only pre-import files keep working for the same reason.
Also restores two frozen-surface re-exports the F401 sweep dropped
(banner._github_compare_behind, cua_backend.resolve_cua_driver_cmd).
Share the real composer, provider-witness and completed-reply check across
post-build bundle smoke and desktop-bearing install/update checkpoints.
Keep native automatic-relaunch proof separate from post-update chat.
Download receipt-bound artifacts without release credentials and install
DMG, ZIP, MSIX and universal MSIXBUNDLE on each native architecture.
Split Windows assembly from feed publication; publish tested bytes only.
Bind candidate smoke results into the manifest used by stable promotion.
Verify historical/source provenance without assuming a version IPC commit,
strip CI identity from source build children, and use the actual Electron
PID rather than Playwright's Windows launcher wrapper.
Validation: real Linux Electron chat and sequential OLD/NEW source smoke
with preserved history; 145 targeted Python tests and 14 JS tests passed;
TypeScript, shell/PowerShell parsing and workflow checks passed.
Native macOS/Windows deployment and historical upgrades need Actions proof.