15 Commits

Author SHA1 Message Date
ethernet
f0ae9e0568 test: copy the whole scripts/releases package into source-tree fixtures
dc11e3b3bc made scripts/releases/versioning.py import the new sibling
scripts/releases/semver.py. Three fixtures hand-copy a file list of that
package into a temp tree, so importing versioning there now dies with
`ModuleNotFoundError: No module named 'scripts.releases.semver'`
(JS & TS checks: channel-build-version.test.ts MSIX manifest case; the
same import chain runs in test_source_build_env.py and
test_commit_stamp_identity.py via distance -> versioning).

Copy the package as a tree, like the fixtures already do for pm/, so the
next intra-package import cannot silently break them again.
2026-09-24 16:17:35 -04:00
ethernet
c13ea774e6 refactor: make install-stamp.json the single runtime version identity
Runtime identity resolved through hermes_cli.__version__ (a static 0.0.0
on source installs, rewritten by release stamping) leaked v0.0.0 into
About, /api/health, User-Agents, and plugin compat, and source updates
showed "couldn't reach update server" because identity and channel
authority disagreed with the checkout.

Now: get_version_info() resolves install stamp -> live git -> unknown,
never pyproject metadata, never a package constant. Source checkouts
derive identity from their reachable release tag; the completion tail of
every successful install/update/historical takeover atomically rewrites
install-stamp.json with that identity; a stale source stamp whose commit
no longer matches HEAD defers to live git. ACP/TUI use derived_version
for display and base_version for protocol fields; all ~44 runtime
__version__ consumers migrated; hermes_cli.__version__ and generated
_version.py are gone; release stamping only touches the native manifests
external builders consume (nix/tauri/cargo) and passes release identity
straight into write_install_stamp.py; pyproject.toml stays inert 0.0.0.
Desktop no longer synthesizes a competing install-stamp.json: the
checkout owns its stamp, and desktop-bootstrap classification keys on
the bootstrap-complete marker. verify-bootstrap-version-stamp.py now
cross-checks the checkout's stamp (baseVersion + commit == HEAD).

Validation: 31-file focused suite green (version identity, stamping,
adoption, providers, gateway, acp/tui runtime identity, api server via
extras env, release graph); desktop tsc + 25 vitest green; real-repo
probe: base=unknown derived=git.0635606.dirty source=git on this
checkout; clean-env imports resolve entirely from this tree; windows
footgun + compat-pointer scans clean.
2026-09-23 11:41:01 -04:00
ethernet
7e9d4239c6 fix(release): preserve reachable version identity in CI 2026-09-22 12:00:06 -04:00
ethernet
77fad51181 test: pwsh probe reports the launcher's PE subsystem and the base interpreter's exit before the stamp step
Under both pwsh 7.6 and Windows PowerShell 5.1 on the lane `& python.exe ...` returns with
$LASTEXITCODE unset and no side effect while Start-Process sees a real exit code — the shape
PowerShell gives a non-console image. Narrate what the venv launcher is and whether the base
interpreter it points at behaves, so the next red run names the cause.
2026-09-21 11:47:17 -04:00
ethernet
f78f2b14f9 fix: round-1 CI backlog (Windows lane probe, obligation test, generated contract)
- test_source_build_env: the pwsh probe dumps the env through a script file, not
  `-c 'import json, ...'` — pwsh 7.6 on the Windows lane re-quotes native argv and the
  venv launcher receives a truncated -c body (`import` → SyntaxError, no stamp). Drop the
  spawn-path diagnostics that answered that question. On nt prefer Windows PowerShell,
  the shell install-e2e-windows-run.yml actually drives the asset with.
- test_update_fleet_completion: the obligation is host-scoped now; assert through
  `_fleet_restart_obligation_armed()`, not the legacy per-home marker path.
- gateway-contract.generated.ts: regenerated (main's `npm run fix` sweep stripped the
  eslint-disable line the generator emits).
2026-09-21 11:36:13 -04:00
ethernet
7b61a92e28 test: pwsh probe compares native call, Start-Process and cmd.exe for the python child
On the Windows lane `& python ...` under pwsh 7.6.5 returns $?=True with $LASTEXITCODE unset and
no side effect: the child is not started. Exercise the three spawn paths so the next run says which
of them reach the interpreter.
2026-09-21 09:57:52 -04:00
ethernet
00d691ccaa test: pwsh probe reports whether the python child even starts
The Windows lane runs the scriptblock (every narration line prints) but $LASTEXITCODE stays
unset after `& $env:PROBE_PYTHON`: the native call itself produced nothing. Log path existence,
run a bare child first, and print $? and the stamp presence right after the call.
2026-09-21 09:24:12 -04:00
ethernet
744ffcfe36 test: launchd survive-collection execs the osascript child; pwsh probe traps and narrates
- test_source_launcher_publication: launchd ProgramArguments are `/usr/bin/osascript -e` since #71206;
  on Linux exec the child argv the script would spawn (minus the shell redirection tail).
- test_source_build_env: pwsh 7.6.5 on the Windows lane exits 0 without running the child; the probe
  now traps any terminating error (exit 97 + stack) and narrates each step to stderr.
2026-09-21 08:52:49 -04:00
ethernet
61ebb55e7e test: source-build-env probe reports the PowerShell it drove
The Windows lane runs the -File probe to exit 0 with no stamp and no output. Log the shell,
PowerShell version and inputs to stderr, close stdin, and include the return code so the next
red run explains itself.
2026-09-21 08:10:09 -04:00
ethernet
d0c91f47f1 fix: round-10 — PowerShell probe via -File; enable-grant test follows #64228; stage-hold fixture requests access
- test_source_build_env: Windows PowerShell 5.1 runs a multi-line -Command argument only up to
  the first line break and exits 0; the probe is a -File script now (the child never ran, hence
  the empty stamp).
- test_plugins_cmd_enable_disable_nested: `enable` no longer prompts for or writes an undeclared
  allow_tool_override grant (09bcf17801); the test asserts that and uses --no-allow-tool-override
  for the persisted False.
- test_stage_only: the directory hold opens with FILE_LIST_DIRECTORY, not access 0 — a
  zero-access handle does not oppose the rename the repin performs.
2026-09-21 07:31:22 -04:00
ethernet
9ee4397408 fix: round-9 Windows lane — retry argv keeps --force; mint fixture carries venv_sync; stamp probe reports the child
- desktop-update/windows.ps1: the legacy-install retry re-sends the identical request
  (--force included); the contract test compares both attempts.
- test_mint_launchers: the bootstrap imports hermes_cli.venv_sync/steward before
  prepare_launch can return early for a fixture repo; copy them into the tree.
- test_source_build_env: when the pwsh child writes no stamp, fail with the child's
  stdout/stderr instead of a bare FileNotFoundError (the Windows lane hides the cause).
2026-09-21 06:48:59 -04:00
ethernet
925c08ceca fix: CI python-tests backlog — no import-time dependency syncs, CI-shaped test fixtures
Production:
- agent/bedrock_adapter.py, agent/vertex_adapter.py: pm.ensure_import ran at
  module import. In any process that imports these modules without a committed
  PM selection (CI's build_environment test venv, a fresh checkout) that sync
  rebuilt the dependency environment mid-process and replaced sys.path with a
  generation missing the caller's own packages (anthropic, aiohttp vanished).
  The extra is now ensured at first client build / credential request.
- plugins/platforms/matrix/adapter.py: a complete install needs no
  ensure_and_bind round trip; only a partial one syncs.
- tools/browser_tool.py: drop the facade's duplicate warm_agent_browser_npx_cache
  shim; the compat pointer already resolves to browser_tool_install.

Test harness:
- tests/home_io_guard.py: PATH-entry probes (shutil.which) and the running
  interpreter's own installation (stdlib reads, realpath ancestry, fixture
  symlinks into it) are not Hermes state; a patched Path.expanduser must not
  crash the guard. run_tests.sh no longer filters PATH — the guard owns it.
- tests/tui_gateway/conftest.py: import hermes_bootstrap before any file opens
  a MagicMock hermes_constants window (6 files exited the process at boot).
- tests/hermes_cli/conftest.py probe_root: scratch checkouts the import guard
  probes need hermes_bootstrap.py (the launcher imports it).
- tests/pm/_fixtures.py stage_host_python: a copied relocatable python needs
  its stdlib beside it (No module named 'encodings' on CI).
- tests/install/e2e-assets/smoke-env.mjs: dependency-free env shaping so the
  source-build-env probe runs under bare node (main deleted the Playwright
  entry it was imported through).
- adapt main's new tests to branch seams (model_metadata_http, launch
  completion tail, CI toolchain exports uv after python, source_launch
  hermes_cli stub, systemd_notify single marker).
2026-09-20 11:47:06 -04:00
ethernet
2eec0d9b64 fix(install): the shared completion tail runs from a source slice
- build_update_products builds only the frontends the checkout carries; a
  python-only slice (the installer's acceptance fixture) publishes commands
  and runs maintenance without asking PM for node.
- stderr_timestamp.py is a launcher boot file copied into published
  commands; it inlines the EX_CONFIG code instead of importing gateway.restart.
- Tests: the stamp-writer slice gains hermes_cli/release_channels.py and
  pm/paths.py (the modules update_channel now imports); the source-launch
  fixture records the source_completion hand-off (--finish-update) instead
  of building products; the stdlib recovery probe blocks PM's engine
  modules, not the pm.environments boot leaf; the memory-provider restart
  test selects a generation the running interpreter has not activated;
  the warm-path installer stage is `products`.
2026-09-19 02:53:58 -04:00
ethernet
bbec973514 refactor(pm): pm owns the dependency-environment layout and interpreter paths
hermes_cli.runtime_paths (venv generations, selection, activation) moves to
pm.environments, and gains venv_bin_dir / venv_python / project_python. Every
in-tree caller asks pm for an interpreter now; pm no longer reaches back into
hermes_cli for its own environment layout (pm.packages, pm.extras, pm.ensure,
pm.paths imported hermes_cli.runtime_paths). The three open-coded
"Scripts/python.exe or bin/python" ladders in pm collapse onto venv_python.

hermes_constants.venv_python_path / venv_bin_dir and hermes_cli.runtime_paths
stay as frozen-updater-surface shims only (tests/compat/old_updater_surface.json).

To keep the boot path light, pm/__init__ resolves its facade lazily (PEP 562)
and pm.registry loads the built-in package definitions on first read instead of
at import: `import hermes_bootstrap` now loads pm + pm.environments only (25ms,
was 37ms with the eager facade dragging in the downloader). The stripped-payload
fixtures that ship only pre-import files keep working for the same reason.

Also restores two frozen-surface re-exports the F401 sweep dropped
(banner._github_compare_behind, cua_backend.resolve_cua_driver_cmd).
2026-09-18 20:02:36 -04:00
ethernet
bf75bc2516 feat(ci): require desktop chat after bundle and install builds
Share the real composer, provider-witness and completed-reply check across
post-build bundle smoke and desktop-bearing install/update checkpoints.
Keep native automatic-relaunch proof separate from post-update chat.

Download receipt-bound artifacts without release credentials and install
DMG, ZIP, MSIX and universal MSIXBUNDLE on each native architecture.
Split Windows assembly from feed publication; publish tested bytes only.
Bind candidate smoke results into the manifest used by stable promotion.

Verify historical/source provenance without assuming a version IPC commit,
strip CI identity from source build children, and use the actual Electron
PID rather than Playwright's Windows launcher wrapper.

Validation: real Linux Electron chat and sequential OLD/NEW source smoke
with preserved history; 145 targeted Python tests and 14 JS tests passed;
TypeScript, shell/PowerShell parsing and workflow checks passed.
Native macOS/Windows deployment and historical upgrades need Actions proof.
2026-09-13 19:57:38 -04:00