Commit Graph

295 Commits

Author SHA1 Message Date
ethernet
ab846213d8 test(macos): use supported host marker for desktop handoff 2026-09-24 06:04:54 -04:00
ethernet
1a495c4033 fix(e2e): wait for macOS setup completion before source verification 2026-09-24 05:57:28 -04:00
ethernet
ebf5f3bdfb test: seed real Git in Linux pwsh installer fixture 2026-09-24 05:45:13 -04:00
ethernet
4ffba2c882 test(ci): prepare pinned Git before Windows installer stages 2026-09-24 05:45:13 -04:00
ethernet
dd744286ed fix(install-e2e): follow staged main with explicit source branch 2026-09-24 04:48:34 -04:00
ethernet
f74ae0d862 test: capture PM desktop launches under isolated interpreter 2026-09-24 04:48:34 -04:00
ethernet
46e9f8746f fix: recognize PM source launcher in DMG install driver 2026-09-24 04:48:34 -04:00
ethernet
fb7fe862ef fix: restore pinned Git in each Windows bootstrap stage 2026-09-24 04:42:28 -04:00
ethernet
656a1ace1e fix: explicitly acquire PTY in installer stage handoff fixture 2026-09-24 04:38:23 -04:00
ethernet
cb7b18431a Merge remote-tracking branch 'origin/main' into ethie/pm-clean
# Conflicts:
#	apps/desktop/src/app/settings/connections-registry.tsx
#	scripts/install.ps1
#	scripts/install.sh
#	tests/hermes_cli/test_update_autostash.py
2026-09-24 03:48:31 -04:00
ethernet
0b8aa8bf83 fix: align Python CI contracts with current PM and checkout behavior
Allow read-only merged-tag queries through the live-system guard, route checkpoint rekeying to its real ref-deletion owner, and update stale fixtures to exercise current update and PM boundaries. Fix the shutdown test wait by patching the bound server global.
2026-09-24 03:42:38 -04:00
brooklyn!
c7d2985ae3 fix(install): keep dropped commits behind a rescue ref on the installer reset
Re-running install.sh / install.ps1 over an existing checkout (desktop
bootstrap and its update retry do this) falls back to
`reset --hard origin/<branch>` when a fast-forward fails, with no anchor for
the commits it drops. Park HEAD under refs/hermes-update-backups/, the same
namespace `hermes update` writes and prunes, and print the ref.
2026-09-24 02:40:53 -05:00
brooklyn!
14a8a771de fix(desktop-update): stop launching a Chrome instance for the macOS update shim
Each update started the user's Chrome binary with its own --user-data-dir,
a second instance of the same bundle that the Dock records as a new
recent-app tile. On macOS the outcome now goes through the existing
notification + next-boot result dialog.

Fixes #96374
2026-09-24 02:36:14 -05:00
ethernet
5f78e110e1 test: align Windows launcher and bootstrap fixtures with native behavior 2026-09-24 03:12:29 -04:00
ethernet
ebf127c33d fix: keep source observer read-only and PTY fixture reusable 2026-09-24 03:12:29 -04:00
ethernet
1aeb53a40b fix: align upgrade CI and installer fixture with PM bootstrap 2026-09-24 02:50:25 -04:00
ethernet
e81bc0f545 test(release): require both Docker variants at publish 2026-09-24 02:31:07 -04:00
ethernet
d6106975e9 fix(docker): promote desktop variant from its own release digest 2026-09-24 02:03:59 -04:00
ethernet
f91bd82286 fix: restore catalog Hindsight and harden installers and test guards 2026-09-24 02:03:59 -04:00
ethernet
29c56a27d4 fix: align CI tests and workflows with PM build contracts 2026-09-24 02:03:59 -04:00
ethernet
33754a37e0 fix(pm): use explicit text encodings in touched paths 2026-09-24 01:31:40 -04:00
ethernet
dcd2bca06a fix(desktop): render icons with core runtime dependencies 2026-09-24 01:30:15 -04:00
ethernet
74c365a85a fix(release): check the draft body before the claim; release takes --no-changelog
The stable cut built its draft body after pushing the attempt ref, so a
body over GitHub's 125000-character limit failed with HTTP 422 and
burned the attempt. The body is now built first, and an oversized one is
refused before anything is claimed, naming --no-changelog.

--no-changelog was defined only on the top-level parser, so
`release.py release --no-changelog` was an argparse error and the flag
never reached the cut. The release subcommand now takes it, with a
SUPPRESS default so the top-level spelling is not reset.
2026-09-23 22:24:22 -04:00
ethernet
e0265925f1 fix(release): --no-changelog no longer raises NameError
generate_changelog() defined all_authors and teknium_aliases inside the
'if not no_changelog' block but read them after it. The canary tests
stub generate_changelog, so nothing ran the real path.
2026-09-23 19:56:46 -04:00
ethernet
c0bd183eef fix(release): build stable draft notes from commits, not generate-notes
GitHub's generate-notes lists merged pull requests since the last
published release. A fork merges none, so the stable draft body was only
a "Full Changelog" link, and it lost the HERMES_BUILDS_TABLE marker that
the stable workflow renders the download tables into.

The cut now builds the body with generate_changelog() over the commits
from the published stable commit (or the seed version's tag before the
first publication) to the cut commit.
2026-09-23 19:56:46 -04:00
ethernet
c58744e59e fix(release): link the draft at cut time, not a page that 404s until green
The stable cut already creates the draft on the claim ref before it
dispatches the gate, but the output pointed at releases/tag/<claim> and
then at releases/tag/v<version> "when it is green". GitHub serves a draft
only at an untagged-* URL, so neither link showed it. Operators read that
as "the draft appears after the build".

Take the URL gh release create prints (the release's html_url) and print
it up front, with a note that notes edited during the build survive:
edit_draft_release keeps the body and strips only the warning fence. The
v<version> URL stays, labelled as where the release lives once published.

The canary resume path had the same broken releases/tag/<tag> link; it
now uses the create output or the url field of gh release view.
2026-09-23 19:20:27 -04:00
ethernet
0384a24edc Merge branch 'ethie/release-attempt-refs' into ethie/pm-clean
Conflicts:
- scripts/releases/stamping.py, tests/scripts/test_version_stamping.py:
  took ethie/pm-clean. The release branch's side was only its base's copy
  of "stamping a payload snapshot skips the bootstrap-installer check"
  (8411fdb333, same patch-id as 8d34601f47 here); the install-stamp
  refactor c13ea774e6 supersedes the rest.
- tests/ci/test_stable_release_graph.py: kept pm-clean's release-epoch
  contract (no HERMES_RELEASE_EPOCH on termux-deb, version on docker and
  nix only) and the release branch's per-group receipt wiring.

Semantic conflict: the dispatch log step (6e64e961d8) read
inputs.termux_only, which the jobs input replaced. It reads JOBS now, and a
dispatch that selects only some groups has no release.py replay, as a
termux-only one had none before.
2026-09-23 19:00:44 -04:00
ethernet
babbec1c4c feat(pm): isolate developer test environment from runtime extras 2026-09-23 18:13:38 -04:00
ethernet
9a3fcf9756 fix(install): pass --no-registry to every bootstrap uv python install
install.ps1 already kept uv's bootstrap Python out of the Windows
registry, but setup-hermes.ps1 did not, so every Windows dev checkout
registered that interpreter under HKCU. The flag is Windows-only; the
POSIX installers take it too so every bootstrap issues the same command.
2026-09-23 18:01:43 -04:00
ethernet
7c41603da9 test(install): installer contracts follow the rerun and invocation fixes
- setup/gateway stages run under a real controlling terminal; with none
  (curl | bash, Docker builds) they are skipped rather than failed.
- The repository-failure frame fixture has a commit; a commitless checkout
  is an interrupted clone that gets re-cloned from the network.
- The unmerged-index fixture merges with an explicit identity; CI has no
  git identity, so the merge never started and no conflict existed.
- The ps1 Python stage expects --no-registry on uv python install.
- pm/native_build.py finds PowerShell on the environment's own PATH, as
  pm/shell.py does for bash; allowlisted alongside it.
2026-09-23 17:51:29 -04:00
ethernet
13ebc163a1 ci: fold the PowerShell installer job into the tests-os Windows lanes
installer-tests.yml predates nothing it still owned. Its pytest step
(test_source_launcher_stages.py) is platforms("windows") and already runs in
both tests-os Windows lanes, so every installer PR ran it twice. The
`installer` lane never gated anything on its own either: every path that set
it also sets `python`, which gates tests-os.

The two standalone scripts/tests/*.ps1 suites become one platforms("windows")
pytest file parametrized over Windows PowerShell 5.1 and pwsh 7, so
list_os_marked_tests picks them up with everything else. The `installer` lane
goes away from the classifier, detect-changes, ci.yaml and the
all-checks-pass gate; the classifier contract now pins that install.ps1 and
its suites turn `python` on.
2026-09-23 17:19:29 -04:00
ethernet
eb877f88c5 fix(release): check the held Store submission instead of releasing it
The Partner Center submission API has no call that releases a held
(Manual) submission, and update refuses a committed one, so the release
step's PUT and re-commit could not work. The publication pass now only
reads the submission: a certified one prints a GitHub warning to click
Publish now in Partner Center, one still in certification says what comes
next, a live one is a no-op, and a failed one leaves the run red.

It finds the held submission through pendingApplicationSubmission on the
app, instead of posting a probe submission and scraping an id out of the
409 error. The HTTP runner also sends the request headers it is given:
before, every API call after the token went out without Authorization.
2026-09-23 17:14:46 -04:00
ethernet
20f3b5f38b feat(release): start each install arm from its own receipt
transitions splits into one job per receipt (darwin-arm64, darwin-x64,
win32-bundle), and each packaged install job waits only on its own. The
Mac install arms no longer wait for the other arch or for the smokes.

candidate-manifest moves into stable-release.yml and waits for every
candidate call, so it still runs after every smoke (decision 23). The
smoke results it records are the calls' own results, mapped to the smoke
job names the final manifest requires. publish-bundles and complete read
its digest again, which the per-group split had left unset.

read_manifest resolves its opener per call instead of binding
urllib.request.urlopen as an import-time default, so the process trust
setup applies. The receipt fixtures gain the runner's RUNNER_TEMP and the
baseline's macOS identity.
2026-09-23 17:08:59 -04:00
ethernet
427d4936c2 test: retarget merge-fallout tests at pm-clean's seams; drop tests of retired code
The merges from main kept or added about 45 test files written against the
legacy updater and installer seams that pm-clean replaced. Each failing test
was checked against the current code:

- Deleted, because every test targets code that pm-clean removed or that is
  only reachable from dead or frozen old-updater code:
  update_orphan/handoff_backend_reap, handoff_desktop_rebuild,
  interrupted_recovery (it also launched a real completion against the live
  checkout), update_stale_virtualenv, update_venv_health,
  verify_core_dependencies, lazy_refresh_venv_repair,
  certifi_repair (already dropped in 2f20ceb6f7; the merge resurrected it),
  banner_git_state (covered by test_source_check).
- Retargeted where production reads now:
  - version identity via version_info.get_code_identity
  - update receipts via a ContextVar scope
  - pm.extras / pm.installed_package / pm.ensure_import for matrix,
    computer_use, fal and tirith
  - install hints via pm.install_hint
  - the lock pins in pm/lock.json
  - probe_root for the critical-module probe
- Fixture repairs:
  - git-committed trees for source stamps
  - activate's real `--runtime-only` argument
  - a semver install stamp for requires_hermes gates
  - the Windows gateway restart after a verified update
  - snowflake-length ids that cannot collide with the runner uid
- Collection fix: one platforms() marker per test in gateway_proc_fallback.
2026-09-23 16:55:09 -04:00
ethernet
1038f8479c fix(install): make both installers survive their real invocation paths
Review findings against the pm-clean installers, each reproduced first:

- install.sh: `curl | bash` aborted before main under `set -u` (empty
  BASH_SOURCE). The entry guard falls back to $0.
- install.sh: setup/gateway read stdin, which under `curl | bash` is the
  script itself. They open /dev/tty when a terminal can be opened, and
  otherwise skip with guidance.
- Both: any uv on PATH was trusted. uv 0.6.17 has no `python install
  --no-bin`. A PATH uv now has to run and be at least the pinned version,
  otherwise the pin is staged.
- install.sh: the staged uv went under ~/.hermes/tools even with a custom
  --hermes-home. It now goes to pm's store_root() default,
  $HERMES_HOME/tools.
- Both: when a stash failed, the script logged "overwritten below" and ran
  `reset --hard` anyway. Local work is now parked before checkout, and a
  stash failure stops the install.
- Both: reruns ignored an explicit HERMES_REPO_URL. It now repoints origin.
- Both: --commit had no ancestor guard. The pin must be on the installed
  branch.
- install.sh: the blobless fallback was `--depth 1 --single-branch`, so a
  non-tip --commit could not check out. It now keeps full history with
  blobs fetched on demand.
- Both: ported main's recovery for a commit-less .git (moved aside, #40998)
  and for an unmerged index (reset -q before the stash, #4735). Stashing
  before checkout makes both reachable.
- install.ps1: on Windows PowerShell 5.1, `native 2>$null` / `2>&1` under
  Stop turns stderr into a terminating NativeCommandError, verified on a
  Win11 host. Every native call now goes through Invoke-Native, which
  relaxes the preference only for that call.
- install.ps1: clone publishes from a staging dir, with retries and a
  blobless fallback, and refuses a non-empty destination (mirrors
  install.sh). UV_NO_CONFIG and `--no-registry` are restored. pwsh 7
  HttpRequestException falls back to the mirror, except TLS trust failures.
  tar resolves from System32. A literal CR/LF in the desktop failure
  message is removed.

Deletes six tests that regex-extracted main's legacy install.sh functions
(node, browsers, PATH block, lockfile churn; pm runs `npm ci` whenever a
lockfile exists). The two behaviours still relevant are covered by new
behavioural tests.
2026-09-23 16:28:00 -04:00
ethernet
c98bdb77f5 fix(pm): prepare the Windows ARM64 compiler environment for every source dependency build
cryptography ships no win_arm64 wheel, so every Windows ARM64 venv sync
compiles it from the sdist and needs MSVC, Clang, Rust and static OpenSSL.
Only setup-hermes.ps1 (and so activate.ps1) prepared that environment,
between a `pm install --tools-only` and the real sync. install.ps1,
`hermes update` and repair ran the same sync without it and failed in
openssl-sys.

PM owns the sync, so PM prepares it. pm/native_build.py holds the adapter
(moved from scripts/build/windows_deps.py) plus source_build_environment(),
which prepares only on win32-arm64 when the synced project carries the
provider script. A payload has prebuilt dependencies and needs no compiler.
VenvPackage.apply and build_environment pass the result to uv children
only. It carries the bridged pip index settings, which managed_environment
applies only to the ambient environment. The state root stays the store
parent, so existing vcpkg/OpenSSL builds are reused.

setup-hermes.ps1 collapses to one `pm install`: the tools-only split existed
only for this preparation, and pm install already puts its tools on PATH
before the venv sync (pm/cli.py activate check).

Not yet verified live on Windows ARM64.
2026-09-23 16:07:47 -04:00
ethernet
fd49308813 fix(ci): the install.sh protocol lane verifies without a source stamp
The products stage (source_completion) writes install-stamp.json, and
this lane deliberately runs only prerequisites/repository/config/complete,
so the checkout never has one. The lane now says so with
--no-source-stamp; full-install callers (windows-e2e.ps1) stay strict.
Replayed locally: the four stages leave no stamp, the old invocation
fails exactly like CI, the lane invocation verifies.
2026-09-23 16:05:55 -04:00
ethernet
6aaff62961 fix(install): verify a tagless checkout's commit-only source stamp
The source completion tail stamps baseVersion from the checkout's
reachable release tag, which is null on a PR checkout, and the bootstrap
verifier demanded a non-null baseVersion, so install.sh protocol failed
on every upstream PR. It now requires the stamp and commit == HEAD, the
identity the runtime actually reports.
2026-09-23 15:53:09 -04:00
ethernet
fe894cca9d test(install): served PowerShell scripts carry no UTF-8 BOM
`& ([scriptblock]::Create((irm ...)))` is the documented Windows install
form. Windows PowerShell 5.1 irm keeps a leading BOM as a literal U+FEFF,
so param( is no longer the first statement and the script dies with "The
assignment expression is not valid". The Windows-lane ParseFile check reads
the BOM as an encoding marker and passes, so nothing caught the BOM that
came back with the MSIX rewrite of install.ps1. This check is
host-independent and runs on the Linux lane.

Red on install.ps1 until its BOM is stripped.
2026-09-23 15:46:26 -04:00
ethernet
86f42bf3b6 fix(docker): stamp a commit-only identity when no release tag is reachable
Upstream carries only CalVer tags, which version_from_tag rejects on
purpose, so every PR image build died in "Write install stamp" with
"no reachable release tag". The runtime already reads a tagless source
checkout as base "unknown" plus its commit; the image now records the
same: the workflow admits GITHUB_SHA via --commit, adds version args only
when a release is reachable, and write_install_stamp accepts a missing
base version when the caller supplied the commit (a local tree still
stays unstamped).
2026-09-23 15:44:18 -04:00
ethernet
107af642b2 feat(release): stage one receipt per build group
Stable now calls the desktop bundle workflow once per build group, and
each Mac arch and the Windows bundle assembly stage a <group>-receipt.json
into its attempt archive before the group's smoke runs. The receipts let
the next commit start each install arm from its own group's bytes.

publish-bundles and complete temporarily lose their candidate-manifest
digest source; the next commit moves that job into stable-release.yml and
wires the digest back.
2026-09-23 14:43:26 -04:00
ethernet
525ead7866 fix(release): gate the whole-build pages on one all-jobs switch
builds-pending ran whenever termux_only was false. The jobs input turned
that into 'termux is selected', so a desktop-only run skipped the pending
page and a termux-only run wrote one that builds-table never finalizes.
Admission now emits all-jobs from the same parser, and builds-pending,
builds-table and commit-builds-summary gate on it.
2026-09-23 14:15:07 -04:00
ethernet
0213af511c fix(release): write the stable mac feed during publication 2026-09-23 14:12:38 -04:00
ethernet
04ee0d7166 feat(release): select desktop build jobs per arch with one jobs input
termux_only is replaced by jobs=termux. smoke-win32-universal is removed: the per-arch MSIX smokes cover each arch, and stable's install arms install the msixbundle on both arches.

validate_receipt no longer requires smoke results: receipts are staged right after the bytes and before the smokes run (decision 11), so only the final manifest (validate_candidates) still requires every SMOKE_JOBS result.
2026-09-23 14:11:21 -04:00
ethernet
b16f953f7c fix(pm): re-activate from the shebang only when an input's mtime differs
The _hermes-python prologue compared uv.lock / pyproject.toml / pm/lock.json
against facts.json with `-nt`. facts.json is only rewritten on a real sync,
so a checkout that rewrites an input without changing it left the input
newer forever: every run from an activated shell re-sourced activate
(~370ms instead of ~13ms).

pm now records, after every successful full-closure install (no-op syncs
included), a stamp per input under installs/<key>/inputs carrying the exact
mtime the install was verified against, snapshotted before installing so
an input edited mid-install still reads as stale. The prologue re-activates
when any input's mtime differs from its stamp in either direction (branch
switches can move it backwards), when an input is missing, or when there
are no stamps. It globs the stamp dir, so pm owns the only input list.

Also read pyvenv.cfg as utf-8-sig (footgun lane, same file).
2026-09-23 13:38:54 -04:00
ethernet
8c050ce93c feat(release): hold the Store submission until publish
The green run no longer lets the Store go live on its own: stable-store
deletes any in-flight submission, uploads the verified msixbundle as a
draft (msstore publish --noCommit), sets targetPublishMode to Manual via
msstore submission get/update, and commits with msstore submission
publish. The publication pass releases it from sequencer production_advance
(after the feeds and Docker aliases move) through the Partner Center
submission REST API with the same MS_STORE_* credentials: it finds the
in-flight submission, and rewrites it with targetPublishMode Immediate and
commits, so a certified (status Release) submission goes live now and one
still in certification goes live when certification passes. Both calls act
on the submission's current state and are safe to rerun; a failed Store
call leaves the run red. The Store product id is optional in the
publication environment, so runs without Store credentials skip the step.
2026-09-23 13:29:06 -04:00
ethernet
6e64e961d8 fix(ci): better logs on bundle builds 2026-09-23 13:17:49 -04:00
ethernet
c0100f5f1c feat(release): validate one receipt without the others
Each install arm starts from its own receipt, so stable must accept a
manifest that covers only one arch or the Windows bundle. The per-row
checks move into one helper shared by validate_candidates and the new
validate_receipt, and the per-target transition logic into one helper
shared by plan_transitions and plan_receipt_transitions. The full
manifest still has to cover every desktop target.
2026-09-23 13:13:36 -04:00
ethernet
3f2e40f07d feat(release): channel records name the attempt archive
Stable archives live under the attempt ref, but channel records only
carried releaseTag, so the protected prefix check rejected the bytes the
pipeline actually writes. An optional archiveRef on the request names the
attempt archive; validators and readers use it for the releases/tag/
prefix and fall back to releaseTag, which fails closed for stable
records without it. Canary records never write the field.
2026-09-23 12:58:33 -04:00
ethernet
b37f37b692 fix(release): send the stripped draft notes as a raw string
gh api --field reads a value that starts with @ as a file and converts
true, false and integers. Generated notes can open with an @mention, so
the body goes through --raw-field like the other string fields.
2026-09-23 12:57:50 -04:00