Commit Graph

1003 Commits

Author SHA1 Message Date
teknium1
1086cc691f chore: map actualrat1984 contributor email
The login-only noreply form lacks the id+login shape the attribution gate auto-resolves.
2026-09-16 14:23:20 -07:00
Teknium
c89a1cbc11 chore: map contributor email for attribution check 2026-09-16 14:20:30 -07:00
Teknium
50520d8fd8 chore: map contributor email for attribution check 2026-09-16 14:20:00 -07:00
Teknium
547c3d49fc chore: map contributor email for attribution check 2026-09-16 14:19:07 -07:00
kshitijk4poor
d6e64c4de5 chore: map 33hodl contributor email (#111861 salvage) 2026-09-16 21:15:09 +05:30
kshitij
c6a9134ab1 chore: contributor mapping for djsanchezsuarez (#112598) 2026-09-16 16:04:27 +05:30
teknium1
1b2a75fa27 chore: map dmelkk-secondbrain contributor email 2026-09-15 19:28:32 -07:00
teknium1
ee1bfef857 fix(mcp): NO_PROXY for MCP servers uses the repo matcher; trim tests to two invariants
Follow-up to the salvaged #111796 commit:

- NO_PROXY matching goes through `agent.proxy_bypass.should_bypass_proxy` (the one
  matcher the LLM transport and the gateway adapters already use), so CIDR ranges and
  `*.host` patterns bypass the proxy for MCP servers exactly as they do for the model
  endpoint. The stdlib `proxy_bypass` stays for the OS bypass list (Windows
  ProxyOverride / macOS exceptions). Live probe: NO_PROXY=10.255.255.0/24 still routed
  the MCP request through the proxy before this commit, direct after.
- Drop the try/except around `getproxies()` / `proxy_bypass()`: the stdlib guards its
  own registry/sysconf reads and httpx calls the same functions unguarded.
- Trim the six contributor tests to two invariants (mount + NO_PROXY incl. CIDR; both
  client builders carry mounts next to the body-cap transport). Fixture uses the stdlib
  `getproxies_environment` / `proxy_bypass_environment` instead of a hand-rolled copy and
  skips when the mcp SDK is absent.
- Docs: one sentence on the MCP page about proxy resolution for HTTP/SSE servers.
- contributors/emails mapping for the PR author.
2026-09-15 19:05:57 -07:00
teknium1
4b1215be2f fix: map MrMongstad's GitHub noreply email for contributor credit
Review finding: the Co-authored-by trailer on 2751fb7 uses stephan@users.noreply.github.com, which resolves to a different GitHub account; the pushed commit cannot be rewritten, so record the correct mapping via scripts/add_contributor.py and co-credit in the PR body.
2026-09-15 19:02:39 -07:00
teknium1
fcd4778e1b fix(gateway): trim planned-restart notice replay to a single write-once marker pass
Slim the salvaged #112111 mechanism (issue #112109) while keeping its
behaviour: the boot pass and the reconnect hook both run
_replay_pending_planned_restart_notification, which sends to every home
channel still owed an online notice, records delivered targets in
.restart_pending.json and unlinks the marker only when every owed target
(configured home with gateway_restart_notification=true) has been reached.

Dropped from the contributor diff:
- the per-target on_delivered checkpoint callback and pending_targets
  field: delivered targets are written once after the pass. Residual is a
  benign duplicate notice only if the process dies mid send-loop.
- getattr-based lazy lock -> class attribute default, same idiom as
  run_profile_reconcile._reconcile_lock.
- _clear_planned_restart_notification in gateway/run.py: no production
  caller remained; the roundtrip test unlinks the path directly.
- tests trimmed to two invariants: offline-at-boot is replayed once on
  reconnect (with live-at-boot control), and partial delivery is persisted
  so a fresh process does not re-notify and an opted-out home never keeps
  the marker alive.

Live probe (temp HERMES_HOME, Discord home, adapter absent at boot then
reconnected): base consumed the marker with 0 sends; fixed head retains it
and sends the online notice exactly once on reconnect, then clears it.
2026-09-15 18:57:39 -07:00
Aurélien Gekiere
0b265ef4fc chore: map aurel282 contributor email 2026-09-15 18:55:19 -07:00
teknium1
88593f0f0d chore: map 0xmosta contributor email
Attribution for the cherry-picked boot-recovery focus-trap commit (#111857).
2026-09-15 18:52:15 -07:00
fangliquanflq
27e3fc51ff fix(tools): keep async delegation results past a failed durable write and never prune live records
Two defects in tools/async_delegation.py:

- _push_completion_event called _persist_completion unguarded before
  publishing onto completion_queue. One sqlite3 error (locked/full
  state.db) dropped the completion event, left the record parked on
  "finalizing" (a permanently leaked max_concurrent_children slot) and
  let recover_abandoned_delegations later rewrite a succeeded unit as
  "unknown". The write is now try/except: the failure is logged and the
  event is still delivered, so _finalize flips the status and frees the
  slot. A lost durable row is acceptable degradation; a lost result and
  a leaked slot are not.

- _prune_completed_locked treated anything != "running" as finished,
  while the module's own _LIVE_STATES also names stalling/finalizing.
  A stalling record has no completed_at, so it sorted oldest and was the
  first eviction candidate once the retained cap overflowed; its late
  runner return then hit the missing-record path and the real result was
  dropped. The predicate is now `status not in _LIVE_STATES`.

Slim redo of #76606 (earliest fix) and #112031: the converge/shield/
delete-row machinery both PRs built around the write is dropped as
defense-in-depth; the two core hunks are ported as-is.

Fixes #76605
Fixes #112030
Co-authored-by: luckystar2026 <1393268817@qq.com>
2026-09-15 18:43:56 -07:00
teknium1
4432bccea8 chore(contributors): map co-author emails for TheNeuralVault and gongyi
Required by scripts/contributor_audit.py --strict for the Co-authored-by
trailers crediting #65182 and #57459 on the daemon-pool 3.14 fix.
2026-09-15 18:41:46 -07:00
jerryhjones
2bd0f1c59e fix(kanban): scope the stop nudge to the dispatcher-owned worker
agent/kanban_stop.py::kanban_stop_nudge_enabled tested only HERMES_KANBAN_TASK,
which in-process delegate_task children (and cron runs fired inside a worker)
inherit from the worker's process environment. Those executions own no board
task and have the kanban toolset withheld, so the turn-end nudge ordered them to
call a tool they cannot reach — burning attempts, and in production driving
children to complete the parent's card through the CLI.

Gate on agent/delegation_context.py::is_dispatcher_owned_worker_context, the
predicate every other HERMES_KANBAN_* identity gate already uses. The real
worker and the HERMES_KANBAN_STOP_NUDGE opt-out are unchanged.

Salvaged from PR #84656 by @jerryhjones (re-applied onto the current facade
shape); the same gate was first proposed in PR #80023 by @webdevfrancisco
using the narrower delegated-child predicate.

Co-authored-by: webdevfrancisco <franciscombautista2015@gmail.com>
2026-09-15 18:41:19 -07:00
teknium1
fa28f43285 fix(contributors): map dresvyanskiydenis@gmail.com to DresvyanskiyDenis
The salvage commit carries a Co-authored-by trailer for this non-noreply
address but no contributors/emails mapping existed, so release attribution
could not resolve it.
2026-09-15 18:40:52 -07:00
teknium1
40b47b84e7 chore(contributors): map Cr4ckMe email for the #20151 co-author credit 2026-09-15 18:39:09 -07:00
teknium1
e47b14f960 chore(contributors): map wangtaotaotao95 author email 2026-09-15 18:28:03 -07:00
teknium1
a1cbed3592 chore: map atmaksri co-author email for contributor audit
Co-authored-by trailer in the STT salvage uses a non-noreply address.
2026-09-15 18:25:17 -07:00
teknium1
c294e945ea chore: map contributor email for salvaged #103067 2026-09-15 11:50:48 -07:00
kshitijk4poor
4a2927d6d4 chore(contributors): map hcnimi for the #109314 salvage 2026-09-15 21:57:59 +05:30
shehjaddev
d205cef418 fix(redact): mask assignments in secret-bearing file reads
read_file/search_files passed file_read=True, which folded into code_file=True and skipped
the ENV/JSON/YAML assignment passes, so an opaque prefix-less credential under a
credential-shaped key reached the model in cleartext from a secret-bearing file — the
file-read half of the #110228 gate (#110567).

Two defects on that path, both fixed here:

- The rendered line-number gutter ("5|      ADS_API_TOKEN: ..." from read_file,
  "6:      ADS_API_TOKEN: ..." from grep -n / cat -n) defeated the line-anchored patterns,
  so the real rendered read leaked exactly what the raw text masked. A gutter-free fixture
  cannot see this, which is why the tool-level tests carry the real render shape.
- _is_secret_file_arg() could not see the RESOLVED Hermes home: the default home's basename
  is an installation detail (".hermes" on POSIX, "hermes" under AppData/Local on Windows) and
  a resolved path never spells $HERMES_HOME, so the managed Windows home's config.yaml was
  classified as ordinary YAML on both the file-read and the terminal surface.

Changes:

- redact_sensitive_text(): secret_file= re-enables the assignment passes for content the
  caller classified with _is_secret_file_arg, keeping code_file behaviour everywhere else.
  It is authoritative over code_file, so a caller cannot be fail-open on the security flag
  by setting both.
- _redact_assignments(): mask_nonreusable selects the non-reusable sentinel for file reads,
  so the #35519 write-back hazard stays closed.
- _should_redact_assignment(): no longer re-masks an already-masked value, which was erasing
  the vendor label the sentinel deliberately keeps.
- _is_secret_file_arg(): consult the resolved Hermes home for the config.yaml arm.
- _CFG_ANCHORED_RE / _YAML_ASSIGN_RE: tolerate a rendered line-number gutter.
- file_tools.py: classify the resolved path at all three file-read call sites.

Closes #110567
2026-09-15 06:26:29 -07:00
kshitijk4poor
b933ad41ab chore: map MohamadKanso contributor email for PR #110933 salvage 2026-09-15 06:22:15 -07:00
teknium1
e89605b4e6 docs(cron): record the due-only occurrence identity in the missed-occurrence contract
Also map the two salvaged contributor emails (kleros109, fangliquanflq).
2026-09-15 06:07:32 -07:00
teknium1
8c176c6f76 chore: map contributor emails for salvaged commits 2026-09-15 05:24:39 -07:00
teknium1
3f60f5dbe8 chore(contributors): map Synero email 2026-09-15 04:49:01 -07:00
teknium1
52f14ff45b chore(contributors): map Louis-Anson email 2026-09-15 04:47:37 -07:00
teknium1
0ba9d90e9a chore(contributors): map moxian (29206394) email 2026-09-15 04:46:36 -07:00
teknium1
8a3cded09c fix(whatsapp): normalize device-qualified ids in every id comparison, bridge and Python
#89322 fixed the bridge-local normalizeWhatsAppId, but bridge.js has since
moved its id handling to bridge_helpers.js::normalizeWhatsAppId, which still
turned `<user>:<device>@lid` into the malformed `<user>@<device>@lid` for
mentionedJid / quoted participant / reaction keys, and the Python side
(gateway/platforms/whatsapp_common.py::_normalize_whatsapp_id) did the same
':'->'@' swap on botIds. Drop the local duplicate in bridge.js, import the
helper, and strip the `:<device>` suffix on both layers so the bot's own ids
compare equal to the bare ids WhatsApp sends for mentions and quotes.

One invariant test: device-qualified botIds match a bare mentionedId and a
bare quotedParticipant; a plain group message still does not trigger.
2026-09-15 04:41:35 -07:00
teknium1
e31466bc5d test(slack): collapse the subtype allowlist tests to two invariants
Drop tests/gateway/test_slack_conversational_senders.py (12 parametrized
cases driving _handle_slack_message end-to-end for allow_bots policies and
canvas mentions — the allow_bots matrix is already covered by the existing
bot-filter tests in test_slack.py) and fold the remaining coverage into two
_prefilter_inbound tests: every housekeeping subtype is dropped, and every
conversational subtype (absent, file_share, thread_broadcast, me_message,
document_mention, bot_message under allow_bots=all) still passes. Distinct
ts per event: the prefilter dedups by (team, ts) before the subtype gate.

Adds the contributor email mapping for the second author.
2026-09-15 04:40:49 -07:00
teknium1
da893c9aba chore: map contributor emails for salvaged commits 2026-09-15 04:37:41 -07:00
teknium1
7e42fc341a chore: map wang2 for #56155 attribution 2026-09-15 04:24:53 -07:00
teknium1
325236d801 chore: map tarkil@gmail.com to @tarkilhk for contributor attribution 2026-09-15 04:12:41 -07:00
teknium1
7fcade0100 chore: map octopustank@foxmail.com to @Octopustank for contributor attribution 2026-09-15 04:11:55 -07:00
teknium1
05fb879609 fix(dashboard): share the fleet's sudo posture; trim to two invariant tests
The root/sudo decision now reuses `update_cmd_fleet._needs_sudo` (the helper `hermes update`'s
own fleet restart already uses for `sudo -n systemctl --no-ask-password`) instead of a second
euid check. Tests reduced to one parametrized argv invariant (system-scope lifecycle verbs get
`sudo -n`; status and both-units-installed never do) plus the no-passwordless-sudo request
failure. Dashboard docs note the passwordless-sudo requirement on system-scope installs.
2026-09-15 04:08:00 -07:00
teknium1
24056f6950 chore: map contributor emails for salvaged commits 2026-09-15 04:06:08 -07:00
teknium1
d47ac8d0e1 chore: map contributor email for @haizaar 2026-09-15 04:03:25 -07:00
Teknium
324da01573 chore: map contributor email for Moodtuner997 (PR #86067 salvage) 2026-09-15 03:58:05 -07:00
Teknium
ee0666bf0e chore: map contributor email for attribution audit 2026-09-15 03:53:13 -07:00
teknium1
31cde4e6ae chore(contributors): map sudhirpatil noreply for the #102557 cherry-pick 2026-09-15 03:44:36 -07:00
kshitijk4poor
6cd9fe1d5b chore: map Zeus-Deus contributor email (salvage #105139) 2026-09-15 16:07:43 +05:30
Danylo Borodchuk
e75b5a2d38 fix(skills): filter providers before limiting search results 2026-09-15 14:15:59 +05:30
kshitijk4poor
5900f0f70a chore: map jmiguellucas and cdbartholomew contributor emails 2026-09-15 13:27:24 +05:30
kshitijk4poor
3ba5602b62 chore: map the earlier RFC 9207 iss relay submitters
#88612 (willfrombr, Aug 17, closed when the author retired their fork) and
#92765 (CoLaOnline, Aug 23) carried the same dashboard/gateway iss relay
before #105610; credit them alongside the commit this stack cherry-picks.

Co-authored-by: Willian Santos <285090322+willfrombr@users.noreply.github.com>
Co-authored-by: Colin Lateano <222331716+CoLaOnline@users.noreply.github.com>
2026-09-15 13:00:12 +05:30
kshitijk4poor
9a1d3920ad chore: map OOOOOAO contributor email 2026-09-15 13:00:12 +05:30
kshitijk4poor
e6f2f2b759 chore: map camilb contributor email 2026-09-15 12:45:29 +05:30
kshitijk4poor
e1bdb026c8 chore: map MohamadKanso contributor email 2026-09-15 12:44:57 +05:30
kshitijk4poor
e6465962c9 chore: map djennewe contributor email for PR #89633 salvage 2026-09-15 10:49:40 +05:30
kshitijk4poor
b18140576d chore: map deadczarvc contributor email for PR #110470 salvage 2026-09-15 10:48:49 +05:30
teknium1
437116f949 chore(contributors): map catalog submitter email to GitHub login 2026-09-14 21:05:36 -07:00