Commit Graph

504 Commits

Author SHA1 Message Date
Teknium
ddc51ec109 fix(update): reload process-scan modules at the dashboard-cleanup entry point
Widen PR #87757 to cover the ZIP path: _update_via_zip() also calls
_finish_dashboard_update_cleanup() but never runs _reload_config_modules,
so the Windows git-broken fallback would still crash with the same
ImportError (cannot import name 'bounded_probe_run' from the stale cached
hermes_cli._subprocess_compat).

- new _reload_process_scan_modules() called inside
  _finish_dashboard_update_cleanup itself, so every current and future
  call site is covered; reloads dependency-first
  (_subprocess_compat, then dashboard_procs)
- reload failures log at warning (a miss surfaces seconds later as an
  ImportError in the same process)
- regression tests: reload-before-kill ordering, node-failure skip,
  stale-module symbol restoration (the exact #87134 boundary state),
  nonfatal reload failure, and the #87757 reload-list contract
2026-08-16 10:31:24 -07:00
Teknium
de254c48fb chore: map contributor email for @yflmq001 2026-08-16 06:31:26 -07:00
Teknium
6ce7922af1 chore: map contributor email for focused-session atoms salvage 2026-08-16 03:15:27 -07:00
Cary Palmer
be38224b49 fix(desktop): lint and map contributor email for running-is-not-busy
Drop the redundant Boolean() on selected in $primaryBusy and add the
professorpalmer9@gmail.com mapping so attribution CI can resolve the PR.
2026-08-16 03:01:45 -07:00
Teknium
f325008ebf chore(contributors): map emails for P2-sweep salvage wave 2026-08-16 02:13:05 -07:00
kshitij
2cd5393af7 chore: map justin@bowes.org to @justinbowes
Attribution mapping for the PR #84982 salvage. The commit email is not
linked to a public GitHub account, so contributor_audit --strict fails
without it; login confirmed from the PR author field.
2026-08-16 13:10:40 +05:30
Teknium
128fb74d98 chore: map contributor email for 5Hyeons 2026-08-15 23:37:15 -07:00
Teknium
411903b6fa chore: contributor mapping for NikolaRHristov 2026-08-15 23:03:52 -07:00
Teknium
951ae62ffc test(computer-use): pin 0.17+ split refs/content_refs merge behavior
Regression test for the _ref_map merge (salvaged from #79515): the live
0.19.3 driver splits action refs into refs[] while content_refs re-lists
every node with empty actions; the empty entries must not clobber the
action-bearing ones. Caught live: every typed click refused with
browser_ref_stale until the merge fix.
2026-08-15 15:36:19 -07:00
Teknium
9859e8852f chore: map 807847218@qq.com -> Tommy00748 for attribution audit 2026-08-15 13:31:35 -07:00
Teknium
07161e1da4 chore: map contributor email for @RGerrish 2026-08-15 04:33:47 -07:00
LordMelkor
6efab28726 feat(auth): add key_cmd credential source for custom providers
Custom providers could only authenticate from a static credential (inline
api_key or a key_env env var). Enterprise gateways -- SSO/OIDC brokers, cloud
IAM, internal auth proxies -- issue short-lived bearers instead, so a value
copied into .env is stale within the hour: long sessions start returning 401s
and the user has to restart or run an external cron that rewrites .env.

The existing `secrets.command` source does not cover this: it runs once per
process at startup (subsequent calls are no-ops by design), so it cannot
re-mint a credential mid-session.

Add providers.<name>.key_cmd: a command that prints a token, wrapped at
resolution in a zero-argument callable. Both wire clients already accept a
callable api_key and invoke it per request (the Entra ID path established
this), so chat_completions, codex_responses and anthropic_messages all work
unchanged and always send a fresh credential. The callable also routes the
Anthropic client through its per-request Authorization hook, which is what
OAuth-gated gateway routes require -- so no per-vendor auth wiring is needed
anywhere in core.

- cached until shortly before the advertised expiry (60s leeway), so the
  helper runs about once per token lifetime rather than once per request
- expiry is read from the OAuth 2.0 relative `expires_in` when present, and
  otherwise from an absolute ISO 8601 deadline (`expiry`, `expiresOn`), which
  is what CLI token helpers commonly print. Reading only `expires_in` treated
  those helpers as advertising no TTL at all, cached their token for the life
  of the process, and returned 401 on every request once the real deadline
  passed. ISO parsing reuses hermes_cli.auth._parse_iso_timestamp rather than
  adding another datetime parser.
- no synthetic expiry: when no TTL is advertised, or the advertised one is
  unparseable or already past, the token is used and refreshed on 401 instead
  of re-minted on an invented schedule
- stdout contract matches OAuth 2.0 token endpoints and existing agent
  helpers (bare token or JSON access_token/expires_in); multi-line output is
  rejected rather than guessed at, so a misconfigured helper surfaces as a
  clear error instead of a corrupt-credential 401
- precedence: explicit --api-key still wins; otherwise key_cmd beats a
  static api_key/key_env on the same entry
- failures never include the helper's output (may hold a partial token) or
  the command string (may embed a client secret)

Resolution happens on two paths. agent/auxiliary_client.py resolves named
custom providers itself rather than calling _resolve_named_custom_runtime, so
key_cmd is honoured in both: wiring only the runtime resolver leaves the main
agent turn working while every auxiliary call (title generation, compression,
vision, embedding) falls back to the no-key-required placeholder and 401s.
Precedence is identical on both paths, so one config entry cannot yield two
different credentials depending on which resolver the caller reached.

Closes #84162

Signed-off-by: LordMelkor <kray@block.xyz>
2026-08-15 03:16:21 -07:00
Teknium
26aa12337a feat: /save exports the current session as json, md, or html on all platforms
Rework of salvaged PR #6372 (@ag9920) onto current main:

- /save promoted from CLI-only JSON snapshot to a cross-platform session
  export: `/save [json|md|html] [filename] [redact]` on CLI and every
  gateway platform (sent as a document via adapter.send_document).
- Rendering routes through the existing shared renderers
  (hermes_cli/session_export.py + session_export_html.py) instead of the
  PR's new hermes_state formatter — new helpers normalize_save_format /
  render_session_for_save / default_save_filename are shared by both
  surfaces.
- `redact` arg runs the export through the force-mode secret redaction
  pass (session_export_md.redact_session_data) before writing.
- Gateway handler awaits AsyncSessionDB correctly, sanitizes user-supplied
  filenames with basename, and lands in gateway/slash_commands.py (the
  handlers moved out of gateway/run.py since the PR was authored).
- /export stays profile export (name collision resolved: session export
  lives on /save).
- Slack 50-slash cap curation: /platform moves to the /hermes-only set to
  free a native slot for /save (parity test updated rationale comment).
- Folds in PR #62268 (@briandevans): None title/model coalescing in the
  single-session HTML export.

Closes #4249. Closes #51200.
2026-08-15 02:04:49 -07:00
Teknium
467ec9208a chore: map content@tyfpro.com -> tyfcontent for #85181 salvage 2026-08-15 02:04:10 -07:00
Teknium
e1dd43bf7b chore: map contributor emails 2026-08-15 01:21:40 -07:00
Nicolas Formenton
5cf6122e87 chore: map contributor email 2026-08-15 01:21:40 -07:00
Teknium
180bd4b5a3 chore: map salvage contributor emails for attribution audit 2026-08-15 01:05:39 -07:00
Teknium
c21dc294b2 chore(contributors): map salvaged author emails 2026-08-15 01:04:19 -07:00
Teknium
aaaea589f6 test+style: align session.new binding pin with #76185 and eslint --fix 2026-08-15 01:04:06 -07:00
Teknium
100098ee2d chore: map salvage contributor emails for attribution audit 2026-08-15 01:04:06 -07:00
Teknium
32efae941f chore: map contributor emails for salvaged commits 2026-08-15 01:03:57 -07:00
Teknium
0930133dbf chore: map contributor email for PaulBlackSwan 2026-08-15 00:37:00 -07:00
Teknium
aa27edd971 chore(contributors): map jackoconner55@icloud.com 2026-08-15 00:36:03 -07:00
Teknium
8a22220ca8 chore: map contributor email (audit_pr_attribution) 2026-08-15 00:35:40 -07:00
Teknium
101740ed36 chore: map contributor email (audit_pr_attribution) 2026-08-15 00:35:28 -07:00
Teknium
a654c52419 chore: map contributor email (audit_pr_attribution) 2026-08-15 00:35:16 -07:00
Teknium
8ea53d7cea chore: map contributor emails for salvage attribution 2026-08-15 00:34:57 -07:00
Teknium
7f84de2775 chore(contributors): map lepetitprince716@gmail.com -> lepetitprince716-prog 2026-08-15 00:34:29 -07:00
Teknium
daa3f66d08 chore: map contributor emails for IME TUI salvage 2026-08-15 00:33:49 -07:00
Teknium
27a22b8de7 chore: map contributor emails for IME salvage 2026-08-15 00:33:40 -07:00
Teknium
eaaecbcc30 chore: update contributor attribution map 2026-08-15 00:33:32 -07:00
Teknium
e0e4d3ab9d chore(contributors): map salvage-branch contributor emails 2026-08-15 00:33:11 -07:00
Teknium
2fecf392a2 chore: map contributor email for Hangzian 2026-08-15 00:33:01 -07:00
Teknium
106207c7fb chore: map contributor emails for attribution audit 2026-08-15 00:32:53 -07:00
Tugrul Guner
6d0d748aa0 chore: add contributor email mapping 2026-08-15 00:32:53 -07:00
Teknium
1c23c2a50b chore: map contributor email for attribution audit 2026-08-15 00:32:44 -07:00
Teknium
18bac64044 chore: map contributor email for icemeng 2026-08-15 00:32:35 -07:00
Teknium
5599dc048f chore: map hbasheer@student.42abudhabi.ae -> hxwvaa for contributor attribution 2026-08-14 22:33:44 -07:00
Teknium
0178aca4a4 chore: map Halldrix contributor email 2026-08-14 22:03:56 -07:00
Teknium
49e30440a2 chore: map contributor emails for mariobgsp (PR #83902 salvage) 2026-08-15 10:29:05 +05:30
Teknium
e6daa7aba5 chore: contributor mapping 2026-08-14 21:57:41 -07:00
Teknium
25857671f7 chore: map contributor email for attribution audit 2026-08-14 21:56:33 -07:00
Teknium
0ea79484d2 chore: map contributor emails for cron salvage 2026-08-14 21:55:14 -07:00
Teknium
3bb83a9a51 chore: map contributor email for salvage 2026-08-15 10:22:47 +05:30
Teknium
169ff2db4f chore: add contributor email mapping for arccat-114 2026-08-14 21:44:28 -07:00
Teknium
b2113202be chore: map contributor email for x1051445024 2026-08-14 21:36:41 -07:00
deacon-botdoctor
ea4cfbb3d6 chore(contributors): map loulanyue email 2026-08-14 21:24:36 -07:00
Teknium
1d958880b3 chore: contributor mapping for Ufonik88 2026-08-14 21:20:03 -07:00
Nicolas Formenton
9184915c42 fix(desktop): skip stale journal duplicate folds
The inflight-turn journal can outlive the turn it recorded (reclaim,
reconnect or restart races skip the settle that clears it). On session
resume the fold then re-appends journaled assistant rows to a transcript
that already holds the committed replies, so the conversation ends with
duplicate answers in scrambled order. The fold also carried the stale
entry's streamId onto the resumed state on an idle resume, which kept the
journal entry alive (persistInFlightTurnState only clears when streamId is
null) and re-folded the same tail on every open.

Detect text-level staleness before the append path: when every recoverable
journaled assistant row already exists as committed text in the base
transcript, treat the entry as caught up and clear it. Only keep a stream
target when the resumed session is genuinely running (keepPending), so an
idle resume self-heals instead of re-folding.
2026-08-14 21:10:13 -07:00
Teknium
cb3ca0af0e chore: add contributor email mapping for razultull 2026-08-14 20:40:24 -07:00