Commit Graph

322 Commits

Author SHA1 Message Date
ethernet
a75d8b420e Merge pull request #122234 from NousResearch/fix/handoff-noninteractive-steps
fix(desktop-update): Windows update steps get NUL stdin; installer asks gateway questions once
2026-09-25 00:05:41 -04:00
ethernet
e39ba502db test(desktop-update): read the console self-test report as UTF-16
Windows PowerShell 5.1 `*>` writes UTF-16LE with a BOM. Decoding it as
UTF-8 hid the PASS line even though the self-test exited 0.
2026-09-25 00:02:54 -04:00
ethernet
746d861504 fix(install): don't ask the gateway install questions twice
The setup stage installs the gateway service through
ensure_gateway_service. On Windows that asks the start-now, Scheduled
Task and UAC questions. The gateway stage then ran `hermes gateway
install`, which asked them all again.

`gateway install --if-missing` does nothing when a service is already
installed. Both installers' gateway stages use it, so they ask only
when setup did not install the service.
2026-09-24 23:49:18 -04:00
ethernet
a3456765ed fix(desktop-update): give Windows update steps NUL stdin, not the hand-off console
Steps inherited the hand-off console's stdin, so any step that asks a
question blocked forever. Its prompt went to the captured stdout, which
is shown only after the step exits. `gateway start --all` did exactly
this: it saw an interactive console and asked "Install it now so the
gateway starts on login?". The update stopped after `hermes update exit
code: 0` and never relaunched the app.

Steps now read NUL. Prompts see a non-interactive stdin and take their
defaults. The working-directory self-test also checks that a step's
stdin is not a console, and a new test runs it under a real console.
2026-09-24 23:49:18 -04:00
ethernet
e3d43c3c24 test: stop relying on the in-tree venv after #122161
PR #122161 stopped boot from activating the in-tree venv or .venv when
PM has committed no environment. Six Linux tests and four Windows tests
still used that tree to supply their probe modules.

- Launcher tests put the probe in a committed generation. A custom
  HERMES_HOME is its own dependency root, so it gets its own commit.
- The legacy row of test_pre_pm_base_dependencies_activate_only_at_boot
  asserted the removed behavior. test_boot_never_activates_the_pre_pm_venv
  now covers the inverse. The payload row stays.
- The mint payload fixture writes manifest.json as real payloads do, so
  boot selects the payload venv.
- The PowerShell activate test expects PYTHONPATH to be the checkout
  alone. The bootstrap .venv packages do not leak in.
2026-09-24 23:40:03 -04:00
ethernet
90963a6f74 install: --skip-browser / -SkipBrowser become PM's persisted opt-out
The flag used to exit 1 as retired. Now that PM installs the browser tools
by default, it maps to `pm.cli install --without agent-browser`, which later
installs and `hermes update` honour.
2026-09-24 17:27:45 -04:00
ethernet
f0ae9e0568 test: copy the whole scripts/releases package into source-tree fixtures
dc11e3b3bc made scripts/releases/versioning.py import the new sibling
scripts/releases/semver.py. Three fixtures hand-copy a file list of that
package into a temp tree, so importing versioning there now dies with
`ModuleNotFoundError: No module named 'scripts.releases.semver'`
(JS & TS checks: channel-build-version.test.ts MSIX manifest case; the
same import chain runs in test_source_build_env.py and
test_commit_stamp_identity.py via distance -> versioning).

Copy the package as a tree, like the fixtures already do for pm/, so the
next intra-package import cannot silently break them again.
2026-09-24 16:17:35 -04:00
ethernet
50de548e49 fix(install.sh): arrow-style output with child noise collapsed on a terminal
The pm-era installer printed "[hermes]" lines between raw git, uv and pm
output. Restore the pre-pm installer's look (→ ✓ ⚠ ✗, banner on the full
ladder) and route every child command through run_logged: on a terminal it
shows one status line rewritten with the command's newest output line
(git clone phases via --progress), appends everything to
$HERMES_HOME/logs/install.log, and on failure prints the last 20 lines plus
the log path. CI, --verbose, HERMES_INSTALL_VERBOSE and a non-terminal
stdout (the Hermes-Setup --json driver, E2E transcripts) keep the full
stream, so their parsers see what they saw before. Errors stay on stderr.
2026-09-24 14:23:48 -04:00
ethernet
e78e3a77be refactor(release): move the author map out of release.py
release.py was 2,804 lines, 2,076 of them the frozen legacy author dict.
The map and its resolver now live in scripts/releases/: authors.py holds
the directory loader, the merged AUTHOR_MAP and resolve_author, and
authors_legacy.py holds only the frozen LEGACY_AUTHOR_MAP literal (same
1,895 entries, same order). release.py drops to 707 lines.

The contributor-check job and audit_pr_attribution.py grep the legacy
file for quoted emails, so both now read authors_legacy.py. The
importers (contributor_audit.py, add_contributor.py), contributors/README
and the tests read the defining modules. No behaviour change.
2026-09-24 14:08:22 -04:00
ethernet
1f264c7205 test(ci): evaluate stable-release and build-cache gates instead of spelling them
test_stable_release_graph and test_desktop_build_cache asserted gate text:
`== "always()"`, `== "false"`, `"conclusion != 'success'" in`,
`"!cancelled()" in`. Both files now evaluate the gate with the shared
evaluator, which also resolves `steps.*` now.

- The stable gates (acceptance, publication, complete) must run when every
  ancestor failed.
- Deferred desktop e2e never runs.
- The publication reconciler runs after a failed, dispatched Stable Release
  of this repository and on manual dispatch. It refuses a successful run, a
  push-triggered run, and a fork's run.
- No desktop-build-cache step runs during cancellation. The service-failure
  report runs when restore or save failed and stays quiet otherwise.
2026-09-24 14:08:22 -04:00
ethernet
b728fdd627 refactor(pm): own the lock/atomic-write primitives in pm.filesystem
pm imported runtime_state's private helpers (_lock, _atomic_bytes, _bytes,
_digest) at a dozen sites while runtime_state imports pm.environments at
module top. The primitives are pm's: move them into the stdlib-only
pm.filesystem as lock_fd, durable_write_bytes, read_bytes_or_none and
file_digest, and repoint every pm caller.

runtime_state keeps the private names only as import aliases: it still
calls them through its own globals, and pre-PM updaters load them by these
names mid-swap (tests/compat/old_updater_surface.json).

Boot-subset test fixtures now copy pm/filesystem.py, since runtime_state
imports it at process boot; worker-injection tests patch the name
pm.publication now reads.
2026-09-24 14:08:03 -04:00
ethernet
dc11e3b3bc feat(release): add --skip-bundles and --skip-tests to stable releases
`release.py release` gains two flags. They can be used together.

--skip-bundles ships only the claim, the GitHub release, the final tag
and the Docker image. No desktop, Termux or PM bundle job runs. The
final tag records candidateManifestSha256: null. Publication moves only
the Docker stable/latest aliases. The R2 stable head, feeds, APT, the
downloads page, the signed-package baseline and the Store stay on the
previous bundle release.

--skip-tests builds, signs and publishes every artifact and runs no
test job: source CI, Nix, PM bundle check, Termux, Windows live,
install/update E2E, bootstrap identity, native smokes, upgrade
acceptance, tests/docker and the in-build vitest step. The candidate
manifest records each smoke as skipped, never as passed.

The flags live in the claim message (skipBundles, skipTests), next to
autopublish. They are not workflow inputs, so a rerun cannot change
them. admit emits them, and every job condition and gate reads them.
stable.validate_claim and stable.validate_final are now the one shape
check for stable.py and the sequencer.

The gates stay strict. SKIPPED_BY in stable.py maps each job to the
flags that remove it. `gate` requires those jobs to report skipped and
every other gated job to report success. A job that ran although a flag
removes it blocks the release.

A release that skipped bundles never moves the R2 stable head. Two
readers depended on that head:

- The next version was derived from it, so the next cut would reuse the
  version. It now takes the newer of the R2 head and the newest
  published non-prerelease GitHub release with a vX.Y.Z tag. Bare v*
  tags do not count, because those refs are not protected yet.
- The sequencer used it to decide which published releases still need
  their publication pass, so a bundle-less release would re-advance
  every 15 minutes. The head is now the newer of the R2 head and the
  published release whose final tag binds the Docker stable alias
  digest.

`release` also refuses a cut when its next version already has a final
tag. That closes the window between the final tag and the public
release, where the published identity still names the old version.

Tests: 42 release test files, 546 passed. Three tests fail on this
Windows host, and they fail the same way on a clean HEAD worktree:

- test_stable_release_graph::test_docker_recovery_refuses_to_replace_a_divergent_version_tag
- test_release_artifacts::test_windows_metadata_is_read_from_package_and_stale_stamp_is_rejected
- test_tag_builds_summary::test_admitted_failure_publishes_tag_info_without_promoting_channel[True]

Not verified: no real Stable Release dispatch ran with either flag, and
actionlint is not installed on this host. The workflow changes are
checked by the graph tests and by running the phase-result step script.
2026-09-24 13:31:33 -04:00
ethernet
7e59364c8f Merge remote-tracking branch 'fork/ethie/pm-clean' into ethie/pm-clean 2026-09-24 11:58:45 -04:00
ethernet
e8d1fc76ec fix(install): run the installed hermes under the Restricted policy
`irm | iex` runs install.ps1 as text, which execution policy never
checks, but Invoke-InstalledHermes then dot-sourced runtime.ps1 from
disk. That is a file load, and the default Restricted policy (Windows
Sandbox, fresh machines) refused it right after "hermes command
installed". Load the helper from its text instead.

That failure hid a second one on the same path: the `$command` local
was shadowed inside Invoke-Native by its case-insensitive `$Command`
parameter, so `& $command[0]` invoked the scriptblock itself until the
call depth overflowed. Rename the local.
2026-09-24 11:56:34 -04:00
ethernet
e0735f8891 docs(tests): name platforms() instead of the retired OS markers
linux_only / macos_only / windows_only were replaced by platforms(...)
and conftest now rejects them, but test docstrings and comments still
explained gating in terms of the old names, which points readers at a
marker they cannot use. Reword them to platforms("<os>") and the
-m platforms lane. ci.yaml's comment already says platforms("windows").
2026-09-24 11:50:30 -04:00
ethernet
2be53ecd7b fix(encoding): read kernel pseudo-files as plain utf-8
utf-8-sig exists to tolerate BOMs that Windows tooling adds to files
users edit. /proc and /sys files are generated by the Linux kernel, never
BOM'd and absent on Windows, so -sig there only muddies the read/write
policy. Switch every literal /proc/ and /sys/ read to utf-8 and teach
the footgun read rule that string literals starting with /proc/ or
/sys/ are exempt (user-edited files keep utf-8-sig).
2026-09-24 11:50:30 -04:00
ethernet
845b61f2b8 fix(release): rerun failed stable runs on the failure event, drop the cron
Stable Release Publication ran every 15 minutes (96 runs a day, each
checking out full history, setting up node and buildx, logging into
Docker Hub, and taking the release-signing environment) only because the
sequencer held a failed run for a 15-minute backoff that the failure
event could never satisfy, so the cron was what actually retried.

Drop the backoff: the reconcile pass started by a failed Stable Release
reruns its failed jobs right away. MAX_ATTEMPTS burning, oldest-first
retry ordering, the attempt-entry check, and the needs_retarget repair
stay. The schedule trigger goes; workflow_run and workflow_dispatch
remain the recovery paths.

The shared stable-release concurrency group cannot deadlock: the rerun
waits as pending behind this job, and the sequencer only confirms the
new attempt is queued before it exits and frees the group.
2026-09-24 11:50:30 -04:00
ethernet
4aadff7bd6 test(install): expect the arch-qualified bootstrap Python request
419a3cbe00 made install.ps1 ask uv for cpython-<minor>-windows-<arch>-none,
but this test still pinned the bare version.
2026-09-24 11:31:09 -04:00
ethernet
bcabc5b881 fix(install): keep the PowerShell session open when an iex install fails
The documented one-liner, iex (irm .../install.ps1), runs the installer
inside the user's own session. Fail ended with exit 1, so any failed
stage closed the user's PowerShell window.

Fail now throws. The two entry points own reporting and the exit code:
-Stage prints the reason, emits the -Json frame and exits 1, as before;
the full install exits 1 only when it runs from a script file, and under
iex it prints the reason, sets LASTEXITCODE=1 and returns. A scriptblock
literal's File tells the two apart: $MyInvocation.MyCommand.Path names the
caller's script under iex.
2026-09-24 11:31:08 -04:00
ethernet
48c78669b1 test(install-e2e): capture PM desktop launches on macOS through the isolated launcher
PM launchers run python -I, which ignores PYTHONPATH, so the macOS
hermes-desktop-app-update route never loaded the sitecustomize capture hook.
Route PM launchers through pm-launch.py as the Linux driver already does, and
cover the packaged .app shape the macOS route launches.
2026-09-24 11:12:27 -04:00
ethernet
f43c38affc test(install-e2e): accept the current checker's countless update offer and the macOS installer marker
The current source checker reports updateAvailable with behind null when GitHub
compare cannot count staged commits; the app-update predicate demanded an integer
behind and refused every HEAD->NEXT leg. Require behind > 0 only for the historical
shape without updateAvailable.

v2026.6.19's DMG bootstrap runs the same install.sh that writes .install_method,
so its macOS leg saw a dirty tree. Share the Linux driver's guarded exclude through
source-driver.sh and apply it before every app-driven macOS update.
2026-09-24 10:42:43 -04:00
ethernet
edcb3346a7 fix(desktop): constrain baked environment and validate registered feeds 2026-09-24 09:20:50 -04:00
ethernet
ff14aaecc0 fix: reject incomplete source installer arguments before install work 2026-09-24 09:20:50 -04:00
ethernet
46a08dddd4 fix: route macOS DMG CLI E2E through staged branch probe 2026-09-24 08:20:14 -04:00
ethernet
0fa8dd08cb test(e2e): distinguish absent and unrelated native DMG receipts 2026-09-24 07:07:08 -04:00
ethernet
7289bff2c3 test(e2e): wait for native DMG bootstrap completion across old releases 2026-09-24 07:06:42 -04:00
ethernet
dcfe8f2d75 fix(install): refuse occupied Windows checkout before Git provisioning 2026-09-24 06:09:17 -04:00
ethernet
ab846213d8 test(macos): use supported host marker for desktop handoff 2026-09-24 06:04:54 -04:00
ethernet
1a495c4033 fix(e2e): wait for macOS setup completion before source verification 2026-09-24 05:57:28 -04:00
ethernet
ebf5f3bdfb test: seed real Git in Linux pwsh installer fixture 2026-09-24 05:45:13 -04:00
ethernet
4ffba2c882 test(ci): prepare pinned Git before Windows installer stages 2026-09-24 05:45:13 -04:00
ethernet
dd744286ed fix(install-e2e): follow staged main with explicit source branch 2026-09-24 04:48:34 -04:00
ethernet
f74ae0d862 test: capture PM desktop launches under isolated interpreter 2026-09-24 04:48:34 -04:00
ethernet
46e9f8746f fix: recognize PM source launcher in DMG install driver 2026-09-24 04:48:34 -04:00
ethernet
fb7fe862ef fix: restore pinned Git in each Windows bootstrap stage 2026-09-24 04:42:28 -04:00
ethernet
656a1ace1e fix: explicitly acquire PTY in installer stage handoff fixture 2026-09-24 04:38:23 -04:00
ethernet
cb7b18431a Merge remote-tracking branch 'origin/main' into ethie/pm-clean
# Conflicts:
#	apps/desktop/src/app/settings/connections-registry.tsx
#	scripts/install.ps1
#	scripts/install.sh
#	tests/hermes_cli/test_update_autostash.py
2026-09-24 03:48:31 -04:00
ethernet
0b8aa8bf83 fix: align Python CI contracts with current PM and checkout behavior
Allow read-only merged-tag queries through the live-system guard, route checkpoint rekeying to its real ref-deletion owner, and update stale fixtures to exercise current update and PM boundaries. Fix the shutdown test wait by patching the bound server global.
2026-09-24 03:42:38 -04:00
brooklyn!
c7d2985ae3 fix(install): keep dropped commits behind a rescue ref on the installer reset
Re-running install.sh / install.ps1 over an existing checkout (desktop
bootstrap and its update retry do this) falls back to
`reset --hard origin/<branch>` when a fast-forward fails, with no anchor for
the commits it drops. Park HEAD under refs/hermes-update-backups/, the same
namespace `hermes update` writes and prunes, and print the ref.
2026-09-24 02:40:53 -05:00
brooklyn!
14a8a771de fix(desktop-update): stop launching a Chrome instance for the macOS update shim
Each update started the user's Chrome binary with its own --user-data-dir,
a second instance of the same bundle that the Dock records as a new
recent-app tile. On macOS the outcome now goes through the existing
notification + next-boot result dialog.

Fixes #96374
2026-09-24 02:36:14 -05:00
ethernet
5f78e110e1 test: align Windows launcher and bootstrap fixtures with native behavior 2026-09-24 03:12:29 -04:00
ethernet
ebf127c33d fix: keep source observer read-only and PTY fixture reusable 2026-09-24 03:12:29 -04:00
ethernet
1aeb53a40b fix: align upgrade CI and installer fixture with PM bootstrap 2026-09-24 02:50:25 -04:00
ethernet
e81bc0f545 test(release): require both Docker variants at publish 2026-09-24 02:31:07 -04:00
ethernet
d6106975e9 fix(docker): promote desktop variant from its own release digest 2026-09-24 02:03:59 -04:00
ethernet
f91bd82286 fix: restore catalog Hindsight and harden installers and test guards 2026-09-24 02:03:59 -04:00
ethernet
29c56a27d4 fix: align CI tests and workflows with PM build contracts 2026-09-24 02:03:59 -04:00
ethernet
33754a37e0 fix(pm): use explicit text encodings in touched paths 2026-09-24 01:31:40 -04:00
ethernet
dcd2bca06a fix(desktop): render icons with core runtime dependencies 2026-09-24 01:30:15 -04:00
ethernet
74c365a85a fix(release): check the draft body before the claim; release takes --no-changelog
The stable cut built its draft body after pushing the attempt ref, so a
body over GitHub's 125000-character limit failed with HTTP 422 and
burned the attempt. The body is now built first, and an oversized one is
refused before anything is claimed, naming --no-changelog.

--no-changelog was defined only on the top-level parser, so
`release.py release --no-changelog` was an argparse error and the flag
never reached the cut. The release subcommand now takes it, with a
SUPPRESS default so the top-level spelling is not reset.
2026-09-23 22:24:22 -04:00