The desktop hands profile values verbatim into 'hermes --profile <value>' in three places (local backend serve, external TUI resume, remote SSH serve). A non-string or non-slug value crossing that boundary hit the CLI's normalize_profile_name str()-coercion, which bootstrapped a phantom profiles/0/ directory (state.db + SOUL.md, no config.yaml) that then counted as a listed profile identity (#88842). Guard all three with a pure backendProfileArg helper (trim + case-fold + PROFILE_ID_RE slug test, 'default' allowed): a value that isn't a valid profile id is dropped from argv instead of spawned. Sibling paths (serveBackendArgs, tuiResumeArgs, buildSpawnCommand) all get the same treatment; existing tests pinning valid profiles stay green and new tests prove the drop/normalize contract on each surface.
63 lines
2.6 KiB
TypeScript
63 lines
2.6 KiB
TypeScript
// Backend subcommand routing for the desktop-managed Hermes process.
|
|
//
|
|
// The desktop app launches its own headless backend via `hermes serve` — it
|
|
// must NEVER depend on or launch the browser `dashboard`. But `serve` is a
|
|
// newer subcommand: a runtime that predates it (an older managed install the
|
|
// app hasn't updated yet, or an older `hermes` resolved from PATH) only knows
|
|
// `dashboard --no-open`. To avoid bricking those users mid-upgrade we detect
|
|
// whether the resolved runtime understands `serve` and, only when it does not,
|
|
// fall back to the legacy `dashboard --no-open` invocation. Both produce the
|
|
// exact same headless gateway; `serve` is just the decoupled name.
|
|
//
|
|
// These helpers are pure so they can be unit-tested without Electron.
|
|
|
|
import { backendProfileArg } from './profile-id-guard'
|
|
|
|
/**
|
|
* Build the canonical headless backend argv (always `serve`).
|
|
* @param {string} [profile] optional Hermes profile to pin via `--profile`.
|
|
*/
|
|
export function serveBackendArgs(profile?: string) {
|
|
// A non-slug value (numeric roster id, display label) must never cross into
|
|
// spawn argv: the CLI used to str()-coerce it into a phantom profiles/0 dir (#88842).
|
|
const pinned = backendProfileArg(profile)
|
|
const head = pinned ? ['--profile', pinned] : []
|
|
|
|
return [...head, 'serve', '--host', '127.0.0.1', '--port', '0']
|
|
}
|
|
|
|
// Flags that consume the next token; the subcommand is the first bare token
|
|
// that is not one of their values. `--profile=serve` never collides (it is a
|
|
// different string), but the two-token `--profile serve` / `-p serve` do.
|
|
const VALUE_FLAGS = new Set(['-m', '--profile', '-p'])
|
|
|
|
/**
|
|
* Rewrite a resolved backend argv from `serve` to the legacy
|
|
* `dashboard --no-open` form, preserving every other argument (incl. a leading
|
|
* `-m hermes_cli.main` and any `--profile <name>`). Returns a copy; if there is
|
|
* no `serve` subcommand token the argv is returned unchanged.
|
|
*/
|
|
export function dashboardFallbackArgs(args) {
|
|
let i = 0
|
|
|
|
while (i < args.length && args[i] !== 'serve') {
|
|
i += VALUE_FLAGS.has(args[i]) ? 2 : 1
|
|
}
|
|
|
|
if (i >= args.length) {
|
|
return args.slice()
|
|
}
|
|
|
|
return [...args.slice(0, i), 'dashboard', '--no-open', ...args.slice(i + 1)]
|
|
}
|
|
|
|
/**
|
|
* True when a runtime's `hermes_cli/subcommands/dashboard.py` source registers
|
|
* the `serve` subcommand. Matches `add_parser("serve"` / `add_parser('serve'`
|
|
* specifically so the substring "server" (e.g. "start_server", "web server")
|
|
* never produces a false positive.
|
|
*/
|
|
export function sourceDeclaresServe(dashboardPySource) {
|
|
return /add_parser\(\s*["']serve["']/.test(String(dashboardPySource || ''))
|
|
}
|