Files
hermes-agent/cron
teknium1 5d027bbd06 fix(cron): -f patterns must match the gateway cmdline, not any "hermes" substring; ledger names agent-issued kills
Review follow-up on #113667:

- _pattern_reaches_host_interpreter: when the `-f` head token is not an
  interpreter image, require the pattern to plausibly reach the gateway
  cmdline (hermes_cli / hermes+gateway tokens, mirroring Branch D). On
  the previous head `pkill -f 'hermes-polis/run.sh'` and
  `pkill -f my_hermes_bot.py` were hard-blocked although both are allowed
  on main and cannot match the gateway; both spellings are now negative
  controls in test_kill_forms_that_do_not_reach_the_gateway.
- lifecycle_ledger: the unclean-exit warning enumerated only OS causes
  (SIGKILL / OOM / VM death); an agent- or descendant-issued kill of the
  host interpreter leaves identical evidence and is now named in the
  cause family. One invariant test.
- test file: encoding="utf-8" on the bare write_text calls the footgun
  scanner flags.
2026-09-18 12:49:13 -07:00
..