* refactor(plugins): remove the Sep 2026 decomposition compat layer on schedule The PLUGIN-COMPAT layer (2776813df3+d63e380324+0a5164cebe) kept pre-#102117 import paths alive for external plugins until 2026-09-14. That window closed two weeks ago; since then the loader has already been skipping plugins that use the old paths. This removes the layer itself: - 328 appended `PLUGIN-COMPAT` blocks (lazy `__getattr__` pointer tables, re-exported third-party names, restored dead definitions) and the three re-export stub modules (gateway/startup_watchdog, hermes_cli/observability/relay_runtime, tools/environments/modal_utils) - COMPAT_MANIFEST.md, compat_manifest.json, scripts/check_compat_pointers.py and its lint step - the reporting surfaces: CLI banner notice, `hermes plugins compat`, the `hermes doctor` section, the post-update notice, the Desktop one-time dialog, the loader's pre-import skip and the `plugins.allow_deprecated_imports` escape hatch An external plugin that still imports an old path now fails to load with its ImportError as the reason in `hermes plugins list`, the same path as any broken plugin. hermes_cli/plugin_compat.py stays as three inert stubs (compat_report, removal_in_effect, summary_lines): an already-running pre-removal `hermes update` lazy-imports them after the checkout swap (tests/compat/old_updater_surface.json). In-tree fallout, both already dead: hermes_cli/setup.py::_check_espeak_ng (no callers; its `shutil` came from a compat block) and gateway/config.py::SessionResetPolicy ("retained solely for the scheduled plugin-compat window"). Two test_run_agent patches targeted the removed `run_agent.handle_function_call` pointer; they now patch `model_tools.handle_function_call`, the seam production reads, like every sibling test in that file. * chore: retrigger CI (zero-job startup_failure phantom) * test: drop resolution allowlist rows for the two deleted which() sites hermes_cli/setup.py::_check_espeak_ng (dead) and tools/skillevaluator_scan.py::scanner_available (a restored definition inside a PLUGIN-COMPAT block) no longer exist; the stale-row gate requires their allowlist entries go with them.
52 lines
2.2 KiB
Python
52 lines
2.2 KiB
Python
"""ACP auth helpers — detect and advertise Hermes authentication methods."""
|
|
|
|
from __future__ import annotations
|
|
|
|
from typing import Any, Optional
|
|
|
|
|
|
TERMINAL_SETUP_AUTH_METHOD_ID = "hermes-setup"
|
|
|
|
|
|
def detect_provider() -> Optional[str]:
|
|
"""Resolve the active Hermes runtime provider, or None if unavailable.
|
|
|
|
A callable ``api_key`` (Azure Foundry Entra ID bearer-token provider, see
|
|
:mod:`agent.azure_identity_adapter`) counts as a valid credential; otherwise
|
|
Entra-configured Foundry deployments would default to ``"openrouter"`` and
|
|
the ACP auth handshake would reject the legitimate provider."""
|
|
try:
|
|
from hermes_cli.runtime_provider import resolve_runtime_provider
|
|
runtime = resolve_runtime_provider()
|
|
api_key, provider = runtime.get("api_key"), runtime.get("provider")
|
|
if isinstance(provider, str) and provider.strip() and (
|
|
(isinstance(api_key, str) and api_key.strip()) or callable(api_key)):
|
|
return provider.strip().lower()
|
|
except Exception:
|
|
pass
|
|
return None
|
|
|
|
|
|
def build_auth_methods() -> list[Any]:
|
|
"""Return registry-compatible ACP auth methods for Hermes.
|
|
|
|
The ACP registry requires at least one usable auth method in the initial
|
|
handshake. A fresh Zed install may have no Hermes credentials yet, so the
|
|
terminal setup method is always advertised; when credentials resolve, the
|
|
provider is also advertised as the default agent-managed runtime method."""
|
|
from acp.schema import AuthMethodAgent, TerminalAuthMethod
|
|
|
|
methods: list[Any] = []
|
|
provider = detect_provider()
|
|
if provider:
|
|
methods.append(AuthMethodAgent(
|
|
id=provider, name=f"{provider} runtime credentials",
|
|
description=f"Authenticate Hermes using the currently configured {provider} runtime credentials.",
|
|
))
|
|
methods.append(TerminalAuthMethod(
|
|
id=TERMINAL_SETUP_AUTH_METHOD_ID, name="Configure Hermes provider", type="terminal", args=["--setup"],
|
|
description=("Open Hermes' interactive model/provider setup in a terminal. "
|
|
"Use this when Hermes has not been configured on this machine yet."),
|
|
))
|
|
return methods
|