Standalone Python cannot locate the system CA bundle on this NixOS host. Use the shell-staged uv to prepare the independent PM runtime before PM fetches managed Python. Declare and lock truststore in that runtime, then activate it before CLI and worker imports construct HTTPS clients. Make setup's awk pin reader follow object nesting rather than indentation. Use the same reader for tool versions and artifact fields. Verified cold activation with CA overrides removed, pinned Python and uv downloads, pm doctor, and a public worker HTTPS install. The targeted suite passed 56 tests with one Windows-only skip. The TLS regression fails when truststore is installed but entrypoint activation is removed. Bash syntax and Ruff checks passed. The full suite was not run. Two additional setup-toolchain tests fail on unchanged HEAD because their fixtures reach the real home before home isolation. CI bootstrap unification is not part of this change.
18 lines
334 B
TOML
18 lines
334 B
TOML
[project]
|
|
name = "hermes-pm-runtime"
|
|
version = "0.0.0"
|
|
requires-python = ">=3.14,<3.15"
|
|
dependencies = [
|
|
"packaging==26.0",
|
|
"tomli-w==1.2.0",
|
|
"ruamel.yaml==0.18.17",
|
|
"truststore==0.10.4",
|
|
]
|
|
|
|
[tool.uv]
|
|
package = false
|
|
|
|
# Deliberately independent: repairing the app cannot require resolving it.
|
|
[tool.uv.workspace]
|
|
members = []
|