Files
hermes-agent/agent/i18n.py
Teknium a9838c2100 fix(multiplex): tool and memory-provider env reads stay inside the routed profile
Under gateway.multiplex_profiles, os.environ holds the DEFAULT profile's .env; a
secondary profile's values exist only in the per-turn secret scope. Every reader
below still read os.environ/os.getenv at call time, so a secondary profile's turn
silently used the default profile's value.

Credentials (F6): FIRECRAWL_API_KEY (read_file hosted OCR), OPENVIKING_API_KEY,
mem0-OSS OPENAI_API_KEY, MODAL_TOKEN_ID/SECRET and BROWSER_USE_API_KEY presence
gates, and the xAI video plugin's os.getenv("XAI_API_KEY") fallback AFTER the
scoped resolver had already missed — the exact fallback-after-miss shape
gateway/AGENTS.md forbids. Deleted, not re-scoped: the resolver is the scope.

Identity / tenant (F7): MEM0_USER_ID/AGENT_ID/HOST/MODE, SUPERMEMORY_CONTAINER_TAG,
RETAINDB_PROJECT, OPENVIKING_ACCOUNT/USER/AGENT (and the whole layered() env
read), HINDSIGHT_BANK_ID/MODE/retain shaping, HERMES_HONCHO_HOST. A raw read
put a secondary profile's memories into the default profile's account/bank/
project/tenant and recalled them back into the default's turns. Each now uses
get_secret with the provider's own per-profile default on a miss.

Endpoints (F8): OPENAI_BASE_URL (aux custom runtime + direct-alias expansion),
XAI_BASE_URL/HERMES_XAI_BASE_URL (aux OAuth), NOUS_INFERENCE_BASE_URL (#65941,
both the aux builder and hermes_cli.auth_nous._nous_inference_env_override),
GATEWAY_PROXY_URL (same UnscopedSecretError-only fallback shape as
GATEWAY_PROXY_KEY three lines below), FIRECRAWL_API_URL, BROWSERBASE_BASE_URL,
SUPERMEMORY/RETAINDB/HONCHO/HINDSIGHT URLs. The keys beside them were already
scoped, so a secondary's key was sent to the default profile's proxy or host.

Targets / display (F11): WEIXIN_HOME_CHANNEL (message posted into the default's
chat), HERMES_LANGUAGE, and agent/i18n's process-wide lru_cache of
display.language — now keyed by HERMES_HOME.

Outbound webhooks: hooks.outbound[].secret_env resolved from os.environ while
the gateway registers each profile's targets inside that profile's scope, so a
secondary's deliveries were signed with the default's secret or left unsigned.

Agent-cache eviction: _spawn_release_thread started a bare threading.Thread, so
commit_memory_session -> provider on_session_end ran with an EMPTY context. The
thread now runs copy_context() and, for the unscoped housekeeping sweep, enters
the owning profile's _profile_runtime_scope resolved from the session key
(agent:<profile>:...). The pressure batch does the same per key.

session_search (#82903): agent/inline_tool_executors.py::_session_search
forwarded every schema argument except `profile`, so a gateway agent could
never select a named profile's store. Forwarded; the ownership-scoping design
in #87779/#87847 is a separate design call and is not attempted here.

Live repro (/tmp/mux_audit/fix-tool-memory-reads/repro.py): 28 FAIL on
origin/main -> 0 FAIL with this change; 10 new invariant tests red on base.

Fixes #82903
Fixes #65941
Fixes #99121
Addresses #87779
Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com>
Co-authored-by: Michael Versluis (Berry) <michael@wve.nl>
2026-09-11 15:26:46 -07:00

182 lines
7.5 KiB
Python

"""Lightweight i18n for Hermes' static user-facing strings (approval prompts, a few gateway replies).
Catalogs are ``locales/<lang>.yaml`` flattened to dotted keys. Missing keys
fall back to English, then to the key itself, so a broken catalog never crashes.
Language resolution: explicit ``lang=`` > ``HERMES_LANGUAGE`` > ``display.language`` > ``en``.
"""
from __future__ import annotations
import logging
import os
import threading
from functools import lru_cache
from pathlib import Path
from typing import Any
logger = logging.getLogger(__name__)
SUPPORTED_LANGUAGES: tuple[str, ...] = (
"en", "zh", "zh-hant", "ja", "de", "es", "fr", "tr", "uk",
"af", "ko", "it", "ga", "pt", "ru", "hu", "ar",
)
DEFAULT_LANGUAGE = "en"
# Natural aliases so "chinese" / "zh-CN" / "jp" hit the right catalog instead of
# silently falling back to English. Bare "chinese" defaults to Simplified;
# Taiwan/HK/Macau tags route to the distinct Traditional catalog. pt-br shares
# the pt catalog (no separate br one).
_LANGUAGE_ALIASES: dict[str, str] = {
"english": "en", "en-us": "en", "en-gb": "en",
"chinese": "zh", "mandarin": "zh", "zh-cn": "zh", "zh-hans": "zh", "zh-sg": "zh",
"traditional-chinese": "zh-hant", "traditional_chinese": "zh-hant",
"zh-tw": "zh-hant", "zh-hk": "zh-hant", "zh-mo": "zh-hant",
"japanese": "ja", "jp": "ja", "ja-jp": "ja",
"german": "de", "deutsch": "de", "de-de": "de", "de-at": "de", "de-ch": "de",
"spanish": "es", "español": "es", "espanol": "es", "es-es": "es", "es-mx": "es", "es-ar": "es",
"french": "fr", "français": "fr", "france": "fr", "fr-fr": "fr", "fr-be": "fr", "fr-ca": "fr", "fr-ch": "fr",
"ukrainian": "uk", "ukrainisch": "uk", "українська": "uk", "uk-ua": "uk", "ua": "uk",
"turkish": "tr", "türkçe": "tr", "tr-tr": "tr",
"afrikaans": "af", "af-za": "af",
"korean": "ko", "한국어": "ko", "ko-kr": "ko",
"italian": "it", "italiano": "it", "it-it": "it", "it-ch": "it",
"irish": "ga", "gaeilge": "ga", "ga-ie": "ga",
"portuguese": "pt", "português": "pt", "portugues": "pt",
"pt-pt": "pt", "pt-br": "pt", "brazilian": "pt", "brasileiro": "pt",
"russian": "ru", "русский": "ru", "ru-ru": "ru",
"hungarian": "hu", "magyar": "hu", "hu-hu": "hu",
"arabic": "ar", "العربية": "ar",
"ar-sa": "ar", "ar-eg": "ar", "ar-ae": "ar", "ar-ma": "ar", "ar-dz": "ar",
}
_catalog_cache: dict[str, dict[str, str]] = {}
_catalog_lock = threading.Lock()
def _locales_dir() -> Path:
"""Locale dir: ``HERMES_BUNDLED_LOCALES`` (sealed packaging, e.g. Nix) if it exists, else ``<repo-root>/locales``.
The source path is returned even when missing so ``_load_catalog`` can log
the path it looked at rather than raise.
"""
override = os.getenv("HERMES_BUNDLED_LOCALES", "").strip()
if override and Path(override).is_dir():
return Path(override)
if override:
logger.warning(
"HERMES_BUNDLED_LOCALES points to a non-directory path (%s); "
"falling back to bundled/source locale resolution", override,
)
return Path(__file__).resolve().parent.parent / "locales"
def _normalize_lang(value: Any) -> str:
"""Map a user-supplied value (code, alias, or regional tag like ``zh-CN``) to a supported code, else default."""
key = value.strip().lower() if isinstance(value, str) else ""
if key in SUPPORTED_LANGUAGES:
return key
if key in _LANGUAGE_ALIASES:
return _LANGUAGE_ALIASES[key]
base = key.split("-", 1)[0] # strip region suffix
return base if base in SUPPORTED_LANGUAGES else DEFAULT_LANGUAGE
def _cache_catalog(lang: str, flat: dict[str, str]) -> dict[str, str]:
with _catalog_lock:
_catalog_cache[lang] = flat
return flat
def _load_catalog(lang: str) -> dict[str, str]:
"""Load one locale YAML flattened to dotted keys; cached per language (empty dict on any failure)."""
with _catalog_lock:
cached = _catalog_cache.get(lang)
if cached is not None:
return cached
path = _locales_dir() / f"{lang}.yaml"
flat: dict[str, str] = {}
if not path.is_file():
logger.debug("i18n catalog missing for %s at %s", lang, path)
return _cache_catalog(lang, flat)
try:
import yaml
with path.open("r", encoding="utf-8") as f:
_flatten_into(yaml.safe_load(f) or {}, "", flat)
except Exception as exc:
logger.warning("Failed to load i18n catalog %s: %s", path, exc)
flat = {}
return _cache_catalog(lang, flat)
def _flatten_into(node: Any, prefix: str, out: dict[str, str]) -> None:
# Non-string, non-dict leaves are ignored -- catalogs are text-only.
if isinstance(node, dict):
for key, value in node.items():
_flatten_into(value, f"{prefix}.{key}" if prefix else str(key), out)
elif isinstance(node, str):
out[prefix] = node
@lru_cache(maxsize=8)
def _config_language_cached(hermes_home: str) -> str | None:
"""``display.language`` from config.yaml, read once per profile home (``t()`` is a hot path).
Keyed by home so a multiplexed gateway serving several profiles doesn't freeze the first
profile's language for every other profile."""
try:
from hermes_cli.config import load_config_readonly
lang = (load_config_readonly().get("display") or {}).get("language")
return _normalize_lang(lang) if lang else None
except Exception as exc:
logger.debug("Could not read display.language from config: %s", exc)
return None
def _config_language() -> str | None:
from hermes_constants import get_hermes_home
return _config_language_cached(str(get_hermes_home()))
def reset_language_cache() -> None:
"""Invalidate cached language resolution and catalogs (call after ``save_config`` changes ``display.language``)."""
_config_language_cached.cache_clear()
with _catalog_lock:
_catalog_cache.clear()
def get_language() -> str:
"""Resolve the active language using env > config > default order. ``HERMES_LANGUAGE`` is a
per-profile ``.env`` value, so it is read through the secret scope: under multiplexing a raw
environ read would impose the default profile's language on every other profile."""
from agent.secret_scope import UnscopedSecretError, get_secret
try:
env_lang = get_secret("HERMES_LANGUAGE")
except UnscopedSecretError:
env_lang = os.environ.get("HERMES_LANGUAGE") # unscoped default-profile path: environ IS its own value
return _normalize_lang(env_lang) if env_lang else _config_language() or DEFAULT_LANGUAGE
def t(key: str, lang: str | None = None, **format_kwargs: Any) -> str:
"""Translate a dotted catalog key to the active (or explicit ``lang``) language.
``format_kwargs`` are applied with ``str.format``. Falls back to English,
then to the bare key; a format failure returns the unformatted string.
"""
target = _normalize_lang(lang) if lang else get_language()
value = _load_catalog(target).get(key)
if value is None and target != DEFAULT_LANGUAGE:
value = _load_catalog(DEFAULT_LANGUAGE).get(key)
if value is None:
logger.debug("i18n miss: key=%r lang=%r", key, target)
value = key
if not format_kwargs:
return value
try:
return value.format(**format_kwargs)
except (KeyError, IndexError, ValueError) as exc:
logger.warning("i18n format failed for key=%r lang=%r kwargs=%r: %s", key, target, format_kwargs, exc)
return value
__all__ = ["SUPPORTED_LANGUAGES", "DEFAULT_LANGUAGE", "t", "get_language", "reset_language_cache"]