Files
hermes-agent/tools/browser_tool_install.py
ethernet 612d542281 Merge remote-tracking branch 'origin/main' into ethie/pm-clean
# Conflicts:
#	.gitignore
#	Dockerfile
#	agent/onboarding.py
#	apps/desktop/electron/main.ts
#	apps/desktop/electron/pool-stop.ts
#	apps/desktop/src/components/model-picker.test.tsx
#	apps/desktop/src/store/updates.ts
#	apps/desktop/vite.config.ts
#	datagen-config-examples/run_browser_tasks.sh
#	docs/rca-ssl-cacert-post-git-pull.md
#	gateway/run.py
#	hermes_cli/backup.py
#	hermes_cli/credential_lifecycle.py
#	hermes_cli/dashboard_procs.py
#	hermes_cli/doctor_state.py
#	hermes_cli/env_loader.py
#	hermes_cli/gateway_windows.py
#	hermes_cli/local_runtime/endpoint.py
#	hermes_cli/psutil_android.py
#	hermes_cli/update_cmd.py
#	hermes_cli/update_cmd_windows.py
#	hermes_cli/web_routers/local_models.py
#	hermes_cli/web_server_config.py
#	hermes_cli/web_server_cron.py
#	plugins/memory/hindsight/__init__.py
#	plugins/memory/holographic/__init__.py
#	plugins/memory/honcho/cli.py
#	plugins/memory/mem0/__init__.py
#	plugins/platforms/google_chat/oauth.py
#	plugins/platforms/photon/adapter.py
#	scripts/ci/list_os_marked_tests.py
#	scripts/run_tests.sh
#	tests/agent/test_compression_stall_fallback.py
#	tests/agent/test_create_openai_client_ssl_verify.py
#	tests/gateway/test_google_chat_oauth_dependencies.py
#	tests/hermes_cli/conftest.py
#	tests/hermes_cli/test_cli_init.py
#	tests/hermes_cli/test_gateway_migrate_multiplex.py
#	tests/hermes_cli/test_psutil_android_extract.py
#	tests/hermes_cli/test_relaunch.py
#	tests/hermes_cli/test_update_check.py
#	tests/hermes_cli/test_update_handoff_desktop_rebuild.py
#	tests/hermes_cli/test_worktree_gc.py
#	tests/scripts/desktop_update/test_desktop_update_windows_python_handoff.py
#	tests/scripts/desktop_update/test_desktop_update_windows_retry_policy.py
#	tests/scripts/desktop_update/test_desktop_update_windows_timestamp.py
#	tests/scripts/install/test_install_autostash_conflict_recovery.py
#	tests/scripts/install/test_install_clone_throttle_fallback.py
#	tests/scripts/install/test_install_commit_pin_rollback.py
#	tests/scripts/install/test_install_diverged_update.py
#	tests/scripts/install/test_install_lockfile_churn.py
#	tests/scripts/install/test_install_macos_launcher.py
#	tests/scripts/install/test_install_no_initial_commit.py
#	tests/scripts/install/test_install_ps1_ascii_only.py
#	tests/scripts/install/test_install_ps1_browser_install.py
#	tests/scripts/install/test_install_ps1_managed_node_swap.py
#	tests/scripts/install/test_install_ps1_native_stderr_eap.py
#	tests/scripts/install/test_install_ps1_node_path_for_npm.py
#	tests/scripts/install/test_install_ps1_python_fallback_venv.py
#	tests/scripts/install/test_install_ps1_resolver_strictmode.py
#	tests/scripts/install/test_install_ps1_uv_install_fallback.py
#	tests/scripts/install/test_install_ps1_uv_powershell_host.py
#	tests/scripts/install/test_install_ps1_venv_process_tree.py
#	tests/scripts/install/test_install_ps1_venv_recreate_safety.py
#	tests/scripts/install/test_install_ps1_venv_rename_abort.py
#	tests/scripts/install/test_install_ps1_venv_transaction_boundary.py
#	tests/scripts/install/test_install_ps1_web_server_syntax_probe.py
#	tests/scripts/install/test_install_scripts_computer_use.py
#	tests/scripts/install/test_install_sh_acp_launcher.py
#	tests/scripts/install/test_install_sh_bootstrap_marker.py
#	tests/scripts/install/test_install_sh_browser_install.py
#	tests/scripts/install/test_install_sh_install_method_stamp.py
#	tests/scripts/install/test_install_sh_node_deps_failure.py
#	tests/scripts/install/test_install_sh_node_deps_workspaces.py
#	tests/scripts/install/test_install_sh_node_global_prefix.py
#	tests/scripts/install/test_install_sh_node_npm_check.py
#	tests/scripts/install/test_install_sh_node_prerelease.py
#	tests/scripts/install/test_install_sh_node_probe.py
#	tests/scripts/install/test_install_sh_node_tarball_without_xz.py
#	tests/scripts/install/test_install_sh_pythonpath_sanitization.py
#	tests/scripts/install/test_install_sh_reuse_supported_python.py
#	tests/scripts/install/test_install_sh_root_fhs_uv_python_path.py
#	tests/scripts/install/test_install_sh_setup_wizard_tty_probe.py
#	tests/scripts/install/test_install_sh_symlink_stomp.py
#	tests/scripts/install/test_install_sh_termux_network_prereqs.py
#	tests/scripts/install/test_install_sh_termux_python_bounds.py
#	tests/scripts/install/test_install_sh_uv_lock_config.py
#	tests/scripts/install/test_install_unmerged_index.py
#	tests/scripts/test_run_tests_parallel.py
#	tests/test_managed_runtime_resolution.py
#	tests/test_project_metadata.py
#	tests/tools/test_browser_use_cli.py
#	tests/tools/test_tts_pythonpath_fallback.py
#	tests/tui_gateway/test_hosted_room_driver_runtime.py
#	tests/tui_gateway/test_tui_gateway_server.py
#	tools/lazy_deps.py
#	tools/voice_mode.py
#	uv.lock
#	website/docs/developer-guide/macos-bundle-updates.md
#	website/docs/developer-guide/pm-audit-status.md
#	website/docs/developer-guide/shared-bundle-builds.md
#	website/docs/developer-guide/source-update-completion.md
#	website/docs/developer-guide/stable-releases.md
2026-09-14 15:38:34 -04:00

185 lines
7.4 KiB
Python

"""PM-owned agent-browser / Chromium discovery, acquisition and readiness.
Split out of ``tools/browser_tool.py``. Facade-owned state is read through ``_bt`` (``tools.browser_tool``, resolved per call) — no import cycle."""
import functools
import os
import shutil
from hermes_constants import agent_browser_runnable, is_termux as _is_termux_environment
from tools.browser_tool_origin import origin_module as _origin
from tools import browser_tool_cdp as _cdp
from tools import browser_tool_cloud as _cloud
from tools import browser_tool_lightpanda_fallback as _lp
@functools.lru_cache(maxsize=1)
def _discover_homebrew_node_dirs() -> tuple[str, ...]:
"""Homebrew versioned Node bin dirs (node@20, ...) that ``brew`` may not link into /opt/homebrew/bin."""
homebrew_opt = "/opt/homebrew/opt"
try:
entries = os.listdir(homebrew_opt) if os.path.isdir(homebrew_opt) else []
except OSError:
entries = []
return tuple(
bin_dir
for entry in entries
if entry.startswith("node") and entry != "node"
if os.path.isdir(bin_dir := os.path.join(homebrew_opt, entry, "bin"))
)
def _browser_candidate_path_dirs() -> list[str]:
"""System PATH fallbacks for externally owned browser helpers."""
_bt = _origin()
return [*_discover_homebrew_node_dirs(), *_bt._SANE_PATH_DIRS]
def _merge_browser_path(existing_path: str = "") -> str:
"""Prepend browser-specific PATH fallbacks without reordering existing entries."""
path_parts = [p for p in (existing_path or "").split(os.pathsep) if p]
prefix_parts: list[str] = []
for part in _browser_candidate_path_dirs():
if part and part not in path_parts and part not in prefix_parts and os.path.isdir(part):
prefix_parts.append(part)
return os.pathsep.join(prefix_parts + path_parts)
def _browser_install_hint() -> str:
if _is_termux_environment():
return "npm install -g agent-browser && agent-browser install"
return "hermes pm install agent-browser (system libraries: npx playwright install-deps chromium)"
def _agent_browser_candidate_present(path: str | None) -> bool:
if not path:
return False
return os.path.isfile(path) and (os.name == "nt" or os.access(path, os.X_OK))
def _find_agent_browser(*, validate: bool = True) -> str:
"""Select PM's exact binary, then an external PATH/Homebrew installation.
Termux owns its browser installation. Elsewhere PM may acquire a missing
CLI at execution time, subject to its lazy-install policy. Readiness checks
(``validate=False``) never execute or install anything. Selection is not
cached: a new PM fact or profile must be visible immediately.
"""
import pm
termux = _is_termux_environment()
if not termux:
installed = pm.installed_package("agent-browser")
if installed and installed.binary is not None:
return str(installed.binary)
usable = agent_browser_runnable if validate else _agent_browser_candidate_present
for search_path in (None, _merge_browser_path("")):
if search_path == "":
continue
candidate = shutil.which("agent-browser", path=search_path)
if candidate and usable(candidate):
return candidate
hint = f"agent-browser CLI not found. Install it with: {_browser_install_hint()}"
if validate and not termux:
try:
pm.ensure("agent-browser")
except (pm.InstallError, OSError) as exc:
raise FileNotFoundError(f"{hint}\n{exc}") from exc
installed = pm.installed_package("agent-browser")
if installed and installed.binary is not None:
return str(installed.binary)
raise FileNotFoundError(hint)
def warm_agent_browser_npx_cache(timeout: float = 60.0) -> bool:
"""Historical updater export: no npx work is performed; relaunch instead."""
return False
def _chromium_installed() -> bool:
"""An explicit browser executable or PM's selected full Chromium exists."""
from hermes_cli.browser_runtime import chromium_executable
ab_path = chromium_executable()
return bool(ab_path and (os.path.isfile(ab_path) or shutil.which(ab_path)))
def _maybe_autoinstall_chromium() -> bool:
"""Install only PM's pinned full Chromium, never the upstream browser pair.
Docker supplies the binary. Other installs require lazy-install consent.
"""
_bt = _origin()
if _bt._chromium_autoinstall_attempted:
return _chromium_installed()
_bt._chromium_autoinstall_attempted = True
if _running_in_docker() or _is_termux_environment() or os.environ.get("AGENT_BROWSER_EXECUTABLE_PATH"):
return False
from pm import InstallError, ensure, lazy_installs_allowed
if not lazy_installs_allowed():
return False
_bt.logger.info("browser: installing PM's pinned Chromium")
try:
ensure("chromium")
except (InstallError, OSError) as exc:
_bt.logger.warning("browser: Chromium auto-install failed: %s", exc)
return False
return _chromium_installed()
def _running_in_docker() -> bool:
"""Best-effort detection of whether we're inside a Docker container."""
if os.path.exists("/.dockerenv"):
return True
try:
with open("/proc/1/cgroup", "rt", encoding="utf-8-sig") as fp:
return "docker" in fp.read()
except OSError:
return False
def check_browser_requirements() -> bool:
"""Whether the browser tools should be advertised.
Local mode needs the ``agent-browser`` CLI plus a Chromium build (except Lightpanda-only text workflows);
cloud mode needs the CLI plus provider credentials (the provider hosts its own Chromium).
"""
_bt = _origin()
# Browser Use CLI backend: browser_exec replaces the whole browser_* surface (incl. browser_cdp/browser_dialog check_fns).
if _bt._is_browser_use_cli_mode():
return False
# Camofox only needs the server URL, no agent-browser CLI.
if _bt._is_camofox_mode():
return True
# CDP override needs no local binary. Raw (no-I/O) check: this runs during schema build, where a stale endpoint must not cost a blocking probe.
if _cdp._get_cdp_override_raw():
return True
# Do not exec ``agent-browser --version`` here: Windows .cmd shims flash a console during Desktop startup. Execution paths still validate.
try:
_find_agent_browser(validate=False)
except FileNotFoundError:
return False
# Cloud mode also requires provider credentials; no local Chromium needed.
provider = _cloud._get_cloud_provider()
if provider is not None:
return provider.is_available()
# Lightpanda provides text/navigation tools without Chromium; screenshots/vision still return install errors.
if _lp._using_lightpanda_engine():
return True
# Local Chrome mode needs Chromium on disk or the CLI hangs until the command timeout.
return _chromium_installed()
def check_browser_vision_requirements() -> bool:
"""Advertise ``browser_vision`` only with BOTH a working browser AND a vision backend.
Without the vision check, the tool stays in the model's tool list even when no vision provider is
configured, then fails at call time with a cryptic provider-side error like ``unknown variant
`image_url`, expected `text``` (issue #31179).
"""
if not check_browser_requirements():
return False
from tools.vision_tools import check_vision_requirements
return check_vision_requirements()