Files
hermes-agent/hermes_cli/subcommands/debug.py
liuhao1024 77ca949b90 fix(cli): stop dpaste.com fallback from leaking debug logs for 7 days
The dpaste.com fallback path kept pastes for 7 days (vs the promised
6-hour auto-delete), could not be deleted by `hermes debug delete`
(anonymous pastes have no owner token), and the pending-paste sweep
skipped dpaste URLs entirely — while the share output still claimed
pastes auto-delete in 6 hours.

- Default the dpaste.com fallback retention to 1 day (dpaste's minimum)
  across --expire, upload_to_pastebin, and build_debug_share so the
  dashboard endpoint benefits too
- Print an accurate warning when uploads fall back to dpaste.com
  (retention window + no delete path) instead of the 6-hour promise
- Mention the fallback retention in the CLI and gateway privacy notices
  before the user consents to uploading
- Explain in `hermes debug delete` errors why dpaste.com pastes cannot
  be deleted and that they expire on their own

Refs #106164

[salvage: trimmed to 2 invariant tests (dpaste delete error, dpaste fallback notice);
5 duplicative default-value tests dropped]
2026-09-09 10:54:34 -07:00

66 lines
3.4 KiB
Python

"""``hermes debug`` subcommand parser."""
from __future__ import annotations
import argparse
from typing import Callable
def build_debug_parser(subparsers, *, cmd_debug: Callable) -> None:
"""Attach the ``debug`` subcommand to ``subparsers``."""
debug_parser = subparsers.add_parser(
"debug", help="Debug tools — upload logs and system info for support",
description="Debug utilities for Hermes Agent. Use 'hermes debug share' to "
"upload a debug report (system info + recent logs) to a paste "
"service and get a shareable URL.",
formatter_class=argparse.RawDescriptionHelpFormatter,
epilog="""\
Examples:
hermes debug share Upload debug report (asks for confirmation)
hermes debug share --yes Skip confirmation (for scripts/CI)
hermes debug share --lines 500 Include more log lines
hermes debug share --expire 30 Keep dpaste.com fallback pastes for 30 days
hermes debug share --local Print report locally (no upload)
hermes debug share --no-redact Disable upload-time secret redaction
hermes debug share --nous Upload to Nous-internal storage (private)
hermes debug delete <url> Delete a previously uploaded paste
""")
debug_sub = debug_parser.add_subparsers(dest="debug_command")
share_parser = debug_sub.add_parser(
"share", help="Upload debug report to a paste service and print a shareable URL")
share_parser.add_argument(
"--lines", type=int, default=200,
help="Number of log lines to include per log file (default: 200)")
share_parser.add_argument(
"--expire", type=int, default=1,
help="dpaste.com fallback retention in days (minimum 1; default: 1). "
"paste.rs pastes are always deleted after 6 hours, but if the "
"upload falls back to dpaste.com the pastes live for this many "
"days and cannot be deleted.")
share_parser.add_argument(
"--local", action="store_true", help="Print the report locally instead of uploading")
share_parser.add_argument(
"-y", "--yes", action="store_true",
help="Skip the confirmation prompt and upload immediately. Required "
"in non-interactive contexts (scripts/CI); without it, and with "
"no TTY on stdin, the command refuses rather than upload silently.")
share_parser.add_argument(
"--no-redact", action="store_true",
help="Disable upload-time secret redaction (default: redact). Logs "
"are normally run through agent.redact.redact_sensitive_text "
"with force=True before upload so credentials are not leaked "
"into the public paste service.")
share_parser.add_argument(
"--nous", action="store_true",
help="Upload the debug bundle to Nous-internal storage (AWS S3) instead "
"of a public paste service. The bundle is private — viewable only "
"by Nous staff (and allowlisted Discord mods) via a Google-login-"
"gated viewer — and auto-deletes after 14 days. Still force-redacts "
"secrets unless --no-redact is also passed.")
delete_parser = debug_sub.add_parser(
"delete", help="Delete a paste uploaded by 'hermes debug share'")
delete_parser.add_argument(
"urls", nargs="*", default=[],
help="One or more paste URLs to delete (e.g. https://paste.rs/abc123)")
debug_parser.set_defaults(func=cmd_debug)