From 34a45b35e5fa5d8dfdf23a279c303781918df627 Mon Sep 17 00:00:00 2001 From: kshitijk4poor <82637225+kshitijk4poor@users.noreply.github.com> Date: Mon, 14 Sep 2026 23:16:14 +0530 Subject: [PATCH] fix(update): also ignore the flat-install config/credential/profile roots The same `git stash push --include-untracked` sweep that took state.db on a flat install (#110648) also takes every other untracked file at the $HERMES_HOME root: config.yaml, auth.json/auth.lock, memories/, profiles/, .credentials/, mcp-tokens/ and pairing/. Losing those on a declined or failed restore strands the user's credentials and profile config just as badly as losing the session store. Extend the root-anchored block with those paths (none are tracked or already ignored on main) and append them to the test's FLAT_INSTALL_RUNTIME_STATE list so the existing stash invariant covers them without a new test. --- .gitignore | 13 +++++++++++-- .../test_update_flat_install_state_gitignore.py | 11 ++++++++++- 2 files changed, 21 insertions(+), 3 deletions(-) diff --git a/.gitignore b/.gitignore index b187c7a36a..f5d6f7ee37 100644 --- a/.gitignore +++ b/.gitignore @@ -172,8 +172,9 @@ docs/superpowers/* # with HERMES_INSTALL_DIR=$HERMES_HOME or by older installers): the live session # store, its SQLite sidecars and retired-WAL capture dirs, quick snapshots, the # legacy transcripts, the cron job store (jobs.json) and executions ledger, -# gateway lock/pid files, and cache/spill directories are Hermes-managed runtime -# state, never code changes. +# gateway lock/pid files, cache/spill directories, and the profile's own +# config/credential/memory/profile roots are Hermes-managed runtime state, +# never code changes. # Ignore them so `hermes update`'s `git stash push --include-untracked` cannot # sweep the live state.db/-wal into the stash and unlink it under the running # gateway (#110648). Nested installs keep all of this under $HERMES_HOME outside @@ -196,6 +197,14 @@ docs/superpowers/* /gateway.pid /hook_outputs/ /cache/ +/config.yaml +/auth.json +/auth.lock +/memories/ +/profiles/ +/.credentials/ +/mcp-tokens/ +/pairing/ # Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent) .hermes-sandbox/ diff --git a/tests/hermes_cli/test_update_flat_install_state_gitignore.py b/tests/hermes_cli/test_update_flat_install_state_gitignore.py index 55fe11753f..9fff6e7583 100644 --- a/tests/hermes_cli/test_update_flat_install_state_gitignore.py +++ b/tests/hermes_cli/test_update_flat_install_state_gitignore.py @@ -22,7 +22,8 @@ REPO_ROOT = Path(__file__).resolve().parents[2] # (gateway/platforms/base.py _ROOT_CREDENTIAL_PATHS enumerates the same set) and # retired-WAL capture dirs, quick snapshots, the legacy transcript dir, the # default kanban board, the cron job store (cron/jobs.py JOBS_FILE) and -# executions ledger, gateway lock/pid files and the cache/spill directories. +# executions ledger, gateway lock/pid files, the cache/spill directories and the +# config/auth/memory/profile/credential/pairing roots. FLAT_INSTALL_RUNTIME_STATE = ( "state.db", "state.db-wal", @@ -42,6 +43,14 @@ FLAT_INSTALL_RUNTIME_STATE = ( "gateway.pid", "hook_outputs/2026-09-14_06-00-00/tool.json", "cache/banner_snapshot.json", + "config.yaml", + "auth.json", + "auth.lock", + "memories/MEMORY.md", + "profiles/work/config.yaml", + ".credentials/github_token", + "mcp-tokens/server.json", + "pairing/telegram.json", )