fix(update): ignore flat-install runtime state by class, not by file name

The flat-install block listed state.db and kanban.db sidecars one by one,
so any other root-level SQLite store (response_store.db, a future ledger)
and its -wal/-shm/-journal sidecars would still be swept by the updater's
`git stash push --include-untracked` and unlinked under the running
gateway (#110648). Replace the per-file lines with root-anchored globs
(`/*.db`, `/*.db-wal`, ...). No tracked root-level *.db exists, and
`git ls-files -ci --exclude-standard` is unchanged before/after, so the
globs newly ignore nothing that is committed.

Also add the rest of the flat-install runtime roots the previous fold
missed: the credential siblings from
gateway/platforms/base.py::_ROOT_CREDENTIAL_PATHS (.anthropic_oauth.json,
google_token.json, google_oauth_pending.json, auth/,
webhook_subscriptions.json), the active pairing location platforms/
(gateway/pairing.py), kanban/, gateway_state.json, processes.json,
cron.pid, the channel directory/alias and feishu pairing stores,
pending_messages/, checkpoints/, plugin-data/, hooks/, and the Discord
message-recovery db under gateway/ (gateway/ itself is tracked, so only
that file pattern is ignored). `/.credentials/` had no producer -- the
real dir is `credentials/` (web_routers/files.py, _ROOT_CREDENTIAL_PATHS)
-- so it is replaced. `/state-snapshots/` is dropped: the existing
unanchored `*-snapshots/` rule already matches it.

The test tuple now carries one representative per ignored class and its
comment no longer claims _ROOT_CREDENTIAL_PATHS enumerates the sidecar
set (that is `_sqlite_files`).
This commit is contained in:
kshitijk4poor
2026-09-15 00:19:02 +05:30
committed by kshitij
parent 34a45b35e5
commit 3ce06055d6
2 changed files with 55 additions and 27 deletions
+31 -17
View File
@@ -169,42 +169,56 @@ docs/superpowers/*
.hermes-bootstrap-complete
# Flat-install runtime state (checkout root == $HERMES_HOME, e.g. installs made
# with HERMES_INSTALL_DIR=$HERMES_HOME or by older installers): the live session
# store, its SQLite sidecars and retired-WAL capture dirs, quick snapshots, the
# legacy transcripts, the cron job store (jobs.json) and executions ledger,
# gateway lock/pid files, cache/spill directories, and the profile's own
# config/credential/memory/profile roots are Hermes-managed runtime state,
# never code changes.
# with HERMES_INSTALL_DIR=$HERMES_HOME or by older installers): every root-level
# SQLite store (state.db, kanban.db, response_store.db, ...) with its
# WAL/SHM/journal sidecars and retired-WAL capture dirs, the legacy transcripts,
# the cron job store (jobs.json) and executions ledger, gateway lock/pid/state
# files, cache/spill directories, and the profile's own config/credential/
# memory/profile/pairing roots are Hermes-managed runtime state, never code
# changes. (`*-snapshots/` above already covers state-snapshots/.)
# Ignore them so `hermes update`'s `git stash push --include-untracked` cannot
# sweep the live state.db/-wal into the stash and unlink it under the running
# gateway (#110648). Nested installs keep all of this under $HERMES_HOME outside
# the checkout, where the `.hermes/` rule above already applies.
/state.db
/state.db-wal
/state.db-shm
/state.db-journal
/state.db.retired-wal-*/
/kanban.db
/kanban.db-wal
/kanban.db-shm
/kanban.db-journal
/state-snapshots/
/*.db
/*.db-wal
/*.db-shm
/*.db-journal
/*.db.retired-wal-*/
/gateway/discord_message_recovery.db*
/sessions/
/browser-profile/
/cron/executions.db
/cron/jobs.json
/cron.pid
/gateway.lock
/gateway.pid
/gateway_state.json
/processes.json
/hook_outputs/
/hooks/
/cache/
/checkpoints/
/pending_messages/
/plugin-data/
/kanban/
/config.yaml
/auth.json
/auth.lock
/auth/
/.anthropic_oauth.json
/google_token.json
/google_oauth_pending.json
/webhook_subscriptions.json
/channel_directory.json
/channel_aliases.json
/feishu_comment_pairing.json
/memories/
/profiles/
/.credentials/
/credentials/
/mcp-tokens/
/pairing/
/platforms/
# Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent)
.hermes-sandbox/