fix(update): also ignore backups/ and the vault on flat installs; document the flat-install rule

`backups/` is where the pre-update snapshot the updater restores a swept
state.db FROM lives — leaving it unignored means the recovery copy is
swept together with the live database. `vault.key`/`vault.json.enc` are
the local secret vault.

Docs: website/docs/getting-started/updating.md explains that on a flat
install (checkout root == $HERMES_HOME) runtime state is git-ignored and
never enters the autostash.
This commit is contained in:
teknium1
2026-09-14 17:58:39 -07:00
committed by Teknium
parent 14ebd48c64
commit a172d76f2d
3 changed files with 11 additions and 2 deletions
+6 -2
View File
@@ -174,8 +174,9 @@ docs/superpowers/*
# WAL/SHM/journal sidecars and retired-WAL capture dirs, the legacy transcripts,
# the cron job store (jobs.json) and executions ledger, gateway lock/pid/state
# files, cache/spill directories, and the profile's own config/credential/
# memory/profile/pairing roots are Hermes-managed runtime state, never code
# changes. (`*-snapshots/` above already covers state-snapshots/.)
# memory/profile/pairing roots, the pre-update backups (the very copies a
# swept state.db is restored from) and the secret vault are Hermes-managed
# runtime state, never code changes. (`*-snapshots/` above already covers state-snapshots/.)
# Ignore them so `hermes update`'s `git stash push --include-untracked` cannot
# sweep the live state.db/-wal into the stash and unlink it under the running
# gateway (#110648). Nested installs keep all of this under $HERMES_HOME outside
@@ -219,6 +220,9 @@ docs/superpowers/*
/mcp-tokens/
/pairing/
/platforms/
/backups/
/vault.key
/vault.json.enc
# Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent)
.hermes-sandbox/
@@ -68,6 +68,9 @@ FLAT_INSTALL_RUNTIME_STATE = (
"mcp-tokens/server.json",
"pairing/telegram.json",
"platforms/pairing/x.json",
"backups/2026-09-14T06-00-00-pre-update/state.db",
"vault.key",
"vault.json.enc",
)
+2
View File
@@ -89,6 +89,8 @@ When the parked branch has **uncommitted changes** (dirty tree), Hermes does **n
When you run `hermes update` in a terminal, Hermes stashes any uncommitted source-tree changes, pulls, then **asks** whether to restore them — exactly as it always has. Nothing changes for interactive updates.
The autostash only ever covers *source-tree* changes. On a **flat install** — where the git checkout root is also `$HERMES_HOME` (for example an install made with `HERMES_INSTALL_DIR=$HERMES_HOME`, or one created by an older installer) — the profile's runtime state (`state.db` and its WAL/SHM sidecars, `state-snapshots/`, `backups/`, `sessions/`, `cron/jobs.json`, `cron/executions.db`, `config.yaml`, `auth.json`, `memories/`, lock/pid files, …) lives inside the checkout as untracked files. Those paths are git-ignored, so the autostash never touches them and the running gateway keeps its database through the update. If you keep other untracked files in a flat install's root, move them out of the checkout or add them to `.git/info/exclude`; anything untracked and not ignored is swept into the autostash like a source edit.
When the update runs **without a terminal** — from the desktop/chat app's "Update" button or a gateway-triggered update — there's no prompt to answer. The `updates.non_interactive_local_changes` setting decides what happens to your stashed changes:
```yaml