Commit Graph

2901 Commits

Author SHA1 Message Date
Teknium 1735ccde44 fix(tools): always redact durable process receipts 2026-09-07 08:25:33 -07:00
Teknium 0522ae934e fix(tools): retain producer profile scope in process readers 2026-09-07 08:25:33 -07:00
Teknium fbed1d4584 fix(tools): keep retained terminal results scoped to their owner
Capture the durable parent session before output readers start, including CLI
and non-notifying spawns. Require that parent or its compression continuation
for retained reads; exact and prefix handles alone do not authorize access.

Live Linux terminal/one-shot linger/fresh-reader A/B: base loses results;
updated owner recovers both streams and exit 7. Unbound, foreign session,
delegated child, and other profile cannot recover the receipt. No notifications
are replayed. Full tools suite is queued behind the campaign test lock.

Follow-up to contributor salvage #104805 for #104511.
2026-09-07 08:25:33 -07:00
maximilliangrand 633955408b fix(tools): keep retained result reads off live status scans 2026-09-07 08:25:33 -07:00
maximilliangrand b72e373e23 fix(tools): retain completed background process results across exit 2026-09-07 08:25:33 -07:00
Teknium f94307a7f7 fix: ignore malformed MCP OAuth metadata caches
Guard device metadata subtype selection with a dictionary check so valid
non-object JSON reaches the existing validation-and-ignore path. Preserve
null handling, cache contents, and normal/device metadata cold-load types.
Extend the existing corrupt-cache invariant rather than adding test functions.

Live filesystem A/B reproduces list/string/number/boolean AttributeError on
the prior head and clean ignore after this change. Nine CLI OAuth wire
scenarios, browser S256 and profile-scoped storage controls pass locally.
2026-09-07 08:22:35 -07:00
Teknium 965f18b02f fix: restore prior device OAuth state if persistence fails 2026-09-07 08:22:35 -07:00
Teknium f5afe8bd40 feat: authorize MCP servers with device codes from the CLI
Add explicit RFC 8628 device login and oauth.flow selection while keeping
browser PKCE and the SDK runtime refresh path. Reuse issuer/resource
validation, configured client authentication and profile-scoped storage.
Only persist an approved, validated grant; never echo endpoint error bodies.

Slim redo of #104752 by @wjorgensen, replacing duplicate HTTP/storage
wrappers with the existing SDK and two real-wire invariant tests.

Refs #104742
Co-authored-by: Wes Hermes <weshermes@Wess-Mac-mini.localdomain>
2026-09-07 08:22:35 -07:00
Teknium 549e6aab38 fix(bot-mode): preserve refusal reasons across local delivery
Emit the one-shot reason marker outside the CLI facade; parse whole codes before falling back to legacy prose. Explicit coordination and unknown codes cannot be labeled target_busy.

Fixes #104784
Co-authored-by: William Echo <2054936695@qq.com>
2026-09-07 08:15:32 -07:00
Teknium 8aaf1aca62 fix(schemas): preserve required intent without invalid boolean flags
Normalize boolean required only at schema positions; lift true property flags into parent arrays. Preserve literal default/const/extension data.

Fixes #104796
Inspired by #104831 and the lifting proposal by @AdJIa.
2026-09-07 08:14:51 -07:00
Teknium 7876d183c9 fix(approval): recover legacy list values without character grants
Recover legacy stringified lists with a warning. Reject malformed shapes and nonstring members without admitting approvals or rewriting user config on read.

Fixes #104779
Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>
2026-09-07 08:13:38 -07:00
Teknium 5904c7a395 fix(threats): keep unrelated role prose in context files
Salvage the bounded target-slot design from #104617, using mandatory
word separators to avoid ambiguous repeated matches. Preserve long
payload detection and execution-verb boundaries. Replace the three
candidate tests with two context-loader invariants and document the
heuristic's limits.

Fixes #104609
Co-authored-by: Konstantin Khlopkov <konstantin.khlopkov93@gmail.com>
2026-09-07 08:09:20 -07:00
Teknium 7a5fc1b2a9 fix: remove automatic session JSON snapshots 2026-09-07 08:08:41 -07:00
Teknium 64950092d5 test: align delegated-child env tests with retained board routing
The descendant fence now keeps HERMES_KANBAN_DB/BOARD/WORKSPACE so a
fenced child can still read the board it belongs to; only worker identity
(TASK, RUN_ID, CLAIM_LOCK) is scrubbed. Three pre-existing tests still
asserted the DB var was dropped and went red on CI.
2026-09-07 07:10:28 -07:00
Teknium b578261584 fix: keep Kanban worker scope out of descendant processes
Carry the existing write fence across Hermes-owned spawn boundaries without
dropping board routing or changing credential policy. Grant dispatcher and
managed tool runtimes explicit task scope; align CLI task mutations with tools.

Verify real shell/CLI descendants, dispatcher startup, and supervised stdio
transport against isolated SQLite boards. This is cooperative runtime scoping,
not OS confinement.

Refs #103974, #104058, #104904
2026-09-07 07:10:28 -07:00
Teknium 9745a7f0f1 fix(terminal): show sudo password prompts for paths and env prefixes 2026-09-07 07:09:30 -07:00
Teknium 727c2d7525 fix: accept the live ClawHub version-list response shape 2026-09-07 07:05:59 -07:00
Teknium 76de6ec5a8 fix: retain ClawHub owner through version and bundle requests 2026-09-07 07:05:59 -07:00
liuhao1024 f986a2b103 fix(skills): pass the ClawHub owner hint as ?owner= so ambiguous slugs resolve
ClawHub's detail endpoint now answers a slug claimed by multiple owners
with 409 AMBIGUOUS_SKILL_SLUG; the bare GET in _skill_detail returned
None for every such slug, so 'skills install clawhub/@owner/slug' (and
the owner/skills/slug URL form) failed at fetch time even though the
requester already knew the owner (#104117).

- _skill_detail forwards expected_owner as the ?owner= query param on
  the detail GET (params already flows through _get_json's **kwargs).
- _parse_identifier also accepts the clawhub/@owner/slug combination:
  the @ surfaces only after the clawhub/ prefix is stripped, so the
  had_at check now re-runs on the stripped form. GitHub-style
  owner/repo/skill paths stay rejected.
2026-09-07 07:05:59 -07:00
Teknium 05315a6f26 fix: keep pagination signature inspection local and preserve exact decoder error 2026-09-07 07:04:52 -07:00
holny 55c223e247 fix(mcp): probe the list signature instead of masking its TypeError (#104150)
_paginate_full_list wrapped the paginated list call in try/except TypeError
to detect the mcp 1.x calling convention. The same except also caught
TypeErrors raised INSIDE the modern list call — e.g. a server response
decode failure — and retried with the legacy cursor= keyword, replacing the
real error with a misleading 'unexpected keyword argument cursor' and
making genuine MCP pagination failures undiagnosable.

Probe list_method's signature instead (_list_method_accepts_params): the
legacy cursor= fallback fires only when the method genuinely doesn't accept
the mcp 2.0 params= keyword (or takes **kwargs), so a TypeError from inside
the list call propagates to the caller. Regression tests: the decode
TypeError surfaces and the legacy retry doesn't run; a genuinely 1.x-shaped
method keeps using the cursor fallback.
2026-09-07 07:04:52 -07:00
Teknium c89f3b8800 fix(delegation): one completion per call by default; queued units no longer stalled; tell the model results land between turns
Three orchestrator failures traced through the Sep 7 gpt-6-astra campaign sessions:

1. delegation.independent_completions (new, default false). #104299 made every
   ungrouped task its own completion message, so a 15-task call woke the
   orchestrator up to 15 times; one chain received 132 notices and answered
   130 of them with "already incorporated". A multi-task call now returns as
   ONE consolidated message unless the flag is on; `group` is inert until then.

2. Queued units were killed before they started. Units of one call share a
   pool slot but the executor was still sized by slots, so with 15 units live
   a new unit queued behind a full pool; the stale monitor's clock ran from
   dispatch, interrupted it at 450 s, and the child exited `interrupted 0.02s`
   when its thread finally came up (13 such lanes in one session). The
   executor now grows to the number of live units and the stall clock arms
   when the runner actually starts.

3. The tool text said "do not wait or poll — just continue" without saying
   that completions are delivered only BETWEEN turns. A model that never ends
   its turn (one 203-minute turn, 717 API calls) never received 40 finished
   results. Tool description, dispatch note and completion header now say to
   finish independent work, give a one-line status, and end the turn.
2026-09-07 06:46:54 -07:00
Teknium fe04d5b36d test: preserve metadata and passthrough assertions after cap removal 2026-09-07 06:15:43 -07:00
Teknium 27f32bd50b test: exercise output-cap removal across native and child surfaces 2026-09-07 06:15:43 -07:00
Teknium fd3565deec fix: remove dedicated user-facing output cap controls 2026-09-07 06:15:43 -07:00
Teknium 65f033a1a2 fix(execute-code): teach the working helper import contract
Slim adaptation of #83772 to the current schema and failure-hint table.
Generated helpers are module exports on every execution path, not globals.
Correct schema, recovery hints and CLI tip rather than injecting names or
changing the execution boundary. Two registry-driven invariants reproduce
both misleading instructions on main and execute the corrected guidance.

Additional tool fix discovered during campaign #104904.
Original diagnosis and correction: @yuzilongleif-collab (#83772).

Co-authored-by: yuzilongleif-collab <235949691+yuzilongleif-collab@users.noreply.github.com>
2026-09-07 06:12:24 -07:00
Teknium 57c60f2e0c fix: explain the launchctl registration restriction without inventing KeepAlive 2026-09-07 06:05:51 -07:00
Teknium 746b14b900 test: use explicit UTF-8 in file sync fixtures 2026-09-07 06:02:41 -07:00
liuzikaii b4e0f4a7bb fix(file-sync): hash the uploaded snapshot instead of mutable host files 2026-09-07 06:02:41 -07:00
Teknium f8c9e93dad fix: round-trip checkpoint path bytes without text translation 2026-09-07 06:00:46 -07:00
liuzikaii d77df6674a fix(checkpoints): preserve literal paths in Git filename output 2026-09-07 06:00:46 -07:00
Teknium a3ad585fd9 fix: limit skill update change to unusable local installs 2026-09-07 05:59:43 -07:00
Teknium 6798a9b8a4 fix: bound skill update wait budget and lingering fetch workers 2026-09-07 05:59:43 -07:00
Teknium 2079e4f08d fix: skip lock entries replaced by non-directory files 2026-09-07 05:59:43 -07:00
Teknium 36b0b6c9f2 fix: enforce complete fetch deadlines and inherit request context 2026-09-07 05:59:43 -07:00
liuhao1024 47887693c6 fix(skills): skip orphaned hub entries and bound per-fetch time in update checks
check_for_skill_updates() fetched every lock-file entry remotely, even
when the entry's install directory no longer existed, and each fetch had
no wall-clock bound — a few dead sources turned a routine
`hermes skills update` into a multi-minute stall (#104291).

- Entries whose recorded install_path resolves but does not exist are
  reported as "orphaned" and skipped without a remote fetch;
  unresolvable paths keep the previous fetch behavior.
- Each fetch now runs under a daemon helper thread with a hard timeout
  (default 30 s) and degrades to "unavailable" when abandoned.
- `hermes skills check` prints a removal hint for orphaned entries.

Fixes #104291
2026-09-07 05:59:43 -07:00
Teknium 76af5ebf09 test: release notification fixtures without writable stdin 2026-09-07 05:57:26 -07:00
Teknium 231828cdac test: synchronize child exit with notification admission 2026-09-07 05:57:26 -07:00
Teknium cfe07df09f test(agent): assert owner-scoped teardown instead of bulk cleanup 2026-09-07 04:38:59 -07:00
Teknium 0d8a1575c5 refactor(mcp): keep the passive status RPC, drop the SDK contract and reason codes
mcp.servers.status now rides the shared _mcp_rpc decorator (profile scope, 4064,
5024 with the real message) instead of a hand-rolled try/finally with a blanket
except. Drop the _MCPConnectErrorText str subclass and reason taxonomy: the
existing status/error fields already carry the state, and a whitelist on the RPC
keeps error text out of the wire. The Desktop connections.health contribution
contract is held back until its consumer plugin is public. Tests trimmed to the
scope invariants (per-profile runtime visibility, scoped shutdown clears only its
own status, launch runtime never leaks into another profile).
2026-09-06 13:18:19 -07:00
Joey a6699d60f4 feat(mcp): expose profile-scoped cached connection health 2026-09-06 13:18:19 -07:00
Teknium b167e81750 fix: legacy Bot Mode section in SOUL.md no longer taxes every session or shadows the live roster
Older desktop builds appended a frozen "## Messaging other agents" section (roster
included) to SOUL.md. Since the server started injecting the live section into Bot Chat
sessions, that copy did two wrong things: every CLI/TUI/messenger session paid ~600 tok
for a bot-only protocol, and in Bot Chat itself the probe went silent when SOUL carried
the heading, so bots saw the stale roster instead of the live one.

- load_soul_md strips the legacy section at read time (covers un-migrated profiles and
  the ambient-home edge cases the same way the SOUL isolation fix does)
- bot_mode_probe drops the SOUL-carries-heading suppression; a SOUL-era stored Bot Chat
  prompt now counts as legacy and is upgraded once (stamped, so it cannot loop)
- config migration v41 rewrites SOUL.md across the default + every profile once
2026-09-06 13:08:31 -07:00
Teknium d0090a147c Merge remote-tracking branch 'origin/main' into fix/async-batch-task-failure-notice
# Conflicts:
#	tools/delegate_tool_dispatch.py
2026-09-06 12:07:50 -07:00
Teknium 6d9c166455 Merge pull request #103529 from NousResearch/fix/terminal-auto-background
fix(terminal): an over-cap foreground timeout runs as a tracked background process instead of being refused (454 refusals in one run)
2026-09-06 12:06:04 -07:00
Teknium fdd140557b Merge pull request #103551 from NousResearch/fix/tool-output-caps
feat(file_tools): write_file flags a whole-file rewrite that mostly re-sends what is on disk (661 such writes, ≈$155, in one run)
2026-09-06 12:05:53 -07:00
Teknium cd658b6a46 Merge pull request #103492 from NousResearch/fix/approval-scanner-quoted-subshell
fix(approval): a grep inside "$(...)" no longer trips the hardline malformed block, and a quoted substitution body keeps its command boundaries (546 false blocks; review-found bypass closed)
2026-09-06 12:03:29 -07:00
Teknium e5f8420be8 Merge pull request #103513 from NousResearch/fix/subagent-context-cap
fix(delegation): compression_threshold_tokens is opt-in (default off, children keep the 500K ratio trigger); validate the value
2026-09-06 12:02:49 -07:00
Teknium 3d5831fa59 Merge pull request #103486 from NousResearch/fix/nested-delegate-deadline-and-summary-budget
fix(delegate): nested orchestrators get their workers' results back — delegate_task exempt from the 420 s tool deadline; summary budget uses current prompt, not the session sum
2026-09-06 12:02:43 -07:00
kshitijk4poor 9158bd8e0d refactor(file-ops): one _run_rg_bounded owns the native-vs-shell transport choice
Three call sites each repeated `if native: _run_rg_native(...) else: _exec(... | head -n N)`.
The choice now lives in _run_rg_bounded; callers pass the words, the bound, and the
one thing the native lane cannot express (a cd prefix → native_ok=False). The grep/find
pipeline keeps its explicit shell form because of the column cap.

Test file: one module-scoped LocalEnvironment instead of thirteen (~0.8 s each).
2026-09-07 00:28:46 +05:30
kshitijk4poor ef5a534c9a fix(file-ops): native rg runner honours deadline and /stop while rg is silent
The first version checked the deadline only after a line arrived, so an rg
that produced nothing for 60 s (huge tree, no hits yet) pinned the caller
past the timeout and ignored the interrupt flag that the shell path honours
via _wait_for_process. Drain on a daemon thread; the waiter owns deadline
(124) and interrupt (130) and kills the process group, so no rg or child
survives the return. Probe: silent 10 s process, timeout=2 → 2.0 s / 124;
interrupt at 0.5 s → 0.5 s / 130; zero stray processes afterwards.
2026-09-07 00:28:46 +05:30