Commit Graph

32948 Commits

Author SHA1 Message Date
Ben Barclay 5a1246f830 fix(observability): attribute ACP and batch execution surfaces
Fleet telemetry showed "unknown" as the single largest execution_surface
bucket. Two construction paths were mis-attributed, both silently:

1. ACP editor sessions (VS Code / Zed / JetBrains) declare platform="acp",
   but "acp" was absent from EXECUTION_SURFACES, so the contract's
   closed-schema fallback folded every editor session into "other" --
   the bucket meant for genuinely unclassifiable traffic.

2. batch_runner built agents from _AGENT_PASSTHROUGH, which omitted
   "platform" entirely, so every batch task run reported "unknown"
   despite "batch" already being a first-class surface.

Neither is a reporting bug in the exporter: both are declaration gaps at
the construction site. "unknown" must mean "this run genuinely could not
be attributed", not "a construction site forgot to say who it was".

Changes:
- add "acp" to EXECUTION_SURFACES and map it to the "interactive"
  entrypoint alongside cli/desktop/tui
- add "acp" to the v2 wire schema enum (kept in sync by an existing test)
- pass platform through batch_runner: added to _AGENT_PASSTHROUGH, set
  self.platform = "batch" on the runner, and defaulted at the worker call
  site so callers that build a config without it stay attributable

Wire compatibility: the ingest service validates the envelope only and
stores metric bodies verbatim, so packages carrying the new value are
accepted by the already-deployed server. No coordinated deploy needed.

Tests: 12 new behavioural tests. Verified red before the fix (4 failed),
green after. Three fix-mutants confirmed killed:
  M1 revert acp from EXECUTION_SURFACES  -> 3 failed
  M2 revert acp entrypoint mapping only  -> 1 failed
  M3 revert batch passthrough            -> 1 failed
No source-text assertions; every test is a contract between the surfaces
the schema accepts and the surface each path declares. A guard test pins
that a genuinely undeclared run still reports "unknown", so attribution
cannot be "fixed" by inventing a default that hides real gaps.
2026-09-09 11:27:36 +10:00
brooklyn! 72a3277cd7 test(desktop): cover project creation scope and reconnect routing 2026-09-08 20:05:07 -05:00
brooklyn! 2b6a5181a3 fix(desktop): allow project creation while browsing all profiles 2026-09-08 20:05:07 -05:00
Teknium 9d865810b6 fix(mcp-oauth): keep refresh_token when a refresh response omits it (#62333)
HermesProviderMixin._handle_refresh_response overrides the SDK's handler (to
accept any 2xx and keep token bodies out of logs) but dropped the SDK's RFC 6749
section 6 carry-forward. An authorization server that does not rotate refresh
tokens (TinyFish, Google, Zoho, Asana, Futu) answers the refresh grant without a
refresh_token; we then stored the response verbatim, erasing the only refresh
token we had, so the next expiry had nothing to refresh with and forced a
browser re-auth roughly one TTL after every login.

Carry the prior refresh_token (and scope, per section 5.1) forward on the
OAuthToken before _store_tokens, so both the live provider and the on-disk
token file keep it. A rotating AS still wins: only None fields are filled.

Tests: two invariants on the real HermesMCPOAuthProvider + HermesTokenStorage
(omitted -> preserved in memory and on disk; provided -> rotated). The
carry-forward test is red on main.
2026-09-08 17:44:51 -07:00
Teknium c32e0acb0e test(desktop): exercise production cwd setup in Windows self-test 2026-09-08 17:13:48 -07:00
fangliquanflq 610b6731d4 fix(desktop): pin Windows update handoff cwd 2026-09-08 17:13:48 -07:00
Teknium facb9eb4f1 fix: trim computer use tool schema guidance 2026-09-08 17:03:01 -07:00
brooklyn! e7eaff6845 docs(desktop): explain background report disclosures 2026-09-08 18:53:48 -05:00
brooklyn! 258b351fc1 fix(desktop): keep background reports behind bounded disclosures 2026-09-08 18:53:48 -05:00
brooklyn! 608b97c305 docs(desktop): document sidebar glass defaults 2026-09-08 18:45:42 -05:00
brooklyn! 1175ac4bb9 feat(desktop): default glass to 29% tint on the sidebar 2026-09-08 18:45:42 -05:00
Teknium b1f003e186 feat: add FAL GPT Image 2.5 generation and editing selections
CI / OSV scan (push) Has been cancelled
Nix flake check / Detect affected areas (push) Has been cancelled
CI / Detect affected areas (push) Has been cancelled
Deploy Site / deploy-vercel (push) Has been cancelled
Deploy Site / deploy-docs (push) Has been cancelled
Docker Build, Test, and Publish / Detect affected areas (push) Has been cancelled
auto-fix lint issues & formatting / Generate eslint --fix patch (push) Has been cancelled
Build Skills Index / build-index (push) Has been cancelled
CI / Desktop E2E (push) Has been cancelled
CI / Docs Site (push) Has been cancelled
CI / Deny unrelated histories (push) Has been cancelled
CI / Check contributors (push) Has been cancelled
CI / Check uv.lock (push) Has been cancelled
CI / Check no committed infographics (push) Has been cancelled
CI / Profile artifact check (push) Has been cancelled
CI / Check no case-colliding filenames (push) Has been cancelled
CI / package-lock.json diff (push) Has been cancelled
CI / Lint Docker scripts (push) Has been cancelled
CI / Supply-chain scan (push) Has been cancelled
CI / Review label gate (push) Has been cancelled
auto-fix lint issues & formatting / Apply patch (push) Has been cancelled
CI / Python tests (push) Has been cancelled
CI / OS-specific tests (push) Has been cancelled
CI / Python lints (push) Has been cancelled
CI / JS & TS checks (push) Has been cancelled
CI / Installer tests (push) Has been cancelled
CI / Rust tests (push) Has been cancelled
CI / All required checks pass (push) Has been cancelled
CI / CI timing report (push) Has been cancelled
Docker Build, Test, and Publish / build (amd64, type=gha,scope=docker-amd64, type=gha,mode=max,scope=docker-amd64, linux/amd64, ubuntu-latest-32-core) (push) Has been cancelled
Docker Build, Test, and Publish / build (arm64, type=gha,scope=docker-arm64, type=gha,mode=max,scope=docker-arm64, linux/arm64, ubuntu-latest-32-arm-core) (push) Has been cancelled
Docker Build, Test, and Publish / publish (amd64, type=gha,scope=docker-amd64, type=gha,mode=max,scope=docker-amd64, linux/amd64, ubuntu-latest-32-core) (push) Has been cancelled
Docker Build, Test, and Publish / publish (arm64, type=gha,scope=docker-arm64, type=gha,mode=max,scope=docker-arm64, linux/arm64, ubuntu-latest-32-arm-core) (push) Has been cancelled
Docker Build, Test, and Publish / merge (push) Has been cancelled
Nix flake check / nix flake check (push) Has been cancelled
Build Skills Index / trigger-deploy (push) Has been cancelled
2026-09-08 14:57:15 -07:00
Teknium 7777f8c350 feat: add GPT Image 2.5 generation and editing to OpenAI provider 2026-09-08 14:57:15 -07:00
unsupportedpastels 7568fb6727 fix(desktop): let subagent header collapse roster and details 2026-09-08 14:54:47 -07:00
Teknium ed6671db83 test(desktop): retire model catalog fixture jobs at teardown 2026-09-08 14:52:59 -07:00
hermes-seaeye[bot] c076d653a2 fmt(js): npm run fix on merge (#106065)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-08 21:28:40 +00:00
hermes-seaeye[bot] e9bb6e86fb fmt(js): npm run fix on merge (#106039)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-08 21:23:02 +00:00
Teknium f03ed94a34 Merge pull request #105960 from NousResearch/fix/group-attention-salvage
fix(bot-mode): clear resolved Group Chat attention and bind prompts across rename
2026-09-08 14:07:46 -07:00
Teknium bc952a78ce fix: integrate group attention with room ordering and working avatars 2026-09-08 13:54:58 -07:00
Teknium 22488b8c62 fix(cli): keep monitor repaints safe during prompt handoff 2026-09-08 13:39:17 -07:00
Teknium 78afbc3c37 fix(desktop): load property card guidance only on demand 2026-09-08 13:39:01 -07:00
Adolanium ab6f4c5408 fix(desktop): show the focused bot's working think pose
Port Adolanium's focused-turn pose from Hermes-Bot-Mode#101 and
hermes-agent#88134 to the current typed Bot Mode implementation.
Match the busy signal's connection-qualified focused owner rather than
the gateway socket, retain worker activity, and ease transitions in
elapsed time on the existing shared face clock.

Includes owner-isolation and animated-pose invariants, both proven red
on origin/main, and native Electron before/after verification against
a real temporary Hermes backend with held loopback inference.

Co-authored-by: Teknium <127238744+teknium1@users.noreply.github.com>
2026-09-08 13:38:53 -07:00
Teknium aa83c6d614 fix: hide inactive grouping options from delegation schema 2026-09-08 13:38:18 -07:00
Teknium 9d66e76c5d feat(desktop): let users order Group Chat rooms
Add Move up/down controls for actual rooms without changing bot or folder
ordering. Preserve default pin/activity ordering until an explicit move,
retain hidden room slots, and persist Desktop-local order through room
updates, mirror merges, and hydration. No membership or routing writes.

Adapted narrowly from the group ordering idea in archived
NousResearch/Hermes-Bot-Mode#105 by @onuraycicek; rename already exists.

Co-authored-by: Onur Aycicek <onur.m.aycicek@gmail.com>
2026-09-08 13:37:19 -07:00
Teknium 19cd839d54 fix(compression): keep lean tails lean after auxiliary feasibility
Lowering the session trigger must not replace the window-relative lean
selection budget with threshold times target_ratio. Invalidate the lean
cache through the existing property while preserving explicit legacy and
external-engine fallback behavior.

Narrow adaptation of the aux-sync diagnosis and invariants in #93576,
without adding a required recalibration method to context engines.
Related: #95681, #93576

Co-authored-by: Turgut Kural <58116817+TurgutKural@users.noreply.github.com>
2026-09-08 13:37:01 -07:00
Teknium 9d661c2c92 fix(prompt): keep memory guidance within available tools 2026-09-08 13:36:05 -07:00
Teknium acbe72ed1f fix: keep Bot Mode pet selection rings inside the gallery 2026-09-08 13:35:51 -07:00
brooklyn! 3c0a84f94b chore: map MacBook-Air contributor email
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:35:19 -05:00
brooklyn! be4bd24a50 fix(desktop): take Import session off the sidebar nav
The importer stays in the command palette. The labeled nav row was
clutter next to New session / Capabilities / Messaging.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:35:19 -05:00
brooklyn! 960dee7fe5 fix(desktop): Hide tabs works on the sessions sidebar
hideOnly chrome pinned the Sessions/Bots strip on at any tab count, so
never was a silent no-op. The panes stay; ⌘⌥T brings the strip back.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-08 15:35:19 -05:00
Teknium f9993d5be2 refactor: extract group member phases and roster presentation 2026-09-08 13:29:18 -07:00
Teknium e1c8764d18 fix: fence retired group member failure cues 2026-09-08 13:29:18 -07:00
Teknium 613ec20304 fix(bot-mode): keep pending group attention bound to its live room
Complete the PR #101452 salvage, preserving sprmn24 authorship. Credit @kokhlo PR #101591 for independently diagnosing the in-flight rename race; use scoped authoritative room bindings rather than persistent aliases. Keep mention attention independent and retire late work after disband.
2026-09-08 13:29:18 -07:00
sprmn24 ad08688bc6 fix(bot-mode): derive group clarify/approval attention from $groupClarify instead of duplicating it into $groupNeedsYou
$groupNeedsYou was written by two independent sources: an @user mention
(appendGroupChatEntry) and, until now, syncGroupClarify whenever a member
blocked on a clarify or approval. Nothing kept the two in sync, so every
path that consumed a clarify -- answering it, the server resolving it,
disbanding or renaming the room -- left a stale badge lit with nothing
behind it, because none of them cleared the copy syncGroupClarify had
written. A naive fix (writing false back into $groupNeedsYou on every
clarify cleanup path) would have created the opposite bug: clearing an
unrelated, still-unresolved @user mention.

$groupClarify is already the source of truth for pending clarify/
approval attention. syncGroupClarify no longer writes $groupNeedsYou; a
new groupHasPendingClarify(clarifies, group) derives the same signal
from a $groupClarify snapshot. It's intentionally pure -- the caller
(roster-pane) subscribes to $groupClarify itself via useValue and passes
the live snapshot in, so the subscription actually drives the
recalculation instead of existing only to force a re-render. A prompt
resolving, being answered, or its room being disbanded all self-correct
through the existing $groupClarify cleanup paths, with nothing left to
keep in sync.

Rename needed its own fix: the old clearGroupClarify(oldName) call on
rename dropped a clarify-only room's attention entirely, since clarify no
longer lives in $groupNeedsYou to be carried over by the existing
old->new key swap there. New renameGroupClarify(oldName, newName) re-keys
matching mirrors onto the new name in two passes -- unrelated entries
first, migrated entries last -- so a stale mirror already stranded at the
destination key (left behind by a known, separate in-flight-poll race)
can never clobber the just-migrated current prompt.

The roster now reads groupNeedsYou[group] || groupHasPendingClarify(...)
and subscribes to both stores so either one repaints the row.

Tests: multi-clarify sequencing, mention+clarify independence (resolving
one must not clear the other), server-side resolution cleanup, rename
migration, rename destination-collision (red-green verified against the
prior single-pass implementation), a GroupRow badge render test, and a
subscription harness using the real stores/useValue/helper end-to-end.

(cherry picked from commit e5038f12ccc1a4d1fb56ecc5f0e1a884f1e8b795)
2026-09-08 13:29:18 -07:00
Teknium 9b0d75ce44 fix: gateway ordering test runs without root access 2026-09-08 13:25:54 -07:00
Teknium b2aa855b62 fix(cli): open subagent monitor with the TUI Ctrl+T shortcut 2026-09-08 10:37:36 -07:00
Teknium abd83ab560 fix(skills): make RSS and Reddit reading optional 2026-09-08 10:07:51 -07:00
kshitijk4poor 6f11a3296e refactor(gateway): wait on the target user's bus socket, not the generic control-socket predicate
_user_systemd_socket_ready() accepts systemd/private alone, which is enough for
systemctl --user but not for the systemd-run --user that restart-safe workers
need; systemd_user_bus_env() requires the bus socket. Replace the uid threading
through five helpers with one _wait_for_target_user_bus(uid) that polls
/run/user/<uid>/bus, and move the post-enable wait + restart hint out of
_ensure_linger_enabled into _ensure_system_service_linger so the activity probe
runs only when linger was actually just enabled. Kanban applies the bus env
unconditionally like the cron sibling. Refs #104893.
2026-09-08 22:35:39 +05:30
kshitijk4poor 4c4845f0af fix(gateway): order the system unit after the target user's manager
run_gateway() adopts the user bus once at boot; the generated system unit had
no ordering against user@<uid>.service, so after a reboot the two race and
the adoption can miss until the next gateway restart. Emit After=/Wants=
user@<uid>.service for the unit's User= (uid now returned by
_system_service_identity, which already resolved the account). Existing
system units are flagged outdated once and refreshed on the next
install/restart. Refs #104893.
2026-09-08 22:35:39 +05:30
ckomma be9c2bd19c fix(cron): derive the user bus env per probe and scoped spawn
A system-level gateway unit has no ordering against user@<uid>.service and
linger may be enabled after boot, so the bus can appear after the one-shot
adoption in run_gateway() ran. Derive XDG_RUNTIME_DIR/DBUS_SESSION_BUS_ADDRESS
fresh for the availability probe and every scoped spawn (cron worker, Kanban
worker, PTY/pipe terminal spawns, scope cleanup) so the 60s failure TTL can
actually recover. Refs #104893.
2026-09-08 22:35:39 +05:30
joaomarcos 748e68432b fix(gateway): provision linger for system-service users
A system unit's `User=` has no login session on a headless host, so
user@<uid>.service never starts and `systemd-run --user --scope` — every
restart-safe cron/Kanban worker — has no bus to reach. `hermes gateway
install --system` runs as root and already knows the target user, so enable
linger for that user on fresh install, on an already-current unit, and on
repair.

- `get_systemd_linger_status()` / `_ensure_linger_enabled()` take the target
  username; root is included (restart-safe workers cross `systemd-run --user`
  regardless of who the gateway runs as).
- After `loginctl enable-linger` succeeds, wait for the TARGET uid's control
  socket (`_wait_for_user_dbus_socket(uid=...)`) — logind starts the user
  manager asynchronously and `--start-now` boots the gateway immediately; the
  caller's own env (root's) says nothing about it and is never adopted.
- Messages and the manual-remediation hint are scope-aware (`sudo systemctl
  restart`, not `systemctl --user`); when the repaired service is already
  active, say that a restart is required — `systemctl start` on an active
  unit is a no-op and the running gateway keeps its bus-less environment.

Refs #104893.
2026-09-08 22:35:39 +05:30
kshitijk4poor 59d1336473 chore: map ckomma contributor email 2026-09-08 22:35:39 +05:30
ethernet c8aa5608c2 Merge pull request #101420 from ethernet8023/ethie/desktop-update-tests
test(install): cross-OS install/update E2E matrix (windows, macos, linux)
2026-09-08 10:30:44 -04:00
Teknium a25967b434 test: keep Desktop pane-focus setup outside cold imports 2026-09-08 07:29:26 -07:00
kshitijk4poor 63ec22e797 fix: correct two stale comments/docs strings left out of the docs batch
The docs batch (#105782-#105787, tracking #105788) fixed the website docs but
flagged two in-code strays it could not touch:

- hermes_cli/tips.py:121 still said delegate_task "spawns up to 3 concurrent
  sub-agents"; the default has been 10 since the v33 config migration
  (config_defaults.py:1256, config_migrations.py:613).
- hermes_cli/config_defaults.py:1778 said "remote backends run per-call",
  contradicted by tools/code_kernel_remote.py (session kernels on remote
  backends, failing open to per-call only when the backend cannot spawn one)
  since #96991.

Comment-only changes: tips.py list entry updated, config_defaults.py comment
rewritten to match the actual kernel lifecycle. No behaviour change.

Validated: test_tips.py 6 passed; ruff, check-windows-footguns, and
check_compat_pointers all clean. Refs #105788 (crumb noted in the issue body).
2026-09-08 19:52:26 +05:30
hermes-seaeye[bot] b3399c1396 fmt(js): npm run fix on merge (#105823)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-08 14:05:24 +00:00
hermes-seaeye[bot] 9a3f1dceba fmt(js): npm run fix on merge (#105818)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-09-08 13:59:05 +00:00
Teknium a529ecfeb5 feat(desktop): nest profile sessions under gateway sections 2026-09-08 06:53:22 -07:00
Teknium f6449ec37c docs: explain gateway session groups and saved Cloud switching 2026-09-08 06:53:22 -07:00
Teknium 6909604f97 fix(desktop): reuse saved Cloud gateways from Settings
Separate saved Cloud instances from the live window source, use the existing
registry activation path instead of repeating sign-in/apply, and persist the
chosen instance name while retaining registry identity and custom labels.

Naming metadata adapted from IAvecilla's contribution in PR #103224.

Co-authored-by: IAvecilla <ignacio.avecilla@lambdaclass.com>
2026-09-08 06:53:22 -07:00