Commit Graph

23852 Commits

Author SHA1 Message Date
Teknium 9c6ecf2ca7 feat(image-gen): OpenRouter image picker lists every live image-output model; xAI edits honor dispatched model
- plugins/image_gen/openrouter: list_models() now queries the endpoint's
  /models catalog filtered to output_modalities containing "image"
  (per-backend 5-min cache, 10s timeout, static 2-model chain as offline
  fallback; openrouter/auto* router pseudo-models excluded). Every image
  model OpenRouter serves — including future releases — is selectable in
  `hermes tools` with no code change. Applies to Nous Portal too via the
  shared provider class.
- plugins/image_gen/xai: forward the dispatched model kwarg into
  _resolve_edit_model() so an explicitly selected edit-capable model is
  honored on /images/edits (extends the salvaged #55893 fix to the edit
  path; text-only models still fall back to quality).
- Tests: OpenRouter live-catalog filtering/exclusions/order, offline
  fallback, cache single-fetch; xAI edit-kwarg forwarding incl. the
  text-only-hijack negative case.

Live-verified against openrouter.ai: 9 image-output models returned and
rendered, matching the public models?output_modalities=image listing.
2026-08-19 02:04:29 -07:00
srojk34 008d469991 fix(xai): forward image_gen.model kwarg to _resolve_model in generate() 2026-08-19 02:04:29 -07:00
69k4xmdfm2-blip 21260c3281 fix(gateway): carry the profile in adapter-derived session keys (#88404)
Adapter ingress derives a session key BEFORE the runner stamps
source.profile in _make_profile_message_handler, so the namespace fell
back to the active profile and every bot in a multiplexed gateway
produced agent:main:<platform>:<chat>. A Telegram private chat reports
the user's own id as chat.id, identical for every bot, so two profiles
sharing one human collapsed onto a single lane: _pending_text_batches,
_active_sessions, the busy-session guard and _post_delivery_callbacks are
all keyed on that string. A day of production logs across two bots shows
60 flushes, none carrying the secondary profile's namespace.

set_owner_profile records credential ownership on the adapter and
_session_key_profile resolves the namespace as source.profile ->
_owner_profile -> the session store's resolver, so a secondary adapter
keys into its own namespace even before the source is stamped. Stamped
sources keep priority, so relay/connector ingress, which routes per event
rather than per credential, is unchanged. _configure_profile_adapter
installs the owner alongside the other handlers, covering startup and
reconnect.

Every candidate is type-checked as a non-blank str, and every attribute
read goes through getattr: adapters are routinely built without
BasePlatformAdapter.__init__, and a duck-typed session store returns a
truthy non-string that would otherwise be interpolated into the key as
agent:<MagicMock ...>:.

Also routes the four call sites that passed no profile at all (feishu
media batches, raft, slack _session_key_for_source, telegram photo
batches) through the same resolver.

test_multiplex_busy_input_mode's secondary-adapter busy case seeded
_active_sessions with the unstamped agent:main: key, asserting the
pre-fix collapse. It now seeds the lane the profile-owned adapter
actually derives.

A primary adapter has no owner and an unstamped source, so it resolves
exactly as before; with multiplex_profiles off the resolver returns None
and every key is byte-identical to today's.
2026-08-19 02:00:16 -07:00
Teknium 5a3410eb9a chore: map contributor email for salvage attribution 2026-08-19 01:58:21 -07:00
royzhrxy-glitch a787bfeab9 fix(desktop): restore profile/agent switching in release builds (nanostores 1.4.2)
nanostores 1.4.0-1.4.1 annotate batch() @__NO_SIDE_EFFECTS__. Rollup
(via vite build) honors that and erases a result-unused batch(...) call
as dead code -- callback included. Since d57f94a33/053eb7aab/4e520f085
moved the gateway-switch publication (activate() +
+ ) inside batch(), packaged desktop builds lost the entire
publication: clicking a profile in the rail did nothing at all.

Dev builds and vitest run unminified, so only the packaged app broke.

nanostores 1.4.2 removes the annotation from batch() (it stays on the
creation functions, where it is correct). Bump all three pinned copies
(apps/desktop, apps/bootstrap-installer, ui-tui) and add a regression
test asserting the installed nanostores never re-annotates batch.
2026-08-19 01:58:21 -07:00
Teknium ceabb030fb feat(image-gen): add Grok Imagine Image 2.0 to the FAL image catalog
Adds xai/grok-imagine-image/v2.0/text-to-image with edit_endpoint
xai/grok-imagine-image/v2.0/edit (max 3 reference images). 1k/2k resolution,
low/medium quality (pinned 1k+medium = $0.06/image), 13 aspect ratios (we map
the standard 3), no seed param in the schema. upscale=True (1k native sub-2MP).
Schema verified against fal.ai llms.txt + OpenAPI.
2026-08-19 01:58:04 -07:00
Teknium 9162ea6db1 Revert "chore(ci): touch ci.yml to bust poisoned workflow-parse cache"
This reverts commit 0f73adb74f.
2026-08-19 01:22:51 -07:00
Teknium 0f73adb74f chore(ci): touch ci.yml to bust poisoned workflow-parse cache 2026-08-19 01:22:49 -07:00
Teknium b154046e4e chore: map contributor email for zhuermu 2026-08-19 01:19:37 -07:00
Teknium ac0a8cd281 feat(image-gen): xAI Grok image catalog goes live-driven; grok-imagine-image-2.0 selectable
- plugins/image_gen/xai: merge the live /v1/image-generation-models catalog
  (5-min cache, 10s timeout, static-table fallback when offline/unauth)
  into the picker so new xAI Imagine models appear automatically the day
  they launch, with generic metadata until curated text is added.
- Add grok-imagine-image-2.0 to the curated static table (typography/
  layout-aware model, API-available since Aug 8 2026).
- Edits honor an explicitly selected image-input-capable model
  (e.g. grok-imagine-image-2.0) instead of always forcing
  grok-imagine-image-quality; quality remains the default edit baseline.
- Tests: hermetic autouse fixture keeps unit runs offline; new coverage
  for live-merge, unknown-future-model selection, offline fallback, and
  edit-model resolution. Docs model table updated (en + zh-Hans).

Live-verified: /image-generation-models returns grok-imagine-image,
grok-imagine-image-2.0, grok-imagine-image-quality; real generation with
2.0 succeeded end to end.
2026-08-19 01:19:37 -07:00
Teknium e6ff4eacdb fix(tools-config): widen stale-model picker guard to legacy image and video pickers
Same bug class as the plugin image picker crash (#77238): an unguarded
`current_model = default_model` fallback that can index the catalog with a
key it doesn't contain when the provider's default drifts from its catalog.
Applies the `default if default in catalog else next(iter(catalog))` guard
to _configure_imagegen_model and _configure_videogen_model_for_plugin.
2026-08-19 01:19:37 -07:00
zhuermu c6b680c445 fix(image-gen): handle stale OpenRouter model defaults 2026-08-19 01:19:37 -07:00
Teknium afa4f4c660 fix: 7 GitHub-adjacent tests no longer fail on developer machines
Three local-environment leaks made tests red locally while green on CI:

- tests/conftest.py: blank HERMES_REAL_HOME and TERMINAL_HOME_MODE per
  test. The terminal tool injects both into subprocess envs, so any
  pytest run launched from a Hermes session inherits them and the
  hermes_constants home-resolution helpers prefer HERMES_REAL_HOME over
  the monkeypatched HOME (4 failures in
  test_subprocess_home_isolation.py).

- test_modal_sandbox_fixes.py: reset the import-time _YOLO_MODE_FROZEN
  flag and pin approval mode to manual in _isolate_approval_state().
  HERMES_YOLO_MODE=1 in the launching shell froze True at collection
  time and every guard auto-approved (2 failures).

- test_noninteractive_git.py: strip GIT_ASKPASS/VS Code askpass vars in
  the fail-fast clone E2E. noninteractive_git_env() intentionally keeps
  a working askpass helper, but this test asserts the no-helper path;
  under VS Code the helper blocks on the editor until the 30s timeout
  (1 failure).

Verified: all 49 tests in the three files pass both in a plain dev
shell (with HERMES_YOLO_MODE=1, HERMES_REAL_HOME, and VS Code askpass
set) and inside an unshare -rn network namespace.
2026-08-19 01:19:28 -07:00
brooklyn! 63565fa26b fix(desktop): keep auto-speak silent across the stream-id rewrite
Supersedes #75649, #86637, #87672, #88642.

Fixes #86601
Fixes #87652
Fixes #87823

Co-authored-by: Charmmy <lilShawtty@qq.com>
Co-authored-by: chelsealong <chelsealong@126.com>
Co-authored-by: Olympusbuildz <Olympus.roots@outlook.com>
Co-authored-by: Ricardo Mendes <ricardo.mendes@maiolabs.ai>
2026-08-19 02:56:55 -05:00
Austin Pickett 4180c3f326 Merge pull request #89623 from NousResearch/fix/tui-focus-regain-atomic-repaint
fix(tui): heal focus regain without a separate screen clear (supersedes #88596)
2026-08-19 02:56:43 -05:00
brooklyn! 70e818c6e3 Merge pull request #89814 from NousResearch/bb/session-group-icon-fix
fix(desktop): close the blank hole in the Sessions header
2026-08-19 02:49:01 -05:00
brooklyn! ca4a0c4358 Merge pull request #88233 from helix4u/fix/get-windows-recovery-command
fix(desktop): recover missing get-windows binding
2026-08-19 02:46:05 -05:00
brooklyn! d2433c176e Merge pull request #89838 from NousResearch/bb/update-desktop-rebuild-status
fix(update): don't report success when the Desktop rebuild failed (supersedes #88359, #87984)
2026-08-19 02:44:51 -05:00
Brooklyn Nicholson ff3dbed3f7 ci: retrigger workflows after the orchestrator died before scheduling jobs 2026-08-19 02:42:48 -05:00
Brooklyn Nicholson 0223710d00 test(desktop): compare get-windows installer path via realpath
require.resolve returns the macOS realpath (/private/var/...) while
os.tmpdir() stays on the /var symlink, so a raw join() deepEqual failed
even though the spawn was correct.
2026-08-19 02:39:44 -05:00
brooklyn! b82f8b0654 Merge pull request #89257 from xxxigm/fix/desktop-files-panel-remote-download
fix(desktop): let Files panel download remote backend files
2026-08-19 02:38:30 -05:00
Brooklyn Nicholson 6907c97847 fix(update): don't report success when the Desktop rebuild failed
hermes update treated a failed desktop pack as non-fatal and still printed
✓ Update complete!, so Windows users kept running an old Hermes.exe after a
"successful" update. Withhold the success banner, surface the stale app in
the summary, and write .update_exit_code=1 for gateway watchers.

Supersedes #88359, #87984.

Co-authored-by: joaomarcos <joaomarcosdias444@gmail.com>
Co-authored-by: liuhao1024 <sunsky.lau@gmail.com>
2026-08-19 02:10:37 -05:00
Teknium 2507bc649f fix(desktop): atomic profile-switch publication v2 — fail open, lease mid-dial entries (#89622, #46651)
Re-lands the goals of the reverted atomic-publish series (#89483, reverted
in #89785) without the fail-closed decline path that killed profile clicks,
and fixes the underlying pruner race the original series exposed.

Two changes relative to the restored (pre-series) behavior:

- Publication is atomic and mode-safe (#46651): the switch resolves the
  target's connection descriptor CONCURRENTLY with the socket work and
  publishes $activeGatewayProfile + $connection in one nanostores batch()
  frame, so no request or plugin mode-listener observes the new gateway
  beside the previous profile's descriptor. Unlike the reverted series, a
  failed descriptor lookup fails OPEN — the switch still lands, the previous
  descriptor stays, boot/reconnect resyncs it later, and the failure is
  logged instead of swallowed.
- The live-work pruner can no longer kill a switch mid-dial (#89622's root
  race): ensureGatewayForProfile / ensureGatewayForAgent lease their entry
  (activationLeaseUntil, 30s bound) for the duration of the dial and
  pruneSecondaryGateways spares leased entries. A switch target is not yet
  active, has no live sessions and holds no request lease, so any prune
  recompute during a cold pool spawn used to dispose the dialing entry.
  Bounded lease: an orphaned one self-expires.

The agent door logs a non-landing activation (target removed mid-dial)
instead of resolving silently, but never fails the switch closed.

Live E2E (Electron over CDP, 3 local profiles, cold + warm): 10 sequential
switches, rapid two-click interleave (last click wins), 6-click stress run —
all land, overlay always clears, fresh pool backends spawn on cold switches.

Tests: gateway-activation-prune-lease suite (mid-dial prune survival on both
doors, lease release, lease expiry); the invalidated-registry-identity pin
updated for the concurrent (read-only) descriptor probe.
2026-08-19 00:03:35 -07:00
brooklyn! b44871db0a Merge pull request #89819 from NousResearch/bb/keep-gui-surface-direct
fix(tool-search): keep GUI surface tools directly available (supersedes #88029)
2026-08-19 01:48:08 -05:00
Brooklyn Nicholson c12d2962db test(tool-search): cover mixed MCP assembly and the HUD note
Prove apply_layout and read_window_below stay direct when MCP tools
activate the bridge, and that a HUD turn still gets its surface note.

Co-authored-by: fangliquan <fangliquan@qq.com>
2026-08-19 01:34:54 -05:00
Brooklyn Nicholson 022898811d fix(tool-search): keep GUI surface tools directly available
Tool Search treated desktop_ui and project as plugin catalog, so
read_window_below dropped out of the model-facing array and the HUD
note never fired. Session-gated GUI tools stay off the core list but
remain direct once a session enables them.

Co-authored-by: fangliquan <fangliquan@qq.com>
2026-08-19 01:34:54 -05:00
Brooklyn Nicholson 0e980e8049 fix(desktop): keep mark-all flush with the sessions header actions
The unread check-all was a sibling of the +/filter cluster. The header
is justify-between, so that extra child sat in the middle as a blank
24px hole until hover.
2026-08-19 01:31:11 -05:00
jonny 649c20629e Merge pull request #85429 from NousResearch/jb/yolo-settings-session-info-emit
fix(desktop): re-emit session.info when approvals config changes out of band
2026-08-19 09:29:42 +03:00
brooklyn! 38f79e25a0 Merge pull request #89798 from NousResearch/bb/tour-demo-remove
Drop the dev-only tour demo
2026-08-19 01:27:34 -05:00
brooklyn! e4771b92a7 Merge pull request #89808 from NousResearch/bb/turn-activity-timer
Time the gaps a working turn spends producing nothing
2026-08-19 01:25:37 -05:00
Brooklyn Nicholson 443c104e61 fix(desktop): treat profile=default as this process's own home
_is_other_profile only allowed empty/current, so a ?profile=default
save skipped the session.info broadcast on the process whose config
it just wrote. Compare the resolved target to the process HERMES_HOME.
2026-08-19 01:23:39 -05:00
Brooklyn Nicholson ff8c4159e8 chore(desktop): drop the dev-only tour demo
The demo existed to iterate on the tour UI without spending an agent turn per
look. That work is done and merged, so it is scaffolding now — a floating
button, a hotkey, a palette row and a window hook, none of which anyone needs
again.

Removing it restores the credit-notice demo's original single-disposer wiring
and drops the Compass icon export, which the demo was the only consumer of.
The tour feature itself is untouched.
2026-08-19 01:20:39 -05:00
Brooklyn Nicholson ccaa4872d8 fix(desktop): time the gaps a working turn spends producing nothing
The transcript's activity row went silent for most of an agentic turn. Two
gates were too narrow. It mounted only while the tail bubble's own status was
`running`, so a turn that seals a bubble mid-flight (message.interim) or
finishes one while the agent keeps going left a settled message at the tail and
unmounted the row entirely. And its activity signature was part count plus text
length, which a landing tool result does not change — a result mutates the part
that was already there — so the pause after a call ended was read as more of
the same silence and dated from whenever the call started.

Between them, the app spent whole stretches with the composer's arc border lit
and Stop armed while the thread showed nothing and counted nothing.

The row now follows the same busy signal the composer does, is mounted by the
tail unconditionally, and decides for itself whether the turn owes the user a
line. A named wait (compaction, provider wait, a tool being drafted) says so
immediately; an unnamed gap earns two seconds of quiet first, so a run of quick
calls doesn't strobe. It still defers to the two waits already accounted for
elsewhere: a prompt the user is answering, and a tool call in flight carrying
its own row and timer — anywhere in the message now, not just the last part,
and excluding the silent tools that render nothing to defer to.

Renamed to TurnActivityIndicator / `aui_turn-activity`: it hasn't measured a
stall since it started measuring the whole turn.
2026-08-19 01:19:33 -05:00
Brooklyn Nicholson 7c3c2d112b refactor(desktop): give each chat surface its own turn clock
`turnStartedAt` was only reachable through the global atom, which mirrors
whichever session is currently viewed — the same trap `$busy` and `$messages`
were moved out of. Anything in a tile that measures a turn was therefore
timing the primary chat's.

Put it on SessionView beside the other per-surface signals: the primary falls
back to the draft atom while a new chat has no slice yet, a tile reads its own.
2026-08-19 01:19:21 -05:00
hermes-seaeye[bot] f82f2dbabd fmt(js): npm run fix on merge (#89795)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-19 06:13:16 +00:00
brooklyn! 6cf6ad47e1 Merge pull request #89620 from NousResearch/bb/agent-tours
Let Hermes give live guided tours of the UI
2026-08-19 01:06:59 -05:00
Teknium d23a4875aa docs: cover hermes chat --query-file and the file-based Bot Mode DM transport
Follows PR #89762: cli-commands reference and CLI guide document the new
--query-file flag; bot-mode.md's DM and peer-dm recipes now show the
file/stdin transport instead of inlining message bodies into the shell.
2026-08-18 23:02:48 -07:00
Brooklyn Nicholson bbd6607968 docs(tour): document navigating steps and the handle vocabulary 2026-08-19 00:52:56 -05:00
Brooklyn Nicholson f0d0971899 feat(desktop): add a dev-only tour demo
Looking at the tour UI needed an agent turn per iteration. This adds a demo
that walks the Artifacts page — a route step, a late-mounting target,
per-step narration, the return trip — behind three triggers: a floating
button, Ctrl+Shift+X, and a palette row. The button is not redundant; a chord
can be eaten by a menu accelerator or the main process before the renderer
sees it.

DEV-gated and dynamically imported, so it is absent from production builds.
2026-08-19 00:52:55 -05:00
Brooklyn Nicholson 702d7bacc9 feat(desktop): name the app's shared surfaces for tours
Tours address elements by selector, and a positional nth-child path breaks on
the next re-render. These are the durable handles, applied at the shared
primitive rather than per screen: every route overlay's nav and its rows, every
settings field (keyed by its config schema key, so new fields are named for
free), the filter tabs on any search shell page, and artifact cards.

One edit per primitive covers every screen built from it, which keeps the tour
vocabulary small enough to stay accurate.
2026-08-19 00:52:55 -05:00
Brooklyn Nicholson d433a452cc feat(desktop): give tours a themed spotlight and directional motion
The stock driver.js look is replaced with the app's own: unfocused UI fades
toward var(--background) and desaturates, so it recedes in light and dark
without a mode branch. The dimming is masked to a feathered cutout that tracks
driver's eased stage rect each frame, keeping the highlighted element crisp —
a plain backdrop-filter blurs the spotlight too, because it clips to the
element box rather than the cutout.

Popovers enter from wherever they land: left, right, above or below their
target, and a shorter settle for centered narration steps, which have nothing
beside them to measure against. Travel, duration and easing are tokens on
.driver-popover, and the whole thing collapses to a fade under
prefers-reduced-motion.
2026-08-19 00:52:55 -05:00
Brooklyn Nicholson 98bbfbda6e fix(desktop): keep a tour bound to its target across navigation and re-renders
A tour step that moved the app deadlocked: driver.js checks waitForElement
before running any hook, so the step waited for an element on a page the hook
had not opened yet. The move now happens in the step's own onHighlightStarted
— the one hook driver fires however a step is reached — so clicking Next,
pressing an arrow key and calling the API all behave the same.

Steps also re-bind themselves. driver.js holds the highlight as a node
reference and re-measures it, so a poll or refetch that swapped the node left
it measuring a detached element and the spotlight vanished, looking like the
tour closed itself. One observer now covers both cases: the target that has
not mounted yet, and the one that was replaced underneath.

Orphaned overlays are swept before a tour starts, since driver.js can only
tear down what its own instance built.
2026-08-19 00:52:55 -05:00
Brooklyn Nicholson 93b50ea0bb test+docs(tour): cover the engine and document the API
Ten behavior tests for target discovery, stable-selector ordering, step
paging, recovery hints, and the self-containment contract the preview
injection depends on. Docs cover data-tour markup and the curated-tour
entry point alongside the tool itself.
2026-08-19 00:52:54 -05:00
Brooklyn Nicholson 23d88c2b0e feat(tools): tour — let the agent walk a user through the UI
One generic tool in the desktop_ui toolset: discover what is on screen,
highlight an element with narration, or hand the user a paged tour. No tour
content lives in the code — the agent authors each one live, which is what
makes 'how does this work?' answerable as a walkthrough instead of a wall
of text.

Rides the existing blocking-prompt bridge (tour.request/.respond) like
read_preview, so it works on every connection topology.
2026-08-19 00:52:54 -05:00
Brooklyn Nicholson 0d572e063b feat(desktop): answer tour.request from the renderer
Translates the wire payload into a normalized action and dynamic-imports
the engine, keeping driver.js off the boot path. Active session only — a
background turn must never paint an overlay over what the user is looking
at.
2026-08-19 00:48:32 -05:00
Brooklyn Nicholson ec69940537 feat(desktop): run tours inside the preview pane
The guest page is out-of-process, so the first action injects a
self-contained bundle over executeJavaScript — the driver.js IIFE, its
stylesheet, and the engine source — parked on window globals so later
actions reuse the live instance. Injection is idempotent and vanishes with
the page, so a navigation resets the tour.

This is what lets a tour walk through any web app open in the in-app
browser, not just Hermes itself.
2026-08-19 00:47:58 -05:00
Brooklyn Nicholson 018176915b feat(desktop): tour engine — highlight and narrate any DOM
A surface-agnostic walkthrough engine plus the API that drives it.
collectTourTargets scans any document for addressable elements and marks
each selector stable (identity-based, survives a re-render) or positional;
runTourEngine turns one action into a driver.js highlight, a multi-step
tour, or a step change.

Both are written self-contained — no imports, no closures — so the same
source runs in the renderer and, stringified, inside a webview guest page.
Popovers are repainted from the app's own theme tokens, so tours follow
every theme and custom skin.

The named verbs (startTour, showTourStep, nextTourStep, …) are the public
API: the agent tool is one caller, and a feature can ship its own curated
tour through the same entry.
2026-08-19 00:47:58 -05:00
Brooklyn Nicholson 5dc20eb319 build(desktop): add driver.js for guided tours
Pure-ESM, MIT, ~5KB gzipped, no runtime deps. Excluded from optimizeDeps:
it only enters the graph through a dynamic import, so letting the scanner
discover it at first use prebundles the ?raw IIFE as a module (breaking the
raw-text transform) and forces a mid-session page reload.
2026-08-19 00:47:58 -05:00
emozilla 5d3c15aaa7 restore profile switching 2026-08-18 22:44:03 -07:00
Teknium 4903993cdd test: enforce -q/--query-file exclusivity at parse time
The subprocess-based exclusivity test invoked hermes_cli.main in the CI
environment where startup exits 1 before the manual guard runs. Enforce
the conflict in argparse itself (mutually exclusive group, exit 2 at parse
time) and test the parser directly; the manual guard stays for programmatic
namespace fills.
2026-08-18 22:31:32 -07:00