- deadline: _result()/_abandon() replace 7 BoundedResult constructions and 2
cancel+callback sites; timers handled as a list; dead raise_if_timed_out removed.
- file_safety: retired classify_cross_profile_target (0 refs; get_cross_profile_warning
stub kept for external callers), _home_and_resolved/_mirror_warning shared by
the sandbox/container mirror guards; _find_sandbox_mirror_segments inlined.
- estop: _hermes_home/_canonical_root now the file_safety helpers;
_reset_log_state_for_tests inlined into its only test.
- subagent_lifecycle: _validate_request driven by _UNSUPPORTED_REQUEST_FIELDS table.
- turn_liveness: dead start()/_abort_message removed, _emit_warning shared.
- process_bootstrap: _enable_happy_eyeballs reused by the client variant.
- Comment/docstring compaction across the remaining leaf modules.
- shell_hooks is the shared home: _ToolMatcherMixin (matcher compile + matches_tool),
_payload_fields, _forget_home_registrations, _home_key, _utc_now_iso now serve
outbound_webhooks too (copies deleted; every log string byte-identical).
- shell_hooks: response parsing is a per-event dispatch table; _spawn diagnostic
dict + _evaluate_result shared by the live callback and run_once;
_locked_update_approvals POSIX/non-POSIX bodies merged via ExitStack.
- tool_guardrails: ToolCallGuardrailConfig thresholds from a _THRESHOLD_SOURCES
table (nested-wins-over-flat preserved); _int_at_least replaces
_positive_int/_non_negative_int; observe_identical_call (0 refs) folded into
observe_call; _halt helper for hard-stop decisions.
- tool_dispatch_helpers: _plan_tool_batch_segments split into _batch_admission +
close/extend helpers with the post-hoc normalization merged in.
- Comment/docstring compaction keeping every stated rule.
Drop dead read_error_body_or_default / LAYER_RUNTIME; inline single-use
_build_default_credential/_safe_close; compact incident narratives to their
invariants in the guards. Byte-cap and deadline semantics of
read_streaming_error_body verified identical.
PluginLlm's four public entry points share _gate/_finish/_host_kwargs; drop
dead classify_failure_scope/_REASON_SCOPES (and their tests) and unify the
three _norm_* helpers; should_skip_candidate routes through a scope predicate
table. Injected caller kwargs, audit dicts and log lines unchanged.
Collapse the four Gemini chat/completions wrapper classes into SimpleNamespace
shims, finish-reason/tool-choice/HTTP-error mappings become dicts, shared
_usage_from_metadata/_assistant_message between sync and streaming translation,
vertex credential loading split into _load_credentials/_needs_refresh.
Gemini request/response/schema output byte-identical against merge-base.
Table-driven model capability checks and beta-header assembly, shared
_cache_control_of/_block_type/_image_block_from_data_url helpers in the message
converter, extracted _apply_claude_code_identity/_base_client_kwargs.
convert_messages_to_anthropic / convert_tools_to_anthropic and request kwargs
verified byte-identical against merge-base.
Split _preflight_codex_input_items into per-item-type helpers over a
_PreflightCtx; streaming assembly moves into _CodexResponseAssembler with a
per-event dispatch table; run_codex_app_server_turn loses its session/usage/
interrupt regions to _ensure_codex_session/_finish_codex_turn/
_consume_user_interrupt/_queue_token_counts (counts built lazily so stub agents
without a session DB are never touched). Responses input/normalization and
stream callback order verified byte-identical against merge-base.
Drop dead call_converse_stream / classify_bedrock_error / is_context_overflow_error
(zero refs) and their tests; stop-reason mapping becomes a dict; extract
_cache_point/_assistant_blocks/_append_turn/_cached_client helpers; compact
incident narratives to their invariants. Converse wire output byte-identical.
apply_all's per-source closure becomes _Applier (same guard chain, same
messages, same provenance); builtin registration iterates a table instead of
three copy-pasted try blocks; getattr() on always-present SecretSource attrs
removed.
- bitwarden: drop dead apply_bitwarden_secrets (0 refs); encrypted cache uses
atomic_write_json/entry_from_payload; fetch goes through SecretCache.lookup
with an encrypted L2 reader; stale-fallback branches merged; _classify_bws_error
is a rule table; token/override hooks come from the ABC.
- onepassword: same substrate; _missing_binary_error, _fingerprint, _guarded
dedupe repeated text/logic; _classify_op_error is a rule table.
- command: drop dead parse_secret_output/get_command_secret/list_command_secrets/
apply_command_secrets (0 refs outside own test); _log helper; tests repointed
to _run_helper / CommandSource.fetch.
- credential_sources: _remove_nous_device_code/_remove_minimax_oauth/xai/codex
share _remove_auth_store_oauth; hint-only steps (claude_code, qwen-cli,
config:*) built by _suppress_only(); registry is a literal ordered list
(register()/_register_all_sources() removed; order preserved, first match wins).
- credential_persistence: fold _fingerprint_value into fingerprint_secret_value;
compact key tables and docstrings.
- Behavior parity verified old vs new: removal-step lookup + hint text for 12
(provider, source) cases; 3000 random sanitize/fingerprint payloads.
- Drop dead code: _telegram_effective_priority, _prioritize_telegram_menu_commands,
discord_skill_commands, _TG_NAME_LIMIT/_clamp_telegram_names compat aliases,
the empty _SLACK_PRIORITY_ALIASES pinning pass (and tests that only pinned them).
- Unify the Telegram and Discord skill collectors behind _iter_gateway_skills
(one eligibility/root-matching implementation) and _truncate_desc.
- Table-drive Telegram menu priority modes (_TELEGRAM_PRIORITY_TIERS) and the
completer's per-command dynamic completions (_DYNAMIC_COMPLETIONS).
- Unify path and @file:/@folder: directory-listing completions (_dir_completions),
command-completion construction (_short_desc), /tools candidate rows, the
Slack canonical/alias passes and the derived COMMANDS/COMMANDS_BY_CATEGORY loops.
- Compact docstrings/comments, keeping every rule, invariant and rationale.
Behavior-neutral: registry-derived outputs, menus, manifests and completions
byte-identical against origin/main on a fixture sweep.
Zero-back-ref region (inputs desktop_dir/source_mode/npm/env, single output
packaged_executable) becomes a helper returning the swapped-in executable.
Removes the unused functools/_add_accept_hooks_flag imports left by the
parser-builder migration.
_run_oneshot_from_args replaces three identical confirm+run_and_exit blocks
(main, fast chat, Termux fast cli); _default_to_chat reuses the existing
_set_chat_arg_defaults instead of a second attr table. Also restores the
'bare hermes profile' note as _profile_status's docstring.
_relative_time, _session_status_tag, _annotate_session_statuses,
_session_browse_picker and _size_delta_label (410 LOC) replace the
call-time delegating wrappers in sessions_cmd; main.py re-exports them via
_LAZY_COMMAND_EXPORTS so hermes_cli.main.<name> imports/patches still work.
The 20-way if/elif on selected_provider becomes a dict of uniform
flow(config, current_model, args) lambdas plus a _GENERIC_API_KEY_PROVIDERS
frozenset; custom-slug / remove-custom / api-key fallthroughs keep their
order. Lambdas resolve _model_flow_* by name at call time so existing
hermes_cli.main monkeypatches still intercept.
The 604-line 14-way if/elif on profile_action becomes one _profile_<action>
handler each, with per-handler imports derived from the branch's free names.
main.py re-exports cmd_profile and _render_distribution_plan so existing
imports/monkeypatches resolve unchanged.
main() is now a ~110-line orchestrator: startup prologue, parser build,
container routing, bpo-9338-safe parse, --version/--yolo/--oneshot, chat
default, dispatch. The two identical plugin add_parser blocks collapse into
_attach_plugin_cli_command; the two default-to-chat attr loops merge. Parser
tree, --help output and set_defaults are unchanged (399 parsers byte-diffed).
moa, fallback, worktree, browser, secrets, egress, migrate, whatsapp-cloud,
checkpoints, bundles, curator, pets, journey, computer-use, sessions and
completion each become a build_<group>_parser() builder. Closure handlers
that only closed over their own parser moved verbatim; sessions/completion
take the handler by injection. --help/usage/defaults byte-identical for all
399 parsers in the tree (in-process dump before/after).