f51aa6a9b5
Three separate reds on main. Two are fixed here; the third needs no code. 1. tests/gateway/test_multiplex_busy_input_mode.py (blocks every merge) Fails "Python tests / Run tests slice 5/12" and therefore "All required checks pass". Semantic merge conflict between two PRs merged ~1h apart:a31be480fix(gateway): respect routed profile busy modes (added the test)c8f235a1feat(gateway): allow selective multiplex profile serving (added the gate)c8f235a1taught _profile_name_for_source to reject a route whose target profile is not in the served set (profiles_to_serve). Each PR was green on its own base; neither ran against the other's merge result. The test asserts a route to profile "research" resolves to that profile's busy mode, but never patches profiles_to_serve — so it reads the runner's REAL on-disk profiles. "research" is not among them, the route is rejected before the busy-mode snapshot is consulted, and the assertion gets the gateway default: WARNING gateway.run: Rejecting profile route 'research-chat': target profile 'research' is not served AssertionError: assert 'interrupt' == 'steer' Patch profiles_to_serve for the assertion — the same seam every sibling test in tests/gateway/test_profile_resolution.py already patches (test_route_inside_allowlist_resolves, test_route_outside_allowlist_rejects). This also removes an ambient-state dependency: the test previously passed or failed based on which profiles happened to exist on the machine running it. Verified passing under an empty HERMES_HOME. Test-only. The serving gate fromc8f235a1is correct and left intact. 2. Skills-index workflows: local action used without actions/checkout check-freshness has failed on all 12 of its last 12 scheduled runs: ##[error]Can't find 'action.yml', 'action.yaml' or 'Dockerfile' under '.../.github/actions/get-app-token'. Did you forget to run actions/checkout before running your local action? ./.github/actions/get-app-token is a LOCAL composite action and cannot resolve without the repo on disk. skills-index-freshness.yml had no checkout step at all. The step is gated on `status != 'ok'`, so the watchdog broke exactly when it was supposed to file its issue — the live index is currently 521.4h stale (limit 26h) and nobody was told. An audit of all workflows for this bug class found one more instance: skills-index.yml's `trigger-deploy` job, which re-triggers the docs deploy so a refreshed index reaches the live site. Its sibling `build-index` job checks out; this one did not. That is plausibly why the index went stale in the first place. Both are fixed; the audit now reports zero remaining jobs that use a local action without a prior checkout. Pinned to the same actions/checkout SHA used by the other 35 call sites. 3. "Publish inline E2E evidence" — no fix needed Failed once at 13:33Z on a transient TLS error reaching api.github.com ("certificate is not valid for any names") while installing a gh extension. The last 25 runs of that workflow are 25/25 success. Infra blip, not a code defect.
83 lines
2.8 KiB
YAML
83 lines
2.8 KiB
YAML
name: Build Skills Index
|
|
|
|
on:
|
|
schedule:
|
|
# Run twice daily: 6 AM and 6 PM UTC
|
|
- cron: "0 6,18 * * *"
|
|
workflow_dispatch: # Manual trigger
|
|
push:
|
|
branches: [main]
|
|
paths:
|
|
- "scripts/build_skills_index.py"
|
|
- ".github/workflows/skills-index.yml"
|
|
|
|
permissions:
|
|
contents: read
|
|
actions: write # to trigger deploy-site.yml on schedule
|
|
|
|
jobs:
|
|
build-index:
|
|
# Only run on the upstream repository, not on forks
|
|
if: github.repository == 'NousResearch/hermes-agent'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
environment: trusted-automation
|
|
steps:
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Get GitHub App token
|
|
id: app-token
|
|
uses: ./.github/actions/get-app-token
|
|
with:
|
|
client-id: ${{ vars.APP_CLIENT_ID }}
|
|
private-key: ${{ secrets.APP_PRIVATE_KEY }}
|
|
|
|
- uses: actions/setup-python@a309ff8b426b58ec0e2a45f0f869d46889d02405 # v6.2.0
|
|
with:
|
|
python-version: "3.11"
|
|
|
|
- name: Install dependencies
|
|
uses: ./.github/actions/retry
|
|
with:
|
|
command: pip install httpx==0.28.1 pyyaml==6.0.2
|
|
|
|
- name: Build skills index
|
|
env:
|
|
GITHUB_TOKEN: ${{ steps.app-token.outputs.token }}
|
|
run: python scripts/build_skills_index.py
|
|
|
|
- name: Upload index artifact
|
|
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7
|
|
with:
|
|
name: skills-index
|
|
path: website/static/api/skills-index.json
|
|
retention-days: 7
|
|
|
|
# Re-trigger the docs deploy so the refreshed index lands on the live site.
|
|
# The deploy itself is owned by deploy-site.yml (which crawls and deploys
|
|
# everything in one pipeline); we just kick it on a schedule.
|
|
trigger-deploy:
|
|
needs: build-index
|
|
if: github.event_name == 'schedule' || github.event_name == 'workflow_dispatch'
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 15
|
|
environment: trusted-automation
|
|
steps:
|
|
# Required: `Get GitHub App token` is a LOCAL composite action
|
|
# (./.github/actions/get-app-token) and cannot resolve without the repo
|
|
# checked out. `build-index` above already does this; this job did not,
|
|
# so the scheduled deploy re-trigger never fired.
|
|
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
|
|
|
|
- name: Get GitHub App token
|
|
id: app-token
|
|
uses: ./.github/actions/get-app-token
|
|
with:
|
|
client-id: ${{ vars.APP_CLIENT_ID }}
|
|
private-key: ${{ secrets.APP_PRIVATE_KEY }}
|
|
|
|
- name: Trigger Deploy Site workflow
|
|
env:
|
|
GH_TOKEN: ${{ steps.app-token.outputs.token }}
|
|
run: gh workflow run deploy-site.yml --repo ${{ github.repository }} -f skills_index_run_id=${{ github.run_id }}
|