The uninstall flow now reads the install stamp to learn who owns the code. Three install kinds exist: - standard (git checkout from the installer or 'hermes desktop'): keeps the full gui/lite/full flow. - bundled (embedded payload): the app can only remove user data. The embedded CPython runs the uninstall module. The OS removes the app (Apps & Features / Trash / delete the AppImage). - nix: the app can only remove user data. The UI shows 'managed by Nix' guidance instead of code-removal options. A new mode 'data' (hermes uninstall --data) removes ~/.hermes user data and the Electron userData dir, and keeps all code. This mode is valid on every install kind. The Python uninstaller enforces the same rule on its own: it reads .hermes_build_info.json through runtime_tree and refuses the code-removal modes on sealed trees, with instructions from the steward. The renderer cannot make a managed install delete code. loadInstallStamp now accepts a stamp with commit:null. A dirty Nix build writes such a stamp, and the provenance fields must survive. |
||
|---|---|---|
| .. | ||
| __init__.py | ||
| _shared.py | ||
| acp.py | ||
| approvals.py | ||
| auth.py | ||
| backup.py | ||
| claw.py | ||
| config.py | ||
| console.py | ||
| cron.py | ||
| dashboard.py | ||
| debug.py | ||
| doctor.py | ||
| dump.py | ||
| gateway.py | ||
| gui.py | ||
| hooks.py | ||
| import_agent.py | ||
| import_cmd.py | ||
| insights.py | ||
| login.py | ||
| logout.py | ||
| logs.py | ||
| mcp.py | ||
| memory.py | ||
| model.py | ||
| monitoring.py | ||
| pairing.py | ||
| pause.py | ||
| plugins.py | ||
| profile.py | ||
| prompt_size.py | ||
| security.py | ||
| setup.py | ||
| skills.py | ||
| skin.py | ||
| slack.py | ||
| status.py | ||
| sync.py | ||
| tools.py | ||
| uninstall.py | ||
| update.py | ||
| verify.py | ||
| version.py | ||
| webhook.py | ||
| whatsapp.py | ||