hermes-agent/agent
ethernet 25d0bcd424 fix(runtime): resolve Hermes-managed Node and uv before bare PATH
Hermes installs runtimes for itself — `uv` at `$HERMES_HOME/bin/uv`, Node
at `$HERMES_HOME/node` — and neither directory is on an arbitrary
process's PATH. Every `shutil.which("node"/"npm"/"npx"/"uv")` in Hermes's
own code therefore has two failure modes: the managed runtime is invisible,
so the caller reports "not installed" or degrades to a slower tier on a
machine that has exactly what it needed; and when a system copy also
exists, the one Hermes does not own wins.

Routed the Hermes-owned call sites through managed-aware resolvers:

- `agent/lsp/install.py`, `hermes_cli/dep_ensure.py`, `hermes_cli/main.py`
  (`_make_tui_argv`), `hermes_cli/tools_config.py` (`_run_post_setup`) now
  use `find_node_executable()`.
- `hermes_cli/tools_config.py::_pip_install` and `hermes_cli/setup.py`'s
  vercel install use `ensure_uv()` (installing uv is in scope during setup,
  and the Windows installer's `uv venv` does not seed pip, so the fallback
  tier is "No module named pip"). `tools/lazy_deps.py` uses `resolve_uv()`
  — a lookup, not a bootstrap, because it runs mid-turn for an optional
  dependency and downloading a runtime as a side effect exceeds what the
  caller asked for.
- `hermes_cli/gateway.py`: extracted `_append_node_dir_for_service()`,
  shared by the systemd unit and launchd plist generators, which appends
  the managed dirs before the PATH-resolved one. A service definition is
  written once and survives reboots, so resolving a system Node that
  happens to lead the installing shell's PATH bakes the wrong interpreter
  in permanently. Managed dirs are profile-scoped, so each profile's unit
  still names its own Node; the existing symlink-parent rule (don't
  `.resolve()`) is preserved verbatim.
- `tools/environments/local.py`: the terminal tool's subshell PATH gains
  the managed dirs, appended alongside the sane entries rather than
  prepended — a tool the user deliberately put on their own PATH still
  wins, and the managed one only fills a gap. This is also what makes the
  bare `which("uv")` in `tools/env_probe.py` correct: that probe reports
  the environment the *model* sees, and the model can only run what is on
  that subshell's PATH.

`scripts/install.ps1`: the persisted User PATH update becomes
`Set-ManagedNodeFirstOnUserPath`, a move-to-front rather than an
add-if-missing. Installs made by an older install.ps1 already have the
managed dir in User PATH — at the tail, behind a system Node — and an
add-if-missing check sees it present and leaves that ordering in place
forever, so the users the bug hurt would never be repaired. Unrelated
entries keep their relative order (empty segments included; a trailing
`;` is legal and the installer's other PATH code preserves them),
duplicates collapse, and it writes only when the string actually changes.

Tests:

- `tests/test_managed_runtime_resolution.py` — AST guard that fails any
  new bare `which()` for a managed runtime, with a short justified
  allow-list and a companion test that fails when an allow-list entry goes
  stale. Reading source is banned by AGENTS.md and this is the documented
  exception: the property is "no call site anywhere spells it this way",
  which no runtime seam can observe.
- `scripts/ci/test_install_ps1_path_migration.ps1` — behavioral, not a
  source regex: it lifts the real `Set-ManagedNodeFirstOnUserPath` out of
  install.ps1's AST and rewrites only the two registry calls into an
  in-memory store, so the shipped split/dedupe/prepend/change-detection
  logic executes for real. Not in the default lane (Linux runners have no
  PowerShell host); runs under `pwsh`. 13/13 assertions pass.
2026-08-01 21:17:51 -04:00
..
lsp fix(runtime): resolve Hermes-managed Node and uv before bare PATH 2026-08-01 21:17:51 -04:00
monitoring feat(monitoring): add hermes.gateway.background_delegations (unit/slot count) 2026-07-25 02:30:20 +00:00
pet
proxy_sources fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide 2026-07-24 11:45:57 -07:00
secret_sources refactor: single build_subprocess_env() factory for all child-process spawns (profile + secret-scrub single owner) 2026-07-29 10:14:11 -07:00
transports fix(codex): defang reserved Harmony tokens in requests 2026-07-31 22:53:20 -07:00
__init__.py
account_usage.py fix(auth): detect upstream Codex quota resets and lift stale pool cooldowns (#69494) 2026-07-22 10:58:22 -07:00
agent_init.py fix(caching): honor prompt_caching.cache_ttl disable in config 2026-08-01 14:14:15 +05:30
agent_runtime_helpers.py refactor(prompt-caching): collapse triplicated destination-plan and label parsing 2026-08-01 15:39:58 +05:30
anthropic_adapter.py fix(auth): route anthropic adapter credential reads through the profile secret scope 2026-08-01 16:42:51 -07:00
async_utils.py refactor(gateway): dedupe detached-task consumer + reconnect backoff policy 2026-07-18 20:01:55 +05:30
aux_accounting.py feat(analytics): record auxiliary model usage per task in session accounting (#65537) 2026-07-16 04:23:12 -07:00
auxiliary_client.py fix(auxiliary): replan cache sections on the async fallback path too 2026-08-01 15:39:58 +05:30
azure_identity_adapter.py
backend_identity.py refactor(fallback): single owner for backend identity and failure-scoped skips 2026-07-26 23:41:54 -07:00
background_review.py fix(background-review): reject unresolved failures as skills 2026-07-31 22:33:03 -07:00
battery.py feat(status-bar): add /battery toggle for a color-coded battery read-out 2026-07-21 13:54:11 -05:00
bedrock_adapter.py feat(bedrock): add Converse API prompt caching (cachePoint) 2026-07-23 11:45:07 -07:00
billing_links.py feat(billing): shared cross-surface out-of-credits signal 2026-07-22 18:08:59 -05:00
billing_usage.py chore: remove unused imports and dead locals (ruff F401/F841 sweep) 2026-07-29 11:53:39 -07:00
billing_view.py chore: remove unused imports and dead locals (ruff F401/F841 sweep) 2026-07-29 11:53:39 -07:00
bounded_response.py
browser_provider.py
browser_registry.py
chat_completion_helpers.py perf(prompt-caching): preserve tool-loop cache boundaries (#20880) 2026-08-01 14:27:12 +05:30
codex_responses_adapter.py fix(codex): defang reserved Harmony tokens in requests 2026-07-31 22:53:20 -07:00
codex_runtime.py fix(codex): don't retry after a valid response.completed on drain error 2026-07-29 16:41:39 -03:00
coding_context.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
context_breakdown.py feat(cli,gateway): unify /context into a visual context-usage breakdown 2026-07-26 18:06:21 -07:00
context_compressor.py refactor(compression): fold simplify-pass findings into feasibility skip 2026-08-01 16:00:52 +05:30
context_engine.py fix(context-engine): snapshot select_context read-only inputs; scope on_turn_complete coverage doc 2026-07-23 19:44:35 -07:00
context_references.py fix(context): keep @ref tokens inline instead of stripping them from the prompt 2026-07-27 22:55:18 -05:00
conversation_compression.py fix(compression): add pre-LLM feasibility check to skip costly no-op summaries 2026-08-01 16:00:52 +05:30
conversation_loop.py perf(prompt-caching): preserve tool-loop cache boundaries (#20880) 2026-08-01 14:27:12 +05:30
copilot_acp_client.py fix(core,cli,gateway,plugins): add encoding='utf-8' to read_text() calls 2026-07-24 17:10:39 -07:00
credential_persistence.py
credential_pool.py fix(credential_pool): use source-path-based write-through to root (#74339) 2026-07-31 22:32:48 -07:00
credential_sources.py fix(windows): sweep remaining bare read_text/write_text sites + linter rule 2026-07-24 17:10:39 -07:00
credits_tracker.py fix(credits): reintroduce grant_spent, gated on an in-session crossing (#73634) 2026-07-28 21:36:23 +00:00
curator.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
curator_backup.py fix(curator): restore the real skills tree when a rollback extract dies part-way 2026-07-31 22:34:57 -07:00
delegation_context.py fix(delegation): prevent child HERMES_SESSION_ID leak into parent process env 2026-07-31 22:32:55 -07:00
display.py feat(gateway): live per-tool status line on Slack 2026-07-18 12:28:59 -07:00
error_classifier.py fix(moa): stream completed aggregator responses safely 2026-07-31 21:52:35 -07:00
errors.py fix(moa): surface stale presets without retries 2026-07-17 13:49:12 -07:00
file_safety.py fix(secrets): harden encrypted Bitwarden cache 2026-07-22 04:40:07 -07:00
gemini_native_adapter.py fix(gemini): sweep hardcoded Gemini default models to gemini-3.6-flash (#32360) 2026-07-28 18:17:56 -07:00
gemini_schema.py fix(gemini): preserve typed enum constraints as strings 2026-07-26 20:59:16 -07:00
i18n.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
image_gen_provider.py
image_gen_registry.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
image_routing.py feat(image_routing): accept vision alias for custom provider models 2026-07-23 08:32:09 -07:00
insights.py perf(state): apply per-call token accounting on a background single-writer queue 2026-07-28 18:47:54 +05:30
iteration_budget.py feat: raise default tool-calling iteration limit from 90 to 500 2026-07-26 12:54:45 -07:00
jiter_preload.py
kanban_stop.py follow-up: integrate agent nudge + dispatcher retry docs and tests 2026-07-14 16:47:33 +05:30
learn_prompt.py
learning_graph.py
learning_graph_render.py chore: remove unused imports and dead locals (ruff F401/F841 sweep) 2026-07-29 11:53:39 -07:00
learning_mutations.py
lmstudio_reasoning.py fix(lmstudio): clamp max/ultra reasoning effort to LM Studio's ceiling 2026-07-16 07:57:51 -07:00
manual_compression_feedback.py fix(compress): classify unconfirmed lock-acquire failures and cover all manual-compress surfaces 2026-07-23 08:19:14 -07:00
markdown_tables.py
memory_manager.py fix(memory): honor disabled toolsets for provider tools 2026-07-24 13:00:53 +05:30
memory_provider.py
message_content.py
message_sanitization.py refactor(agent): single-owner call_id + reasoning_content sanitization policies (wire-parity verified) 2026-07-29 12:29:39 -07:00
moa_loop.py refactor(prompt-caching): collapse triplicated destination-plan and label parsing 2026-08-01 15:39:58 +05:30
moa_trace.py
model_metadata.py fix: widen fallback warning to the sibling custom-endpoint 256K path 2026-08-01 15:05:05 +05:30
models_dev.py Revert "remove Vercel AI Gateway and Vercel Sandbox (#33067)" 2026-07-29 19:48:37 -07:00
moonshot_schema.py fix(agent): inject empty required array on Moonshot object schemas 2026-07-20 11:05:52 -07:00
nous_rate_guard.py fix: decode config and state files as UTF-8 on non-UTF-8 locales 2026-07-24 17:10:39 -07:00
onboarding.py feat(surfaces): route busy-input corrections through active-turn redirect 2026-07-22 12:10:58 -05:00
oneshot.py
plugin_llm.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
portal_tags.py feat(portal): ambient conversation context entangles aux/MoA/delegate calls 2026-07-16 01:13:43 -07:00
process_bootstrap.py
prompt_builder.py feat(terminal): raise Docker sandbox /dev/shm to 1g by default (configurable) 2026-07-31 21:31:51 -07:00
prompt_caching.py perf(prompt-caching): make PromptCachePlan.marker_count lazy 2026-08-01 15:39:58 +05:30
rate_limit_tracker.py
reactions.py feat(agent): core affection reaction detector + reaction_callback 2026-07-10 05:41:59 -05:00
reasoning_timeouts.py fix(compression): coherent context_length setter — no-op guard, re-floor on new window, un-strandable init log 2026-07-28 20:04:58 +05:30
redact.py perf(redact): eliminate exponential backtracking in config-key patterns 2026-08-01 15:58:25 +05:30
relay_llm.py fix(moa): carry completed responses through the managed Relay path 2026-07-31 21:52:35 -07:00
relay_runtime.py fix(relay): close logical calls in stack order 2026-07-28 10:19:53 -07:00
relay_tools.py Reapply "feat(observability): integrate NeMo Relay runtime and shared metrics" 2026-07-27 21:10:51 -07:00
replay_cleanup.py refactor: shared helpers for api_content sidecar pop/drop/extract 2026-07-19 08:25:35 +05:30
retry_utils.py refactor: single shared Retry-After parser 2026-07-29 10:13:50 -07:00
runtime_cwd.py fix(agent): scope install-tree guard to fallback-picked cwds, allow cli/tui in-tree dev 2026-07-16 04:32:23 -07:00
secret_scope.py fix(secrets): scope BWS-injected provider keys 2026-07-22 04:39:17 -07:00
shell_hooks.py feat(delegate): expose redacted child tool history 2026-07-26 20:36:47 -07:00
skill_bundles.py
skill_commands.py fix(gateway): project a /skill turn onto its invocation for every client 2026-07-28 03:44:17 -05:00
skill_preprocessing.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
skill_utils.py Merge origin/main into feat/hsp-sync-client 2026-07-29 13:01:36 -07:00
ssl_guard.py fix(ssl): detect and repair a missing certifi cacert.pem via existing venv-repair infra 2026-07-24 15:53:38 -07:00
ssl_verify.py
stream_diag.py
stream_single_writer.py fix(streaming): make the single-writer fence best-effort so a missing guard can't crash a turn (#66448) 2026-07-17 18:31:09 +00:00
subagent_lifecycle.py chore: remove unused imports and dead locals (ruff F401/F841 sweep) 2026-07-29 11:53:39 -07:00
subdirectory_hints.py
subscription_view.py feat(cli): plan catalog on Free + plan= deep link + top-up/auto-refill copy split (#68689) 2026-07-22 08:11:09 +05:30
system_prompt.py refactor(agent): share static-prefix reconstruction, memoize failed rebuilds 2026-07-28 01:10:05 +05:30
think_scrubber.py fix(agent): re-arm think scrubber boundary after stream flush 2026-07-16 01:07:29 +05:30
thinking_timeout_guidance.py
thread_scoped_output.py
title_generator.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
tool_dispatch_helpers.py fix(agent): scope parallel batches from V4A patch headers 2026-08-01 11:40:59 -07:00
tool_executor.py fix(tool-executor): emit tool results on hard interrupt to keep alternation 2026-08-01 16:42:57 -07:00
tool_guardrails.py refactor(guardrails): make runaway-loop caps per-turn, not session-total 2026-07-26 21:27:45 -07:00
tool_result_classification.py fix(agent): preserve none vs unknown tool effects (#61783) 2026-07-11 05:41:58 -07:00
trace_upload.py fix(windows): sweep remaining unguarded text-mode subprocess sites codebase-wide 2026-07-24 11:45:57 -07:00
trajectory.py
transcription_provider.py
transcription_registry.py fix(deepinfra): harden multimodal provider routing 2026-07-14 02:59:39 +05:30
tts_provider.py
tts_registry.py feat(providers): Support DeepInfra as an LLM provider 2026-07-14 02:59:39 +05:30
turn_context.py Merge upstream main into fix/hermes-relay-anthropic-context 2026-07-28 08:10:58 -07:00
turn_finalizer.py fix(agent): invalidate flush-scan cursor at the defrag marker-pop sibling site 2026-07-31 23:18:12 -07:00
turn_retry_state.py fix(copilot): recover from stale/degraded token 400 AND expired IDE-token 401 2026-07-31 22:31:09 -07:00
turn_summary.py fix(cli): report unknown line deltas for content-free diffs instead of +0 -0 2026-07-26 17:47:51 -07:00
usage_pricing.py Revert "remove Vercel AI Gateway and Vercel Sandbox (#33067)" 2026-07-29 19:48:37 -07:00
verification_evidence.py fix(state): make journal mode canonical and behaviorally verified 2026-07-29 18:13:09 -07:00
verification_stop.py flux3 messaging system fixes 2026-07-30 15:20:09 -07:00
verify_hooks.py
vertex_adapter.py
video_gen_provider.py feat(providers): Support DeepInfra as an LLM provider 2026-07-14 02:59:39 +05:30
video_gen_registry.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00
web_search_provider.py
web_search_registry.py perf: use load_config_readonly() at read-only call sites in agent/ 2026-07-29 15:28:15 -07:00