hermes: align authorization and recover inbound delivery - #106
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Open intake let unapproved senders run Inline-local commands and create reply threads before Hermes authorized them. Buttons and settings reconstructed only part of native policy, denying paired users and inconsistently applying local restrictions or parent-profile routes. A failed metadata lookup could also consume a valid message before it reached Hermes.
The adapter now requires Inline sender/chat restrictions plus native host authorization before local effects. It preserves persisted pairing and revocation, complete parent/child route identity, and native pairing handling for unapproved input. Child-only access cannot change parent-wide reply settings. Media/context work and settings inspection happen only after authorization.
Inbound recovery now retains the existing SDK receipt through Python handling instead of acknowledging a socket write:
Validation: isolated registry-dependency package build, typecheck, lint and all 85 tests; canonical tracked source-bundle equality; real SDK cursor/order/replay tests; actual Hermes source-install and runtime tests on minimum 0.21.3 and stable 0.21.5. Real-host coverage uses persisted pairing, approval/revocation, profile isolation and routes, transient authorization recovery, admission while the model task remains active, and fatal teardown cancelling the carrier without losing recovery. Tests use offline transport.
This is at-least-once adapter/native handoff, not durable exactly-once execution or proof of completed model turns. The parent-source gate uses the native runner predicate because the public callback omits parent identity, covered by actual-host tests. Structured self-mentions still skip sidecar sender resolution; complete native bot-loop parity remains a separate provenance issue. No live bot/provider test, package release, merge, or deployment.
References used: the SDK's handler-completion receipt contract and per-bucket scheduler; Hermes 0.21.3/0.21.5 BasePlatformAdapter tri-state authorization, quick message admission and shielded fatal handler; Python asyncio task ownership/cancellation guidance. This branch was built independently from main and uses none of PR105's patch or commits.
Upstream-main compatibility: Hermes removed its deprecated-import scanner while retaining the module as updater stubs. CI and status probes now use the optional scanner exports only when present; successful native loading and tool registration remain mandatory. Verified the exact previously failing upstream SHA
7c799a6565dca33ad8774cb01efb17f88a8c7c43through native source installation and runtime tests, plus stable 0.21.5 and 40 installer/diagnostic tests.