Skip to content

hermes: align authorization and recover inbound delivery - #106

Merged
morajabi merged 4 commits into
mainfrom
codex/hermes-native-auth
Sep 29, 2026
Merged

morajabi merged 4 commits into
mainfrom
codex/hermes-native-auth

Conversation

@morajabi

@morajabi morajabi commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Open intake let unapproved senders run Inline-local commands and create reply threads before Hermes authorized them. Buttons and settings reconstructed only part of native policy, denying paired users and inconsistently applying local restrictions or parent-profile routes. A failed metadata lookup could also consume a valid message before it reached Hermes.

The adapter now requires Inline sender/chat restrictions plus native host authorization before local effects. It preserves persisted pairing and revocation, complete parent/child route identity, and native pairing handling for unapproved input. Child-only access cannot change parent-wide reply settings. Media/context work and settings inspection happen only after authorization.

Inbound recovery now retains the existing SDK receipt through Python handling instead of acknowledging a socket write:

  • A sidecar-generated delivery ID and authenticated loopback ACK extend the existing receipt; no public protocol/schema migration or separate retry queue.
  • Temporary metadata or native authorization failures retry before deduplication/effects. Successful-but-empty or mismatched metadata is not cached; confirmed inaccessible targets retire cleanly.
  • Reconnects replay the same delivery ID. Lost ACK responses retry only the ACK; Python caps outstanding tasks so response loss cannot grow memory without bound.
  • Agent-button target failures retry before creating a turn. Interactive preflight is bounded, then reports a retry prompt instead of indefinitely holding the SDK user-event barrier. Other buttons/settings report unavailable access checks accurately.
  • Unexpected errors notify Hermes's native shielded teardown/reconnect handler. Normal native admission returns before model completion, preserving further input and interrupts.

Validation: isolated registry-dependency package build, typecheck, lint and all 85 tests; canonical tracked source-bundle equality; real SDK cursor/order/replay tests; actual Hermes source-install and runtime tests on minimum 0.21.3 and stable 0.21.5. Real-host coverage uses persisted pairing, approval/revocation, profile isolation and routes, transient authorization recovery, admission while the model task remains active, and fatal teardown cancelling the carrier without losing recovery. Tests use offline transport.

This is at-least-once adapter/native handoff, not durable exactly-once execution or proof of completed model turns. The parent-source gate uses the native runner predicate because the public callback omits parent identity, covered by actual-host tests. Structured self-mentions still skip sidecar sender resolution; complete native bot-loop parity remains a separate provenance issue. No live bot/provider test, package release, merge, or deployment.

References used: the SDK's handler-completion receipt contract and per-bucket scheduler; Hermes 0.21.3/0.21.5 BasePlatformAdapter tri-state authorization, quick message admission and shielded fatal handler; Python asyncio task ownership/cancellation guidance. This branch was built independently from main and uses none of PR105's patch or commits.

Upstream-main compatibility: Hermes removed its deprecated-import scanner while retaining the module as updater stubs. CI and status probes now use the optional scanner exports only when present; successful native loading and tool registration remain mandatory. Verified the exact previously failing upstream SHA 7c799a6565dca33ad8774cb01efb17f88a8c7c43 through native source installation and runtime tests, plus stable 0.21.5 and 40 installer/diagnostic tests.

@morajabi morajabi changed the title hermes: align local actions with native host authorization hermes: align authorization and recover inbound delivery Sep 28, 2026
@morajabi
morajabi merged commit 3ec22dc into main Sep 29, 2026
41 of 42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant