mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-23 16:36:23 +00:00
Removes Homebrew and PyPI wheel/sdist as Hermes distribution paths while
preserving the supported source, Docker, and Nix workflows.
Changes:
- Removes the Homebrew formula, PyPI publish workflow, sdist manifest
(MANIFEST.in), and wheel/sdist release-attachment logic from scripts/release.py.
- Keeps setuptools metadata and entry points required by editable installs
and Docker/Nix builds, but adds a setup.py guard that rejects wheel/sdist
builds outside a sealed Nix derivation (HERMES_NIX_BUILD=1).
- Removes pip/Homebrew install detection, PyPI update checks, the pip
self-update path, the deprecation-banner state, the postinstall subcommand,
wheel data-directory fallbacks in agent/i18n.py and hermes_constants.py,
and the ACP Registry manifest/version-lockstep release logic.
- Adds /nix/store/ path detection so `nix run` / `nix profile install`
installs (which don't set HERMES_MANAGED) are correctly identified as
"nix" rather than falling through to "git"/"unknown".
- Retired install-method values ("pip", "homebrew") in existing
.install_method stamps (both code-scoped and home-scoped) are ignored by
the allowlist reader and fall through to "unknown" instead of resurrecting
a retired enum value.
- Updates Nix packaging to ship bare runtime data (locales, optional-mcps)
through store symlinks and wrapper env vars instead of wheel data-files.
- Removes the ACP Registry manifest/icon and their version-lockstep tests.
- Deletes or rewrites packaging, pip-update, Homebrew, and ACP Registry
tests; adds parametrized coverage for the packaging build guard covering
BOTH sdist and wheel paths (the guards live in separate cmdclass entries
— a passing sdist test proves nothing about the wheel path).
- Updates installation/platform documentation and related user-facing copy.
- Adjusts the supply-chain scan so deleted install-hook files do not trigger
a finding, while additions or modifications still require the existing
ci-reviewed label gate.
Supported installation paths (unchanged):
- git installer (install.sh)
- Docker
- Nix/NixOS
- editable development installs (uv sync, uv pip install -e ., pip install -e .)
157 lines
4.7 KiB
Nix
157 lines
4.7 KiB
Nix
# nix/python.nix — uv2nix virtual environment builder
|
|
{
|
|
python312,
|
|
lib,
|
|
callPackage,
|
|
uv2nix,
|
|
pyproject-nix,
|
|
pyproject-build-systems,
|
|
stdenv,
|
|
# Filtered Python source (see lib.nix pythonSrc) — keeps JS/docs/skills
|
|
# edits from invalidating the venv derivation.
|
|
pythonSrc,
|
|
dependency-groups ? [ "all" ],
|
|
}:
|
|
let
|
|
workspace = uv2nix.lib.workspace.loadWorkspace { workspaceRoot = pythonSrc; };
|
|
hacks = callPackage pyproject-nix.build.hacks { };
|
|
|
|
overlay = workspace.mkPyprojectOverlay {
|
|
sourcePreference = "wheel";
|
|
};
|
|
|
|
isAarch64Darwin = stdenv.hostPlatform.system == "aarch64-darwin";
|
|
|
|
# Keep the workspace locked through uv2nix, but supply the local voice stack
|
|
# from nixpkgs so wheel-only transitive artifacts do not break evaluation.
|
|
mkPrebuiltPassthru = dependencies: {
|
|
inherit dependencies;
|
|
optional-dependencies = { };
|
|
dependency-groups = { };
|
|
};
|
|
|
|
mkPrebuiltOverride =
|
|
final: from: dependencies:
|
|
hacks.nixpkgsPrebuilt {
|
|
inherit from;
|
|
prev = {
|
|
nativeBuildInputs = [ final.pyprojectHook ];
|
|
passthru = mkPrebuiltPassthru dependencies;
|
|
};
|
|
};
|
|
|
|
# Legacy alibabacloud packages ship only sdists with setup.py/setup.cfg
|
|
# and no pyproject.toml, so setuptools isn't declared as a build dep.
|
|
buildSystemOverrides =
|
|
final: prev:
|
|
builtins.mapAttrs
|
|
(
|
|
name: _:
|
|
prev.${name}.overrideAttrs (old: {
|
|
nativeBuildInputs = (old.nativeBuildInputs or [ ]) ++ [ final.setuptools ];
|
|
})
|
|
)
|
|
(
|
|
lib.genAttrs [
|
|
"alibabacloud-credentials-api"
|
|
"alibabacloud-endpoint-util"
|
|
"alibabacloud-gateway-dingtalk"
|
|
"alibabacloud-gateway-spi"
|
|
"alibabacloud-tea"
|
|
] (_: null)
|
|
);
|
|
|
|
pythonPackageOverrides =
|
|
final: _prev:
|
|
if isAarch64Darwin then
|
|
{
|
|
numpy = mkPrebuiltOverride final python312.pkgs.numpy { };
|
|
|
|
pyarrow = mkPrebuiltOverride final python312.pkgs.pyarrow { };
|
|
|
|
av = mkPrebuiltOverride final python312.pkgs.av { };
|
|
|
|
humanfriendly = mkPrebuiltOverride final python312.pkgs.humanfriendly { };
|
|
|
|
coloredlogs = mkPrebuiltOverride final python312.pkgs.coloredlogs {
|
|
humanfriendly = [ ];
|
|
};
|
|
|
|
onnxruntime = mkPrebuiltOverride final python312.pkgs.onnxruntime {
|
|
coloredlogs = [ ];
|
|
numpy = [ ];
|
|
packaging = [ ];
|
|
};
|
|
|
|
ctranslate2 = mkPrebuiltOverride final python312.pkgs.ctranslate2 {
|
|
numpy = [ ];
|
|
pyyaml = [ ];
|
|
};
|
|
|
|
faster-whisper = mkPrebuiltOverride final python312.pkgs.faster-whisper {
|
|
av = [ ];
|
|
ctranslate2 = [ ];
|
|
huggingface-hub = [ ];
|
|
onnxruntime = [ ];
|
|
tokenizers = [ ];
|
|
tqdm = [ ];
|
|
};
|
|
}
|
|
else
|
|
{ };
|
|
|
|
pythonSet =
|
|
(callPackage pyproject-nix.build.packages {
|
|
python = python312;
|
|
}).overrideScope
|
|
(
|
|
lib.composeManyExtensions [
|
|
pyproject-build-systems.overlays.default
|
|
overlay
|
|
buildSystemOverrides
|
|
pythonPackageOverrides
|
|
# ``setup.py`` permits wheel/sdist creation only from the sealed
|
|
# Hermes derivation. This is deliberately a derivation environment
|
|
# variable, not a devShell variable: ``nix develop -c uv build``
|
|
# must remain blocked.
|
|
(final: prev: {
|
|
hermes-agent = prev.hermes-agent.overrideAttrs (_old: {
|
|
HERMES_NIX_BUILD = "1";
|
|
});
|
|
})
|
|
]
|
|
);
|
|
|
|
# The editable venv points at the live checkout, so it uses an
|
|
# UNFILTERED workspace rooted at a real path — mkEditablePyprojectOverlay
|
|
# computes relative paths via lib.path.splitRoot, which rejects the
|
|
# filtered pythonSrc (a cleanSourceWith set, not a path). Filtering
|
|
# buys nothing here anyway: the editable install reads from
|
|
# $HERMES_PYTHON_SRC_ROOT at runtime.
|
|
workspaceRoot = ./..;
|
|
editableWorkspace = uv2nix.lib.workspace.loadWorkspace { inherit workspaceRoot; };
|
|
editableOverlay = editableWorkspace.mkEditablePyprojectOverlay {
|
|
root = "$HERMES_PYTHON_SRC_ROOT"; # resolved at shellHook time
|
|
};
|
|
|
|
editableSet = pythonSet.overrideScope (
|
|
lib.composeManyExtensions [
|
|
editableOverlay
|
|
(final: prev: {
|
|
hermes-agent = prev.hermes-agent.overrideAttrs (old: {
|
|
# point straight at the real source instead of the filtered nix store copy
|
|
src = workspaceRoot;
|
|
nativeBuildInputs = old.nativeBuildInputs ++ final.resolveBuildSystem { editables = [ ]; };
|
|
});
|
|
})
|
|
]
|
|
);
|
|
in
|
|
{
|
|
venv = pythonSet.mkVirtualEnv "hermes-agent-env" {
|
|
hermes-agent = dependency-groups;
|
|
};
|
|
editableVenv = editableSet.mkVirtualEnv "hermes-agent-editable-env" {
|
|
hermes-agent = dependency-groups;
|
|
};
|
|
}
|