mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-30 19:09:28 +00:00
The stale-.pyc bug class (#6207, #60242, live WhatsApp report: gateway ImportError 'cannot import name parse_model_flags_detailed' after /update) has one shared shape: the checkout's .py files change while __pycache__ retains bytecode from the previous revision, and a later process trusts the stale .pyc. Update-time clears can never fully close this class: 'hermes update' always executes the PRE-pull updater code, so hardening added to it takes effect one update late — and a manual 'git pull' never runs the updater at all. Class fix: - Launch-time guard in main(): compare the checkout fingerprint (cheap file reads via _read_git_revision_fingerprint, no git subprocess) against a .bytecode-fingerprint stamp; sweep __pycache__ once when they diverge. Covers manual pulls, old updaters, ZIP restores — every entry point (CLI, gateway service, desktop backend) passes through main(). - Record the stamp at all three update-time clear sites (git path pre- install, git path post-install, ZIP path) so a normal update never triggers a redundant launch sweep. - Sibling site: 'hermes plugins update' + dashboard plugin update now clear __pycache__ under the plugin dir after git pull (plugin trees live outside the repo guard). E2E validated: reproduced the stale-pyc shadowing (same-size same-mtime source swap → old symbol wins in a fresh process), confirmed the launch sweep restores the new symbol, no-ops when the checkout is unchanged, and re-sweeps on the next pull. Sabotage-tested: reverting the sweep fails 4 of the new tests.
192 lines
5.6 KiB
Text
192 lines
5.6 KiB
Text
.DS_Store
|
|
/venv/
|
|
/venv.old/
|
|
/venv.stale.runtime-*/
|
|
/.hermes-runtime/
|
|
/_pycache/
|
|
*.pyc*
|
|
__pycache__/
|
|
act/
|
|
.act-sandbox-agent.*
|
|
.venv/
|
|
.venv
|
|
.vscode/
|
|
.env
|
|
.op.env
|
|
.env.local
|
|
.env.development.local
|
|
.env.test.local
|
|
.env.production.local
|
|
.env.development
|
|
.env.test
|
|
.hermes-docker/
|
|
.notebooklm-home/
|
|
.notebooklm-cli-venv/
|
|
.notebooklm-playwright/
|
|
.pip-cache/
|
|
.uv-cache/
|
|
compose.hermes.local.yml
|
|
export*
|
|
__pycache__/model_tools.cpython-310.pyc
|
|
__pycache__/web_tools.cpython-310.pyc
|
|
logs/
|
|
data/
|
|
.pytest_cache/
|
|
test_durations.json
|
|
.pytest-cache/
|
|
tmp/
|
|
temp_vision_images/
|
|
hermes-*/*
|
|
examples/
|
|
tests/quick_test_dataset.jsonl
|
|
tests/sample_dataset.jsonl
|
|
run_datagen_kimik2-thinking.sh
|
|
run_datagen_megascience_glm4-6.sh
|
|
run_datagen_sonnet.sh
|
|
source-data/*
|
|
run_datagen_megascience_glm4-6.sh
|
|
data/*
|
|
# No trailing slash: also matches node_modules SYMLINKS (worktrees often
|
|
# symlink node_modules to the main checkout; the dir-only pattern let one
|
|
# slip into a commit and break `npm ci` on CI with ENOTDIR).
|
|
node_modules
|
|
browser-use/
|
|
agent-browser/
|
|
# Private keys
|
|
*.ppk
|
|
*.pem
|
|
privvy*
|
|
images/
|
|
__pycache__/
|
|
hermes_agent.egg-info/
|
|
wandb/
|
|
testlogs
|
|
playwright-report/
|
|
test-results/
|
|
# Playwright visual regression baselines — cached from main in CI, not committed
|
|
*-snapshots/
|
|
|
|
# CLI config (may contain sensitive SSH paths)
|
|
cli-config.yaml
|
|
|
|
# Skills Hub state (lives in ~/.hermes/skills/.hub/ at runtime, but just in case)
|
|
skills/.hub/
|
|
ignored/
|
|
.worktrees/
|
|
environments/benchmarks/evals/
|
|
|
|
# Web UI build output
|
|
hermes_cli/web_dist/
|
|
# Cross-process web UI build lock (flock target, always empty)
|
|
.web_ui_build.lock
|
|
apps/desktop/build/
|
|
apps/desktop/dist/
|
|
|
|
# tsc-emitted artifacts (a stray `tsc -b` compiles into src/, and vite then
|
|
# resolves the stale .js OVER the .tsx — never track these)
|
|
apps/desktop/src/**/*.js
|
|
apps/desktop/src/**/*.js.map
|
|
apps/desktop/src/**/*.d.ts
|
|
!apps/desktop/src/global.d.ts
|
|
!apps/desktop/src/vite-env.d.ts
|
|
apps/shared/src/**/*.js
|
|
apps/shared/src/**/*.js.map
|
|
apps/shared/src/**/*.d.ts
|
|
apps/desktop/release/
|
|
*.tsbuildinfo
|
|
|
|
# Web UI assets — synced from @nous-research/ui at build time via
|
|
# `npm run sync-assets` (see web/package.json).
|
|
web/public/fonts/
|
|
web/public/ds-assets/
|
|
|
|
# Release script temp files
|
|
.release_notes.md
|
|
mini-swe-agent/
|
|
|
|
# Nix
|
|
.direnv/
|
|
.nix-stamps/
|
|
result
|
|
website/static/api/skills-index.json
|
|
# skills.json + skills-meta.json are build artifacts emitted by
|
|
# website/scripts/extract-skills.py during prebuild — keep them out of
|
|
# git for the same reason as skills-index.json (large, generated, change
|
|
# every build).
|
|
website/static/api/skills.json
|
|
website/static/api/skills-meta.json
|
|
# automation-blueprints-index.json is a build artifact emitted by
|
|
# website/scripts/extract-automation-blueprints.py during prebuild.
|
|
website/static/api/automation-blueprints-index.json
|
|
models-dev-upstream/
|
|
|
|
# Local editor / agent tooling (machine-specific; keep in global config, not the repo)
|
|
.codex/
|
|
.cursor/
|
|
.gemini/
|
|
.zed/
|
|
.mcp.json
|
|
opencode.json
|
|
config/mcporter.json
|
|
|
|
hermes_cli/tui_dist/*
|
|
hermes_cli/scripts/
|
|
docs/superpowers/*
|
|
# Working directory for the Hermes Agent's session state (~/.hermes/ at runtime;
|
|
# also created in-repo when an agent operates in this checkout). Plans, audit
|
|
# logs, and per-session caches are never artifacts of the codebase.
|
|
.hermes/
|
|
|
|
# Desktop/bootstrap install marker written into the managed checkout root by the
|
|
# bootstrap installer. It is Hermes-managed runtime state, never a code change —
|
|
# ignore it so `hermes update`'s `git stash push --include-untracked` does not
|
|
# treat it as a local edit and autostash it on every run (#38529).
|
|
.hermes-bootstrap-complete
|
|
|
|
# Persistent dev sandbox dir (scripts/dev-sandbox.sh --persistent)
|
|
.hermes-sandbox/
|
|
|
|
# Interrupted-update breadcrumb + recovery lock written next to the shared venv
|
|
# by `hermes update` / launch-time self-heal. Runtime state, never a code change
|
|
# — ignore so `git status` stays clean and update's autostash skips them.
|
|
.update-incomplete
|
|
.update-incomplete.lock
|
|
|
|
# Checkout fingerprint the __pycache__ tree was last validated against
|
|
# (launch-time stale-bytecode sweep). Runtime state, never a code change.
|
|
.bytecode-fingerprint
|
|
.bytecode-fingerprint.tmp
|
|
|
|
# Installer-written method stamp in the managed checkout root (scripts/install.sh).
|
|
# Runtime metadata only — never a code change. Ignore so `git status` stays clean
|
|
# and `hermes update`'s untracked autostash does not treat it as a local edit (#66189 / #54855).
|
|
/.install_method
|
|
|
|
# Tool Search live-test harness output — non-deterministic model transcripts,
|
|
# regenerated by scripts/tool_search_livetest.py. Never an artifact of the repo.
|
|
scripts/out/
|
|
|
|
# Per-release changelog drafts. These exist only transiently during a release
|
|
# cut (passed to `gh release create --notes-file`); the GitHub Release itself
|
|
# stores the published notes. They are not a build artifact and must never be
|
|
# committed to the repo root. See the hermes-release skill.
|
|
RELEASE_v*.md
|
|
|
|
# Desktop demo-run scratch output (hermes writes demo/*.txt during recorded
|
|
# walkthroughs). Throwaway artifacts, never part of the app.
|
|
apps/desktop/demo/
|
|
|
|
# PR infographics are rendered locally and embedded in PR descriptions via the
|
|
# image-provider (fal.media) URL — they are NEVER committed to the repo. The
|
|
# PR body is the archive. See the hermes-agent-dev skill's
|
|
# pr-infographic-workflow reference (storage rule + lapse #8 / #COMMIT-1).
|
|
#
|
|
# Spelling variants are listed because a single `infographic/` pattern was
|
|
# sidestepped by an `infograficos/` directory (#70552). .gitignore is only
|
|
# the first line of defence and cannot stop `git add -f` at all — the
|
|
# infographic-check CI job is what actually enforces this.
|
|
infographic/
|
|
infographics/
|
|
infograficos/
|
|
infografico/
|
|
native/fts5_cjk/*.so
|