mirror of
https://github.com/NousResearch/hermes-agent.git
synced 2026-07-31 19:16:29 +00:00
Electron-free SSH connection manager for Desktop SSH remote mode, using the system OpenSSH client so it inherits ~/.ssh/config, the agent, ProxyJump, and hardware keys for free (same rationale as tools/environments/ssh.py). - SshConnection: exec(), forward()/cancelForward(), isAlive(), open(), close() over a persistent ControlMaster (ControlMaster=auto + ControlPersist), with a SHA256-hashed control-socket path kept short for macOS's 104-byte sun_path limit. - BatchMode=yes everywhere: a programmatic ssh never hangs on a passphrase/2FA prompt; auth-needing-interactivity fails fast with guidance to load the key into the agent. - Host-key policy StrictHostKeyChecking=accept-new (TOFU, fingerprint logged); a host-key CHANGE fails closed with the verbatim OpenSSH error surfaced. - Every op raced against a hard timeout; timeout => connection-dead (half-open TCP after sleep) so the caller reconnects rather than retrying in place. - redactSecrets() scrubs HERMES_DASHBOARD_SESSION_TOKEN, X-Hermes-Session-Token, Authorization: Bearer, and ?token=/?ticket= before any line hits desktop.log. All lifecycle logging routes through it. - classifySshError() => distinct unreachable / auth-failed / host-key-changed / timeout kinds for actionable UI errors. 23 node --test cases cover command construction, redaction, error classification, and the lifecycle with an injected fake spawn. Wired into test:desktop:platforms. |
||
|---|---|---|
| .. | ||
| bootstrap-installer | ||
| desktop | ||
| shared | ||