Commit Graph
4949 Commits
Author SHA1 Message Date
DottaandPaperclip 36125adb4e test(hermes): pin lower qualification campaign budgets
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:57:55 -05:00
DottaandPaperclip ec40b1eb32 fix(hermes): retain the owned billing receipt during Stop
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip d4eee95165 Verify native Stop callback and terminal settlement
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip b7ea45ae9c Preserve cancelled native questions and their Stop evidence
Use the canonical question converter for durable fallbacks. Retire pending native input only on its confirmed cancelled turn. Pass cancelled status to shared account and billing checks and retain the original browser acknowledgement before polling.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip f198406e80 Navigate to the native Hermes Stop task before interaction
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 0bda651f21 Qualify browser Stop at an unanswered Hermes callback
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip b0bbaffec6 Clarify the Hermes native question fixture objective
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 3c7e0ef3a1 Test Hermes native question batches through the browser
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 1500900ece Test Hermes native question batches through runnerd
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a8cce899fc Fix recovery question submission labels
Use the canonical saved question presentation when submitting recovery answers and record current Mac qualification evidence.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 6788c30cf2 fix(hermes): make Mac runtime signing reproducible across hosts
Specify 16 KiB code-signing pages for the normalized Python library. The 4 KiB default reproduces the exact rejected cloud hash; 16 KiB reproduces the existing reviewed bytes. Keep closure pins and dependency locks unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a60b6badb8 ci(hermes): retain rejected Mac closure manifest for byte comparison
Preserve file-level provisioning evidence before cleanup without weakening reviewed closure admission. Record the original cloud failure and the passing current-source native fixtures on macOS 26.5.2.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 40f6ddac33 ci(hermes): qualify Mac arm64 and export tested cloud runner
Build both native targets on standard cloud runners. Keep fixtures credential-free, validate host and binary architecture, and publish exact source, runtime, tool and binary provenance for acceptance without local Rust builds.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 1b31d77c17 fix(hermes): admit verified generated assets without weakening source checks
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a49b9c20b9 test(hermes): exercise shutdown receipts with the v7 input contract
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 83f4a1a136 fix(hermes): retain v7 permissions after master synchronization
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip efd5f5d74b fix(hermes): settle native usage before governed confirmations
Extend the managed human-input boundary to confirmations and checkbox
confirmations. Preserve native receipts before controller parking and
cover immediate shutdown for all three canonical input kinds.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip f29f7d89b9 fix(hermes): delay bridge question completion until native receipt
Return the committed question to Hermes before publishing the tool bridge's
own completion fact. Hold that fact until native terminal delivery, after
final prompt usage. Keep other harnesses on their existing order and treat a
typed already-terminal passive interrupt as settled cancellation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 23919a8787 fix(hermes): settle native usage before question yield
Stop native Hermes at a committed assigned question. Preserve final prompt
usage before its completed tool result reaches the controller cancellation
boundary. Keep ordinary tools streaming and add an immediate-shutdown native
regression with pinned runtime closure updates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip e3be06f25e fix(hermes): retain usage after input-yield shutdown
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 842925d08c fix(hermes): settle closed retry work with unknown usage
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip e5afbd7107 fix(hermes): retain per-turn reported OpenRouter billing
Capture pinned SDK wire attempts, carry closed versioned receipts through ACPX and PRP, and bind reported subtotals to native turn accounting. Keep incomplete attempts unpriced and require settled cost plus budget health in the live OpenRouter oracle.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 01855199ad fix(hermes): verify approved qualification lockfile
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6d81d5c0dd fix(hermes): record checked-out qualification source before credentials
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 29f1c087c5 fix(hermes): preserve pinned setup configuration and verify runtime files
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 51700ff8c6 feat(hermes): ship explicit public runtime setup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip af50ff553d test(hermes): add bounded managed Bedrock qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 08d9803b8f test(hermes): verify the expected account owner independently
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6f5748bb95 docs(hermes): record API completion and answer-limit evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 49e99eca47 test(hermes): use the current Google qualification model
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6f75f7a59c ci(hermes): supply the selected Google qualification key
Map GEMINI_API_KEY only for the selected paid matrix credential. Extend the trusted-workflow credential checks to prevent ambient Google secrets in unapproved workflows. This fixes the reviewed Google cells startup failure.

Validation: all 15 workflow security tests, actionlint, and diff checks pass.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 4313a55dde test(hermes): bound API qualification before task dispatch
Require one attempt and public readback of scoped 200-cent company and agent budgets before the paid API task is created. Reject unlimited or foreign budget records. Preserve unknown usage as unknown.

Record all five successful paid Linux browser workflows and verified temporary AWS host/access cleanup. The complete support suite passes 1,833 Vitest tests and 128 Node assertions, with one skipped Vitest test. Product E2E TypeScript and diff checks pass.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip b10746b4e6 test(hermes): qualify managed API accounts through the runner
Add ten explicit pending API-account browser cells and independently grade the selected account, native harness, and exact model. Keep fixture credential staging on the shared Connections path. Carry candidate metadata into CI so every selected Hermes profile receives verified runtime assets before secrets.

Record the private AWS image build and three actual Linux browser passes without promoting Hermes. Product E2E support typecheck and all 102 affected tests pass; the broader support suite passed 1,826 Vitest tests and 128 node assertions before the final oracle refinements.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 6f87ea523b ci(hermes): cover shared native fixture inputs
Trigger credential-free Linux native fixtures for shared Runner sources, Rust and build manifests, dependency patches, and workspace inputs. Verify actual glob matching for attachment, backend, transport and dependency changes. Paid workflow authority is unchanged.

Validation: 15 workflow security tests and actionlint passed. Also record 26 passing real-database authority tests, the expected old-lock negative proof, and 143 passing ACPX lifecycle regressions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip d8453bf775 docs(hermes): record review fixes and replayed Linux proof
Record the encoded attachment and independent planning fixes, the routine contention regression awaiting a healthy database host, and the passing replayed Linux transport evidence. Preserve all paid qualification failures and the pending release gate.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 3dfd3da7f9 docs(hermes): record Linux transport proof and stack replay
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 3561e1edca ci(hermes): qualify the fixture Node interpreter
Remove group/world write bits from the dedicated CI job's Node interpreter,
matching the protected paid workflow setup. Preserve the Rust launch verifier
and record the first Linux fixture result and interrupted PR checks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 6cf6cef34a fix(hermes): bound cold native admission separately
Give Hermes native session opening a 60-second bound for verified private
runtime copying and ACP initialization. Allow controller startup and per-turn
restoration overhead while preserving ordinary command and stop deadlines.

Add delayed-admission regressions and credential-free Linux native fixture CI.
Record the failed final-head paid campaign without promoting qualification.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 42f91e33ac docs(hermes): record paid acceptance and qualification limits
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 5c2a78fa45 ci(hermes): provision pinned runtime for selected paid campaigns
Select candidate assets consistently for immutable image identity and remote packs; provision local Linux assets before the protected paid step exposes credentials. Preserve default-branch dispatch and qualification gates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 4a0b327727 test(hermes): add paid browser qualification campaigns
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 1bd40b69e2 fix(hermes): release assigned skill copies after failed state save
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:27:37 -05:00
DottaandPaperclip 19ab7e06df fix(hermes): pin v7 permission policy in the independent server launch
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip a2643eb538 fix(runner): preserve Dot v6 while versioning Hermes input as v7
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 8cf6f8335d fix(hermes): publish and enforce native answer limits
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip fd054630f1 fix(runner): bound encoded Hermes attachment messages
Count serialized message, attachments, and metadata before turn admission. Keep TypeScript and Rust on a 7 MiB encoded content allowance within the existing encrypted frame bound. Validate before active-turn state changes, and prove accepted images and escaped documents traverse the secure PRP command frame.

Validation: 28 attachment/permission tests, two encrypted-frame regressions, the Rust encoded-admission regression, and Runner TypeScript compilation passed.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 6d68b96bc5 fix(hermes): preserve planning authority and native transcript results
Qualification exposed denied plan workflows, missing structured tool output, and cancellation replay in subsequent turns. Admit assigned control-plane operations through their existing semantic authority, project denied native calls by identity, and keep managed history restoration separate from transcript replay.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip eda7dd0ab7 docs(runner): pass resolved lock digest in image commands
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 63ec34ee79 fix(hermes): require the resolved image lock digest
Require the caller-verified target lock checksum instead of an incompatible checked-in default. Document lock-bot ownership and the companion browser qualification PR.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 7d89e304f0 fix(acpx): separate restored history from active turn events
Keep history reconstruction without publishing restored text and tools as live output. Version the changed Cursor contract as profile 16 and retain replay compatibility.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00