Commit Graph
1662 Commits
Author SHA1 Message Date
DottaandPaperclip 9794f657b7 test(hermes): cover early steering ownership and timeout
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 07:08:50 -05:00
DottaandPaperclip 01ad83057b Merge verified native controls into Hermes qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 07:08:50 -05:00
DottaandPaperclip f01a5f02f8 fix(hermes): bound question responses and await native steering identity
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 07:08:06 -05:00
DottaandPaperclip 84aa0fad11 Merge verified native assistant channel preservation
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 06:35:01 -05:00
DottaandPaperclip 7be8858576 Merge verified native assistant channel preservation
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/hermes-routines:
  fix(runner): preserve validated native assistant delta channels
2026-10-09 06:34:17 -05:00
DottaandPaperclip 58cb562866 fix(runner): preserve validated native assistant delta channels
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 06:33:59 -05:00
DottaandPaperclip dc53d4d6b7 fix(hermes): retain reported charges from interrupted requests
Keep authenticated verified OpenRouter usage frames in the known subtotal even when transport fails, without certifying complete cost or token totals. Cover the real pinned SDK interruption plus a successful retry and update both reviewed runtime closure pins.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 06:20:15 -05:00
Dotta 4f40b5b666 Merge branch 'codex/hermes-native-runner' into codex/hermes-qualification
* codex/hermes-native-runner:
  test(db): set PostgreSQL deadlines before suite declarations
2026-10-09 02:53:57 -05:00
Dotta a8805d61af Merge branch 'codex/hermes-routines' into codex/hermes-native-runner
* codex/hermes-routines:
  test(db): set PostgreSQL deadlines before suite declarations
2026-10-09 02:53:53 -05:00
Dotta 7a03294664 test(db): set PostgreSQL deadlines before suite declarations 2026-10-09 02:53:47 -05:00
Dotta 7de8063a04 Merge branch 'codex/hermes-native-runner' into codex/hermes-qualification
* codex/hermes-native-runner:
  test: separate cold route setup and bound backup integration cases
2026-10-09 02:46:39 -05:00
Dotta 43697be47c Merge branch 'codex/hermes-routines' into codex/hermes-native-runner
* codex/hermes-routines:
  test: separate cold route setup and bound backup integration cases
2026-10-09 02:46:31 -05:00
Dotta ffa25aa9a3 test: separate cold route setup and bound backup integration cases 2026-10-09 02:46:28 -05:00
Dotta c87bb7017d Merge branch 'codex/hermes-native-runner' into codex/hermes-qualification
* codex/hermes-native-runner:
  fix(runner): carry steering identity into Hermes parent
  test(server): load feedback routes within suite setup
2026-10-09 02:18:42 -05:00
DottaandPaperclip 3fce49c5b9 fix(runner): carry steering identity into Hermes parent
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 02:18:38 -05:00
DottaandPaperclip 0afd50696d fix(hermes): bind cloud image identity to public setup helpers
Hash all three Hermes setup inputs. Keep the PR below the review limit by moving the unchanged public setup and account-cache test files to the stacked qualification follow-up.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 01:30:25 -05:00
DottaandPaperclip 48bea8a9a8 fix(hermes): synchronize native parent distribution pins
Refresh both source-owned native parent pins for the sandbox payload change. Retain the prior reviewed interpreter and dependency entries; only tool_process.py changes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 23:20:11 -05:00
DottaandPaperclip 6136eb1397 fix(hermes): pin the Linux device sandbox closure
Derive platform pins from previously verified manifests with only tool_process.py changed. Require fresh cloud materialization and retain the prior concurrent-write failure.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 23:07:47 -05:00
DottaandPaperclip a9e033c4e7 Merge the native Linux device sandbox fix into Hermes qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/hermes-native-runner:
  fix(hermes): mount usable Linux sandbox devices
2026-10-08 23:06:31 -05:00
DottaandPaperclip 4e050e9650 fix(hermes): mount usable Linux sandbox devices
Provide the minimal bubblewrap device mount for native shell redirects and atomic writes, probe it before credential staging, and cover concurrent writes plus protected paths.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 23:06:10 -05:00
DottaandPaperclip 3e9e54964c fix(runner): bind ACPX steering to the active provider turn
Preserve flat Runner acknowledgement receipts so native steering emits one
transcript item. Add a pinned Hermes regression across Rust PRP with distinct
durable and provider turn identities and stale-control rejection.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 22:33:24 -05:00
DottaandPaperclip 638296ab2a fix(hermes): retain managed permissions through native restore
Cover native edit approval within the authorized invocation and record bounded,
versioned tool grants per conversation. Recheck policy and cancellation before
each operation. Restore named custom connections through their configured
identity and reject native route fallback. Bind assigned skill contents across
temporary lease replacements while preserving their write protection.

Qualify real native once/deny/session file effects, provider restart, distinct
same-name tool identities, conversation isolation and unanswered permission
cancellation with the credential-free production ACPX fixture. Update the
reviewed platform closure pins and document the remaining release gates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 21:20:42 -05:00
DottaandPaperclip a14a752ec8 fix(hermes): preserve cancelled usage at the ACPX wire boundary
Bind usage to the admitted native session and turn before cancelled prompt settlement. Check its durable PRP carrier and harden qualification receipt identity and budget capture.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 13:37:58 -05:00
DottaandPaperclip ec40b1eb32 fix(hermes): retain the owned billing receipt during Stop
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip d4eee95165 Verify native Stop callback and terminal settlement
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip b7ea45ae9c Preserve cancelled native questions and their Stop evidence
Use the canonical question converter for durable fallbacks. Retire pending native input only on its confirmed cancelled turn. Pass cancelled status to shared account and billing checks and retain the original browser acknowledgement before polling.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 1500900ece Test Hermes native question batches through runnerd
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 6788c30cf2 fix(hermes): make Mac runtime signing reproducible across hosts
Specify 16 KiB code-signing pages for the normalized Python library. The 4 KiB default reproduces the exact rejected cloud hash; 16 KiB reproduces the existing reviewed bytes. Keep closure pins and dependency locks unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 40f6ddac33 ci(hermes): qualify Mac arm64 and export tested cloud runner
Build both native targets on standard cloud runners. Keep fixtures credential-free, validate host and binary architecture, and publish exact source, runtime, tool and binary provenance for acceptance without local Rust builds.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a49b9c20b9 test(hermes): exercise shutdown receipts with the v7 input contract
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip efd5f5d74b fix(hermes): settle native usage before governed confirmations
Extend the managed human-input boundary to confirmations and checkbox
confirmations. Preserve native receipts before controller parking and
cover immediate shutdown for all three canonical input kinds.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip f29f7d89b9 fix(hermes): delay bridge question completion until native receipt
Return the committed question to Hermes before publishing the tool bridge's
own completion fact. Hold that fact until native terminal delivery, after
final prompt usage. Keep other harnesses on their existing order and treat a
typed already-terminal passive interrupt as settled cancellation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 23919a8787 fix(hermes): settle native usage before question yield
Stop native Hermes at a committed assigned question. Preserve final prompt
usage before its completed tool result reaches the controller cancellation
boundary. Keep ordinary tools streaming and add an immediate-shutdown native
regression with pinned runtime closure updates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip e3be06f25e fix(hermes): retain usage after input-yield shutdown
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 842925d08c fix(hermes): settle closed retry work with unknown usage
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip e5afbd7107 fix(hermes): retain per-turn reported OpenRouter billing
Capture pinned SDK wire attempts, carry closed versioned receipts through ACPX and PRP, and bind reported subtotals to native turn accounting. Keep incomplete attempts unpriced and require settled cost plus budget health in the live OpenRouter oracle.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 29f1c087c5 fix(hermes): preserve pinned setup configuration and verify runtime files
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 51700ff8c6 feat(hermes): ship explicit public runtime setup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6cf6cef34a fix(hermes): bound cold native admission separately
Give Hermes native session opening a 60-second bound for verified private
runtime copying and ACP initialization. Allow controller startup and per-turn
restoration overhead while preserving ordinary command and stop deadlines.

Add delayed-admission regressions and credential-free Linux native fixture CI.
Record the failed final-head paid campaign without promoting qualification.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00
DottaandPaperclip 1bd40b69e2 fix(hermes): release assigned skill copies after failed state save
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:27:37 -05:00
DottaandPaperclip a2643eb538 fix(runner): preserve Dot v6 while versioning Hermes input as v7
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 8cf6f8335d fix(hermes): publish and enforce native answer limits
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip fd054630f1 fix(runner): bound encoded Hermes attachment messages
Count serialized message, attachments, and metadata before turn admission. Keep TypeScript and Rust on a 7 MiB encoded content allowance within the existing encrypted frame bound. Validate before active-turn state changes, and prove accepted images and escaped documents traverse the secure PRP command frame.

Validation: 28 attachment/permission tests, two encrypted-frame regressions, the Rust encoded-admission regression, and Runner TypeScript compilation passed.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 6d68b96bc5 fix(hermes): preserve planning authority and native transcript results
Qualification exposed denied plan workflows, missing structured tool output, and cancellation replay in subsequent turns. Admit assigned control-plane operations through their existing semantic authority, project denied native calls by identity, and keep managed history restoration separate from transcript replay.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 63ec34ee79 fix(hermes): require the resolved image lock digest
Require the caller-verified target lock checksum instead of an incompatible checked-in default. Document lock-bot ownership and the companion browser qualification PR.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 7d89e304f0 fix(acpx): separate restored history from active turn events
Keep history reconstruction without publishing restored text and tools as live output. Version the changed Cursor contract as profile 16 and retain replay compatibility.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
DottaandPaperclip 68b1a39459 fix(hermes): keep native candidate independently restorable
Reject replaced learned-state parents, include authenticated run attachment and the advertised native transport fixtures in this candidate. Keep paid browser campaign definitions in the qualification PR.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
Dotta c834f9dd8a fix(hermes): release credentials and reproduce relocatable runtime assets 2026-10-08 12:07:09 -05:00
DottaandPaperclip 9e07748e91 feat(runner): add native Hermes ACP qualification candidate
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:07:09 -05:00
Dotta 79e5d38139 fix(routines): remap annotations and verify atomic schedule edits 2026-10-08 02:27:42 -05:00