Commit Graph
4968 Commits
Author SHA1 Message Date
DottaandPaperclip f628d54bc8 fix(hermes): project native completion and tool activity
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 01:57:28 -05:00
DottaandPaperclip 300afb3fe3 test(hermes): retain public setup and account-cache qualification
Keep the unchanged Hermes setup and account-cache fixtures in a focused follow-up so the native and core qualification reviews each stay below 100 files.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 01:31:27 -05:00
DottaandPaperclip 930860cd74 test(cursor): retain baseline setup checks in core qualification
Move only the additional Hermes setup assertions to the stacked follow-up. Keep all existing Cursor setup tests in place.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 01:31:25 -05:00
DottaandPaperclip 0afd50696d fix(hermes): bind cloud image identity to public setup helpers
Hash all three Hermes setup inputs. Keep the PR below the review limit by moving the unchanged public setup and account-cache test files to the stacked qualification follow-up.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 01:30:25 -05:00
DottaandPaperclip ef0f626781 Merge Hermes stack worker cleanup
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/hermes-native-runner:
  fix(test): remove immutable runtime contexts at worker exit
2026-10-09 01:24:43 -05:00
DottaandPaperclip a6672a81be Merge Hermes foundation worker cleanup
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/hermes-routines:
  fix(test): remove immutable runtime contexts at worker exit
2026-10-09 01:24:42 -05:00
DottaandPaperclip 0effdedd07 fix(test): remove immutable runtime contexts at worker exit
Restore directory write access inside the private worker home before removal, without following external directory symlinks.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-09 01:24:30 -05:00
Dotta 7ab7747fe3 Merge synchronized native parent Hermes pins
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/hermes-native-runner:
  fix(hermes): synchronize native parent distribution pins

# Conflicts:
#	packages/paperclip-runner/src/drivers/acpx/hermes-installation.ts
2026-10-08 23:21:06 -05:00
DottaandPaperclip 48bea8a9a8 fix(hermes): synchronize native parent distribution pins
Refresh both source-owned native parent pins for the sandbox payload change. Retain the prior reviewed interpreter and dependency entries; only tool_process.py changes.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 23:20:11 -05:00
DottaandPaperclip 6136eb1397 fix(hermes): pin the Linux device sandbox closure
Derive platform pins from previously verified manifests with only tool_process.py changed. Require fresh cloud materialization and retain the prior concurrent-write failure.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 23:07:47 -05:00
DottaandPaperclip a9e033c4e7 Merge the native Linux device sandbox fix into Hermes qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>

* codex/hermes-native-runner:
  fix(hermes): mount usable Linux sandbox devices
2026-10-08 23:06:31 -05:00
DottaandPaperclip 4e050e9650 fix(hermes): mount usable Linux sandbox devices
Provide the minimal bubblewrap device mount for native shell redirects and atomic writes, probe it before credential staging, and cover concurrent writes plus protected paths.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 23:06:10 -05:00
DottaandPaperclip 3e9e54964c fix(runner): bind ACPX steering to the active provider turn
Preserve flat Runner acknowledgement receipts so native steering emits one
transcript item. Add a pinned Hermes regression across Rust PRP with distinct
durable and provider turn identities and stale-control rejection.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 22:33:24 -05:00
DottaandPaperclip 638296ab2a fix(hermes): retain managed permissions through native restore
Cover native edit approval within the authorized invocation and record bounded,
versioned tool grants per conversation. Recheck policy and cancellation before
each operation. Restore named custom connections through their configured
identity and reject native route fallback. Bind assigned skill contents across
temporary lease replacements while preserving their write protection.

Qualify real native once/deny/session file effects, provider restart, distinct
same-name tool identities, conversation isolation and unanswered permission
cancellation with the credential-free production ACPX fixture. Update the
reviewed platform closure pins and document the remaining release gates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 21:20:42 -05:00
DottaandPaperclip ef0d855034 test(hermes): enforce native image evidence gate
Require saved image checks to pass after account and billing evidence is collected. Advance the explicit image definition to version 2.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 15:16:21 -05:00
DottaandPaperclip 9478ead982 test(hermes): add native image acceptance journey
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 14:58:47 -05:00
DottaandPaperclip af87a249c1 docs(hermes): record the passing local native Stop proof
Record the committed-source browser cancellation, stale-answer denial, process retirement and reported cost. Keep historical failures and remaining release gates explicit.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 14:13:01 -05:00
DottaandPaperclip 2400ecdb8d test(hermes): require the persisted native cancellation receipt
Bind the expired card to its original unanswered request and require the canonical zero-answer cancellation result. Preserve the failed live measurement and advance qualification definitions.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 14:01:00 -05:00
DottaandPaperclip a14a752ec8 fix(hermes): preserve cancelled usage at the ACPX wire boundary
Bind usage to the admitted native session and turn before cancelled prompt settlement. Check its durable PRP carrier and harden qualification receipt identity and budget capture.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 13:37:58 -05:00
DottaandPaperclip 36125adb4e test(hermes): pin lower qualification campaign budgets
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:57:55 -05:00
DottaandPaperclip ec40b1eb32 fix(hermes): retain the owned billing receipt during Stop
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip d4eee95165 Verify native Stop callback and terminal settlement
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip b7ea45ae9c Preserve cancelled native questions and their Stop evidence
Use the canonical question converter for durable fallbacks. Retire pending native input only on its confirmed cancelled turn. Pass cancelled status to shared account and billing checks and retain the original browser acknowledgement before polling.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip f198406e80 Navigate to the native Hermes Stop task before interaction
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 0bda651f21 Qualify browser Stop at an unanswered Hermes callback
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip b0bbaffec6 Clarify the Hermes native question fixture objective
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 3c7e0ef3a1 Test Hermes native question batches through the browser
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 1500900ece Test Hermes native question batches through runnerd
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a8cce899fc Fix recovery question submission labels
Use the canonical saved question presentation when submitting recovery answers and record current Mac qualification evidence.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 6788c30cf2 fix(hermes): make Mac runtime signing reproducible across hosts
Specify 16 KiB code-signing pages for the normalized Python library. The 4 KiB default reproduces the exact rejected cloud hash; 16 KiB reproduces the existing reviewed bytes. Keep closure pins and dependency locks unchanged.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a60b6badb8 ci(hermes): retain rejected Mac closure manifest for byte comparison
Preserve file-level provisioning evidence before cleanup without weakening reviewed closure admission. Record the original cloud failure and the passing current-source native fixtures on macOS 26.5.2.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 40f6ddac33 ci(hermes): qualify Mac arm64 and export tested cloud runner
Build both native targets on standard cloud runners. Keep fixtures credential-free, validate host and binary architecture, and publish exact source, runtime, tool and binary provenance for acceptance without local Rust builds.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 1b31d77c17 fix(hermes): admit verified generated assets without weakening source checks
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip a49b9c20b9 test(hermes): exercise shutdown receipts with the v7 input contract
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip 83f4a1a136 fix(hermes): retain v7 permissions after master synchronization
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip efd5f5d74b fix(hermes): settle native usage before governed confirmations
Extend the managed human-input boundary to confirmations and checkbox
confirmations. Preserve native receipts before controller parking and
cover immediate shutdown for all three canonical input kinds.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:13 -05:00
DottaandPaperclip f29f7d89b9 fix(hermes): delay bridge question completion until native receipt
Return the committed question to Hermes before publishing the tool bridge's
own completion fact. Hold that fact until native terminal delivery, after
final prompt usage. Keep other harnesses on their existing order and treat a
typed already-terminal passive interrupt as settled cancellation.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 23919a8787 fix(hermes): settle native usage before question yield
Stop native Hermes at a committed assigned question. Preserve final prompt
usage before its completed tool result reaches the controller cancellation
boundary. Keep ordinary tools streaming and add an immediate-shutdown native
regression with pinned runtime closure updates.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip e3be06f25e fix(hermes): retain usage after input-yield shutdown
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 842925d08c fix(hermes): settle closed retry work with unknown usage
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip e5afbd7107 fix(hermes): retain per-turn reported OpenRouter billing
Capture pinned SDK wire attempts, carry closed versioned receipts through ACPX and PRP, and bind reported subtotals to native turn accounting. Keep incomplete attempts unpriced and require settled cost plus budget health in the live OpenRouter oracle.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 01855199ad fix(hermes): verify approved qualification lockfile
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6d81d5c0dd fix(hermes): record checked-out qualification source before credentials
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 29f1c087c5 fix(hermes): preserve pinned setup configuration and verify runtime files
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 51700ff8c6 feat(hermes): ship explicit public runtime setup
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip af50ff553d test(hermes): add bounded managed Bedrock qualification
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 08d9803b8f test(hermes): verify the expected account owner independently
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6f5748bb95 docs(hermes): record API completion and answer-limit evidence
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 49e99eca47 test(hermes): use the current Google qualification model
Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:12 -05:00
DottaandPaperclip 6f75f7a59c ci(hermes): supply the selected Google qualification key
Map GEMINI_API_KEY only for the selected paid matrix credential. Extend the trusted-workflow credential checks to prevent ambient Google secrets in unapproved workflows. This fixes the reviewed Google cells startup failure.

Validation: all 15 workflow security tests, actionlint, and diff checks pass.

Co-Authored-By: Paperclip <noreply@paperclip.ing>
2026-10-08 12:28:11 -05:00