Skip to content

feat(hermes): bump Hermes Agent to v2026.6.19 - #5594

Merged
cv merged 77 commits into
mainfrom
dep/hermes-v2026.6.19
Jun 25, 2026
Merged

cv merged 77 commits into
mainfrom
dep/hermes-v2026.6.19

Conversation

@ericksoa

@ericksoa ericksoa commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Refs #5591 for the Hermes dependency-upgrade slice.

  • Bumps Hermes to v2026.6.19 / hermes-agent@0.17.0.
  • Pins the Hermes release tarball SHA256 and npm integrity, with scripts/update-hermes-agent.sh check support.
  • Carries the Hermes v0.16+ integration work needed for the current runtime shape: bearer-token API access, dashboard/model-picker config, dashboard-home seeding, npm workspace build handling, /dev/pts access, python-multipart, and Hermes secret-boundary updates.
  • Updates NemoClaw CLI/dashboard token plumbing so gateway-token can retrieve a bearer-token agent key when the manifest declares one.

Validation

  • npm install --ignore-scripts
  • npm run build:cli
  • npm run typecheck
  • scripts/update-hermes-agent.sh --check --tag v2026.6.19
  • python3 -m py_compile agents/hermes/seed-dashboard-config.py agents/hermes/runtime-config-guard.py agents/hermes/validate-env-secret-boundary.py
  • bash -n agents/hermes/start.sh scripts/update-hermes-agent.sh test/e2e/test-hermes-sandbox-secret-boundary.sh test/e2e/test-hermes-root-entrypoint-smoke.sh
  • npx vitest run --project cli test/hermes-runtime-api-key.test.ts test/hermes-start.test.ts src/lib/agent/defs.test.ts test/cli/snapshot-shields.test.ts test/update-hermes-agent-script.test.ts test/seed-hermes-dashboard-config.test.ts test/hermes-share-mount-deps.test.ts test/sandbox-provisioning.test.ts
  • npm run test-conditionals:scan -- --top 25
  • npx prek run --all-files --stage pre-push --skip tsc-plugin --skip tsc-js --skip tsc-cli --skip version-tag-sync --skip test-cli --skip test-plugin --skip source-shape-test-budget --skip test-file-size-budget --skip test-skills-yaml
  • npm run source-shape:check
  • npm run test-size:check
  • npx vitest run test/skills-frontmatter.test.ts
  • python3 scripts/generate-platform-docs.py --check
  • git diff --check
  • GitHub PR checks on head ff03680e4c3c24fe04df3631331380aaa0e8e9cb: PR Review Advisor, E2E recommendation, CodeQL, ShellCheck, sandbox image builds, required static/CLI checks, and PR-gated E2E smoke jobs all passing.

Review Notes

  • PR Review Advisor is green on head ff03680e4c3c24fe04df3631331380aaa0e8e9cb with no blocking findings; the prior API_SERVER_KEY/runtime-config and workspace-lockfile findings are resolved by code and focused regression coverage.
  • The remaining PRA-T1 acceptance-clause follow-up is justified against [NemoClaw] Dependency Updates (Hermes, OpenShell, OpenClaw) #5591, which is a broad design/dependency proposal without concrete acceptance clauses; the changed Hermes behavior is covered by the validation above and the passing PR checks.
  • Earlier broad Vitest E2E result comments are historical for older heads/all-job dispatches. The latest required PR checks and E2E recommendation are green on the current head.
  • Docker was not run locally, but GitHub build-sandbox-images and build-sandbox-images-arm64 both passed on the current head.

Signed-off-by: Aaron Erickson aerickson@nvidia.com

ericksoa and others added 11 commits June 22, 2026 10:28
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
…arts

Hermes v0.16.0+ guards its OpenAI-compatible API server with a bearer token
read from API_SERVER_KEY. Without it the gateway refuses to start, so the
install health check fails.

- Generate a per-sandbox API_SERVER_KEY into the Hermes .env.
- Allow that single raw key past the secret-boundary validator (env-file and
  runtime-env), mirroring OPENCLAW_GATEWAY_TOKEN: it is a self-minted,
  loopback-only token, not an egress credential, so it legitimately lives raw
  in .env rather than as an openshell:resolve placeholder.
- Accept HTTP 401 (not just 200) as "gateway alive" in the in-sandbox health
  wait, since the probe is unauthenticated and v0.16 may 401 it.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The v0.16 gateway's bearer token was minted but not retrievable, so users
had no way to call the OpenAI-compatible API.

- Add an agent web-auth model (AgentWebAuth { method, env }) read from the
  manifest; Hermes is bearer_token/API_SERVER_KEY, OpenClaw stays none.
- Make `gateway-token` agent-aware: it now returns a bearer_token agent's
  web-auth key (Hermes' API_SERVER_KEY) as well as OpenClaw's gateway token,
  reading it group-readably from the sandbox .env without ever logging it.
- Onboard prints the OpenAI-compatible API endpoint and the retrieval
  command for bearer_token agents.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Three independent v0.16 install/runtime regressions:

- Vendor python-multipart (pinned + hash-verified to the release's uv.lock)
  so the bundled kanban dashboard plugin's file-upload route mounts. It is
  not a dependency of hermes core or the `web` extra (only of mcp/daytona),
  so a slim extras install omits it; FastAPI then fails the Form/File route.
  Vendored directly rather than pulling the MCP client or the Daytona SDK.
- Grant /dev/pts in both Hermes sandbox policies. The TUI, the dashboard
  chat pty bridge, and terminal.backend: local allocate a pty via openpty();
  without the grant landlock denies /dev/ptmx with EACCES, surfaced as
  "out of pty devices". Mirrors the existing OpenClaw grant (#4513).
- Fix the bump script's post-rebuild verify to use `exec` not `connect`:
  connect is a strict interactive shell that ignores a trailing `-- <cmd>`
  and just prints its usage, so the version check always failed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The model picker (CLI `hermes model` and the dashboard Models page via
/api/model/options) showed zero models even though inference worked: it
enumerates providers through get_compatible_custom_providers(), which only
reads custom_providers/providers — never the inline `model:` block NemoClaw
writes for routing.

Emit a custom_providers entry mirroring the proxied endpoint
(inference.local/v1) with discover_models: true, so the picker live-lists
/v1/models (already served by the proxy and allowlisted in policy). Verified
live: the picker then lists the routed models with is_current set.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…routed model

The Hermes dashboard runs as the sandbox user under its own isolated
HERMES_HOME (/tmp/hermes-dashboard-home) for privilege separation from the
gateway user, so it never sees the model/custom_providers block NemoClaw
writes to the gateway's /sandbox/.hermes/config.yaml. Its load_config() reads
a Hermes-default config with model: '' and no providers, so the dashboard
Models page (/api/model/options -> inventory.build_models_payload) listed zero
models and the kanban specifier/dispatcher (get_text_auxiliary_client) resolved
no client — even though the TUI/CLI on the gateway home worked. Verified live.

Add seed-dashboard-config.py, invoked from start.sh::seed_hermes_dashboard_config
before the dashboard launches, mirroring model/custom_providers/_nemoclaw_upstream
into the dashboard home config while preserving its other keys. custom_providers
carries discover_models: true so the model list stays live-discovered from
/v1/models rather than pinned. Idempotent, symlink-guarded, best-effort (a seed
failure never blocks startup). Confirmed end-to-end in a live sandbox: the
dashboard then lists the 3 routed models and kanban resolves nvidia-routed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
generate-hermes-config.test.ts's findRawSecretEnvEntries flagged the raw
API_SERVER_KEY messaging-config.ts writes to .env, but the production validator
(validate-env-secret-boundary.py) already exempts it via
ENV_FILE_ALLOWED_RAW_SECRET_KEYS — it is Hermes' self-generated api_server
bearer token (v0.16.0+) that never transits the OpenShell proxy, so it has no
resolver placeholder. Mirror that allowlist in the test helper.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Seed the Hermes dashboard's config so the Models page and kanban see the
routed model, mirror the routed provider, and align Dockerfile.base/start.sh
with the v0.16 dashboard launch path.
start.sh invoked seed-dashboard-config.py with bare `python3`, which at
container boot is the base-image interpreter without PyYAML (an interactive
login shell activates the venv, masking this). The seeder then hit its
"PyYAML unavailable; skipping model seed" branch and returned 0, so the
gateway's model routing was silently never mirrored into the dashboard
HERMES_HOME — leaving model:'' / providers:{} and an empty Models page after
a rebuild. Resolve the Hermes venv interpreter explicitly
(/opt/hermes/.venv/bin/python, fallback python3) and run the seeder with it.
That binary is already an allowlisted blueprint binary and the prefer-venv
fallback idiom is used elsewhere in the repo.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
… add hermes doctor --fix

Agent-Logs-Url: https://github.com/tyeth-ai-assisted/NemoClaw/sessions/cc04407b-b2a0-4a6b-8625-2512fab13384

Co-authored-by: tyeth-ai-assisted <259968460+tyeth-ai-assisted@users.noreply.github.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review
📝 Walkthrough

Walkthrough

This PR upgrades Hermes to v2026.6.19 with Node 24, introduces bearer-token web auth with auto-generated API_SERVER_KEY, restructures provider config for model discovery, adds seed-dashboard-config.py for dashboard config routing sync, refactors gateway-token to support both bearer-token and OpenClaw agents, and provides version pinning automation.

Changes

Hermes v16 runtime, auth, and packaging updates

Layer / File(s) Summary
Agent webAuth contract and loader parsing
src/lib/agent/defs.ts, src/lib/agent/defs.test.ts, src/lib/agent/hermes-recovery-boundary-fixtures.ts, src/lib/agent/base-image.test.ts, src/lib/agent/onboard.test.ts, src/lib/agent/runtime.test.ts
Exports AgentWebAuthMethod (bearer_token | none) and AgentWebAuth types, adds webAuth: AgentWebAuth to AgentDefinition contract, parses web_auth_method/web_auth_env from manifest YAML via readWebAuth() helper in loadAgent(), and updates all fixture factories and manifest property assertions to include OpenClaw's method: "none" and Hermes' method: "bearer_token" with env: "API_SERVER_KEY".
Provider config, API_SERVER_KEY, and secret/policy boundary
agents/hermes/config/hermes-config.ts, agents/hermes/config/hermes-env.ts, agents/hermes/config/yaml.ts, agents/hermes/validate-env-secret-boundary.py, agents/hermes/policy-additions.yaml, agents/hermes/policy-permissive.yaml, test/generate-hermes-config.test.ts, test/hermes-start.test.ts, test/runner.test.ts
buildHermesConfig derives providerName from settings.upstreamProvider, emits top-level providers (with discover_models: true) and custom_providers; buildHermesEnvLines generates hex-encoded 32-byte API_SERVER_KEY; YAML serializer adjusts sequence item indentation (itemPad); secret-boundary validator allowlists API_SERVER_KEY as raw env key in .env and runtime; Landlock policies grant read_write to /dev/pts for PTY/TUI support; tests updated with provider-name and config expectations.
Dashboard bearer token fetch helper
src/lib/onboard/agent-web-auth-token.ts, src/lib/onboard/dashboard.ts, src/lib/onboard/dashboard-web-auth-token.test.ts
New fetchAgentWebAuthTokenFromSandbox reads agent.webAuth, constructs in-sandbox grep/cut shell command to extract env var value from config_dir/.env, executes via runCaptureOpenshell, strips matching surrounding quotes, returns null for missing/empty; exposed via OnboardDashboardHelpers interface and wiring; comprehensive Vitest coverage validates sandbox invocation, quote handling, and non-bearer-token agent pass-through.
Agent-aware gateway-token runtime and CLI
src/lib/gateway-token-command.ts, src/commands/sandbox/gateway/token.ts, src/lib/agent/onboard.ts, src/lib/gateway-token-command.test.ts, src/commands/simple-global-oclif-adapters.test.ts, test/cli/doctor-gateway-token.test.ts, test/onboard-gateway-runtime.test.ts
GatewayTokenCommandDeps adds optional agentExposesToken(agentName) hook; GatewayTokenRuntimeBridge now resolves sandbox agent, checks webAuth.method === "bearer_token", and dispatches to bearer-token or OpenClaw gateway-token fetchers; printDashboardUi emits bearer-auth port-forwarding and key-retrieval command instructions; CLI summary/description updated to agent-agnostic wording; command adapter and help/runtime regression tests realigned.
Dashboard config seeding script and startup integration
agents/hermes/seed-dashboard-config.py, agents/hermes/start.sh, test/seed-hermes-dashboard-config.test.ts, test/hermes-start.test.ts
New seed-dashboard-config.py mirrors gateway routing (model, providers, custom_providers, _nemoclaw_upstream) and .env with normalized provider names, symlink security checks, and atomic temp-file writes at mode 0600; start.sh defaults HERMES_DASHBOARD_HOME to /sandbox/.hermes/dashboard-home, resolves Hermes venv Python, integrates seeder in prepare_hermes_dashboard_home, enforces chmod 600 on seeded files, adds verify_hermes_config_integrity root-mode wrapper, updates gateway health probe to accept both 200/401 status; 300-line Vitest test suite covers routing synthesis, env mirroring, merge/idempotency, missing-input handling, and four symlink security regressions.
Hermes Docker build hardening and version pins
agents/hermes/Dockerfile.base, agents/hermes/Dockerfile, agents/hermes/manifest.yaml, test/hermes-share-mount-deps.test.ts, test/sandbox-provisioning.test.ts
Upgrades base image to node:24-trixie-slim with updated apt pins; bumps expected_version to 2026.6.19; adds tarball pyproject.toml semver extraction and verification against ARG HERMES_SEMVER, fetches npm package dist.integrity and validates match; extends UI builds to support workspace-style package-lock.json layout; vendors python-multipart==0.0.27 with hash verification; runs hermes doctor --fix as build repair step; wires seed-dashboard-config.py chmod and /sandbox/.hermes/dashboard-home directory permissions; test fixtures supply HERMES_SEMVER, HERMES_NPM_INTEGRITY env and pyproject.toml version.
Hermes version pinning automation
scripts/update-hermes-agent.sh, test/update-hermes-agent-script.test.ts
New Bash script supporting --tag, --check, --build, --rebuild modes: resolves GitHub release tag, derives calver/semver/npm integrity from release assets and tarball, rewrites Dockerfile.base ARGs and manifest.yaml expected_version, discovers and repins installer-managed Dockerfile copies under ~/.hermes and ~/.nemoclaw, optionally rebuilds sandbox against immutable base-image tag with semver output verification; tests validate installed-copy flag defaults and conditional branch presence.

Sequence Diagrams

sequenceDiagram
  participant CLI as GatewayTokenCliCommand
  participant CMD as runGatewayTokenCommand
  participant Bridge as GatewayTokenRuntimeBridge
  participant FetchBT as fetchAgentWebAuthTokenFromSandbox
  participant FetchOC as fetchGatewayAuthTokenFromSandbox

  CLI->>Bridge: getSandboxAgent(sandboxName)
  Bridge-->>CMD: agentName
  CMD->>Bridge: agentExposesToken(agentName)
  alt bearer_token agent (e.g. hermes)
    Bridge->>FetchBT: runCaptureOpenshell grep API_SERVER_KEY
    FetchBT-->>Bridge: token string
  else openclaw or null
    Bridge->>FetchOC: fetchGatewayAuthTokenFromSandbox(sandboxName)
    FetchOC-->>Bridge: gateway token
  end
  Bridge-->>CMD: fetchToken result
  CMD->>CLI: print token to stdout
Loading
sequenceDiagram
  participant StartSH as start.sh
  participant Seeder as seed-dashboard-config.py
  participant GWConfig as gateway config.yaml
  participant GWEnv as gateway .env
  participant DashYAML as dashboard config.yaml
  participant DashEnv as dashboard .env

  StartSH->>Seeder: python seed-dashboard-config.py
  Seeder->>GWConfig: yaml.safe_load gateway config
  Seeder->>Seeder: normalize routing, synthesize providers
  Seeder->>DashYAML: atomic write with symlink guard
  Seeder->>GWEnv: read and filter
  Seeder->>DashEnv: atomic mirror at 0600 with symlink guard
  Seeder-->>StartSH: exit 0 or 1
  StartSH->>DashYAML: chown + chmod 600
  StartSH->>DashEnv: chown + chmod 600
Loading

Estimated code review effort

🎯 4 (Complex) | ⏱️ ~75 minutes

Possibly related PRs

  • NVIDIA/NemoClaw#4981: This PR updates agents/hermes/validate-env-secret-boundary.py to allow raw API_SERVER_KEY, matching the runtime validator behavior enforced by related Hermes gateway invocation security checks.
  • NVIDIA/NemoClaw#5389: Both PRs modify src/lib/agent/onboard.ts's printDashboardUi output—main PR adds bearer-token API access instructions, while the retrieved PR adds per-agent.forward_ports forwarding blocks—so they overlap in the same function's rendering logic.

Suggested labels

feature, integration: hermes, v0.0.66

Suggested reviewers

  • cv
  • jyaunches

Poem

🐇 Hop, hop! A new key is born,
API_SERVER_KEY minted each morn.
The dashboard seeds from the gateway's map,
No symlink tricks slip through the trap.
Node 24 lifts Hermes up high—
A doctor --fix, and we're ready to fly! 🚀

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.81% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The PR title accurately describes the primary change: bumping the Hermes Agent to v2026.6.19, which is the main version update across multiple integration files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dep/hermes-v2026.6.19

Comment @coderabbitai help to get the list of available commands.

@github-code-quality

github-code-quality Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Code Coverage Overview

Languages: TypeScript

TypeScript / code-coverage/plugin

The overall coverage in the dep/hermes-v2026.6.1... branch is 96%. Coverage data for the main branch is not yet available.

Show a code coverage summary of the most covered files.
File main dep/hermes-v2026.6.1... 00c19e7 +/-
nemoclaw/src/se...cret-scanner.ts — 100% —
nemoclaw/src/commands/slash.ts — 100% —
nemoclaw/src/li...bprocess-env.ts — 100% —
nemoclaw/src/bl...eprint/state.ts — 98% —
nemoclaw/src/onboard/config.ts — 98% —
nemoclaw/src/bl...int/snapshot.ts — 97% —
nemoclaw/src/bl...print/runner.ts — 95% —
nemoclaw/src/co...ration-state.ts — 94% —
nemoclaw/src/bl...ate-networks.ts — 94% —
nemoclaw/src/index.ts — 94% —

TypeScript / code-coverage/cli

The overall coverage in the dep/hermes-v2026.6.1... branch is 47%. Coverage data for the main branch is not yet available.

Show a code coverage summary of the most covered files.
File main dep/hermes-v2026.6.1... 00c19e7 +/-
src/lib/state/o...oard-session.ts — 91% —
src/lib/inference/local.ts — 76% —
src/lib/sandbox/config.ts — 72% —
src/lib/actions...dbox/rebuild.ts — 71% —
src/lib/onboard/preflight.ts — 64% —
src/lib/actions...licy-channel.ts — 60% —
src/lib/state/sandbox.ts — 55% —
src/lib/policy/index.ts — 49% —
src/lib/onboard...er-gpu-patch.ts — 44% —
src/lib/onboard.ts — 19% —

Updated June 25, 2026 20:11 UTC
Code Coverage is in Public Preview. Learn more and provide us with your feedback.

Comment thread agents/hermes/seed-dashboard-config.py Fixed
Comment thread agents/hermes/seed-dashboard-config.py Fixed
Comment thread agents/hermes/seed-dashboard-config.py Fixed
Comment thread agents/hermes/seed-dashboard-config.py Fixed
@github-actions

github-actions Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

E2E Advisor Recommendation

Required E2E: hermes-root-entrypoint-smoke-e2e, hermes-secret-boundary-e2e, hermes-e2e, hermes-dashboard-e2e, hermes-inference-switch-e2e, network-policy-e2e, hermes-slack-e2e, hermes-discord-e2e, rebuild-hermes-e2e, cloud-onboard-e2e, token-rotation-e2e
Optional E2E: common-egress-agent-e2e, rebuild-hermes-stale-base-e2e, shields-config-e2e, credential-sanitization-e2e, channels-stop-start-hermes-e2e

Dispatch hint: cloud-onboard-e2e,hermes-e2e,hermes-dashboard-e2e,hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e,hermes-inference-switch-e2e,network-policy-e2e,hermes-slack-e2e,hermes-discord-e2e,rebuild-hermes-e2e,token-rotation-e2e

Auto-dispatched E2E: hermes-root-entrypoint-smoke-e2e, hermes-secret-boundary-e2e via nightly-e2e.yaml at 00c19e79ca6a178e6dc42ec054a2551d13b73378 — nightly run

Workflow run

Full advisor summary

E2E Recommendation Advisor

Base: origin/main
Head: HEAD
Confidence: high

Required E2E

  • hermes-root-entrypoint-smoke-e2e (medium): Required because start.sh, Dockerfile layering, Hermes version, runtime config guard, dashboard-home, permissions, and entrypoint startup behavior changed. This verifies the real Hermes image and root entrypoint smoke path.
  • hermes-secret-boundary-e2e (medium): Required because the PR changes secret-boundary validation, runtime .env placeholder refresh, API_SERVER_KEY minting, and descriptor-safe config/hash updates. This must be validated against the real sandbox image and startup boundary.
  • hermes-e2e (high): Required because Hermes install/onboard, generated config, health, gateway runtime, and live inference paths changed. This validates the main real-user Hermes assistant flow.
  • hermes-dashboard-e2e (high): Required because the PR adds dashboard config seeding, changes dashboard home, auth/env mirroring, and model-provider discovery config. The dashboard flow must prove the UI can start and see the routed model.
  • hermes-inference-switch-e2e (high): Required because generated Hermes model/custom_providers/providers routing, provider placeholder handling, and API mode behavior changed. This checks routed inference changes across provider switching.
  • network-policy-e2e (high): Required because Hermes default/permissive policy changed, including PTY filesystem grants and /v1/models allow rules. Live policy enforcement must validate allow/deny behavior through OpenShell.
  • hermes-slack-e2e (high): Required because Hermes messaging env rendering and provider placeholder normalization changed for Slack tokens, plus the live Slack E2E helper/script was touched. This validates placeholder isolation and credential rewrite for a real Hermes messaging onboarding flow.
  • hermes-discord-e2e (high): Required because shared Hermes messaging credential placeholder generation and runtime provider placeholder refresh also cover Discord. This validates a second Hermes messaging credential path and native gateway rewrite isolation.
  • rebuild-hermes-e2e (high): Required because Hermes image layout, manifest state dirs/files, runtime symlinks, dashboard-home, config hashes, and agent runtime recovery changed. Rebuild must prove state preservation and regenerated image compatibility.
  • cloud-onboard-e2e (high): Required because the PR changes onboarding-adjacent agent definitions, agent onboard/web-auth handling, dashboard web auth token code, gateway token command behavior, and hosted inference routing. Full hosted onboarding should be exercised.
  • token-rotation-e2e (medium): Required because shared messaging credential persistence and provider placeholder normalization changed. This validates credential hash persistence, reuse, and rotation propagation across onboarding/rebuild.

Optional E2E

  • common-egress-agent-e2e (high): Useful adjacent coverage because Hermes policy, inference routing, and common-egress agent live tests changed. It gives end-to-end confidence that real assistant turns still egress only through the intended gateway.
  • rebuild-hermes-stale-base-e2e (high): Useful because the final Dockerfile adds compatibility fallbacks for stale published Hermes bases and the PR updates base-image expectations. Run if the PR is expected to support stale-base rebuilds before the new base is published.
  • shields-config-e2e (medium): Useful because runtime config hashes, config integrity verification, .env updates, and permissions changed. This can catch shields-up/down regressions around locked config files.
  • credential-sanitization-e2e (medium): Useful because gateway token and credential placeholder paths changed. This gives extra assurance that no raw secret values leak into logs, registry, or artifacts.
  • channels-stop-start-hermes-e2e (medium): Useful because Hermes messaging placeholder rendering and runtime provider placeholder refresh changed. This exercises Hermes channel lifecycle behavior after initial onboarding.

New E2E recommendations

  • Hermes dashboard routing (high): The new dashboard config seeder is security-sensitive and fixes a specific isolated HERMES_DASHBOARD_HOME model-picker/kanban-routing failure. If hermes-dashboard-e2e does not explicitly assert /api/model/options returns the NemoClaw-routed provider/model and that dashboard-launched auxiliary/kanban code can resolve a client, add a focused assertion or new E2E.
    • Suggested test: hermes-dashboard-model-routing-e2e
  • Hermes runtime config guard (high): runtime-config-guard.py performs descriptor-safe writes over sandbox-writable config paths. Existing secret-boundary coverage should be extended if it does not attempt symlink, hardlink, raced replacement, and group/world-writable .env/config/hash paths during API_SERVER_KEY minting and provider-placeholder refresh.
    • Suggested test: hermes-runtime-config-guard-e2e
  • Hermes messaging credential rotation (medium): The existing token-rotation E2E primarily covers shared credential persistence; the PR adds Hermes-specific .env provider-placeholder refresh at startup. Add a Hermes-specific rotation/rebuild check if current Hermes Slack/Discord tests do not re-run onboard with changed tokens and assert only placeholders, not raw tokens, reach the sandbox.
    • Suggested test: hermes-messaging-token-rotation-e2e

Dispatch hint

  • Workflow: .github/workflows/nightly-e2e.yaml
  • jobs input: cloud-onboard-e2e,hermes-e2e,hermes-dashboard-e2e,hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e,hermes-inference-switch-e2e,network-policy-e2e,hermes-slack-e2e,hermes-discord-e2e,rebuild-hermes-e2e,token-rotation-e2e

@github-actions

github-actions Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

Vitest E2E Scenario Recommendation

Required Vitest E2E scenarios: common-egress-agent-vitest, hermes-root-entrypoint-smoke-vitest, hermes-sandbox-secret-boundary-vitest, rebuild-hermes-stale-base-vitest, rebuild-hermes-vitest, hermes-inference-switch-vitest, hermes-slack-vitest
Optional Vitest E2E scenarios: hermes-discord-vitest

Dispatch required Vitest E2E scenarios:

  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=common-egress-agent-vitest
  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-root-entrypoint-smoke-vitest
  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-sandbox-secret-boundary-vitest
  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=rebuild-hermes-stale-base-vitest
  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=rebuild-hermes-vitest
  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-inference-switch-vitest
  • gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-slack-vitest

Workflow run

Full Vitest E2E advisor summary

Vitest E2E Scenario Advisor

Base: origin/main
Head: HEAD
Confidence: high

Required Vitest E2E scenarios

  • common-egress-agent-vitest: Focused free-standing Vitest job wired for changed live test test/e2e-scenario/live/common-egress-agent.test.ts.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=common-egress-agent-vitest
  • hermes-root-entrypoint-smoke-vitest: Focused free-standing Vitest job wired for changed live test test/e2e-scenario/live/hermes-root-entrypoint-smoke.test.ts.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-root-entrypoint-smoke-vitest
  • hermes-sandbox-secret-boundary-vitest: Focused free-standing Vitest job wired for changed live test test/e2e-scenario/live/hermes-sandbox-secret-boundary.test.ts.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-sandbox-secret-boundary-vitest
  • rebuild-hermes-stale-base-vitest: Focused free-standing Vitest job wired for changed live test test/e2e-scenario/live/rebuild-hermes.test.ts.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=rebuild-hermes-stale-base-vitest
  • rebuild-hermes-vitest: Focused free-standing Vitest job wired for changed live test test/e2e-scenario/live/rebuild-hermes.test.ts.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=rebuild-hermes-vitest
  • hermes-inference-switch-vitest: Hermes model/provider routing, config hash refresh, dashboard routing seed, and runtime config mutation changed; the inference-switch job validates live route/config updates and hash stability.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-inference-switch-vitest
  • hermes-slack-vitest: Messaging credential placeholder rendering and the Hermes Slack live helper changed; run the Slack job to exercise placeholder isolation and messaging-provider secret-boundary behavior.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-slack-vitest

Optional Vitest E2E scenarios

  • hermes-discord-vitest: Adjacent Hermes messaging coverage for the same generalized provider-placeholder and secret-boundary changes, using Discord instead of Slack.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=hermes-discord-vitest

Relevant changed files

  • agents/hermes/Dockerfile
  • agents/hermes/Dockerfile.base
  • agents/hermes/config/build-env.ts
  • agents/hermes/config/hermes-config.ts
  • agents/hermes/config/hermes-env.ts
  • agents/hermes/config/yaml.ts
  • agents/hermes/manifest.yaml
  • agents/hermes/policy-additions.yaml
  • agents/hermes/policy-permissive.yaml
  • agents/hermes/runtime-config-guard.py
  • agents/hermes/seed-dashboard-config.py
  • agents/hermes/start.sh
  • agents/hermes/validate-env-secret-boundary.py
  • scripts/update-hermes-agent.sh
  • src/commands/sandbox/gateway/token.ts
  • src/lib/agent/defs.ts
  • src/lib/agent/hermes-recovery-boundary-fixtures.ts
  • src/lib/agent/onboard.ts
  • src/lib/agent/runtime.ts
  • src/lib/agent/web-auth-ui.ts
  • src/lib/agent/web-auth.ts
  • src/lib/gateway-token-command.ts
  • src/lib/messaging/applier/agent-config.ts
  • src/lib/messaging/persisted-placeholders.ts
  • src/lib/messaging/persistence.ts
  • src/lib/messaging/provider-placeholders.ts
  • src/lib/onboard/agent-web-auth-token.ts
  • src/lib/onboard/dashboard.ts
  • test/e2e-scenario/live/common-egress-agent.test.ts
  • test/e2e-scenario/live/hermes-root-entrypoint-smoke.test.ts
  • test/e2e-scenario/live/hermes-sandbox-secret-boundary.test.ts
  • test/e2e-scenario/live/hermes-slack-e2e-helpers.ts
  • test/e2e-scenario/live/rebuild-hermes.test.ts

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 5

🧹 Nitpick comments (1)
agents/hermes/seed-dashboard-config.py (1)

323-334: 🧹 Nitpick | 🔵 Trivial | 💤 Low value

Consider setting restrictive permissions on config.yaml before atomic replace.

The .env file gets chmod 0o600 on the temp file before os.replace() (line 249), but the config.yaml write doesn't. While start.sh applies chmod 600 after seeding (line 708), the config file could briefly exist with default umask permissions between os.replace() and the caller's chmod. This is a minor inconsistency since the dashboard home dir is already chmod 700.

Suggested fix for consistency
     try:
         with open(tmp, "w", encoding="utf-8") as handle:
             yaml.safe_dump(dashboard, handle, sort_keys=False)
+        os.chmod(tmp, 0o600)
         os.replace(tmp, dst)
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@agents/hermes/seed-dashboard-config.py` around lines 323 - 334, The temporary
file written in the dashboard config seeding block does not have restrictive
permissions set before the atomic replace operation, creating a brief window
where the file could exist with default umask permissions. In the try block
where the YAML is dumped to the tmp file and before the os.replace(tmp, dst)
call, add an os.chmod(tmp, 0o600) call to set restrictive permissions on the
temporary file, matching the pattern used for the .env file seeding mentioned in
the review comment, ensuring consistency and security of the configuration file.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@agents/hermes/start.sh`:
- Line 724: The function seed_hermes_dashboard_config is being called
redundantly in the start.sh script. Since prepare_hermes_dashboard_home already
calls seed_hermes_dashboard_config with the owner argument internally, the
additional calls to seed_hermes_dashboard_config at lines 724 and 738 are
unnecessary and should be removed entirely. This will eliminate duplicate work
on every dashboard launch while maintaining the same functionality, as the
seeding is still handled by the prepare_hermes_dashboard_home invocation.

In `@scripts/update-hermes-agent.sh`:
- Around line 84-89: The prerequisite tool check in the for loop iterating
through curl, python3, npm, sha256sum, tar, and sed does not include realpath,
which is required by the discover_installed_dockerfiles function but will only
fail later with an unclear error message. Add realpath to the list of tools
being validated in the for loop to ensure this dependency is checked upfront
with a clear error message.
- Around line 336-339: The parameter expansion ${BASE_REF%:*} in the pin_tag
assignment incorrectly strips everything after the last colon regardless of
whether it is a registry port or an image tag. For references like
localhost:5000/hermes-base without an explicit tag, this strips the port number
leaving only localhost. Fix this by checking whether BASE_REF contains an image
tag (a colon that appears after the last forward slash) before stripping it.
Only apply the %:* pattern if a tag actually exists in BASE_REF, otherwise
append the new tag directly to the full BASE_REF value.

In `@src/lib/agent/defs.ts`:
- Around line 317-334: In the readWebAuth function, the env variable is not
being normalized to null when the method is normalized to "none". Currently, if
web_auth_method is not "bearer_token", the method is set to "none", but env
retains whatever value was assigned from the rawEnv validation check. To fix
this, after determining that method is "none" (meaning web_auth_method is not
"bearer_token"), explicitly set env to null before returning the object to
ensure the AgentWebAuth contract is honored where env should only be non-null
when method is "bearer_token".

In `@test/cli/snapshot-shields.test.ts`:
- Line 52: The `it()` function on line 52 is being called with a fourth
positional argument `15_000`, which exceeds Vitest's API that only accepts up to
3 arguments. Since the timeout is already configured via
`testTimeoutOptions(30_000)` passed as the second argument, remove the trailing
`15_000` argument from the `it()` call to match the correct API signature.

---

Nitpick comments:
In `@agents/hermes/seed-dashboard-config.py`:
- Around line 323-334: The temporary file written in the dashboard config
seeding block does not have restrictive permissions set before the atomic
replace operation, creating a brief window where the file could exist with
default umask permissions. In the try block where the YAML is dumped to the tmp
file and before the os.replace(tmp, dst) call, add an os.chmod(tmp, 0o600) call
to set restrictive permissions on the temporary file, matching the pattern used
for the .env file seeding mentioned in the review comment, ensuring consistency
and security of the configuration file.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Enterprise

Run ID: 2ffc0b1a-1213-451c-aa69-d390fe38af23

📥 Commits

Reviewing files that changed from the base of the PR and between 32d5008 and 3351ea9.

📒 Files selected for processing (34)
  • agents/hermes/Dockerfile
  • agents/hermes/Dockerfile.base
  • agents/hermes/config/hermes-config.ts
  • agents/hermes/config/hermes-env.ts
  • agents/hermes/config/yaml.ts
  • agents/hermes/manifest.yaml
  • agents/hermes/policy-additions.yaml
  • agents/hermes/policy-permissive.yaml
  • agents/hermes/seed-dashboard-config.py
  • agents/hermes/start.sh
  • agents/hermes/validate-env-secret-boundary.py
  • scripts/update-hermes-agent.sh
  • src/commands/sandbox/gateway/token.ts
  • src/commands/simple-global-oclif-adapters.test.ts
  • src/lib/agent/base-image.test.ts
  • src/lib/agent/defs.test.ts
  • src/lib/agent/defs.ts
  • src/lib/agent/hermes-recovery-boundary-fixtures.ts
  • src/lib/agent/onboard.test.ts
  • src/lib/agent/onboard.ts
  • src/lib/agent/runtime.test.ts
  • src/lib/gateway-token-command.test.ts
  • src/lib/gateway-token-command.ts
  • src/lib/onboard.ts
  • src/lib/onboard/dashboard-web-auth-token.test.ts
  • src/lib/onboard/dashboard.ts
  • test/cli/doctor-gateway-token.test.ts
  • test/cli/snapshot-shields.test.ts
  • test/generate-hermes-config.test.ts
  • test/hermes-share-mount-deps.test.ts
  • test/hermes-start.test.ts
  • test/onboard-gateway-runtime.test.ts
  • test/sandbox-provisioning.test.ts
  • test/seed-hermes-dashboard-config.test.ts

Comment thread agents/hermes/start.sh Outdated
Comment thread scripts/update-hermes-agent.sh Outdated
Comment thread scripts/update-hermes-agent.sh Outdated
Comment thread src/lib/agent/defs.ts Outdated
Comment thread test/cli/snapshot-shields.test.ts Outdated
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ❌ Some jobs failed

Run: 27973065752
Target ref: 3351ea940428d66822aa5f2876de8990fcd2904b
Workflow ref: main
Requested jobs: hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e
Summary: 1 passed, 1 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ❌ failure
hermes-secret-boundary-e2e ✅ success

Failed jobs: hermes-root-entrypoint-smoke-e2e. Check run artifacts for logs.

ericksoa added 2 commits June 22, 2026 11:08
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ❌ Some jobs failed

Run: 27973695448
Target ref: 2385b153cb4336d4ecfba6d6c107c35d9e7cecc8
Workflow ref: main
Requested jobs: hermes-secret-boundary-e2e,hermes-root-entrypoint-smoke-e2e
Summary: 1 passed, 1 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ❌ failure
hermes-secret-boundary-e2e ✅ success

Failed jobs: hermes-root-entrypoint-smoke-e2e. Check run artifacts for logs.

@github-actions

github-actions Bot commented Jun 22, 2026 •

Copy link
Copy Markdown
Contributor

PR Review Advisor — No blocking findings

Merge posture: No blocking advisor findings
Primary next action: Add or justify PRA-T1 and any related test follow-ups.
Open items: 0 required · 0 warnings · 0 suggestions · 2 test follow-ups
Since last review: 2 prior items resolved · 0 still apply · 0 new items found

Action checklist

  • PRA-T1 Add or justify test follow-up: Runtime validation
  • PRA-T2 Add or justify test follow-up: Acceptance clause
Test follow-ups to resolve or justify

If these cover changed behavior, prefer adding them in this PR; otherwise state why existing coverage is enough or link the follow-up.

  • PRA-T1 Runtime validation — Dashboard-only recovery in a live Hermes container deletes stale /sandbox/.hermes/dashboard-home/gateway_state.json, reseeds dashboard-home/config.yaml and dashboard-home/.env from the gateway config/env, and relaunches hermes dashboard with HERMES_HOME=/sandbox/.hermes/dashboard-home.. Unit/static coverage is strong for the new helpers and generated shell strings, and live scenarios cover root entrypoint startup, bearer auth, dashboard-home seeding, secret-boundary rejection, dependency provisioning, compiler purge, and PTY access. Because this PR also changes recovery behavior, one additional runtime recovery probe would improve confidence without duplicating existing tests.
  • PRA-T2 Acceptance clause — Linked issue acceptance clauses for [NemoClaw] Dependency Updates (Hermes, OpenShell, OpenClaw) #5591 — add test evidence or identify existing coverage. The deterministic validation context reported linkedIssues: [] and did not include [NemoClaw] Dependency Updates (Hermes, OpenShell, OpenClaw) #5591 issue body or comments, so no linked-issue acceptance clauses were available to quote literally. PR-stated scope was treated as untrusted review context only.

Workflow run details

This is an automated, non-binding review; it still expects maintainers and agents to respond to each required or warning item. Treat suggestions as current-PR improvements when they touch changed code; defer only with maintainer rationale or a linked follow-up. A human maintainer must make the final merge decision.

@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ❌ Some jobs failed

Run: 27974261930
Target ref: 7c177ee72635782f7e615b56a60df38335d1909a
Workflow ref: main
Requested jobs: hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e
Summary: 1 passed, 1 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ❌ failure
hermes-secret-boundary-e2e ✅ success

Failed jobs: hermes-root-entrypoint-smoke-e2e. Check run artifacts for logs.

@ericksoa ericksoa self-assigned this Jun 22, 2026
Comment thread agents/hermes/start.sh Fixed
Comment thread agents/hermes/seed-dashboard-config.py Fixed
Comment thread agents/hermes/seed-dashboard-config.py Fixed
@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ✅ All requested jobs passed

Run: 28194483287
Target ref: 2aeb2b61d7ebb7a9ec51559e6ab9f999d3ee8cf3
Workflow ref: main
Requested jobs: hermes-secret-boundary-e2e,hermes-root-entrypoint-smoke-e2e
Summary: 2 passed, 0 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ✅ success
hermes-secret-boundary-e2e ✅ success

ericksoa added 2 commits June 25, 2026 12:25
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@ericksoa

Copy link
Copy Markdown
Contributor Author

Processed PR Review Advisor follow-ups for head 0b01aaf32bd966dca08bc3d9a0dada17fe24ec4a.

Required advisor items handled in code:

  • PRA-1: extracted persisted credential placeholder repair into src/lib/messaging/persisted-placeholders.ts; src/lib/messaging/persistence.ts is now 768 lines, below the prior 784-line base noted by the advisor.
  • PRA-2 / PRA-T4: moved Hermes persisted placeholder coverage from src/lib/messaging/plan-validation.test.ts into focused src/lib/messaging/persisted-placeholders.test.ts; plan-validation.test.ts is back to 453 lines.
  • PRA-3 / PRA-T5: removed // @ts-nocheck from test/hermes-dashboard-provisioning.test.ts and reused test/helpers/hermes-dockerfile-run.ts.

Runtime-validation follow-ups:

  • PRA-T1: existing changed live coverage for generated API_SERVER_KEY, dashboard seeding, gateway privilege separation, runtime layout, and port readiness is in test/e2e-scenario/live/hermes-root-entrypoint-smoke.test.ts.
  • PRA-T2: existing changed live/image coverage for no baked API_SERVER_KEY, /dev/pts openpty, python-multipart, compiler purge, and raw-secret rejection is in test/e2e-scenario/live/hermes-sandbox-secret-boundary.test.ts plus test/e2e/test-hermes-sandbox-secret-boundary.sh.
  • PRA-T3: rebuild/runtime placeholder persistence is covered by the focused persisted-placeholder unit coverage added here and the changed Hermes rebuild path in test/e2e-scenario/live/rebuild-hermes.test.ts / test/e2e/test-rebuild-hermes.sh.

Acceptance-clause follow-up:

  • PRA-T6: issue #5591 is a broad dependency-update design proposal for Hermes/OpenShell/OpenClaw and does not define deterministic acceptance clauses that map one-for-one to this Hermes PR. The acceptance evidence for this PR is therefore the focused regression coverage above plus the exact-head CI/advisor result for this branch.

Local validation run before pushing this head:

  • npx vitest run --project cli src/lib/messaging/persisted-placeholders.test.ts src/lib/messaging/plan-validation.test.ts test/hermes-dashboard-provisioning.test.ts test/sandbox-rlimit-hooks.test.ts
  • npx tsc -p tsconfig.cli.json
  • npm run typecheck
  • npm run test-size:check
  • npm run test-conditionals:scan -- --top 25
  • git diff --check

@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ✅ All requested jobs passed

Run: 28195533141
Target ref: 0b01aaf32bd966dca08bc3d9a0dada17fe24ec4a
Workflow ref: main
Requested jobs: hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e
Summary: 2 passed, 0 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ✅ success
hermes-secret-boundary-e2e ✅ success

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ✅ All requested jobs passed

Run: 28196107154
Target ref: 3ae729ae2c6a068d63e72505686fb851519342bf
Workflow ref: main
Requested jobs: hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e,onboard-resume-e2e
Summary: 3 passed, 0 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ✅ success
hermes-secret-boundary-e2e ✅ success
onboard-resume-e2e ✅ success

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
@cv
cv merged commit ae43168 into main Jun 25, 2026
40 checks passed
@cv
cv deleted the dep/hermes-v2026.6.19 branch June 25, 2026 20:17
@github-actions

Copy link
Copy Markdown
Contributor

Selective E2E Results — ✅ All requested jobs passed

Run: 28197637423
Target ref: 00c19e79ca6a178e6dc42ec054a2551d13b73378
Workflow ref: main
Requested jobs: hermes-root-entrypoint-smoke-e2e,hermes-secret-boundary-e2e
Summary: 2 passed, 0 failed, 0 cancelled, 0 skipped

Job Result
hermes-root-entrypoint-smoke-e2e ✅ success
hermes-secret-boundary-e2e ✅ success

@coderabbitai coderabbitai Bot mentioned this pull request Jun 26, 2026
10 of 21 tasks
@coderabbitai coderabbitai Bot mentioned this pull request Jun 28, 2026
12 of 21 tasks
@miyoungc miyoungc mentioned this pull request Jun 29, 2026
8 of 21 tasks
cv pushed a commit that referenced this pull request Jun 29, 2026
## Summary
Adds the v0.0.69 release notes to the published release-notes page so
users can see the shipped sandbox recovery, Deep Agents Code, Hermes,
inference, policy, and release-validation changes.
The section is based on the v0.0.69 announcement and links each
user-facing theme to the deeper docs pages that already cover the
behavior.

## Changes
- Added a new `v0.0.69` section to `docs/about/release-notes.mdx`.
- Linked release-note themes to lifecycle, backup, troubleshooting, Deep
Agents Code, commands, workspace, messaging, Hermes, inference,
security, monitoring, and network-policy docs.

Source summary:
- #5455 -> `docs/about/release-notes.mdx`: Summarized persistent
workspace and state cleanup during sandbox destroy.
- #5738 -> `docs/about/release-notes.mdx`: Summarized nonzero exit
status preservation for failed hosted endpoint validation.
- #5786 -> `docs/about/release-notes.mdx`: Summarized live sandbox
rediscovery when local registry state is missing.
- #5881 -> `docs/about/release-notes.mdx`: Summarized the
`nemo-deepagents` alias command surface.
- #5594 -> `docs/about/release-notes.mdx`: Summarized the Hermes Agent
2026.6.19 update.
- #5777 -> `docs/about/release-notes.mdx`: Summarized manifest-derived
messaging channel support.
- #5825 -> `docs/about/release-notes.mdx`: Summarized DeepSeek V4 Flash
managed-vLLM defaults for DGX Station.
- #5877 -> `docs/about/release-notes.mdx`: Summarized provider switch
metadata preservation.
- #5932 -> `docs/about/release-notes.mdx`: Summarized transient
inference smoke retry behavior.
- #5934 -> `docs/about/release-notes.mdx`: Summarized constrained
inference smoke retry boundaries.
- #5681 -> `docs/about/release-notes.mdx`: Summarized Shields
config-hash sealing during auto-restore.
- #5682 -> `docs/about/release-notes.mdx`: Summarized sandbox connect
process-limit enforcement.
- #5683 -> `docs/about/release-notes.mdx`: Summarized JSON agent failure
provenance warnings.
- #5711 -> `docs/about/release-notes.mdx`: Summarized sparse-source log
breadcrumbs.
- #5838 -> `docs/about/release-notes.mdx`: Summarized host-authoritative
Shields status.
- #5880 -> `docs/about/release-notes.mdx`: Summarized policy round-trip
documentation updates.
- #5886 -> `docs/about/release-notes.mdx`: Summarized network request
approval-flow documentation updates.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates
- [ ] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [x] Tests not applicable — justification: doc-only release-notes
prose; no runtime behavior changed.
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [x] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [ ] Targeted tests pass for changed behavior
- [ ] Full `npm test` passes (broad runtime changes only)
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only)
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

`npm run docs` passed with 0 errors and the existing Fern light-mode
accent contrast warning.
`fern check --warnings` reported the same accent-color warning.

---
Signed-off-by: Miyoung Choi <miyoungc@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added release notes for **v0.0.69**, covering improved sandbox
lifecycle recovery (state preservation across
destroy/recreate/rebuild/recovery/validation failures), clearer Deep
Agents Code terminal/CLI behavior, and safer Hermes messaging/provider
switching with manifest-driven channels.
* Improved inference setup validation guidance, including handling of
local/compatible endpoints and redaction of sensitive validation errors.
* Refreshed release-gate documentation with clearer approval examples
and validation behavior for NVIDIA API keys vs hosted inference keys.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
## Summary
Refs NVIDIA#5591 for the Hermes dependency-upgrade slice.

- Bumps Hermes to `v2026.6.19` / `hermes-agent@0.17.0`.
- Pins the Hermes release tarball SHA256 and npm integrity, with
`scripts/update-hermes-agent.sh` check support.
- Carries the Hermes v0.16+ integration work needed for the current
runtime shape: bearer-token API access, dashboard/model-picker config,
dashboard-home seeding, npm workspace build handling, `/dev/pts` access,
`python-multipart`, and Hermes secret-boundary updates.
- Updates NemoClaw CLI/dashboard token plumbing so `gateway-token` can
retrieve a bearer-token agent key when the manifest declares one.

## Validation
- `npm install --ignore-scripts`
- `npm run build:cli`
- `npm run typecheck`
- `scripts/update-hermes-agent.sh --check --tag v2026.6.19`
- `python3 -m py_compile agents/hermes/seed-dashboard-config.py
agents/hermes/runtime-config-guard.py
agents/hermes/validate-env-secret-boundary.py`
- `bash -n agents/hermes/start.sh scripts/update-hermes-agent.sh
test/e2e/test-hermes-sandbox-secret-boundary.sh
test/e2e/test-hermes-root-entrypoint-smoke.sh`
- `npx vitest run --project cli test/hermes-runtime-api-key.test.ts
test/hermes-start.test.ts src/lib/agent/defs.test.ts
test/cli/snapshot-shields.test.ts
test/update-hermes-agent-script.test.ts
test/seed-hermes-dashboard-config.test.ts
test/hermes-share-mount-deps.test.ts test/sandbox-provisioning.test.ts`
- `npm run test-conditionals:scan -- --top 25`
- `npx prek run --all-files --stage pre-push --skip tsc-plugin --skip
tsc-js --skip tsc-cli --skip version-tag-sync --skip test-cli --skip
test-plugin --skip source-shape-test-budget --skip test-file-size-budget
--skip test-skills-yaml`
- `npm run source-shape:check`
- `npm run test-size:check`
- `npx vitest run test/skills-frontmatter.test.ts`
- `python3 scripts/generate-platform-docs.py --check`
- `git diff --check`
- GitHub PR checks on head `ff03680e4c3c24fe04df3631331380aaa0e8e9cb`:
PR Review Advisor, E2E recommendation, CodeQL, ShellCheck, sandbox image
builds, required static/CLI checks, and PR-gated E2E smoke jobs all
passing.

## Review Notes
- PR Review Advisor is green on head
`ff03680e4c3c24fe04df3631331380aaa0e8e9cb` with no blocking findings;
the prior `API_SERVER_KEY`/runtime-config and workspace-lockfile
findings are resolved by code and focused regression coverage.
- The remaining `PRA-T1` acceptance-clause follow-up is justified
against NVIDIA#5591, which is a broad design/dependency proposal without
concrete acceptance clauses; the changed Hermes behavior is covered by
the validation above and the passing PR checks.
- Earlier broad Vitest E2E result comments are historical for older
heads/all-job dispatches. The latest required PR checks and E2E
recommendation are green on the current head.
- Docker was not run locally, but GitHub `build-sandbox-images` and
`build-sandbox-images-arm64` both passed on the current head.

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>

---------

Signed-off-by: Aaron Erickson <aerickson@nvidia.com>
Co-authored-by: tyeth <tyethgundry@googlemail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: anthropic-code-agent[bot] <242468646+Claude@users.noreply.github.com>
Co-authored-by: tyeth-ai-assisted <259968460+tyeth-ai-assisted@users.noreply.github.com>
Co-authored-by: Carlos Villela <cvillela@nvidia.com>
Hadar301 pushed a commit to Hadar301/NemoClaw-OpenShift that referenced this pull request Jul 12, 2026
## Summary
Adds the v0.0.69 release notes to the published release-notes page so
users can see the shipped sandbox recovery, Deep Agents Code, Hermes,
inference, policy, and release-validation changes.
The section is based on the v0.0.69 announcement and links each
user-facing theme to the deeper docs pages that already cover the
behavior.

## Changes
- Added a new `v0.0.69` section to `docs/about/release-notes.mdx`.
- Linked release-note themes to lifecycle, backup, troubleshooting, Deep
Agents Code, commands, workspace, messaging, Hermes, inference,
security, monitoring, and network-policy docs.

Source summary:
- NVIDIA#5455 -> `docs/about/release-notes.mdx`: Summarized persistent
workspace and state cleanup during sandbox destroy.
- NVIDIA#5738 -> `docs/about/release-notes.mdx`: Summarized nonzero exit
status preservation for failed hosted endpoint validation.
- NVIDIA#5786 -> `docs/about/release-notes.mdx`: Summarized live sandbox
rediscovery when local registry state is missing.
- NVIDIA#5881 -> `docs/about/release-notes.mdx`: Summarized the
`nemo-deepagents` alias command surface.
- NVIDIA#5594 -> `docs/about/release-notes.mdx`: Summarized the Hermes Agent
2026.6.19 update.
- NVIDIA#5777 -> `docs/about/release-notes.mdx`: Summarized manifest-derived
messaging channel support.
- NVIDIA#5825 -> `docs/about/release-notes.mdx`: Summarized DeepSeek V4 Flash
managed-vLLM defaults for DGX Station.
- NVIDIA#5877 -> `docs/about/release-notes.mdx`: Summarized provider switch
metadata preservation.
- NVIDIA#5932 -> `docs/about/release-notes.mdx`: Summarized transient
inference smoke retry behavior.
- NVIDIA#5934 -> `docs/about/release-notes.mdx`: Summarized constrained
inference smoke retry boundaries.
- NVIDIA#5681 -> `docs/about/release-notes.mdx`: Summarized Shields
config-hash sealing during auto-restore.
- NVIDIA#5682 -> `docs/about/release-notes.mdx`: Summarized sandbox connect
process-limit enforcement.
- NVIDIA#5683 -> `docs/about/release-notes.mdx`: Summarized JSON agent failure
provenance warnings.
- NVIDIA#5711 -> `docs/about/release-notes.mdx`: Summarized sparse-source log
breadcrumbs.
- NVIDIA#5838 -> `docs/about/release-notes.mdx`: Summarized host-authoritative
Shields status.
- NVIDIA#5880 -> `docs/about/release-notes.mdx`: Summarized policy round-trip
documentation updates.
- NVIDIA#5886 -> `docs/about/release-notes.mdx`: Summarized network request
approval-flow documentation updates.

## Type of Change

- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [x] Doc only (prose changes, no code sample modifications)
- [ ] Doc only (includes code sample changes)

## Quality Gates
- [ ] Tests added or updated for changed behavior
- [ ] Existing tests cover changed behavior — justification:
- [x] Tests not applicable — justification: doc-only release-notes
prose; no runtime behavior changed.
- [x] Docs updated for user-facing behavior changes
- [ ] Docs not applicable — justification:
- [ ] Sensitive paths changed (security, policy, credentials, preflight,
onboarding, inference, runner, sandbox, or messaging)
- [ ] Sensitive-path review completed or maintainer-approved waiver
recorded — reviewer/approval link/justification:
- [ ] Non-success, skipped, or missing CI check accepted by maintainer —
check name, approval link, and follow-up issue:

## Verification
- [x] PR description includes the DCO sign-off declaration and every
commit appears as `Verified` in GitHub
- [x] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [ ] Targeted tests pass for changed behavior
- [ ] Full `npm test` passes (broad runtime changes only)
- [x] Quality Gates section completed with required justifications or
waivers
- [x] No secrets, API keys, or credentials committed
- [ ] `npm run docs` builds without warnings (doc changes only)
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

`npm run docs` passed with 0 errors and the existing Fern light-mode
accent contrast warning.
`fern check --warnings` reported the same accent-color warning.

---
Signed-off-by: Miyoung Choi <miyoungc@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Documentation**
* Added release notes for **v0.0.69**, covering improved sandbox
lifecycle recovery (state preservation across
destroy/recreate/rebuild/recovery/validation failures), clearer Deep
Agents Code terminal/CLI behavior, and safer Hermes messaging/provider
switching with manifest-driven channels.
* Improved inference setup validation guidance, including handling of
local/compatible endpoints and redaction of sensitive validation errors.
* Refreshed release-gate documentation with clearer approval examples
and validation behavior for NVIDIA API keys vs hosted inference keys.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: onboarding Onboarding FSM, provider setup, sandbox launch, or first-run flow area: packaging Packages, images, registries, installers, or distribution area: sandbox OpenShell sandbox lifecycle, runtime, config, or recovery area: security Security controls, permissions, secrets, or hardening chore Build, CI, dependency, or tooling maintenance dependencies Pull requests that update a dependency file integration: hermes Hermes integration behavior

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants