Skip to content

audit(unresolved): batched fork-PR audit reverts — 6 PRs (#1189, #1192, #1188, #1194, #1193, #1190) - #1230

Merged
ang-fleet-lander[bot] merged 18 commits into
mainfrom
audit/batch/unresolved
Sep 26, 2026
Merged

ang-fleet-lander[bot] merged 18 commits into
mainfrom
audit/batch/unresolved

Conversation

@Kyzcreig

@Kyzcreig Kyzcreig commented Sep 26, 2026 •

Copy link
Copy Markdown
Collaborator

Fork-PR audit batch for the unresolved area (card t_7c5e08a5, campaign t_f201acde, lead t_03e35f0e; rulings in #1128 / #1186).

It replaces 6 separate queue entries with 1. Each separate squash invalidated every group behind it, and the members' overlapping files caused the 2026-09-25 UNMERGEABLE wave. From now on each audit area gets at most 1 open queue entry.

PR Title Card
#1189 revert(tui_gateway): drop the heavy session-read admission gate (#215, #441) t_7c17872a
#1192 revert: drop #358 empty prompt.submit guard + no-op model-switch short-circuit t_28b13602
#1188 Revert #620: strip relay routing prefix before model-listing lookup (audit DROP) t_111298c6
#1194 revert: drop #894 residual pasteable-hint sites (fork-PR audit DROP) t_ceb111f9
#1193 revert(recap): drop backtick-wrap guard on dead session_recap module (audit DROP nopr:8a8b81638c) t_08d470c3
#1190 revert(skills): drop write-time skill-hygiene guard A3 (8dcc696 + 08fc3af) — audit DROP t_cad124fd

How it was built: branched from origin/main (cebd579), then git merge --no-ff of each member PR head in order. No revert content was rewritten. Each member's own conflict resolutions come through unchanged.

Identity check: every file a member touches is byte-identical to that member's head, with two exceptions. (a) Files two members share, or files main changed after a member's base: the +/- lines were compared as a multiset against the union of the members' own diffs, with 0 missing and 0 extra. (b) The file deletions noted below. No file outside the members' changes differs from main. Total: 24 files, +33/-2093.

#1194 carried "Do not merge without Apollo pass" — that condition carries over to this batch. Merge conflicts vs main (#1194 was 62 commits behind): staging/ was deleted on main by #1158, so it stays deleted; tests/test_residual_cli_hint_pasteable.py is deleted as #1194 intends (main's only edit to it dropped the staging group).

Local verification (narrow, repo venv py3.11): py_compile passes on every changed .py file. On the unresolved batch (the server.py overlap between #1189 and #1192), pytest tests/test_tui_gateway_server.py tests/test_tui_gateway_ws.py tests/hermes_cli/test_model_validation.py gives 739 passed. The full suite and matrix are left to CI.

The member PRs will be closed and pointed here once this PR is open.


View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Kyzcreig and others added 17 commits September 25, 2026 19:21
…as a script → CI collection abort)"

This reverts commit 08fc3af.
…lookup (#620)"

This reverts commit ac92718.

Fork-PR audit verdict DROP (t_63023f77, docs/plans/fork-pr-audit/UNRESOLVED.md):
0/34,120 sessions across 12 profile state.db (2026-05-08..2026-09-26) use a
name:<sub>/<model> model string; 0 config.yaml/cron jobs use one; 0 'could not
verify name:' log lines. Upstream validate_requested_model has no equivalent
strip. Warning-text fix for a model-string form nobody uses.

Conflict in tests/hermes_cli/test_model_validation.py resolved by deleting
only TestSubRoutingPrefixStripped; later-added classes kept.

Verified: test-gate pytest tests/hermes_cli/test_model_validation.py -> 64 passed.
Card: t_111298c6
…#441)

Reverts 66d98d3 (#215) and its re-land 0986938 (#441) as one unit,
per the fork-PR audit UNRESOLVED ruling (DROP, t_63023f77 / t_7c17872a).

Removed:
- hermes_cli/session_db_heavy_gate.py (SessionDBHeavyReadBusy, the slot,
  stats, lazy dashboard.heavy_read_max_concurrency read)
- tui_gateway/ws.py: gate import + _dispatch_ws_request; WS requests go
  back to asyncio.to_thread(server.dispatch, ...)
- tui_gateway/server.py: _SESSION_DB_HEAVY_METHODS,
  is_session_db_heavy_method, backend_busy_error, handle_request_bound
  (_err's data= param kept: methods_prompt/methods_bot_relay use it)
- hermes_cli/web_server.py: gate import, 503 shed handler and the
  /api/status session_db_heavy_reads field; _session_db_read(heavy=True)
  returns to the pre-#215 per-loop asyncio.Semaphore(2)
- config_defaults: dashboard.heavy_read_max_concurrency
- gate tests in tests/test_web_server_sessiondb_eventloop.py and
  tests/scripts/test_preyield_permit_release.py; the guard script's
  live-site list. The guard sweep keeps a live site
  (gateway/turn_admission.py) and its named coverage test.

Why: 0 'session_db_heavy_read' log lines across ~/.hermes/logs and
profiles/*/logs (no read ever queued >= 1 ms); 473/474 loc across 5 files
conflicting in all 3 upstream syncs; upstream bounds reads in its
SessionDB read pool instead.

Verified: test-gate (ACE-AI) pytest tests/test_web_server_sessiondb_eventloop.py
tests/scripts/test_preyield_permit_release.py tests/test_tui_gateway_ws.py
tests/tui_gateway/test_ws_keepalive.py -> 85 passed. ruff --select F on the
touched files: no new findings vs origin/main.
Reverts e1de835. Fork-PR audit UNRESOLVED ruling (t_63023f77,
#1186): the trigger is whitespace in a
home/interpreter/skill-category/plugin path; measured 0 occurrences on
both fleet hosts, so the hints never needed quoting here. The gateway/run.py
hunk conflicted in all 3 upstream syncs.

Kept: #889's hermes_cli.cli_hint.hint_value and its callers (KEEP row).
gateway/run.py conflict resolved by keeping current main's
_skill_slug_index loop and dropping only the hint_value() wrap.

Card: t_ceb111f9
…t-circuit

Reverts 2850311 (#358) per fork-PR audit DROP ruling (t_63023f77,
docs/plans/fork-pr-audit/UNRESOLVED.md). The prompt.submit guard now lives in
tui_gateway/methods_prompt.py after the parity sync split, so it is removed
there; the _apply_model_switch no-op block is removed from server.py; the 4
tests the commit added are removed from tests/test_tui_gateway_server.py.

Why: the path carries ~no traffic (8 source=tui sessions of 15,265, 0 empty
user rows from tui) and the looping client (fork desktop reconnect) is retired
by D9. 237 loc across files that conflict every sync. Reopen if a desktop
empty-submit loop recurs.
… auto-attach"

This reverts commit 8a8b816.

Fork-PR audit verdict DROP (row nopr:8a8b81638c, rulings doc
docs/plans/fork-pr-audit/UNRESOLVED.md, PR #1186): build_recap, the only
public entry of hermes_cli/session_recap.py, has 0 non-test callers on
fork main (git grep over *.py/*.ts/*.tsx/*.yaml at 702addb) and on
upstream. The guarded path cannot run, so the guard fires 0 by construction.

Test-file conflict (parity merge aa27fd8 reshaped the file) resolved by
taking main's version and deleting only the two tests 8a8b816 added.

Card: t_08d470c3
Conflicts vs main (PR was 62 behind): staging/ deleted on main by #1158 -> stays deleted;
tests/test_residual_cli_hint_pasteable.py deleted per #1194 (main's edit only dropped the staging group).
@blacksmith-sh

blacksmith-sh Bot commented Sep 26, 2026 •

Copy link
Copy Markdown

Found 1 test failure on Blacksmith runners:

Failure

Test View Logs
TestPinTransition/test_cache_busting_signature_reflects_pin_peer_name View Logs

Fix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need.

@ang-fleet-lander

Copy link
Copy Markdown

🤖 merged-by: apollo · lane: discord · gate: BYPASS: FR paused by Ace 2026-09-22; Argus off card review (Ace 09-24 13:08); gate = handoff + CI green + Apollo read (review-of-record on card) · why: batched audit reverts unresolved

@ang-fleet-lander
ang-fleet-lander Bot added this pull request to the merge queue Sep 26, 2026
Merged via the queue into main with commit 4e9dbb7 Sep 26, 2026
55 checks passed
@ang-fleet-lander
ang-fleet-lander Bot deleted the audit/batch/unresolved branch September 26, 2026 16:16
@ang-prism

ang-prism Bot commented Sep 27, 2026

Copy link
Copy Markdown

FleetReview

Post-merge review (fleetreview:post-merge override): this reviewed the merge commit against its first parent — the bytes that already shipped. It is not a pre-merge gate pass.

Confidence: 2/5

Findings

  • P1 tools/skill_manager_tool.py:1213 — Unprotected placement
  • P1 agent/skill_utils.py:118 — Queue notes
  • P1 hermes_cli/models.py:6984 — Incorrect lookup
  • P2 hermes_cli/web_server.py:3269 — Unbounded waiting
  • P2 tools/self_repo_guard.py:736 — Broken clone command
  • P2 hermes_cli/web_server.py:3254 — Stale semaphore
  • P1 hermes_cli/session_recap.py:302 — File disclosure
  • P1 tui_gateway/server.py:6844 — No-op switch
  • P1 tui_gateway/methods_prompt.py:335 — Blank submissions
  • P2 tui_gateway/ws.py:490 — Ungated scans
  • P2 plugins/platforms/whatsapp/adapter.py:612 — Unquoted paths
  • P1 hermes_cli/plugins_cmd.py:1103 — Shell-quote plugin sources in copy-paste install commands
  • P1 tests/hermes_cli/test_session_recap.py:49 — Removed Security Test
  • P1 tests/test_residual_cli_hint_pasteable.py:384 — Pinned-plugin update hint prints an executable, unquoted source

FleetReview provenance · models: B=gpt-6-sol, C=claude-code-opus-5-5, D=grok-4.6, F=gpt-6-sol · cost: $4.48 · duration: 13m 10s · rounds: 1 · files examined: 24

ang-fleet-workers Bot added a commit that referenced this pull request Sep 27, 2026
…s (t_9c9e757c)

FleetReview retro-backfill 2026-09-27, class C4. Each finding re-verified at
5a9d284; one RED-on-base / GREEN test per confirmed instance.

- #813 agent/quota_registry_gate.py: missing/unparseable observed_at now fails
  open (docstring contract), no longer skips a working fallback.
- #1017 cron/lifecycle_guard.py: mask allowlist refuses module callables passed
  as values (json.dumps(p, default=subprocess.run), sorted(key=...)).
- #1019 agent/lsp/manager.py: slot-dir OSError in _has_capacity -> run without
  LSP instead of raising out of enabled_for()/write_file.
- #1026 cron/scheduler.py: owner-deadman exemption scoped to the host it owns;
  a note naming only another DOWN host is gated.
- #1229 scripts/ci/live_comment.py: comment lookup/update network errors no
  longer kill the poller; a failed post is retried next poll.
- #1230 plugins_cmd.py: pinned-plugin remedy shell-quotes the recorded source
  (CLI + dashboard).
- #1238 tools/mixture_of_agents_tool.py: reference responses move from the
  aggregator system message to a tagged data block in the user message.

Verified: test-gate narrow pytest; new tests 13 RED on base, all GREEN with fix;
neighbouring suites (lifecycle_guard x4, host_down_gate, quota wiring,
plugins_cmd, fallback_policy, fork toolsets) pass.
ang-fleet-workers Bot added a commit that referenced this pull request Sep 27, 2026
…s (t_9c9e757c)

FleetReview retro-backfill 2026-09-27, class C4. Each finding re-verified at
5a9d284; one RED-on-base / GREEN test per confirmed instance.

- #813 agent/quota_registry_gate.py: missing/unparseable observed_at now fails
  open (docstring contract), no longer skips a working fallback.
- #1017 cron/lifecycle_guard.py: superseded by #1348 (6662bbd) on main; this
  slice's 5 callback cases pass against it, so the edit was dropped on rebase.
- #1019 agent/lsp/manager.py: slot-dir OSError in _has_capacity -> run without
  LSP instead of raising out of enabled_for()/write_file.
- #1026 cron/scheduler.py: owner-deadman exemption scoped to the host it owns;
  a note naming only another DOWN host is gated.
- #1229 scripts/ci/live_comment.py: comment lookup/update network errors no
  longer kill the poller; a failed post is retried next poll.
- #1230 plugins_cmd.py: pinned-plugin remedy shell-quotes the recorded source
  (CLI + dashboard).
- #1238 tools/mixture_of_agents_tool.py: reference responses move from the
  aggregator system message to a tagged data block in the user message.

Verified: test-gate narrow pytest; new tests 13 RED on base, all GREEN with fix;
neighbouring suites (lifecycle_guard x4, host_down_gate, quota wiring,
plugins_cmd, fallback_policy, fork toolsets) pass.
Kyzcreig pushed a commit that referenced this pull request Sep 27, 2026
…s (t_9c9e757c) (#1353)

FleetReview retro-backfill 2026-09-27, class C4. Each finding re-verified at
5a9d284; one RED-on-base / GREEN test per confirmed instance.

- #813 agent/quota_registry_gate.py: missing/unparseable observed_at now fails
  open (docstring contract), no longer skips a working fallback.
- #1017 cron/lifecycle_guard.py: superseded by #1348 (6662bbd) on main; this
  slice's 5 callback cases pass against it, so the edit was dropped on rebase.
- #1019 agent/lsp/manager.py: slot-dir OSError in _has_capacity -> run without
  LSP instead of raising out of enabled_for()/write_file.
- #1026 cron/scheduler.py: owner-deadman exemption scoped to the host it owns;
  a note naming only another DOWN host is gated.
- #1229 scripts/ci/live_comment.py: comment lookup/update network errors no
  longer kill the poller; a failed post is retried next poll.
- #1230 plugins_cmd.py: pinned-plugin remedy shell-quotes the recorded source
  (CLI + dashboard).
- #1238 tools/mixture_of_agents_tool.py: reference responses move from the
  aggregator system message to a tagged data block in the user message.

Verified: test-gate narrow pytest; new tests 13 RED on base, all GREEN with fix;
neighbouring suites (lifecycle_guard x4, host_down_gate, quota wiring,
plugins_cmd, fallback_policy, fork toolsets) pass.

Co-authored-by: ang-fleet-workers[bot] <333956806+ang-fleet-workers[bot]@users.noreply.github.com>
ang-fleet-workers Bot added a commit that referenced this pull request Oct 2, 2026
…m undo, shlex remedy, root-equality noqa

- plugin_dev._load_model_provider: undo registry additions via provider_seam._restore
  (fork additive facades forbid pop/clear).
- plugins_cmd_update: re-thread fork _shell_quoted_source (#1230 C4) that upstream's
  extraction of cmd_update/dashboard_update dropped.
- root-equality lint: annotate 7 upstream-new relative_to sites (all FILE paths or
  non-derived rmtree targets) with reasoned noqa.
- test_ollama_cloud_auth: seed _DIRECT_ALIAS_LOADED so the hot-reload test exercises
  the loader-owned-cache path (upstream NousResearch#16767 keeps caller-seeded dicts).
- test_oneshot_reasoning_and_tier: FakeAgent.run_conversation accepts conversation_history.

Verified (e45-pt-M2.sh / e45-pt-M2-314.sh via test-gate):
  test_ollama_cloud_auth + test_direct_alias_reload + test_model_alias_credentials: 79 passed
  test_oneshot_reasoning_and_tier: 9 passed
  test_plugin_dev + test_provider_discovery_in_progress: 10 passed (also 1 passed on py3.14)
  test_root_equality_containment_lint: 3 passed
  test_plugin_install_ref (py3.14, uv on PATH): 33 passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant