docs(handoff): overnight Codex queue — 1 master + 6 task briefs + roadmap - #31
Conversation
…dmap
Pre-writes the next overnight Codex queue, audit-vetted, scope-tight.
Master prompt:
- HANDOFF_TO_CODEX_OVERNIGHT_AUTOPILOT.md — loop protocol, NO auto-merge
(PRs queue for morning architect review), bright-line boundaries, circuit
breaker, heartbeat, morning report convention. Fixes from round 1 audit:
dynamic owner-from-brief in step 3, distinct owner per task, consolidated
COMPLETE filename for both normal and circuit-breaker halt paths.
Task briefs (priority order):
1. SOTA-MARKETING-V2 (already on develop pre-overnight)
2. BLENDER-AUDIT — research-only ADR; 4 verdicts (ADOPT/FORK/REJECT/
NEEDS-DEEPER-AUDIT); ./tmp/ workspace-relative path; pytest dropped
from docs-only PR; ADR sections 8 not 7
3. HERMESPROOF-0.6 — gitleaks + auto_linter + agentic-testing + ENV_FILE
resolution + hardened .gitignore. Round-1 fixes: HERMES3D_PROFILE=vps
instead of fictional --vps-mode argv flag; gates vs tools count
distinction; lock list expanded to include event-manager/queue-manager/
hardening-smoke-test; owner string codex-impl-hp; tightened DeepSeek
regex to require keyword co-location.
4. LOCAL-INTELLIGENCE — SUPERSEDED by 4a/4b/4c after audit FAIL. Split
per audit's M2 recommendation:
4a. LOCAL-LM-STUDIO — LM Studio default + Ollama fallback (existing
ollama_client.py, NOT ollama_provider.py) + Hipfire optional.
Hermes 4 weights recommended (Hermes-4-14B-FP8) per Hermes Agent
research finding (Nous Research repo is ACTIVE not stale; 130k
stars, last push 2026-05-03; MIT). MERGE not REPLACE for
llm_policy.yaml.
4b. MNEMOSYNE-RECALL — mnemosyne-memory PyPI package (NOT bare
mnemosyne); confirmed pip-installable. Recall layer ONLY — NOT
canonical. Soft-import wrapper degrades silently if absent.
4c. SERVICE-HEALTH — in-house stdlib socket probe (NOT port-monitor
library; that's C++/Qt6 desktop GUI). NEW top-level /health route
(NOT a Settings subtab; SettingsTab.tsx doesn't exist on develop).
PROJECT_COMPLETION_ROADMAP.md updated to reflect splits + future
checkpoint stub for HERMES-AGENT-PORT-PATTERNS (Nous Research's
registry/injection-defense/delegate-isolation patterns).
Round 1 audits caught 16 critical issues across 4 briefs.
Round 2 audits + Codex round 3 audits pending before any execution
authorization. NO auto-merge; Codex opens PRs and leaves them OPEN.
Task: H3D-DOCS-OVERNIGHT-BRIEFS
Hermes evidence chain: PASS
📝 WalkthroughWalkthroughAdded eight handoff documents establishing an overnight task queue system for the Codex agent: four independent Hermes3D/HermesProof feature tasks, one Blender-MCP audit, and master orchestration files (overnight autopilot loop, project roadmap). All changes are markdown specifications with no code modifications. ChangesOvernight Task Queue System
Estimated code review effort🎯 2 (Simple) | ⏱️ ~12 minutes
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Review rate limit: 4/5 reviews remaining, refill in 12 minutes. Comment |
There was a problem hiding this comment.
Code Review
This pull request introduces a comprehensive set of handoff documents and an autopilot protocol designed to automate overnight development tasks. Key additions include specifications for a Blender MCP audit, a security-focused gate pack for HermesProof, and integrations for local LLM providers, a recall memory layer, and service health monitoring. The review feedback identifies several critical improvements: correcting a missing configuration parameter in the Hipfire provider's initialization, replacing hardcoded temporary paths with cross-platform alternatives, ensuring the recall database is stored in the correct directory, and mapping missing status states in the health UI.
| def __init__(self) -> None: | ||
| if os.environ.get("HERMES3D_AMD_NODE") != "1": | ||
| raise ProviderDisabled("Hipfire is opt-in; set HERMES3D_AMD_NODE=1 to enable") | ||
| super().__init__() |
There was a problem hiding this comment.
The __init__ method for HipfireProvider is missing the config parameter required by the BaseLLMClient base class. Calling super().__init__() without arguments will result in a TypeError at runtime. Ensure the constructor accepts and passes the ProviderConfig object.
| def __init__(self) -> None: | |
| if os.environ.get("HERMES3D_AMD_NODE") != "1": | |
| raise ProviderDisabled("Hipfire is opt-in; set HERMES3D_AMD_NODE=1 to enable") | |
| super().__init__() | |
| def __init__(self, config: ProviderConfig) -> None: | |
| if os.environ.get("HERMES3D_AMD_NODE") != "1": | |
| raise ProviderDisabled("Hipfire is opt-in; set HERMES3D_AMD_NODE=1 to enable") | |
| super().__init__(config) |
|
|
||
| **`scripts/truth-gates.mjs`** — add a new gate `secret.scan`: | ||
|
|
||
| - Calls `gitleaks detect --config .gitleaks.toml --no-git --redact --report-format json --report-path /tmp/gitleaks-report.json --exit-code 1` |
There was a problem hiding this comment.
Hardcoding /tmp/ for report paths is not cross-platform and will fail on Windows systems. Since the project already uses a PROOF/ directory for artifacts (as seen in line 138), it is better to store reports there or use a platform-agnostic temporary directory. This applies to lines 161 and 162 as well.
| - Calls `gitleaks detect --config .gitleaks.toml --no-git --redact --report-format json --report-path /tmp/gitleaks-report.json --exit-code 1` | |
| - Calls `gitleaks detect --config .gitleaks.toml --no-git --redact --report-format json --report-path PROOF/gitleaks-report.json --exit-code 1` |
| return | ||
| try: | ||
| self._db = mnemosyne_memory.open( | ||
| str(db_path or Path.home() / ".hermes3d" / "mnemosyne.db") |
There was a problem hiding this comment.
The default database path uses Path.home(), which is inconsistent with the "Hard rules" (line 271) stating that the database should be located in the gitignored var/ directory. Using a project-relative path like var/mnemosyne.db ensures consistency with other persistent stores in the system (e.g., var/queue.json).
| str(db_path or Path.home() / ".hermes3d" / "mnemosyne.db") | |
| str(db_path or Path("var/mnemosyne.db")) |
|
|
||
| **`ui/src/components/health/ServiceCard.tsx`** (NEW): | ||
| - Service name + category badge | ||
| - Status pill (online green / offline red / unreachable amber / auth-required purple / disabled gray) |
There was a problem hiding this comment.
There was a problem hiding this comment.
Actionable comments posted: 5
🤖 Prompt for all review comments with AI agents
Verify each finding against the current code and only fix it if needed.
Inline comments:
In `@handoffs/HANDOFF_TO_CODEX_HERMES3D_MNEMOSYNE_RECALL.md`:
- Line 83: Resolve the conflicting failure protocol for the mnemosyne-memory
install by standardizing both occurrences of the "Failure protocol" text to the
same behavior: when `pip install mnemosyne-memory` fails (renamed/taken
down/unpublished), create a blocked-handoff and skip further work (do not
attempt git clone into node_modules/site-packages). Update the section labeled
"Failure protocol" and the later paragraph that currently suggests "partial ship
without dependency" so they both instruct the blocked-handoff+skip behavior and
remove any instruction to git clone the repo into site-packages/node_modules;
ensure the wording is identical and unambiguous.
In `@handoffs/HANDOFF_TO_CODEX_HERMES3D_SERVICE_HEALTH.md`:
- Around line 200-203: The docs propose adding a standalone route but the app
uses a tab-based architecture; instead add the health view as a new tab: add a
"health" entry to the TABS list and map its component to ServiceHealthPage in
TAB_COMPONENTS (so the tab system will render ServiceHealthPage), and update the
AppShell/side navigation to include the tab entry (use Heart or Activity from
lucide-react) positioned between the Logs tab and Settings (or at end if
Settings is absent) rather than adding a separate `{ path: "/health", element:
... }` route.
In `@handoffs/HANDOFF_TO_CODEX_HERMESPROOF_0.6_GATE_PACK.md`:
- Line 7: The owner identity is inconsistent: the metadata owner value
"codex-impl-05" and the claim/command owner "codex-impl-hp" must match; update
either the metadata owner field or the claim arguments so both use the same
canonical owner string (choose one of "codex-impl-05" or "codex-impl-hp") and
then ensure every occurrence of owner=... in the document (including the
claim/lock/release examples) uses that exact same token to avoid breaking task
lifecycle tooling.
- Around line 299-300: Update the test instruction so it matches the env-file
resolution contract: replace the claim that HERMES3D_VPS_ENV_FILE "only resolves
when --vps-mode arg present" with a statement that HERMES3D_VPS_ENV_FILE
resolves when the environment variable HERMES3D_PROFILE is set to "vps" (i.e.,
HERMES3D_PROFILE=vps), and remove any dependency or reference to the --vps-mode
argv flag; ensure the test/spec references the HERMES3D_VPS_ENV_FILE symbol and
the HERMES3D_PROFILE env-var explicitly to reflect §5.4.
In `@handoffs/PROJECT_COMPLETION_ROADMAP.md`:
- Around line 98-99: Update PROJECT_COMPLETION_ROADMAP.md to replace the
outdated Task 4 pointer that currently references
HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE.md with the new split-task pointers
(4a/4b/4c). Locate the line referencing "Task 4" and change it to point to the
three new handoff files (e.g.,
HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE_4a.md, _4b.md, _4c.md) and adjust
any accompanying label or ordering text so it matches the split-task queue
above; ensure the labels "Task 4a/4b/4c" and filenames exactly match how they
are named elsewhere in the repo so links resolve correctly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: defaults
Review profile: CHILL
Plan: Pro
Run ID: 05238ec6-a00b-4b21-837b-cd068567e292
📒 Files selected for processing (8)
handoffs/HANDOFF_TO_CODEX_BLENDER_MCP_AUDIT.mdhandoffs/HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE.mdhandoffs/HANDOFF_TO_CODEX_HERMES3D_LOCAL_LM_STUDIO.mdhandoffs/HANDOFF_TO_CODEX_HERMES3D_MNEMOSYNE_RECALL.mdhandoffs/HANDOFF_TO_CODEX_HERMES3D_SERVICE_HEALTH.mdhandoffs/HANDOFF_TO_CODEX_HERMESPROOF_0.6_GATE_PACK.mdhandoffs/HANDOFF_TO_CODEX_OVERNIGHT_AUTOPILOT.mdhandoffs/PROJECT_COMPLETION_ROADMAP.md
|
|
||
| The package name is `mnemosyne-memory` (NOT `mnemosyne` — the audit confirmed this is the actual PyPI name; the bare name `mnemosyne` doesn't resolve). If your install fails, double-check the user's repo at `https://github.com/rakaarwaky/mnemosyne` for the canonical pip-installable name in their README. | ||
|
|
||
| **Failure protocol:** if `pip install mnemosyne-memory` fails (package renamed, taken down, or never published), write a blocked-handoff and skip. Don't `git clone` the repo into `node_modules` / `site-packages`. |
There was a problem hiding this comment.
Resolve the conflicting failure protocol for mnemosyne-memory install failures.
Line 83 and Line 278 prescribe different outcomes (blocked-handoff+skip vs. partial ship without dependency). This ambiguity will produce inconsistent agent behavior.
Also applies to: 278-279
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@handoffs/HANDOFF_TO_CODEX_HERMES3D_MNEMOSYNE_RECALL.md` at line 83, Resolve
the conflicting failure protocol for the mnemosyne-memory install by
standardizing both occurrences of the "Failure protocol" text to the same
behavior: when `pip install mnemosyne-memory` fails (renamed/taken
down/unpublished), create a blocked-handoff and skip further work (do not
attempt git clone into node_modules/site-packages). Update the section labeled
"Failure protocol" and the later paragraph that currently suggests "partial ship
without dependency" so they both instruct the blocked-handoff+skip behavior and
remove any instruction to git clone the repo into site-packages/node_modules;
ensure the wording is identical and unambiguous.
| **`ui/src/app/routes.tsx`** — add a new route `{ path: "/health", element: <ServiceHealthPage /> }`. | ||
|
|
||
| **`ui/src/app/AppShell.tsx`** — add a sidebar nav entry for `/health` with an icon (use `Heart` or `Activity` from lucide-react). Place it between the existing Logs and any future Settings items, or at the end if Settings doesn't exist. | ||
|
|
There was a problem hiding this comment.
Align route instructions with the actual tab-based UI architecture.
Line 200 and Line 203 currently direct a path-route pattern ({ path: "/health", element: ... }) that conflicts with the existing TABS + TAB_COMPONENTS architecture (03_implementation/ui/src/app/routes.tsx, 03_implementation/ui/src/App.tsx). This will drive an incorrect implementation approach.
Suggested doc fix
-**`ui/src/app/routes.tsx`** — add a new route `{ path: "/health", element: <ServiceHealthPage /> }`.
-
-**`ui/src/app/AppShell.tsx`** — add a sidebar nav entry for `/health` with an icon (use `Heart` or `Activity` from lucide-react). Place it between the existing Logs and any future Settings items, or at the end if Settings doesn't exist.
+**`ui/src/app/routes.tsx`** — add a new tab entry in `TABS`, e.g. `{ id: "health", label: "Health", icon: Activity }`.
+
+**`ui/src/App.tsx`** — wire `"health": ServiceHealthPage` into `TAB_COMPONENTS`.
+
+**`ui/src/app/AppShell.tsx`** — ensure sidebar rendering picks up the new `TABS` item consistently with existing tabs.🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@handoffs/HANDOFF_TO_CODEX_HERMES3D_SERVICE_HEALTH.md` around lines 200 - 203,
The docs propose adding a standalone route but the app uses a tab-based
architecture; instead add the health view as a new tab: add a "health" entry to
the TABS list and map its component to ServiceHealthPage in TAB_COMPONENTS (so
the tab system will render ServiceHealthPage), and update the AppShell/side
navigation to include the tab entry (use Heart or Activity from lucide-react)
positioned between the Logs tab and Settings (or at end if Settings is absent)
rather than adding a separate `{ path: "/health", element: ... }` route.
| > | ||
| > **Sequence position:** Task 3 in overnight queue (after BLENDER-AUDIT). | ||
| > | ||
| > **Owner:** `codex-impl-05`. |
There was a problem hiding this comment.
Unify owner identity across metadata and claim commands.
Line 7 (codex-impl-05) conflicts with Line 32 (owner=codex-impl-hp). This can break task lifecycle operations (pick/lock/release) if tools key by owner string.
Also applies to: 32-33
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@handoffs/HANDOFF_TO_CODEX_HERMESPROOF_0.6_GATE_PACK.md` at line 7, The owner
identity is inconsistent: the metadata owner value "codex-impl-05" and the
claim/command owner "codex-impl-hp" must match; update either the metadata owner
field or the claim arguments so both use the same canonical owner string (choose
one of "codex-impl-05" or "codex-impl-hp") and then ensure every occurrence of
owner=... in the document (including the claim/lock/release examples) uses that
exact same token to avoid breaking task lifecycle tooling.
| - `HERMES3D_VPS_ENV_FILE only resolves when --vps-mode arg present` | ||
| - `pre-commit hook blocks staging of a synthetic secret` |
There was a problem hiding this comment.
Fix test instruction to match the env-file resolution contract.
Line 299 says VPS env resolution depends on a --vps-mode arg, but §5.4 explicitly states argv flags are not used and HERMES3D_PROFILE=vps controls behavior. The test spec should follow the env-var contract.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@handoffs/HANDOFF_TO_CODEX_HERMESPROOF_0.6_GATE_PACK.md` around lines 299 -
300, Update the test instruction so it matches the env-file resolution contract:
replace the claim that HERMES3D_VPS_ENV_FILE "only resolves when --vps-mode arg
present" with a statement that HERMES3D_VPS_ENV_FILE resolves when the
environment variable HERMES3D_PROFILE is set to "vps" (i.e.,
HERMES3D_PROFILE=vps), and remove any dependency or reference to the --vps-mode
argv flag; ensure the test/spec references the HERMES3D_VPS_ENV_FILE symbol and
the HERMES3D_PROFILE env-var explicitly to reflect §5.4.
| HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE.md ← Task 4 | ||
| PROJECT_COMPLETION_ROADMAP.md ← this file (forward-look) |
There was a problem hiding this comment.
Replace the superseded Task 4 pointer with 4a/4b/4c files.
Line 98 currently points to HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE.md as “Task 4,” which conflicts with the split-task queue above and can misroute execution.
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.
In `@handoffs/PROJECT_COMPLETION_ROADMAP.md` around lines 98 - 99, Update
PROJECT_COMPLETION_ROADMAP.md to replace the outdated Task 4 pointer that
currently references HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE.md with the
new split-task pointers (4a/4b/4c). Locate the line referencing "Task 4" and
change it to point to the three new handoff files (e.g.,
HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE_4a.md, _4b.md, _4c.md) and adjust
any accompanying label or ordering text so it matches the split-task queue
above; ensure the labels "Task 4a/4b/4c" and filenames exactly match how they
are named elsewhere in the repo so links resolve correctly.
|
Codex audit: not LGTM yet; marked The PR is docs-only and CI is green, but the handoff content has Tier-B contradictions that make several briefs unsafe to execute without architect cleanup:
Recommendation: split or patch the handoff PR before merge. Highest safe executable task from this queue remains |
[needs-architect-review] Codex audit found brief contradictions; see latest Codex review comment before executing these handoffs.
Summary
Task: H3D-DOCS-OVERNIGHT-BRIEFS
Hermes evidence chain: PASS
Pre-writes the next overnight Codex queue, audit-vetted across 4 round-1 audit agents that caught 16 critical issues. NO auto-merge — Codex opens PRs and leaves them OPEN for morning architect review.
What's in this PR (8 files)
Master prompt:
HANDOFF_TO_CODEX_OVERNIGHT_AUTOPILOT.md— loop protocol, bright-line boundaries, circuit breaker, heartbeat, morning reportTask briefs (priority order):
HANDOFF_TO_CODEX_SOTA_MARKETING_V2.md(already on develop pre-overnight) — Codex's design-led marketing upgradeHANDOFF_TO_CODEX_BLENDER_MCP_AUDIT.md— research-only ADR, 4 verdicts (ADOPT/FORK/REJECT/NEEDS-DEEPER-AUDIT)HANDOFF_TO_CODEX_HERMESPROOF_0.6_GATE_PACK.md— gitleaks + auto_linter + agentic-testing + ENV_FILE resolution + hardened .gitignore (in HermesProof repo)4a.
HANDOFF_TO_CODEX_HERMES3D_LOCAL_LM_STUDIO.md— LM Studio default + Ollama fallback + Hipfire optional4b.
HANDOFF_TO_CODEX_HERMES3D_MNEMOSYNE_RECALL.md— mnemosyne-memory PyPI; recall layer NOT canonical4c.
HANDOFF_TO_CODEX_HERMES3D_SERVICE_HEALTH.md— in-house stdlib port probe + new top-level /health routeSuperseded:
HANDOFF_TO_CODEX_HERMES3D_LOCAL_INTELLIGENCE.md— replaced by 4a/4b/4c after audit FAIL on path mismatchesRoadmap:
PROJECT_COMPLETION_ROADMAP.md— forward-look, status legend, audit postureRound-1 audit findings (all fixed in this PR)
/tmppath, REJECT misuse, pytest in docs PR, ADR section count (5)--vps-modeargv flag, gates vs tools count, lock list missed 3 files, owner collision, regex collision (5)16 critical issues caught before Codex saw the briefs. This is exactly the value of audit-before-handoff.
Hermes Agent finding
Research agent (background) returned: Nous Research's
hermes-agentrepo is NOT outdated — it's at 130k stars, last push 2026-05-03, v0.12.0 "Curator" release. ADOPT-SELECTIVELY verdict: lift Hermes 4 model weights for LM Studio (Hermes-4-14B-FP8 runs on 24 GB GPU, tool-calling + hybrid reasoning), the registry pattern, the injection-defense scanner, the delegate isolation pattern. Future checkpoint queued:H3D-HERMES-AGENT-PORT-PATTERNS(stub in roadmap).Round 2 + 3 audits
Round 2 (Claude's audit agents on the FIXED/NEW briefs) and Round 3 (Codex's own audit) are pending before any execution authorization. The user has explicitly requested defense in depth.
Summary by CodeRabbit