Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions 03_implementation/ROADMAP.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,8 +69,8 @@ Definition of roadmap completion:
| P0 | 3D Generation executor and preview proof | DONE | Live proof job `56954aa084b94a71a3bea4cb38f72f55` generated `calibration_cube_c8f48130af.stl`, `calibration_cube_c8f48130af.preview.svg`, `calibration_cube_c8f48130af.proof.json`, inserted proof event `bff1c6b5608e4384ad2e9c3fe4e5e5b5`, and passed truth status `pass`. Unsupported arbitrary prompts fail closed with provider setup guidance. |
| P0 | Jobs repair/rollback transitions | DONE | Live proof job `a936044cad8e4b07b378bd53c0ed1187` created REPAIR_APPROVAL `c998960a23e74b7ea1da4aca6390b5b9`, appended proposal proof `12f27d2e5eae4e0d95caaea28421b5c0`, apply/escalation proof `2421f6f2f80a4abd99b888e5d2eb9d82`, retry proof `cd752dcbed3c4add913c9d2901ed07ab`, and rollback proof `41583d82acb34f4db5df313c9e4b4e10`. UI controls call real routes and show blocked reasons. |
| P0 | Source OS + Plugins update execution | PARTIAL | Source OS Verify All, Setup Queue, selected-app Verify, selected-app Setup Plan, Backup, Check Update, no-op/current Update, Rollback routing, and proof events are wired. Runtime proof: Verify All `521e8565cfaf4115b3cd66c4fef66cc6` / backend route proof `e07a6629533c4a4c9333ba657120cecc`, Setup Queue proof `96885b17bdaf47b590b57da4d4515ca1`, PrusaSlicer setup-plan proof `5bce091c12c44656a4f3f1209fc6522d`, Azure Speech SDK setup-plan proof `9a7bd64d01644e8fb81359a196288179`, PrusaSlicer CLI `84e425b7fe514d42896ad16083eed561`, FLSUN Slicer CLI `eb18f6c1b98b4f52b8f955aee4b2503c`, source-only Azure Speech SDK `ae75bb3c53d6418ab7c603c7d7747e90`. Update proof on `blender_mcp_candidates`: backup `20260505T225446Z_blender_mcp_candidates_7636d13bded8`, backup proof `fa26b7f476d24de4b74a46f06b182ae5`, check proof `c89d2ea4965d4d9182c53e8b71e086b9`, update proof `970908d222734767a55401644878fa4a`. Remaining: all-app release watch, registering safe setup runners, and richer post-update app-specific smoke gates for the 60-app registry. |
| P0 | Hermes Agent full OS operator coverage | IN_PROGRESS | `/api/agents/action-catalog` now exposes 71 cataloged OS/code actions with public ready/partial/blocked state, proof requirements, approval/rollback flags, payload requirements, and no leaked internal handler names. Current code action surface includes MCP-locked patch/restore plus git readiness, branch, stage-owned, commit-owned, push, and PR actions; git actions are high-risk and proof/approval/rollback-marked where appropriate. Earlier safe sweep returned 25/25 accepted/completed proofs, protected missing-payload probes failed closed 5/5, and non-physical artifact actions passed 3/3: generation proof `783d06b27087489a8914956a5df559dd`, design proof `1ad2e99d3f9541d58b4a38a0e1ff5b16`, T1 #1 camera evidence proof `4a6143a9ef6a47c993530539d31a0dd1`, Azure voice preview proof `e4bbebf265e34035b3e3f47ecb3c4238` / TTS proof `324cbb9c902643a388ef773d83613c61`, Azure catalog proof `cb64df49be2f4036b1945d88ce2cd861`, and Roadmap truth proof `19f7ecf90f8a4a1ba303bf7fd0ec3142`. Focused Playwright passed 10/10 and screenshot proof is `03_implementation/proof/screenshots/agents-operator-catalog-expanded-2026-05-06.png`. Remaining: complete safe registered runners for the 30 Source OS runner gaps, update-all backup/smoke/rollback orchestration, and blocked idle work kinds before calling Hermes Agents fully e2e complete. |
| P0 | Hermes Agent programming ecosystem | IN_PROGRESS | Source inputs are required, not optional: `https://github.com/NousResearch/hermes-agent.git` and `https://github.com/AtomicBot-ai/atomic-hermes.git`, with local source at `G:/Github/hermes-agent-fresh` and `G:/Github/atomic-hermes`. First safe code-operator slice is live and verified: programming readiness, Hermes MCP lock readiness, write readiness, repo status/tree/search, bounded file read, snapshot/diff/restore, proof-backed patch proposal, MCP-locked patch apply, exact-worktree MCP gate list/run APIs, exact-worktree MCP claim/lock/heartbeat/evidence/release APIs, and proof-gated git branch/stage/commit/push/PR APIs are exposed through `/api/code-operator/*` and mirrored into `/api/agents/action-catalog` with proof-required contracts. Route smoke proves `GET /api/code-operator/gates` returns 11 MCP gates and `POST /api/code-operator/gates/run` runs `git-diff-check` through `hermes_run_gate` as PASS while invalid owners fail closed; evidence `ev_4a3482659b8b91d3`. MCP coordination route smoke claimed task `h3d-agent-lock-route-smoke`, locked/hearted/released `03_implementation/ROADMAP.md`, recorded evidence, and rejected `../G/private/.env`; evidence `ev_77276b2ded845997`. Patch-apply route smoke created proposal `642990660dde4b688f14c35589eaf408`, applied it only under active same-owner MCP lock with pre/post snapshots, recorded chained MCP evidence, and passed `git-diff-check`; evidence `ev_2cd18d787167bc33`. PR #73 hardening proof is `ev_dfe36e14a23d418c`. Git shipping lane is implemented as the next stacked Codex slice: it creates only `codex/` or `hermes-agent/` branches from clean worktrees, stages only changed source files that have same-owner snapshots and active MCP file locks, commits with proof IDs, pushes to origin without force, and opens PRs through authenticated `gh`. Remaining before autonomous source mutation is fully complete: provider-backed coding loop, second-agent review lane, and rollback-gated repair workflow. Acceptance: both Hermes agent teams can take real Hermes3D tasks, claim/lock/heartbeat/gate/evidence/release through Hermes MCP locks, edit code through source-backed tools, run real tests/gates, produce proof artifacts, create branches/PRs, and restore any agent-touched file. |
| P0 | Hermes Agent full OS operator coverage | IN_PROGRESS | `/api/agents/action-catalog` now exposes 74 cataloged OS/code actions with public ready/partial/blocked state, proof requirements, approval/rollback flags, payload requirements, and no leaked internal handler names. Current code action surface includes MCP-locked patch/restore, proof-gated git readiness/branch/stage/commit/push/PR, plus provider-team readiness, assignment, and second-team review-request contracts; git actions are high-risk and proof/approval/rollback-marked where appropriate. Earlier safe sweep returned 25/25 accepted/completed proofs, protected missing-payload probes failed closed 5/5, and non-physical artifact actions passed 3/3: generation proof `783d06b27087489a8914956a5df559dd`, design proof `1ad2e99d3f9541d58b4a38a0e1ff5b16`, T1 #1 camera evidence proof `4a6143a9ef6a47c993530539d31a0dd1`, Azure voice preview proof `e4bbebf265e34035b3e3f47ecb3c4238` / TTS proof `324cbb9c902643a388ef773d83613c61`, Azure catalog proof `cb64df49be2f4036b1945d88ce2cd861`, and Roadmap truth proof `19f7ecf90f8a4a1ba303bf7fd0ec3142`. Focused Playwright passed 10/10 and screenshot proof is `03_implementation/proof/screenshots/agents-operator-catalog-expanded-2026-05-06.png`. Remaining: complete safe registered runners for the 30 Source OS runner gaps, update-all backup/smoke/rollback orchestration, and blocked idle work kinds before calling Hermes Agents fully e2e complete. |
| P0 | Hermes Agent programming ecosystem | IN_PROGRESS | Source inputs are required, not optional: `https://github.com/NousResearch/hermes-agent.git` and `https://github.com/AtomicBot-ai/atomic-hermes.git`, with local source at `G:/Github/hermes-agent-fresh` and `G:/Github/atomic-hermes`. First safe code-operator slice is live and verified: programming readiness, Hermes MCP lock readiness, write readiness, repo status/tree/search, bounded file read, snapshot/diff/restore, proof-backed patch proposal, MCP-locked patch apply, exact-worktree MCP gate list/run APIs, exact-worktree MCP claim/lock/heartbeat/evidence/release APIs, proof-gated git branch/stage/commit/push/PR APIs, and provider-team readiness/assignment/review-request APIs are exposed through `/api/code-operator/*` and mirrored into `/api/agents/action-catalog` with proof-required contracts. Route smoke proves `GET /api/code-operator/gates` returns 11 MCP gates and `POST /api/code-operator/gates/run` runs `git-diff-check` through `hermes_run_gate` as PASS while invalid owners fail closed; evidence `ev_4a3482659b8b91d3`. MCP coordination route smoke claimed task `h3d-agent-lock-route-smoke`, locked/hearted/released `03_implementation/ROADMAP.md`, recorded evidence, and rejected `../G/private/.env`; evidence `ev_77276b2ded845997`. Patch-apply route smoke created proposal `642990660dde4b688f14c35589eaf408`, applied it only under active same-owner MCP lock with pre/post snapshots, recorded chained MCP evidence, and passed `git-diff-check`; evidence `ev_2cd18d787167bc33`. PR #73 hardening proof is `ev_dfe36e14a23d418c`. Git shipping lane is implemented as the next stacked Codex slice: it creates only `codex/` or `hermes-agent/` branches from clean worktrees, stages only changed source files that have same-owner snapshots and active MCP file locks, commits with proof IDs, pushes to origin without force, and opens PRs through authenticated `gh`. The provider-team slice exposes Team A MiniMax builders and Team B DeepSeek reviewers as real readiness/assignment/review boundaries: it records proof-backed tasks only when selected source, provider config, and MCP lock prerequisites pass, and returns exact blocked reasons when they do not. It does not yet pretend to invoke providers to write/review code. Remaining before autonomous source mutation is fully complete: provider-backed coding/review execution loop and rollback-gated repair workflow. Acceptance: both Hermes agent teams can take real Hermes3D tasks, claim/lock/heartbeat/gate/evidence/release through Hermes MCP locks, edit code through source-backed tools, run real tests/gates, produce proof artifacts, create branches/PRs, and restore any agent-touched file. |
| P0 | Claude 20-agent completion contract kit | IN_PROGRESS | The first 20-lane contract exists at `03_implementation/docs/handoffs/CLAUDE_20_AGENT_COMPLETION_CONTRACT.md`; the follow-up six-agent polish/audit contract exists at `03_implementation/docs/handoffs/CLAUDE_6_AGENT_POLISH_AUDIT_2026-05-06.md`. Acceptance: every Claude lane has exact files, locks, task id, branch/worktree rule, pass/fail gates, proof output, no-fake rule, S1 lock rule, GitHub push/PR rule, and "fix until pass" instruction. Claude agents may complete Source OS runners, tab polish, tests, docs/proof, visual checks, and missing runtime integrations, but must not touch files owned by the current Codex code-operator lane. |
| P0 | 60 source-app runtime completion | IN_PROGRESS | Keep the visible Source OS target at the proven 60 source-backed rows. Acceptance: `SOURCE_REGISTRY_TRUTH_AUDIT.json`, `/api/modules`, `/api/modules/runtime/verifiers`, `/api/modules/runtime/setup-queue`, `/api/modules/runtime/cli-surface`, `SOURCE_APP_60_COMPLETION_AUDIT.json`, `SOURCE_APP_CLI_AGENT_READINESS_AUDIT.json`, `SOURCE_APP_CLI_SURFACE_AUDIT.json`, `SOURCE_APP_RUNTIME_ACTION_PLAN.md`, and Playwright Source OS/Plugins/Settings/Roadmap proof all agree; each row is either runtime-ready through a registered verifier or source-ready with an exact runner gap, every available CLI is exposed as an agent-usable verifier/runner before desktop fallback, and no row remains in an unclassified launch-kind bucket. |
| P1 | Voice Azure STT pipeline | DONE | Backend `/api/voice/stt` reads Azure Speech secrets only from runtime/private env, returns transcript or exact blocker, appends proof, and chat mic inserts transcript while preserving the audio artifact. Live Azure TTS-to-STT proof event: `5d9b8a25a1ac454f85ea46e5a59866f4`. |
Expand Down
53 changes: 53 additions & 0 deletions 03_implementation/src/hermes3d/api/routes/agents.py
Original file line number Diff line number Diff line change
Expand Up @@ -667,6 +667,43 @@ def _execute_catalog_handler(handler: str, actor: str, payload: dict[str, Any])
from hermes3d.services import code_history

return code_history.programming_readiness()
if handler == "code.teams.readiness":
from hermes3d.services import code_history

return code_history.provider_team_readiness()
if handler == "code.teams.assign_task":
from hermes3d.services import code_history

files = payload.get("files")
if not isinstance(files, list) or not files:
raise ValueError("Payload field files must be a non-empty list.")
Comment on lines +677 to +679

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

This validation logic for a non-empty list is also used for files and proof_ids in the code.teams.request_review handler (lines 695-698). To improve maintainability and reduce code duplication, consider extracting this logic into a helper function, similar to how _required_payload_text is used for string validation.

return code_history.assign_provider_team_task(
owner=actor,
team_id=_required_payload_text(payload, "team_id"),
task_id=_required_payload_text(payload, "task_id"),
title=_required_payload_text(payload, "title"),
files=files,
objective=_required_payload_text(payload, "objective"),
target_branch=str(payload.get("target_branch") or "") or None,
review_required=bool(payload.get("review_required", True)),
)
if handler == "code.teams.request_review":
from hermes3d.services import code_history

files = payload.get("files")
proof_ids = payload.get("proof_ids")
if not isinstance(files, list) or not files:
raise ValueError("Payload field files must be a non-empty list.")
if not isinstance(proof_ids, list) or not proof_ids:
raise ValueError("Payload field proof_ids must be a non-empty list.")
return code_history.request_provider_team_review(
owner=actor,
task_id=_required_payload_text(payload, "task_id"),
summary=_required_payload_text(payload, "summary"),
files=files,
proof_ids=proof_ids,
reviewer_team_id=str(payload.get("reviewer_team_id") or "deepseek-reviewers"),
)
if handler == "code.mcp_locks.readiness":
from hermes3d.services import code_history

Expand Down Expand Up @@ -1176,11 +1213,17 @@ def _agent_action_contracts() -> list[dict[str, Any]]:
from hermes3d.services import code_history

mcp_locks = code_history.mcp_lock_readiness()
provider_teams = code_history.provider_team_readiness()
except Exception:
mcp_locks = {"ready": False, "blocked_reason": "Hermes MCP lock readiness could not be evaluated."}
provider_teams = {"ready": False, "status": "blocked", "blocked_reasons": ["Hermes Agent provider-team readiness could not be evaluated."]}
team_blocked_reason = "; ".join(str(item) for item in provider_teams.get("blocked_reasons", [])[:4]) if provider_teams.get("blocked_reasons") else None
contracts = [
_contract("agents.health.refresh", "Refresh Hermes Agent runtime health", "agents", "ready" if runtime.get("hermes_agent_runtime") == "ready" else "blocked", "read", "low", "GET /api/agents/health", "agents.health", "Checks the configured local/private agent runtime bridge."),
_contract("code.programming_readiness.refresh", "Refresh Hermes Agent programming readiness", "agents", "ready", "read", "low", "GET /api/code-operator/programming-readiness", "code.programming_readiness", "Checks true source inputs from Nous Hermes Agent and Atomic Hermes plus MiniMax/DeepSeek provider readiness."),
_contract("code.teams.readiness.refresh", "Refresh Hermes Agent team readiness", "agents", str(provider_teams.get("status") or "blocked"), "read", "low", "GET /api/code-operator/teams/readiness", "code.teams.readiness", "Checks MiniMax builder and DeepSeek reviewer team readiness without exposing provider secrets.", None if provider_teams.get("ready") else (team_blocked_reason or "Hermes Agent provider teams are not ready.")),
_contract("code.teams.assign_task", "Assign provider-backed code task", "agents", "ready" if provider_teams.get("ready") else "blocked", "proof", "medium", "POST /api/code-operator/teams/assign-task", "code.teams.assign_task", "Records a proof-backed provider-team coding task only after selected source, provider, and MCP lock prerequisites are ready.", None if provider_teams.get("ready") else (team_blocked_reason or "Hermes Agent provider teams are not ready.")),
_contract("code.teams.request_review", "Request second-team code review", "agents", "ready" if provider_teams.get("ready") else "blocked", "proof", "medium", "POST /api/code-operator/teams/request-review", "code.teams.request_review", "Requests a proof-backed DeepSeek/Atomic Hermes review for files and proof ids before PR shipping.", None if provider_teams.get("ready") else (team_blocked_reason or "Hermes Agent reviewer team is not ready.")),
_contract("code.mcp_locks.readiness.refresh", "Refresh Hermes MCP lock readiness", "agents", "ready" if mcp_locks.get("ready") else "partial", "read", "low", "GET /api/code-operator/mcp-locks/readiness", "code.mcp_locks.readiness", "Checks that the Hermes Agent runtime has hermes3d-locks source/server access and that MCP_LOCK_WORKSPACE matches the actual edit workspace before write tools can enable.", None if mcp_locks.get("ready") else str(mcp_locks.get("blocked_reason") or "Hermes MCP locks are not ready for code writes.")),
_contract("code.write_readiness.refresh", "Refresh Hermes Agent write readiness", "agents", "ready" if mcp_locks.get("ready") else "blocked", "read", "low", "GET /api/code-operator/write/readiness", "code.write.readiness", "Explains whether Hermes Agents may enable patch/apply/command/git coding tools yet. Read-only context stays available; write tools stay blocked until locks, source inputs, providers, snapshots, and proof gates are ready.", None if mcp_locks.get("ready") else str(mcp_locks.get("blocked_reason") or "Hermes MCP locks are not ready for code writes.")),
_contract("code.history.files.refresh", "Refresh agent-touched file history", "agents", "ready", "read", "low", "GET /api/code-operator/history/files", "code.history.files", "Lists files already snapshotted by Hermes Agent code operations."),
Expand Down Expand Up @@ -1316,6 +1359,16 @@ def _contract_payload_schema(action_id: str) -> dict[str, Any]:
"voice.catalog.refresh": {"required": [], "optional": {"locale": "Azure voice locale prefix, defaults to en"}},
"voice.preview": {"required": [], "optional": {"agent_id": "agent id", "voice": "Azure short name", "text": "preview text", "rate": "0.5-2.0", "pitch_pct": "-50..50"}},
"voice.stt": {"required": ["artifact_id"], "optional": {"locale": "speech locale, defaults to en-US"}, "safety": "Reads an existing audio artifact; no secret values are returned."},
"code.teams.assign_task": {
"required": ["team_id", "task_id", "title", "files", "objective"],
"optional": {"target_branch": "safe git ref", "review_required": "defaults true"},
"safety": "Team id must be minimax-builders, deepseek-reviewers, or dual; selected source/provider/MCP prerequisites must be ready before assignment is accepted.",
},
"code.teams.request_review": {
"required": ["task_id", "summary", "files", "proof_ids"],
"optional": {"reviewer_team_id": "defaults to deepseek-reviewers"},
"safety": "Review requests require at least one proof/evidence id and route through the proof ledger; no provider secret values are returned.",
},
"code.history.snapshot": {"required": ["relative_path"], "optional": {"action_id": "agent action identifier", "reason": "why this snapshot is needed"}, "safety": "Project-relative source files only; secrets, binary/generated files, .git, node_modules, and printer config writes are blocked."},
"code.repo.tree.refresh": {"required": [], "optional": {"root": "project-relative directory or file; defaults to repository root", "limit": "1-1200 returned paths"}, "safety": "Secrets, generated output, caches, node_modules, and VCS internals are excluded."},
"code.repo.search": {"required": ["pattern"], "optional": {"root": "project-relative search root", "max_results": "1-200"}, "safety": "Bounded ripgrep only; absolute paths, parent traversal, secrets, and generated folders are blocked."},
Expand Down
Loading