Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
63 commits
Select commit Hold shift + click to select a range
50fdb15
test(runtime): expose Hermes activation transport bound
rsliter Aug 25, 2026
1397355
fix(runtime): preserve activation transport response
rsliter Aug 25, 2026
4cab78f
merge: refresh Hermes transport fix from main
rsliter Aug 25, 2026
8c3518e
fix(runtime): keep release transport bound
rsliter Aug 25, 2026
e89ddd5
merge: refresh Hermes transport fix from main
rsliter Aug 25, 2026
e50c63e
test(runtime): parse activation window portably
rsliter Aug 25, 2026
577bd04
merge: refresh Hermes transport fix from main
rsliter Aug 25, 2026
efc5b2a
fix(runtime): acknowledge Hermes activation release
rsliter Aug 25, 2026
4c9fd8b
fix(onboard): cover activation replay deadline
rsliter Aug 25, 2026
d22dff5
fix(runtime): cover retained activation deadline
cjagwani Aug 25, 2026
079b9b1
fix(runtime): use full response allowance
cjagwani Aug 25, 2026
897d867
merge: refresh Hermes Shields fix from main
cjagwani Aug 26, 2026
68343f9
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
cjagwani Aug 26, 2026
60c2567
fix(runtime): make release acknowledgement failure explicit
rsliter Aug 26, 2026
f9e7e51
fix(runtime): resolve release acknowledgement feedback
rsliter Aug 26, 2026
df1c5b3
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
rsliter Aug 26, 2026
83519cf
fix(runtime): make acknowledgement failure return explicit
rsliter Aug 26, 2026
8ece9a0
test(runtime): diagnose repeated Shields transitions
cjagwani Aug 26, 2026
c141740
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
rsliter Aug 26, 2026
f50ff0f
test(ci): refresh Hermes Shields validation
rsliter Aug 26, 2026
f6a02e5
fix(onboard): wait for verified create handoff
cjagwani Aug 26, 2026
77550ea
fix(onboard): wait for exact sandbox publication
cjagwani Aug 26, 2026
33112b2
Merge remote-tracking branch 'origin/main' into codex/fix-hermes-shie…
cjagwani Aug 26, 2026
24c8a0d
test(onboard): cover sandbox publication rejection
cjagwani Aug 26, 2026
4ee5047
fix(hermes): preserve startup identity for release ack
cjagwani Aug 26, 2026
45e7e98
merge: resolve conflicts with main
github-actions[bot] Aug 27, 2026
d0743bb
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
sandl99 Aug 27, 2026
7f91eb7
test(runtime): refresh Shields merge coverage
sandl99 Aug 27, 2026
c203f10
test(runtime): cover release acknowledgement order
sandl99 Aug 27, 2026
1bec8ca
fix(runtime): rescan replaced Hermes writers
sandl99 Aug 27, 2026
c63f95c
fix(runtime): wait for Hermes release publisher
sandl99 Aug 27, 2026
e74baa6
fix(runtime): stabilize Hermes release observation
sandl99 Aug 27, 2026
098abe9
test(runtime): stabilize helper timeout allowance
sandl99 Aug 27, 2026
76ce503
fix(runtime): require Hermes parent release acknowledgement
sandl99 Aug 27, 2026
338257c
fix(runtime): rescan vanished mutation processes
sandl99 Aug 27, 2026
d647734
fix(runtime): recapture exact mutation processes
sandl99 Aug 27, 2026
eb6856a
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
cjagwani Aug 27, 2026
cceb629
fix(runtime): retry raced mutation signals
cjagwani Aug 27, 2026
05aed98
fix(shields): observe settled Hermes lock
cjagwani Aug 27, 2026
f0d17d2
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
cv Aug 28, 2026
9637671
Merge branch 'main' into codex/fix-hermes-shields-transport-10155
cv Aug 28, 2026
369bfa3
ci: retrigger PR review advisor
cv Aug 28, 2026
15141cd
fix(shields): use read-only Hermes timer confirmation
rsliter Aug 28, 2026
30e78c8
fix(shields): confirm fresh Hermes lockdown
rsliter Aug 28, 2026
6e66aba
fix(runtime): retain Hermes transport recovery
rsliter Aug 28, 2026
69f4a41
merge: refresh Hermes transport repair from main
prekshivyas Aug 29, 2026
3667b6d
fix(runtime): bind pidfd to immutable task identity
prekshivyas Aug 29, 2026
52a3c43
merge: refresh Hermes pidfd repair from main
prekshivyas Aug 29, 2026
425301f
fix(runtime): retain the pinned OpenShell supervisor
prekshivyas Aug 29, 2026
a4f1e66
fix(shields): preserve the production settle window
prekshivyas Aug 29, 2026
e51aa98
merge: refresh Hermes repair from main
prekshivyas Aug 29, 2026
6628681
test(shields): reuse the Hermes publisher harness
prekshivyas Aug 29, 2026
3361440
test(shields): close advisor feedback
prekshivyas Aug 29, 2026
99c4c72
fix(runtime): bind supervisor executable identity
prekshivyas Aug 29, 2026
a424235
fix(runtime): distinguish invalid startup gate state
prekshivyas Aug 29, 2026
7649bfb
refactor(runtime): install fixed transport broker
prekshivyas Aug 29, 2026
e2b8c81
refactor(runtime): close broker review findings
prekshivyas Aug 29, 2026
565569c
Merge remote-tracking branch 'origin/main' into codex/refresh-pr-10272
prekshivyas Aug 29, 2026
702f72a
Merge remote-tracking branch 'origin/main' into codex/refresh-pr-10272
prekshivyas Aug 29, 2026
a2a59e2
refactor(runtime): close final advisor findings
prekshivyas Aug 29, 2026
24ca693
Merge remote-tracking branch 'origin/main' into codex/refresh-pr-10272
prekshivyas Aug 30, 2026
4bfd3f6
fix(runtime): bind broker interpreter identity
prekshivyas Aug 30, 2026
8f10786
docs(shields): clarify immutable lock fallback
prekshivyas Aug 30, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions agents/hermes/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,7 @@ COPY agents/hermes/cron-restore-control.py /usr/local/lib/nemoclaw/hermes-cron-r
COPY src/lib/actions/sandbox/openshell-child-visible-credentials.v0.0.106.json /usr/local/lib/nemoclaw/openshell-child-visible-credentials.v0.0.106.json
COPY scripts/state-dir-guard.py /usr/local/lib/nemoclaw/state-dir-guard.py
COPY scripts/runtime-state-mutation-control.py /usr/local/lib/nemoclaw/runtime-state-mutation-control.py
COPY scripts/runtime-state-mutation-transport-broker.py /usr/local/lib/nemoclaw/runtime-state-mutation-transport-broker.py
COPY scripts/runtime-state-mutation-startup-gate.py /usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py
COPY scripts/runtime_state_mutation_hermes_publisher.py /usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py
COPY agents/hermes/state-lock-plan.json /usr/local/share/nemoclaw/state-lock-plan.json
Expand Down Expand Up @@ -493,14 +494,14 @@ RUN chmod -R a+rX /opt/nemoclaw-blueprint/
# minimum supported Hermes sandbox base tag guarantees those artifacts and
# test/runtime/sandbox/sandbox-rlimit-hooks.test.ts covers that base.
RUN chmod 755 /usr/local/bin/nemoclaw-start /usr/local/bin/nemoclaw-managed-startup-hold /usr/local/bin/nemoclaw-managed-bootstrap /usr/local/lib/nemoclaw/sandbox-init.sh /usr/local/lib/nemoclaw/validate-hermes-env-secret-boundary.py /usr/local/lib/nemoclaw/patch-hermes-session-list-preview.py /usr/local/lib/nemoclaw/patch-hermes-sqlite-temp-store.py /usr/local/lib/nemoclaw/patch-hermes-discord-recovery-permissions.py /usr/local/lib/nemoclaw/patch-hermes-profile-policy-defaults.py /usr/local/lib/nemoclaw/seed-hermes-dashboard-config.py /usr/local/lib/nemoclaw/hermes-runtime-config-guard.py /usr/local/lib/nemoclaw/finalize-tirith-marker.py /usr/local/lib/nemoclaw/hermes-mcp-config-transaction.py \
&& chown root:root /usr/local/bin/nemoclaw-gateway-control /usr/local/lib/nemoclaw/gateway-supervisor.sh /usr/local/lib/nemoclaw/state-dir-guard.py /usr/local/lib/nemoclaw/runtime-state-mutation-control.py /usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py /usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py /usr/local/share/nemoclaw/state-lock-plan.json /usr/local/share/nemoclaw/runtime-state-mutation-publisher-v1.json /usr/local/lib/nemoclaw/managed-gateway-control.py /usr/local/lib/nemoclaw/build-hermes-mcp-digest.py /usr/local/lib/nemoclaw/hermes-cron-restore-control.py /usr/local/lib/nemoclaw/openshell-child-visible-credentials.v0.0.106.json \
&& chown root:root /usr/local/bin/nemoclaw-gateway-control /usr/local/lib/nemoclaw/gateway-supervisor.sh /usr/local/lib/nemoclaw/state-dir-guard.py /usr/local/lib/nemoclaw/runtime-state-mutation-control.py /usr/local/lib/nemoclaw/runtime-state-mutation-transport-broker.py /usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py /usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py /usr/local/share/nemoclaw/state-lock-plan.json /usr/local/share/nemoclaw/runtime-state-mutation-publisher-v1.json /usr/local/lib/nemoclaw/managed-gateway-control.py /usr/local/lib/nemoclaw/build-hermes-mcp-digest.py /usr/local/lib/nemoclaw/hermes-cron-restore-control.py /usr/local/lib/nemoclaw/openshell-child-visible-credentials.v0.0.106.json \

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

[P1] Keep the stale-base replay fixture complete

Adding the broker to this unconditional ownership and mode replay breaks the extracted Dockerfile fixture in test/runtime/sandbox/sandbox-rlimit-hooks.test.ts because that fixture never stages the new path. Required CLI shard 2 is red, and the focused local test reproduces the same missing-file failure at line 770. Stage the broker in that fixture and assert its root-only mode so the stale-base replay remains executable and the required suite returns green.

&& chmod 700 /usr/local/bin/nemoclaw-gateway-control /usr/local/lib/nemoclaw/hermes-cron-restore-control.py \
&& chmod 500 /usr/local/lib/nemoclaw/state-dir-guard.py /usr/local/lib/nemoclaw/runtime-state-mutation-control.py /usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py /usr/local/lib/nemoclaw/managed-gateway-control.py \
&& chmod 500 /usr/local/lib/nemoclaw/state-dir-guard.py /usr/local/lib/nemoclaw/runtime-state-mutation-control.py /usr/local/lib/nemoclaw/runtime-state-mutation-transport-broker.py /usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py /usr/local/lib/nemoclaw/managed-gateway-control.py \
&& chmod 555 /usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py \
&& chmod 444 /usr/local/lib/nemoclaw/corporate-ca-runtime.sh /usr/local/lib/nemoclaw/entrypoint-env-wrapper.sh /usr/local/share/nemoclaw/state-lock-plan.json /usr/local/share/nemoclaw/runtime-state-mutation-publisher-v1.json /usr/local/lib/nemoclaw/gateway-supervisor.sh /usr/local/lib/nemoclaw/build-hermes-mcp-digest.py /usr/local/lib/nemoclaw/managed_policy.py \
&& chmod 444 /usr/local/lib/nemoclaw/patch-hermes-langfuse-credentials.mts \
&& chmod 444 /usr/local/lib/nemoclaw/openshell-child-visible-credentials.v0.0.106.json \
&& /opt/hermes/.venv/bin/python3 -I -c 'import runpy, yaml; assert yaml.safe_load("ready: true")["ready"] is True; runpy.run_path("/usr/local/lib/nemoclaw/runtime-state-mutation-control.py", run_name="nemoclaw_runtime_state_mutation_control_probe"); runpy.run_path("/usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py", run_name="nemoclaw_runtime_state_mutation_publisher_probe"); runpy.run_path("/usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py", run_name="nemoclaw_runtime_state_mutation_gate_probe"); runpy.run_path("/usr/local/lib/nemoclaw/hermes-runtime-config-guard.py", run_name="nemoclaw_runtime_config_guard_probe")' \
&& /opt/hermes/.venv/bin/python3 -I -c 'import runpy, yaml; assert yaml.safe_load("ready: true")["ready"] is True; runpy.run_path("/usr/local/lib/nemoclaw/runtime-state-mutation-control.py", run_name="nemoclaw_runtime_state_mutation_control_probe"); runpy.run_path("/usr/local/lib/nemoclaw/runtime-state-mutation-transport-broker.py", run_name="nemoclaw_runtime_state_mutation_transport_broker_probe"); runpy.run_path("/usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py", run_name="nemoclaw_runtime_state_mutation_publisher_probe"); runpy.run_path("/usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py", run_name="nemoclaw_runtime_state_mutation_gate_probe"); runpy.run_path("/usr/local/lib/nemoclaw/hermes-runtime-config-guard.py", run_name="nemoclaw_runtime_config_guard_probe")' \
&& if [ -d /usr/local/lib/nemoclaw/preloads ]; then \
chown -R 0:0 /usr/local/lib/nemoclaw/preloads \
&& find /usr/local/lib/nemoclaw/preloads -type f -exec chmod 444 {} + \
Expand Down Expand Up @@ -1450,6 +1451,7 @@ RUN check_metadata() { \
&& check_metadata /usr/local/bin/nemoclaw-gateway-control 'root:root 700' \
&& check_metadata /usr/local/share/nemoclaw/state-lock-plan.json 'root:root 444' \
&& check_metadata /usr/local/lib/nemoclaw/runtime-state-mutation-control.py 'root:root 500' \
&& check_metadata /usr/local/lib/nemoclaw/runtime-state-mutation-transport-broker.py 'root:root 500' \
&& check_metadata /usr/local/lib/nemoclaw/runtime-state-mutation-startup-gate.py 'root:root 555' \
&& check_metadata /usr/local/lib/nemoclaw/runtime_state_mutation_hermes_publisher.py 'root:root 500' \
&& check_metadata /var/lib/nemoclaw/runtime-state-mutation 'root:root 711' \
Expand Down
16 changes: 15 additions & 1 deletion agents/hermes/start.sh
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,11 @@ while :; do
printf '%s\n' '[SECURITY] Hermes startup held by an active runtime state mutation.' >&2
/bin/sleep 1 || true
;;
76)
printf '%s\n' '[SECURITY] Hermes startup refused invalid runtime state mutation state.' >&2
printf '%s\n' "[SECURITY] Run 'nemoclaw <sandbox-name> shields status' on the host to recover the retained transition." >&2
exit 1
;;
*)
printf '%s\n' '[SECURITY] Runtime state mutation startup gate failed.' >&2
exit 1
Expand All @@ -106,7 +111,16 @@ nemoclaw_runtime_state_mutation_checkpoint() {
fi
kill -STOP "$$"
if nemoclaw_runtime_state_mutation_gate resume; then
return 0
if nemoclaw_runtime_state_mutation_gate acknowledge; then
# The acknowledgement helper stops itself after publishing. The root
# controller resumes that exact child, then this parent stops only after
# Bash has reaped it and observed success.
kill -STOP "$$"
return 0
fi
printf '%s\n' '[SECURITY] Runtime state mutation release acknowledgement failed; holding startup.' >&2
kill -STOP "$$"
return 1
else
status=$?
fi
Expand Down
2 changes: 1 addition & 1 deletion docs/reference/commands.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -5560,7 +5560,7 @@ The following flags change defaults for commands that manage existing sandboxes.
</AgentOnly>
| `NEMOCLAW_DISABLE_SUPERVISOR_RELAUNCH` | `1` to enable | Skips the automatic trusted container recreation during `$$nemoclaw <name> recover` when two managed scans find no supervisor while PID 1 remains stable. Use only as a troubleshooting escape hatch; recovery then falls back to the rebuild or re-onboard guidance. |
| `NEMOCLAW_SHIELDS_ACCEPT_LEGACY_BASELINE` | `1` to opt in | Allows advanced immutable-config verification to trust the current on-disk bytes for older or partial content baselines. Use only after you have rebuilt or manually inspected the sandbox state and accepted that the baseline is operator-approved. |
| `NEMOCLAW_SHIELDS_SETTLE_MS` | milliseconds (default `750`, clamped to `0` to `10000`) | Settle window NemoClaw waits after re-applying a config lockdown (during shields auto-restore and `$$nemoclaw <name> shields up` drift remediation) before re-confirming the lock still holds. Detects when an in-sandbox reconciler changes config file permissions after lockdown and re-applies the lock; if NemoClaw cannot re-confirm the lock within the retry budget, shields stay down. This narrows the window in which a reconciler can revert permissions rather than eliminating it. The best-effort `chattr +i` immutable bit remains the only fully durable lock. Raise it on hosts where the gateway settles slowly. |
| `NEMOCLAW_SHIELDS_SETTLE_MS` | positive whole-number milliseconds (default `750`, maximum `10000`) | NemoClaw waits this long after re-applying a config lockdown before checking that the lock still holds. It applies during ordinary `$$nemoclaw <name> shields up` transitions, shields auto-restore, and `shields up` drift remediation. Values above `10000` use `10000`. Fractional, zero, negative, blank, and invalid values use the default. If NemoClaw cannot re-confirm the lock within the retry budget, shields stay down. This check narrows the window in which an in-sandbox reconciler can revert permissions; it does not eliminate that window. When the best-effort `chattr +i` operation succeeds, its immutable bit provides the durable lock. If that operation is unavailable or fails, no durable lock is available. Raise the value on hosts where the gateway settles slowly. |
| `NEMOCLAW_SKIP_UNREACHABLE_SANDBOX_BACKUP` | Exactly `1` to opt in (`true`, `yes`, `0` are not accepted) | Applies to standalone `$$nemoclaw backup-all` runs. Skips running sandboxes whose in-sandbox SSH endpoint does not answer. It does not relax the installer's strict pre-upgrade backup, which still aborts if any registered sandbox is skipped or fails. Any uncommitted state since the last successful backup is not included in the skipped backup. |
| `NEMOCLAW_UNINSTALL_ALL_GATEWAY_PORTS` | `1` to opt in | Makes `$$nemoclaw uninstall` remove every gateway port on the host instead of only the port `NEMOCLAW_GATEWAY_PORT` selects. Equivalent to passing the `--all-gateway-ports` flag; the whole-host `Proceed?` confirmation still applies unless `--yes` is also passed. Each port runs as its own uninstall, and the variable is dropped from those runs so the sweep cannot re-enter itself. |
| `NEMOCLAW_UNINSTALL_DESTROY_USER_DATA` | `1` to opt in | Acknowledges data loss during `$$nemoclaw uninstall`, skips eligible fresh sandbox backups, and removes the otherwise-preserved entries (`rebuild-backups/`, `backups/`, `sandboxes.json`) in the selected gateway's state root. It does not select the explicit `--destroy-user-data` CLI-shim removal path; shim handling follows the ordinary selected-gateway scope. The global `Proceed?` confirmation still applies unless `--yes` is also passed. |
Expand Down
5 changes: 5 additions & 0 deletions docs/reference/troubleshooting.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -1834,6 +1834,11 @@ Do not kill or manually restart the held entrypoint.
Run `$$nemoclaw <name> shields status` from the host so NemoClaw can recover the retained target and authenticate the startup release.
If recovery still fails, preserve the owner-only lifecycle ledger and the complete error for diagnosis instead of removing a marker or changing in-sandbox permissions.

If the startup gate instead reports `invalid-state code=<code> transaction=<id>` and Hermes refuses startup, the error code identifies rejected gate state rather than an active transition that can make progress by waiting.
The transaction is a 64-character identifier when the gate safely parsed it, or `unknown` when it could not.
Run `$$nemoclaw <name> shields status` from the host to recover the retained transition.
If status cannot recover it, preserve `~/.nemoclaw/state/runtime-provider-lifecycle/`, the error code, and the transaction identifier for diagnosis; do not remove or edit the root-owned in-sandbox receipts.

### Hermes startup reports `HERMES_CONFIG_MUTATION_ORPHANED`

This refusal means a root-owned config or shields transaction stopped without a safely recoverable complete state.
Expand Down
1 change: 1 addition & 0 deletions docs/security/tcb-boundary.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,7 @@ A successful build does not replace review of privilege, process identity, descr
| `src/lib/onboard/runtime-provider/docker-operation-authority.ts` | Runs in the host CLI under the operator account and invokes Docker without a shell from a fixed working directory and sanitized environment. | One qualified absolute Docker executable and its absolute interpreter chain; an absolute-only fixed `PATH`; the effective PATH-selected `docker-credential-*` executables and their interpreter chains; the effective SSH executable for an `ssh://` endpoint; the context, host, TLS, and endpoint bindings; and the non-`PATH` execution-environment digest. The complete `PATH` enters authority identity for host-local inference and `ssh://`. A local `sandbox-lifecycle` authority omits helper-free added directories from persisted identity while still binding selected delegated helpers. | Revalidates executable, interpreter, delegated-command, and engine-endpoint metadata before provider actions; rejects authority drift and unverified remote TCP; and prevents ambient Docker configuration or command delegation from redirecting a fenced runtime provider state mutation. |
| `src/lib/onboard/runtime-provider/persisted-engine-lifecycle.ts` and `~/.nemoclaw/state/runtime-provider-lifecycle/` | The host CLI manages an owner-only private directory and durable artifacts under the operator account. | A runtime target claim and phase-bound transaction, release receipt, or tombstone whose sandbox lifecycle, engine binding, container, state root, plan, projection, target, rollback, and nonce match. | Preserves recovery authority across host process restart, excludes a second target, advances only the transaction through `prepared`, `mutation-authorized`, `fence-established`, and `completed` phases, and releases only the matching claim. |
| `src/lib/sandbox/privileged-exec.ts` and `src/lib/adapters/sandbox/command-transport.ts` | Run in the host CLI and hold a privileged sandbox execution lease through command completion and transport cleanup. | The canonical per-sandbox host transition lock, the durable runtime target claim, and the registered container identity. | Drains an earlier execution lease before provider fencing and rejects later direct-container, OpenShell, and SSH execution before argument resolution or process spawn. One OpenShell lease covers its direct Docker fallback so transport selection cannot cross the fence. |
| `scripts/runtime-state-mutation-transport-broker.py` | The current managed Hermes image installs a root-owned, mode `0500` copy. The qualified Docker provider starts its fixed path as root before the supervisor stops. | One 64-character transaction identifier, fixed controller and transport paths, root-owned private request files, and bounded action-specific timeouts. | Keeps the fixed controller reachable while ordinary command transports are fenced, validates transaction-bound requests and acknowledgements, normalizes helper failures, and removes its private session only after the released supervisor is confirmed running. |
| `scripts/runtime-state-mutation-control.py` | The current managed Hermes image installs a root-owned, mode `0500` copy, invoked as root through the qualified Docker provider authority. | Fixed actions; container, engine, mount-namespace, state-root, plan, projection, posture, and nonce bindings; installed controller and publisher identities; and stable process evidence. | Establishes and verifies the in-container fence, stops the bound entrypoint and sandbox processes, invokes only the fixed Hermes publisher, starts only the bound entrypoint, requires a fresh healthy gateway and authenticated startup checkpoint, and retains restrictive state when release is not proved. |
| `scripts/runtime_state_mutation_hermes_publisher.py` | The current managed Hermes image installs a root-owned, mode `0500` copy that only the runtime provider state mutation controller imports. | The root-owned controller marker, nonce-bound canonical plan and projection, installed state-lock plan, state-root descriptor, and requested posture. | Applies the normalized Hermes recursive posture, publishes fresh protected inodes where required, maintains its root-only journal, verifies the result, and returns a bounded receipt to the controller. |
| `scripts/runtime-state-mutation-startup-gate.py` and `agents/hermes/start.sh` | The gate is root-owned and mode `0555`; the Hermes entrypoint invokes it before sourcing helpers or reading mutable state. | The parent process, root-owned controller handoff, active runtime provider state mutation identity, candidate checkpoint, and authenticated release for the same target. | Holds or refuses startup on active, malformed, uninspectable, or unauthenticated state, publishes a checkpoint only after the complete Hermes topology is healthy, and resumes only the controller-authenticated candidate. |
Expand Down
Loading
Loading