Skip to content

fix(policy): drop github from Hermes baseline - #5267

Merged
cv merged 3 commits into
mainfrom
fix/hermes-baseline-drop-github-default
Jun 12, 2026
Merged

fix(policy): drop github from Hermes baseline#5267
cv merged 3 commits into
mainfrom
fix/hermes-baseline-drop-github-default

Conversation

@laitingsheng

@laitingsheng laitingsheng commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Summary

The Hermes baseline policy agents/hermes/policy-additions.yaml hardcoded a github network_policies block, so every Hermes sandbox received unscoped access to github.com and api.github.com regardless of which presets the user selected at onboard. The Balanced tier — which lists no github preset — therefore still surfaced ● github (active on gateway, missing from local state) in policy-list, contradicting the documented Hermes baseline. The block is now removed and github ships only via the discoverable opt-in preset that already exists for OpenClaw.

Related Issue

Fixes #5251

Changes

  • agents/hermes/policy-additions.yaml — drop the github network policy stanza (hosts + binaries) and replace it with the same NOTE breadcrumb the OpenClaw baseline carries, so the opt-in path becomes the single source of truth.
  • test/validate-blueprint.test.ts — add a regression asserting the Hermes baseline never re-declares github and that no other baseline entry references github.com / api.github.com; helper-wrapped to satisfy the source-shape budget.
  • test/policies.test.ts — drop the now-obsolete phantom-gh shape assertion (the binary list it pinned no longer exists once the baseline block is gone).
  • ci/test-file-size-budget.json — ratchet test/policies.test.ts from 2763 → 2753 after the obsolete test was removed.

Type of Change

  • Code change (feature, bug fix, or refactor)
  • Code change with doc updates
  • Doc only (prose changes, no code sample modifications)
  • Doc only (includes code sample changes)

Verification

  • npx prek run --all-files passes
  • npm test passes
  • Tests added or updated for new or changed behavior
  • No secrets, API keys, or credentials committed
  • Docs updated for user-facing behavior changes
  • npm run docs builds without warnings (doc changes only)
  • Doc pages follow the style guide (doc changes only)
  • New doc pages include SPDX header and frontmatter (new pages only)

Signed-off-by: Tinson Lai tinsonl@nvidia.com

Summary by CodeRabbit

  • Behavior Changes

    • GitHub access is no longer provided by default in the Hermes sandbox. Users can now opt-in to GitHub access through a dedicated preset.
  • Chores

    • Updated internal validation and testing frameworks.

Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
Signed-off-by: Tinson Lai <tinsonl@nvidia.com>
@coderabbitai

coderabbitai Bot commented Jun 12, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

GitHub access is moved from the base Hermes sandbox policy to an opt-in preset. The base policy removes GitHub endpoints and binary permissions, a regression test verifies this absence, an old GitHub allowlist test is replaced with a deprecation scanner for tls: terminate, and the test budget is adjusted accordingly.

Changes

GitHub policy extraction to preset

Layer / File(s) Summary
Base policy: remove GitHub access
agents/hermes/policy-additions.yaml
GitHub network and binary policy block is removed and replaced with a comment redirecting users to the separate presets/github.yaml for opt-in GitHub access.
Regression test: GitHub access verification
test/validate-blueprint.test.ts
New expectGithubBaselineAbsent helper and regression test enforce that the base Hermes policy does not include github.com or api.github.com endpoints, confirming access is only granted via the opt-in preset.
Test suite updates: deprecation check and budget
test/policies.test.ts, ci/test-file-size-budget.json
Old GitHub allowlist test is removed; new test scans all policy YAML files for the deprecated tls: terminate directive; test file size budget is updated to reflect the changes.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Poem

🐰 A GitHub key once lived in the sand,
Now moved to a preset, as planned!
The base stays lean, clean, and pure,
Users choose access—they're in control for sure! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title 'fix(policy): drop github from Hermes baseline' accurately and concisely describes the primary change: removing hardcoded GitHub access from the Hermes baseline policy.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/hermes-baseline-drop-github-default

Comment @coderabbitai help to get the list of available commands and usage tips.

@laitingsheng laitingsheng added integration: hermes Hermes integration behavior area: policy Network policy, egress rules, presets, or sandbox policy bug-fix PR fixes a bug or regression labels Jun 12, 2026
@github-actions

Copy link
Copy Markdown
Contributor

PR Review Advisor

Findings: 0 needs attention, 0 worth checking, 0 nice ideas
Top item: No actionable findings

Consider writing more tests for
  • **Acceptance clause:** Presets: github is visible but unchecked. — add test evidence or identify existing coverage. The changed tests confirm the preset source exists and the Hermes baseline does not include GitHub by default. The PR does not modify or directly test the onboard UI/listing path, but that surface is outside this small YAML baseline change.
  • **Acceptance clause:** git clone → 403 CONNECT tunnel failed. — add test evidence or identify existing coverage. The PR adds deterministic source-shape coverage proving the Hermes baseline no longer grants GitHub egress. It does not add a live sandbox `git clone` denial check, which is reasonable for this unit-sufficient policy-source change.

Workflow run details

This is an automated advisory review. A human maintainer must make the final merge decision.

@github-actions

Copy link
Copy Markdown
Contributor

E2E Advisor Recommendation

Required E2E: hermes-e2e-vitest
Optional E2E: network-policy-vitest

Dispatch hint: hermes-e2e-vitest

Workflow run

Full advisor summary

E2E Recommendation Advisor

Base: origin/main
Head: HEAD
Confidence: high

Required E2E

  • hermes-e2e-vitest (high; live sandbox install with NVIDIA_API_KEY, timeout 75 minutes): Runs a real Hermes install/onboard flow, verifies the Hermes sandbox is created and healthy, retrieves the full OpenShell policy, and proves inference.local still works. This is the closest existing E2E coverage for changes to agents/hermes/policy-additions.yaml.

Optional E2E

  • network-policy-vitest (high; live sandbox/network-policy suite, timeout 90 minutes): Useful adjacent confidence for live network-policy enforcement, policy-add behavior, allow/deny probes, and preset hot-reload. It is OpenClaw-focused rather than Hermes-specific, so it is recommended but not merge-blocking for this Hermes base-policy change.

New E2E recommendations

  • Hermes GitHub opt-in egress boundary (high): Existing Hermes E2E validates that a full policy is present but does not appear to assert that github.com/api.github.com are absent by default, nor that selecting the github preset restores only the intended git-based access. This PR changes exactly that security boundary.
    • Suggested test: Add a Hermes live E2E that onboards Hermes without the github preset, asserts openshell policy get --full lacks github.com/api.github.com and sandbox git ls-remote to GitHub is blocked, then applies/selects the github preset and verifies GitHub access is allowed only through the intended git binary policy.

Dispatch hint

  • Workflow: .github/workflows/e2e-vitest-scenarios.yaml
  • jobs input: hermes-e2e-vitest

@github-actions

Copy link
Copy Markdown
Contributor

Vitest E2E Scenario Recommendation

Required Vitest E2E scenarios: None
Optional Vitest E2E scenarios: network-policy-vitest

Workflow run

Full Vitest E2E advisor summary

Vitest E2E Scenario Advisor

Base: origin/main
Head: HEAD
Confidence: high

Required Vitest E2E scenarios

  • None.

Optional Vitest E2E scenarios

  • network-policy-vitest: Adjacent policy coverage: the network-policy live Vitest job exercises restricted sandbox allow/deny behavior and policy preset application, but the primary changed surface is Hermes-specific policy configuration.
    • Dispatch: gh workflow run e2e-vitest-scenarios.yaml --ref <pr-head-ref> --field jobs=network-policy-vitest

Relevant changed files

  • agents/hermes/policy-additions.yaml

@cv
cv merged commit fb4c2b6 into main Jun 12, 2026
48 checks passed
@cv
cv deleted the fix/hermes-baseline-drop-github-default branch June 12, 2026 06:17
@miyoungc miyoungc mentioned this pull request Jun 16, 2026
13 tasks
cv pushed a commit that referenced this pull request Jun 17, 2026
## Summary
Refreshes release-prep documentation for NemoClaw v0.0.65.
Adds the v0.0.65 release-notes section and refreshes generated
`nemoclaw-user-*` skills from the Fern MDX source docs.

## Changes
- Added the v0.0.65 release notes to `docs/about/release-notes.mdx` with
links to the deeper docs pages for lifecycle, troubleshooting,
inference, CLI commands, messaging, credentials, network policy, Hermes,
and sub-agents.
- Regenerated the `nemoclaw-user-*` skills with
`scripts/docs-to-skills.py` so release-prep skill output matches the
merged source docs.
- Used the v0.0.65 announcement discussion as release context:
#5472.

## Source Summary
- #2492 -> `docs/about/release-notes.mdx`: Documents deadline-based
gateway wait reliability in the v0.0.65 recovery summary.
- #4958 -> `docs/about/release-notes.mdx`: Documents re-execed OpenClaw
gateway health check recovery in the sandbox recovery summary.
- #5163 -> `docs/about/release-notes.mdx`: Documents safer uninstall TTY
confirmation behavior in the day-two CLI summary.
- #5178 -> `docs/about/release-notes.mdx`: Documents fail-closed config
restore merge behavior in the rebuild and restore summary.
- #5179 -> `docs/about/release-notes.mdx`: Documents WeChat QR token
redaction in the messaging summary.
- #5182 -> `docs/about/release-notes.mdx`: Documents sustained gateway
serving checks in the recovery summary.
- #5194 -> `docs/about/release-notes.mdx`: Documents model-router
teardown during uninstall in the day-two CLI summary.
- #5195 -> `docs/about/release-notes.mdx`: Documents Shields
auto-restore lock reconfirmation in the rebuild and restore summary.
- #5198 -> `docs/about/release-notes.mdx`: Documents Docker Desktop WSL
CDI injection failure handling in the onboarding diagnostics summary.
- #5201 -> `docs/about/release-notes.mdx`: Documents sandbox
download/upload wrappers and sessions export in the day-two CLI summary.
- #5205 -> `docs/about/release-notes.mdx`: Documents reporter-owned
model metadata preservation in the rebuild and restore summary.
- #5214 -> `docs/about/release-notes.mdx`: Documents managed vLLM model
preflight before side effects in the inference setup summary.
- #5215 -> `docs/about/release-notes.mdx`: Documents managed vLLM extra
serve arguments in the inference setup summary.
- #5216 -> `docs/about/release-notes.mdx`: Documents silent OpenClaw
runtime fallback surfacing in the onboarding diagnostics summary.
- #5225 -> `docs/about/release-notes.mdx`: Documents persisted sandbox
gateway lookup in the gateway recovery summary.
- #5238 -> `docs/about/release-notes.mdx`: Documents sub-agent gateway
dial-back through the sandbox interface in the Hermes and sub-agent
summary.
- #5248 -> `docs/about/release-notes.mdx`: Documents Discord per-account
proxy resolution in the messaging summary.
- #5264 -> `docs/about/release-notes.mdx`: Documents reserved Hermes
port `8642` handling in the Hermes compatibility summary.
- #5267 -> `docs/about/release-notes.mdx`: Documents the narrower Hermes
baseline policy in the Hermes compatibility summary.
- #5321 -> `docs/about/release-notes.mdx`: Documents restored gateway
guard chains in the gateway recovery summary.
- #5328 -> `docs/about/release-notes.mdx`: Documents compact persisted
messaging plans in the messaging summary.
- #5338 -> `docs/about/release-notes.mdx`: Documents manifest channel
migration in the messaging summary.
- #5352 -> `docs/about/release-notes.mdx`: Documents persisted agent
preservation through registry recovery in the rebuild and restore
summary.
- #5371 ->
`.agents/skills/nemoclaw-user-reference/references/commands.md`:
Refreshes generated skill output for custom build cache and
layer-ordering source docs.
- #5379 -> `docs/about/release-notes.mdx`: Documents dashboard port
allocation across multiple NemoClaw gateways in the recovery summary.
- #5382 -> `docs/about/release-notes.mdx`: Documents recovery when an
active gateway has no sandbox spec in the recovery summary.
- #5389 ->
`.agents/skills/nemoclaw-user-reference/references/troubleshooting.md`:
Refreshes generated skill output for declared agent `forward_ports`
recovery source docs.
- #5400 -> `docs/about/release-notes.mdx`: Documents bounded compatible
endpoint probes in the inference setup summary.
- #5410 -> `docs/about/release-notes.mdx`: Documents provider credential
hash removal from sandbox registry entries in the messaging summary.
- #5418 -> `docs/about/release-notes.mdx`: Documents summarized
inference validation failures in the onboarding diagnostics summary.
- #5457 -> `docs/about/release-notes.mdx`: Documents context-window
recomputation after runtime model switches in the inference setup
summary.
- #5463 -> `docs/about/release-notes.mdx`: Documents cleanup of
hard-coded messaging channel stragglers in the messaging summary.

## Skipped
- #5366 matched `docs/.docs-skip` entries through skipped experimental
paths, so this PR does not add new release-note text for that commit.

## Type of Change
- [ ] Code change (feature, bug fix, or refactor)
- [ ] Code change with doc updates
- [ ] Doc only (prose changes, no code sample modifications)
- [x] Doc only (includes code sample changes)

## Verification
- [x] Git hooks passed during commit and push, or `npx prek run
--from-ref main --to-ref HEAD` passes
- [ ] Targeted tests pass for changed behavior
- [ ] Full `npm test` passes (broad runtime changes only)
- [ ] Tests added or updated for new or changed behavior
- [x] No secrets, API keys, or credentials committed
- [x] Docs updated for user-facing behavior changes
- [ ] `npm run docs` builds without warnings (doc changes only)
- [x] Doc pages follow the [style
guide](https://github.com/NVIDIA/NemoClaw/blob/main/docs/CONTRIBUTING.md)
(doc changes only)
- [ ] New doc pages include SPDX header and frontmatter (new pages only)

Verification notes:
- `npm run docs` passed after rerunning outside the sandbox. Fern
reported 0 errors and 1 hidden warning.
- The first sandboxed `npm run docs` attempt failed before validation
because `tsx` could not create its local IPC pipe under sandbox
restrictions.
- `npm run build:cli` passed before push to refresh the local `dist/`
artifacts used by the CLI typecheck hook.
- `npm test` was not run because this is a docs-only release refresh.

---
Signed-off-by: Miyoung Choi <miyoungc@nvidia.com>

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Released NemoClaw v0.0.65 with improved gateway/sandbox recovery,
safer day-two workflows, and enhanced Hermes compatibility.
* Added managed vLLM extra-arguments configuration via
`NEMOCLAW_VLLM_EXTRA_ARGS_JSON`.
* Added Hermes troubleshooting guidance for port forwarding and health
checks.

* **Documentation**
* Updated NVIDIA Endpoints/NIM setup and examples to use
`NVIDIA_INFERENCE_API_KEY`.
* Refined NVIDIA network policy and Model Router API base configuration.
* Expanded CLI/environment variable documentation (including sub-agent
gateway connectivity) and plugin build performance tips.

* **Tests**
  * Expanded Vitest-backed E2E release validation coverage.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
@wscurran wscurran added NV QA Bugs found by the NVIDIA QA Team VDR Linked to VDR finding labels Jun 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area: policy Network policy, egress rules, presets, or sandbox policy bug-fix PR fixes a bug or regression integration: hermes Hermes integration behavior NV QA Bugs found by the NVIDIA QA Team VDR Linked to VDR finding

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[All Platforms][Policy&Network] Hermes Balanced baseline unexpectedly applies GitHub preset

3 participants