Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
67 commits
Select commit Hold shift + click to select a range
fd5a8a2
fix(hermes): unify WhatsApp session state
sandl99 Aug 4, 2026
d7d2c17
test(hermes): keep session patch cases linear
sandl99 Aug 4, 2026
c3e80d3
refactor(messaging): use runtime manifest for Hermes WhatsApp
sandl99 Aug 4, 2026
2cc4096
fix(build): resolve Hermes runtime preload types
sandl99 Aug 4, 2026
57f4e94
fix(messaging): address runtime preload review
sandl99 Aug 4, 2026
8b2aa86
test(messaging): keep secret scan setup linear
sandl99 Aug 4, 2026
af461ff
test(messaging): always clean secret scan fixtures
sandl99 Aug 4, 2026
02e10e0
test(hermes): repair runtime preload fixtures
sandl99 Aug 4, 2026
ea3a556
Merge branch 'main' into fix/hermes-whatsapp-session-path
apurvvkumaria Aug 4, 2026
a5c3e2b
Merge branch 'main' into fix/hermes-whatsapp-session-path
senthilr-nv Aug 5, 2026
350724e
Merge branch 'main' into fix/hermes-whatsapp-session-path
senthilr-nv Aug 5, 2026
2216e9c
fix(messaging): scope Hermes session preload
apurvvkumaria Aug 5, 2026
5ecaa0c
Merge branch 'main' into fix/hermes-whatsapp-session-path
senthilr-nv Aug 5, 2026
b9f1345
fix(messaging): apply Hermes runtime aliases
apurvvkumaria Aug 5, 2026
8269976
fix(messaging): reject missing Hermes session values
senthilr-nv Aug 5, 2026
1f3bb77
merge(main): refresh PR #8229
senthilr-nv Aug 5, 2026
3e1a70a
merge(main): refresh PR #8229
senthilr-nv Aug 5, 2026
280951d
Merge branch 'main' into fix/hermes-whatsapp-session-path
sandl99 Aug 5, 2026
e994ddc
fix(messaging): reject unsafe runtime preload paths
apurvvkumaria Aug 5, 2026
9ee45be
Merge remote-tracking branch 'origin/main' into codex/pr8229-traversa…
apurvvkumaria Aug 5, 2026
8ea4a4d
test(messaging): cover Hermes session preload wiring
apurvvkumaria Aug 5, 2026
344fbc0
merge(messaging): refresh PR 8229 with main
apurvvkumaria Aug 5, 2026
4fdb936
test(messaging): keep runtime setup harness linear
apurvvkumaria Aug 5, 2026
0634898
merge: refresh PR #8229 with current main
apurvvkumaria Aug 5, 2026
24c4688
fix(messaging): preserve Hermes WhatsApp config integrity
sandl99 Aug 5, 2026
0a3f3fe
test(messaging): keep command route fixture linear
sandl99 Aug 5, 2026
bf7a892
fix(whatsapp): keep Hermes CLI pairing unchanged
sandl99 Aug 5, 2026
2e84a3e
docs(whatsapp): describe dashboard session storage
sandl99 Aug 5, 2026
d309d0e
Merge remote-tracking branch 'origin/main' into fix/hermes-whatsapp-s…
sandl99 Aug 5, 2026
1ff42e8
fix(whatsapp): scope session patch to dashboard
sandl99 Aug 5, 2026
a742997
chore(whatsapp): revert broad session implementation
sandl99 Aug 5, 2026
a7a7f3e
fix(hermes): align dashboard WhatsApp session path
sandl99 Aug 5, 2026
545c490
fix(hermes): pin WhatsApp session base image
sandl99 Aug 5, 2026
1daba19
Merge remote-tracking branch 'origin/main' into fix/hermes-whatsapp-s…
sandl99 Aug 5, 2026
9dcef91
docs(security): record Hermes WhatsApp base image
sandl99 Aug 5, 2026
49fce0a
merge(main): refresh PR #8229
apurvvkumaria Aug 5, 2026
f9c4e82
merge: resolve conflicts with main
github-actions[bot] Aug 6, 2026
4963d1c
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 6, 2026
589c492
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 6, 2026
5401ca9
Merge branch 'main' into fix/hermes-whatsapp-session-path
sandl99 Aug 6, 2026
ea18717
Merge remote-tracking branch 'origin/main' into fix/hermes-whatsapp-s…
apurvvkumaria Aug 6, 2026
3c1f7fd
docs(whatsapp): remove obsolete Hermes session workaround
apurvvkumaria Aug 6, 2026
6d8bb3d
docs(whatsapp): document legacy Hermes re-pairing
apurvvkumaria Aug 6, 2026
8197641
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 6, 2026
868a2cc
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 7, 2026
e879cb3
Merge branch 'main' into fix/hermes-whatsapp-session-path
sandl99 Aug 7, 2026
634d631
Merge branch 'main' into fix/hermes-whatsapp-session-path
sandl99 Aug 7, 2026
96ee9e0
test(docs): align Hermes WhatsApp rendering contract
sandl99 Aug 7, 2026
9060fc6
fix(messaging): update Hermes session recovery hint
apurvvkumaria Aug 7, 2026
e9b1ead
docs(messaging): align Hermes session recovery guidance
apurvvkumaria Aug 7, 2026
cbdf76e
Merge branch 'main' into fix/hermes-whatsapp-session-path
cv Aug 7, 2026
f39d67e
fix(hermes): address WhatsApp review findings
sandl99 Aug 7, 2026
e1dd866
Merge branch 'main' into fix/hermes-whatsapp-session-path
cv Aug 7, 2026
c3f631a
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 7, 2026
fc60ee0
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 7, 2026
3d3ce74
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 7, 2026
b69f733
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 8, 2026
110c16f
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 8, 2026
2ced3af
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 9, 2026
d642cac
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 9, 2026
ef14268
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 9, 2026
33a5fa1
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 10, 2026
6908108
Merge branch 'main' into fix/hermes-whatsapp-session-path
hunglp6d Aug 10, 2026
f4038cd
Merge branch 'main' into fix/hermes-whatsapp-session-path
cv Aug 10, 2026
eda36e8
Merge branch 'main' into fix/hermes-whatsapp-session-path
apurvvkumaria Aug 10, 2026
b84247e
docs(messaging): name the supported cleanup for legacy WhatsApp sessions
hunglp6d Aug 11, 2026
d9a381d
fix(messaging): send the WhatsApp session split through channel removal
hunglp6d Aug 11, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion agents/hermes/Dockerfile
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@
# Layers PR-specific code (plugin, config, startup script) on top of the
# pre-built Hermes base image. Mirrors the OpenClaw Dockerfile structure.

ARG BASE_IMAGE=ghcr.io/nvidia/nemoclaw/hermes-sandbox-base@sha256:57c091ab9b31c924eac0050e66c834c37df875154a254964302a31b119b50b96
ARG BASE_IMAGE=ghcr.io/nvidia/nemoclaw/hermes-sandbox-base@sha256:3d54b928baef9df403227e846f73079d13ca8424a27cd5268ca97bac3f030b27
ARG NEMOCLAW_CORPORATE_CA_B64=
ARG NEMOCLAW_MANAGED_IMAGE_CAPABILITY_UNION=0

Expand Down
18 changes: 16 additions & 2 deletions agents/hermes/whatsapp-proxy.patch
Original file line number Diff line number Diff line change
Expand Up @@ -2,8 +2,22 @@
# SPDX-License-Identifier: Apache-2.0
#
# Routes the pinned Hermes v2026.7.20 WhatsApp bridge through the OpenShell
# proxy. Remove this patch when the minimum supported Hermes release passes
# an HTTPS proxy agent to Baileys natively.
# proxy and keeps dashboard pairing state in the gateway's session directory.
# Remove the web_server.py hunk when the minimum supported Hermes release stores
# Dashboard pairing state in the gateway session directory natively.
# Remove the scripts/whatsapp-bridge hunks when that release routes the WhatsApp
# bridge through HTTPS_PROXY natively.
diff --git a/hermes_cli/web_server.py b/hermes_cli/web_server.py
index d0c78a6b3..5f6d801b5 100644
--- a/hermes_cli/web_server.py
+++ b/hermes_cli/web_server.py
@@ -8110,5 +8110,3 @@ def _normalize_whatsapp_allowed_users(value: Any) -> str:
def _whatsapp_session_path() -> Path:
- from hermes_constants import get_hermes_dir
-
- return get_hermes_dir("platforms/whatsapp/session", "whatsapp/session")
+ return Path("/sandbox/.hermes/platforms/whatsapp/session")

diff --git a/scripts/whatsapp-bridge/bridge.js b/scripts/whatsapp-bridge/bridge.js
index 4b5733d16..22f1ec3e1 100644
--- a/scripts/whatsapp-bridge/bridge.js
Expand Down
33 changes: 17 additions & 16 deletions docs/manage-sandboxes/set-up-whatsapp.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -33,25 +33,22 @@ NemoClaw validates the gateway URL before pairing and renders the WhatsApp QR co
If pairing exits with a gateway close such as `1008`, rerun the login command once, then check `$$nemoclaw <sandbox> channels status --channel whatsapp` to diagnose the gateway and session path separately from QR rendering.
</AgentOnly>
<AgentOnly variant="hermes">
Hermes can pair from the Dashboard profile while the gateway reads the default `platforms/whatsapp/session` path.
After scanning a dashboard QR code, run `$$nemoclaw <sandbox> channels status --channel whatsapp`.
If the report says `dashboard-home has WhatsApp credentials, but the Hermes gateway session path is empty`, point the gateway at the dashboard session with the supported config command:
Hermes dashboard pairing and the gateway share `/sandbox/.hermes/platforms/whatsapp/session`.
After scanning a dashboard QR code, run `$$nemoclaw <sandbox> channels status --channel whatsapp` to confirm that the shared session is available to the gateway.

If `channels status` reports credentials only under the legacy `profiles/dashboard-home` path, the sandbox has credentials from an image that wrote dashboard sessions to that path.
Rebuilding and pairing again writes new credentials to the shared path, but it leaves the legacy credentials in durable state, and sandbox startup treats that copy as migration input.
Clear every WhatsApp session path first with the supported removal command, then re-add the channel:

```bash
$$nemoclaw <sandbox> shields down --reason "repair Hermes WhatsApp session path"
$$nemoclaw <sandbox> config set --key platforms.whatsapp.extra.session_path --value /sandbox/.hermes/profiles/dashboard-home/platforms/whatsapp/session --restart --config-accept-new-path
$$nemoclaw <sandbox> shields up
$$nemoclaw <sandbox> channels remove whatsapp
$$nemoclaw <sandbox> channels add whatsapp
```

Keep Shields down until `config set` finishes, then restore the restrictive posture with `shields up`.
The `--config-accept-new-path` flag lets the command write the `platforms.whatsapp.extra.session_path` configuration key when the generated config does not already contain it.
Dashboard pairing writes session credentials under `profiles/dashboard-home`; this bounded compatibility repair redirects the gateway to that session path while it still reads the default path otherwise.
The repair stays documented until Hermes dashboard pairing state and gateway startup converge on one shared session path; NemoClaw can redirect the configured path but does not rewrite Hermes pairing state.
Before removing the override, run `$$nemoclaw <sandbox> channels status --channel whatsapp` after dashboard pairing and gateway startup and confirm the report no longer shows a dashboard-home session with an empty gateway session path.
Remove the override only after Hermes uses one shared WhatsApp session path for dashboard pairing and gateway startup.
Do not edit `/sandbox/.hermes/.env` or `/sandbox/.hermes/config.yaml` by hand.
Manual edits can cause the Hermes config-integrity guard to reject restart with `hash-mismatch`.
Supervisor quarantine happens after repeated relaunch failures or other integrity failures.
`channels remove` clears `/sandbox/.hermes/platforms/whatsapp`, the dashboard profile session at `/sandbox/.hermes/profiles/dashboard-home/platforms/whatsapp/session`, and the legacy migration source at `/sandbox/.hermes/dashboard-home/platforms/whatsapp/session`.
The sandbox must be running for that cleanup to succeed; `channels remove` refuses to proceed when it cannot reach the sandbox.
Pair again from the dashboard so the credentials are written to `/sandbox/.hermes/platforms/whatsapp/session`.
Rerun `$$nemoclaw <sandbox> channels status --channel whatsapp` and confirm that the gateway session path holds the credentials and that the report no longer lists a `profiles/dashboard-home` session.
</AgentOnly>

## Protect Paired Session State
Expand All @@ -60,9 +57,13 @@ Supervisor quarantine happens after repeated relaunch failures or other integrit
The sandbox stores mutable session credentials in durable `whatsapp` state.
</AgentOnly>
<AgentOnly variant="hermes">
The sandbox stores mutable session credentials in durable `platforms/whatsapp` state for the gateway and `profiles/dashboard-home/platforms/whatsapp` state for Dashboard pairing.
The sandbox stores mutable session credentials in durable `platforms/whatsapp` state for both dashboard pairing and the gateway.
</AgentOnly>
The credentials survive rebuilds without re-pairing.
<AgentOnly variant="hermes">
A sandbox that also holds legacy `profiles/dashboard-home` or `dashboard-home` credentials keeps both copies across a rebuild, because both paths are part of the durable state that a rebuild restores.
Run `$$nemoclaw <sandbox> channels remove whatsapp` to clear every WhatsApp session path, then re-add the channel and pair again.
</AgentOnly>
This is the runtime tradeoff of enabling WhatsApp without a host bridge: a paired sandbox can use that WhatsApp account until you unpair it or clear the durable state.

NemoClaw cannot detect cross-sandbox WhatsApp conflicts the way it does for token-based channels.
Expand Down
4 changes: 3 additions & 1 deletion docs/reference/commands.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -2494,7 +2494,9 @@ For an OpenClaw WhatsApp sandbox, `--channel whatsapp` probes the sandbox to sep
A paired channel with no observed inbound delivery exits non-zero with verdict `idle` so an unhealthy bridge cannot pass as healthy.
The detailed WhatsApp probe stays focused on QR/session runtime diagnostics and does not include rendered-config comparison lines.
For a Hermes WhatsApp sandbox, `--channel whatsapp` probes only whether the default gateway session path and the `profiles/dashboard-home` session path contain `creds.json`.
If the dashboard path has credentials and the gateway path is empty, the report prints the supported `config set` command for the `platforms.whatsapp.extra.session_path` configuration key, including the new-configuration-key opt-in when generated configs do not already contain that key.
If the dashboard path has credentials and the gateway path is empty, the report tells you to run `$$nemoclaw <sandbox> channels remove whatsapp` and then `$$nemoclaw <sandbox> channels add whatsapp`, because a rebuild restores the legacy session instead of dropping it.
Pair again from the dashboard so credentials use `/sandbox/.hermes/platforms/whatsapp/session`.
Rerun `$$nemoclaw <sandbox> channels status --channel whatsapp`.
NemoClaw does not treat a Hermes session file as live inbound-health evidence.

For Telegram, `--channel telegram` probes the sandbox to report the gateway process, Bot API reachability, and inbound delivery alongside the config comparison.
Expand Down
Loading
Loading