fix(update): hermes update no longer hangs on a GitHub username prompt during outages (salvage #73751, #101421) - #101557
Merged
Merged
Conversation
GitHub answers anonymous fetches with HTTP 401 during outages (and for renamed/private repos). git then prompts `Username for 'https://github.com':` on the inherited terminal and `hermes update` sits there — users read it as Hermes demanding a GitHub login. Every network git call in the updater (fetch/pull/push, apply + --check + fork sync) now runs with GIT_TERMINAL_PROMPT=0 / stdin=DEVNULL, so the 401 fails fast into the fetch-failure classifier, which now reports it as a GitHub-side rejection (likely outage) rather than blaming the user's credentials. Credential helpers/askpass are left configured so private-fork origins still authenticate. Live repro: PTY-attached update --check against a 401 origin hung 15s+ on the prompt before; exits rc=1 in 0.2s with the diagnosis after. Same class as #73751 (@Frowtek, pre-main.py decomposition); passive banner half salvaged from #101421 (@RobbertC5).
૮ >ﻌ< ა ci reviewran on 0d116bc — chore: map contributor email for RobbertC5
|
This was referenced Sep 2, 2026
13 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
hermes updateno longer hangs onUsername for 'https://github.com':when GitHub answers the anonymous fetch with HTTP 401 (outages, renamed/private repos); it fails fast with a GitHub-side diagnosis instead of looking like Hermes demands a GitHub login.Root cause: the updater's
git fetch/pull/pushcalls inherited the interactive terminal, so a 401 made git prompt for credentials and block forever. The passive banner probe (ls-remote/ background fetch) had the same gap.Same class as #73751 by @Frowtek (pre-dates the
main.py→update_cmd.pydecomposition, no longer applies); passive-banner half salvaged from #101421 by @RobbertC5 (cherry-picked, authorship preserved).Changes
hermes_cli/update_cmd.py:_no_prompt_git_kwargs()(GIT_TERMINAL_PROMPT=0,GCM_INTERACTIVE=Never,stdin=DEVNULL) applied to all 7 network git calls (apply path fetch,--checkupstream/origin fetches, fork-sync fetch/pull/push). Credential helpers / askpass are left configured so private-fork origins still authenticate._classify_fetch_failure:could not read Username/terminal prompts disablednow reports "GitHub rejected the anonymous fetch — usually an outage" instead of "check your git credentials".hermes_cli/banner.py(@RobbertC5): passive_upstream_main_sha+_check_via_local_gitfetch run undernoninteractive_git_env().fetch/pull/pushsubprocess.runin the updater spreads the no-prompt kwargs (sabotage-verified: fails when one site is stripped).Validation
Live A/B — real
_cmd_update_check()under a controlling PTY against a local origin returning HTTP 401:→ Fetching from origin...thenUsername for 'http://…':— hung 15s+ (killed)✗ GitHub rejected the anonymous fetch (asked for a login) — this usually means a GitHub outage; try again in a few minutes (https://www.githubstatus.com). If it persists, check git remote -v points at a public repo.+ raw git linetests/hermes_cli/test_update_fetch_failure_classifier.py test_noninteractive_git.py test_update_check.py: 25 passed. ruff clean.Infographic