Skip to content

fix(update): hermes update no longer hangs on a GitHub username prompt during outages (salvage #73751, #101421) - #101557

Merged
teknium1 merged 3 commits into
mainfrom
hermes/hermes-3a3bfa9e
Sep 2, 2026
Merged

teknium1 merged 3 commits into
mainfrom
hermes/hermes-3a3bfa9e

Conversation

@teknium1

@teknium1 teknium1 commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator

Summary

hermes update no longer hangs on Username for 'https://github.com': when GitHub answers the anonymous fetch with HTTP 401 (outages, renamed/private repos); it fails fast with a GitHub-side diagnosis instead of looking like Hermes demands a GitHub login.

Root cause: the updater's git fetch/pull/push calls inherited the interactive terminal, so a 401 made git prompt for credentials and block forever. The passive banner probe (ls-remote / background fetch) had the same gap.

Same class as #73751 by @Frowtek (pre-dates the main.py → update_cmd.py decomposition, no longer applies); passive-banner half salvaged from #101421 by @RobbertC5 (cherry-picked, authorship preserved).

Changes

  • hermes_cli/update_cmd.py: _no_prompt_git_kwargs() (GIT_TERMINAL_PROMPT=0, GCM_INTERACTIVE=Never, stdin=DEVNULL) applied to all 7 network git calls (apply path fetch, --check upstream/origin fetches, fork-sync fetch/pull/push). Credential helpers / askpass are left configured so private-fork origins still authenticate.
  • _classify_fetch_failure: could not read Username / terminal prompts disabled now reports "GitHub rejected the anonymous fetch — usually an outage" instead of "check your git credentials".
  • hermes_cli/banner.py (@RobbertC5): passive _upstream_main_sha + _check_via_local_git fetch run under noninteractive_git_env().
  • Tests: classifier case for the 401 shape; one invariant test that every fetch/pull/push subprocess.run in the updater spreads the no-prompt kwargs (sabotage-verified: fails when one site is stripped).

Validation

Live A/B — real _cmd_update_check() under a controlling PTY against a local origin returning HTTP 401:

Before (origin/main) After
Behavior → Fetching from origin... then Username for 'http://…': — hung 15s+ (killed) exits rc=1 in 0.2s
Message (prompt) ✗ GitHub rejected the anonymous fetch (asked for a login) — this usually means a GitHub outage; try again in a few minutes (https://www.githubstatus.com). If it persists, check git remote -v points at a public repo. + raw git line

tests/hermes_cli/test_update_fetch_failure_classifier.py test_noninteractive_git.py test_update_check.py: 25 passed. ruff clean.

Infographic

hermes update no longer hangs on a login prompt

RobbertC5 and others added 3 commits September 2, 2026 12:13
GitHub answers anonymous fetches with HTTP 401 during outages (and for
renamed/private repos). git then prompts `Username for 'https://github.com':`
on the inherited terminal and `hermes update` sits there — users read it as
Hermes demanding a GitHub login.

Every network git call in the updater (fetch/pull/push, apply + --check +
fork sync) now runs with GIT_TERMINAL_PROMPT=0 / stdin=DEVNULL, so the 401
fails fast into the fetch-failure classifier, which now reports it as a
GitHub-side rejection (likely outage) rather than blaming the user's
credentials. Credential helpers/askpass are left configured so private-fork
origins still authenticate.

Live repro: PTY-attached update --check against a 401 origin hung 15s+ on
the prompt before; exits rc=1 in 0.2s with the diagnosis after.

Same class as #73751 (@Frowtek, pre-main.py decomposition); passive banner
half salvaged from #101421 (@RobbertC5).
@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 0d116bc — chore: map contributor email for RobbertC5

⚠️ Warnings

OSV vulnerability scan · View job

28 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.


debug info

CI timings

CI timings · View report · View job

Wall time 4m21s vs 4m17s (+1.6%). 5 job(s) slower, 8 faster, 1 unchanged.

  • Python tests / e2e: -47.0s
  • Python tests / Run tests: -23.0s
  • OS-specific tests / Windows-only tests: +8.0s
  • Python lints / ruff enforcement (blocking): +5.0s
  • Python lints / Windows footguns (blocking): +5.0s

@alt-glitch alt-glitch added type/bug Something isn't working comp/cli CLI entry point, hermes_cli/, setup wizard area/install-update Installer, updater, packaging, wheels, doctor P2 Medium — degraded but workaround exists sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades labels Sep 2, 2026
@teknium1
teknium1 merged commit 30b83ab into main Sep 2, 2026
41 checks passed
@teknium1
teknium1 deleted the hermes/hermes-3a3bfa9e branch September 2, 2026 19:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/install-update Installer, updater, packaging, wheels, doctor comp/cli CLI entry point, hermes_cli/, setup wizard P2 Medium — degraded but workaround exists sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants