Skip to content

catalog: bump hindsight to 1.0.1 (pin f7a153d) - #120076

Merged
teknium1 merged 2 commits into
NousResearch:mainfrom
nicoloboschi:catalog/hindsight-1.0.1
Sep 23, 2026
Merged

teknium1 merged 2 commits into
NousResearch:mainfrom
nicoloboschi:catalog/hindsight-1.0.1

Conversation

@nicoloboschi

Copy link
Copy Markdown

Follow-up to #119767, and the SHA-bump @teknium1 asked for at the end of vectorize-io/hindsight#4640.

sha dc75038 → f7a153d, version 1.0.0 → 1.0.1.

What moved

The two post-handoff fixes from #4640 (vectorize-io/hindsight#4655), ported from your commits rather than reimplemented:

  • Bounded append-mode turn buffer (6e1de4850e6) — sync_turn now clears _session_turns after an append retain instead of advancing the watermark to its length. Overwrite mode untouched.
  • Gated root warning (cd3de040ab9) — initialize() records warning_callback / platform; _start_embedded_daemon routes the "cannot run as root" notice through the host sink, falling back to gateway.warning_notifications.render_notification.
  • Dropped the hooks: key from plugin.yaml (the nit — 72ee40fa680).

A dependency floor, which is the part worth your attention: hindsight-embed/hindsight-client now floor at >=0.10.1 instead of >=0.6.1. Our 0.10.0 (on PyPI 2026-09-14 → 09-21) shipped a probe that ran asyncio.run on the caller's thread, clearing its event loop, so the next client call hit an aiohttp session bound to a dead loop and local_embedded failed outright with Timeout context manager should be used inside a task. Anyone who installed in that window is pinned to the broken release until a floor moves them off it. Fixed in 0.10.1; the floor is what carries the fix to them.

One thing you may want to know about the buffer fix

6e1de4850e6 also removes a duplicate write we hadn't spotted: on_session_switch flushes the whole buffer under the old document id, so after an append retain it re-shipped turns that were already stored. Our test was pinning that second retain as correct — it now expects one retain per session. The pre-fix bundled copy has the same shape, so it was double-writing on every session switch too.

Checks

  • scripts/validate_plugin_catalog.py plugin-catalog/hindsight.yaml → OK: 1 file(s) valid
  • f7a153d is the tip of vectorize-io/hindsight main; the plugin at that commit declares version: 1.0.1 in plugin.yaml, so the catalog label and the manifest agree
  • hermes plugins validate passes at this commit — our CI runs it against hermes-agent@main on every change to the plugin, along with a full MemoryProvider round-trip (load → is_available → initialize → sync_turn → prefetch → recall tool → on_session_end) on a real embedded daemon
  • Both behaviour fixes have a regression test, each verified to fail on the pre-fix code

@alt-glitch alt-glitch added type/bug Something isn't working P3 Low — cosmetic, nice to have Plugin Catalog Plugin catalog entries, discovery, metadata, and catalog management tool/memory Memory tool and memory providers labels Sep 23, 2026
@teknium1

Copy link
Copy Markdown
Collaborator

Held for now, not on quality: this pin floors hindsight-client>=0.10.1, whose wheels landed on PyPI 2026-09-21, and Hermes applies a 14-day dependency quarantine to plugin installs (supply-chain rule; now enforced from any cwd). A fresh install of this pin fails with "only hindsight-client<=0.9.2 is available", and the auto-migration would hit the same gate. Two ways forward: (1) widen the floor to the oldest API-compatible SDK, e.g. >=0.6.1,!=0.10.0,<1, keep _MIN_CLIENT_VERSION compatible, re-pin — installs today; or (2) we merge as-is on/after 2026-10-05 when the quarantine lapses. Delta itself reviewed clean (both #4640 fixes carried, no new egress). General rule for future re-pins: floor on the oldest SDK the plugin actually needs, not the newest release.

@teknium1

Copy link
Copy Markdown
Collaborator

Correction on the hold above: it was based on a policy we have since corrected. Hermes's 14-day dependency quarantine applies to Hermes's own dependencies only — plugin dependencies follow the plugin's own security policy (maintainer ruling: "plugins dont have to abide by our 14 day rule … Only hermes' dependencies themselves have to"). #118841 had extended the quarantine to plugin installs from any cwd; #120231 reverses that (install_specs(policy="plugin") → uv --no-config, still inside Hermes's core constraints). Live A/B on this exact pin: base refuses with "only hindsight-client<=0.9.2 is available"; with the fix hermes plugins install vectorize-io/hindsight#hindsight-integrations/hermes --ref f7a153dd… installs hindsight-client 0.10.1 into a fresh venv.

So this re-pin is not held on the floor; it lands once the core fix merges (I'll re-run the install probe at the merged SHA and the delta review already read clean).

Recommendation for future re-pins, not a requirement: floor on the oldest API-compatible SDK version (>=old,!=broken,<1 rather than the release of the week), keep an upper bound, and run your own new-release quarantine in your CI (uv --exclude-newer "14 days") — the catalog README and the plugin developer guide now carry that guidance. Thanks @nicoloboschi, and sorry for the detour.

@nicoloboschi

Copy link
Copy Markdown
Author

Updated: re-pinned to 176f8c2 and added image:.

The banner is 1200x600 (2:1), served from the pinned raw URL on raw.githubusercontent.com — verified http=200, image/png, 1200x600. It's composed from our existing GitHub banner (the source is 5.7:1, so the lockup was re-laid out for 2:1); no new artwork.

scripts/validate_plugin_catalog.py plugin-catalog/hindsight.yaml → OK: 1 file(s) valid, and the plugin's own plugin.yaml at 176f8c2 declares version: 1.0.1, so the card label and the manifest agree.

176f8c2 is dc75038 + the #4640 fixes + the 0.10.1 dependency floor + this banner — nothing else touches the plugin between them.

teknium1 added a commit that referenced this pull request Sep 23, 2026
…licy

Hermes's 14-day `[tool.uv] exclude-newer` quarantine applies to Hermes's own
dependencies only (uv lock/sync, `hermes update`, LAZY_DEPS extras via
`ensure()`). A plugin's declared `python_dependencies` install under the
PLUGIN's policy: `install_specs(policy="plugin")` runs uv with `--no-config`
from any cwd, still inside the core constraints file.

Reverses item 3 of #118841, which ran the uv tier with cwd=<checkout> for
every install so the quarantine reached plugin deps from any cwd. That made
catalog re-pins floored on a <14-day release uninstallable (#120076:
"only hindsight-client<=0.9.2 is available"; #114530 held on the same gate).

Maintainer ruling (Teknium): "plugins dont have to abide by our 14 day rule
btw. They can have their own security policy on that. Only hermes'
dependencies themselves have to. We should recommend that they do this for
their plugins and we should give guidance to plugin devs that they should
though."

- tools/lazy_deps.py: INSTALL_POLICIES ("core" | "plugin"); `_uv_policy_args`
  replaces `_uv_policy_cwd`; `_venv_pip_install(policy=)` defaults to core
  (ensure/LAZY_DEPS), `install_specs(policy=)` defaults to plugin.
- hermes_cli/plugin_python_deps.py: `resolve()` passes policy="plugin".
- Docs: developer guide "Dependency security policy" section, catalog README
  admission rule 9, AGENTS.md pinning policy — plugin authors are responsible
  for their deps and strongly recommended to pin upper bounds, floor on the
  oldest API-compatible version and run their own release quarantine
  (`uv --exclude-newer` in their CI); operators can set UV_EXCLUDE_NEWER.
- Tests: the #118841 cwd test is replaced by two invariants — a plugin install
  carries `--no-config` and no checkout cwd (red on base), a core lazy install
  keeps the checkout cwd and no `--no-config`.
teknium1 added a commit that referenced this pull request Sep 23, 2026
…licy

Hermes's 14-day `[tool.uv] exclude-newer` quarantine applies to Hermes's own
dependencies only (uv lock/sync, `hermes update`, LAZY_DEPS extras via
`ensure()`). A plugin's declared `python_dependencies` install under the
PLUGIN's policy: `install_specs(policy="plugin")` runs uv with `--no-config`
from any cwd, still inside the core constraints file.

Reverses item 3 of #118841, which ran the uv tier with cwd=<checkout> for
every install so the quarantine reached plugin deps from any cwd. That made
catalog re-pins floored on a <14-day release uninstallable (#120076:
"only hindsight-client<=0.9.2 is available"; #114530 held on the same gate).

Maintainer ruling (Teknium): "plugins dont have to abide by our 14 day rule
btw. They can have their own security policy on that. Only hermes'
dependencies themselves have to. We should recommend that they do this for
their plugins and we should give guidance to plugin devs that they should
though."

- tools/lazy_deps.py: INSTALL_POLICIES ("core" | "plugin"); `_uv_policy_args`
  replaces `_uv_policy_cwd`; `_venv_pip_install(policy=)` defaults to core
  (ensure/LAZY_DEPS), `install_specs(policy=)` defaults to plugin.
- hermes_cli/plugin_python_deps.py: `resolve()` passes policy="plugin".
- Docs: developer guide "Dependency security policy" section, catalog README
  admission rule 9, AGENTS.md pinning policy — plugin authors are responsible
  for their deps and strongly recommended to pin upper bounds, floor on the
  oldest API-compatible version and run their own release quarantine
  (`uv --exclude-newer` in their CI); operators can set UV_EXCLUDE_NEWER.
- Tests: the #118841 cwd test is replaced by two invariants — a plugin install
  carries `--no-config` and no checkout cwd (red on base), a core lazy install
  keeps the checkout cwd and no `--no-config`.
@teknium1
teknium1 merged commit 2ae5584 into NousResearch:main Sep 23, 2026
@teknium1

Copy link
Copy Markdown
Collaborator

Merged — thanks @nicoloboschi. Landed as 2ae5584 (plugin-catalog/hindsight.yaml → sha: 176f8c2, version: "1.0.1", image: banner).

Proof on merged main (after #120231, plugin deps now follow the plugin's own policy): from a bare venv holding only hermes-agent, hermes plugins install vectorize-io/hindsight#hindsight-integrations/hermes --ref 176f8c2 into a scratch home installed hindsight-client 0.10.1 + hindsight-embed 0.10.1; plugins validate 13/13, scanner safe. Migration smoke: a scratch home with memory.provider: hindsight and no plugin installed auto-installed the catalog entry at 176f8c2 and enabled it on the first hermes chat.

One non-blocking note for future bumps: we recommend (not require) the oldest API-compatible floor with an exclusion for the known-broken release (e.g. >=0.6.1,!=0.10.0,<1) rather than flooring on the release of the week — it keeps older installs resolvable while still fencing off the bad wheel.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P3 Low — cosmetic, nice to have Plugin Catalog Plugin catalog entries, discovery, metadata, and catalog management tool/memory Memory tool and memory providers type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants