Repository navigation
catalog: bump hindsight to 1.0.1 (pin f7a153d) - #120076
Conversation
|
Held for now, not on quality: this pin floors |
|
Correction on the hold above: it was based on a policy we have since corrected. Hermes's 14-day dependency quarantine applies to Hermes's own dependencies only — plugin dependencies follow the plugin's own security policy (maintainer ruling: "plugins dont have to abide by our 14 day rule … Only hermes' dependencies themselves have to"). #118841 had extended the quarantine to plugin installs from any cwd; #120231 reverses that ( So this re-pin is not held on the floor; it lands once the core fix merges (I'll re-run the install probe at the merged SHA and the delta review already read clean). Recommendation for future re-pins, not a requirement: floor on the oldest API-compatible SDK version ( |
|
Updated: re-pinned to The banner is 1200x600 (2:1), served from the pinned raw URL on
|
…licy Hermes's 14-day `[tool.uv] exclude-newer` quarantine applies to Hermes's own dependencies only (uv lock/sync, `hermes update`, LAZY_DEPS extras via `ensure()`). A plugin's declared `python_dependencies` install under the PLUGIN's policy: `install_specs(policy="plugin")` runs uv with `--no-config` from any cwd, still inside the core constraints file. Reverses item 3 of #118841, which ran the uv tier with cwd=<checkout> for every install so the quarantine reached plugin deps from any cwd. That made catalog re-pins floored on a <14-day release uninstallable (#120076: "only hindsight-client<=0.9.2 is available"; #114530 held on the same gate). Maintainer ruling (Teknium): "plugins dont have to abide by our 14 day rule btw. They can have their own security policy on that. Only hermes' dependencies themselves have to. We should recommend that they do this for their plugins and we should give guidance to plugin devs that they should though." - tools/lazy_deps.py: INSTALL_POLICIES ("core" | "plugin"); `_uv_policy_args` replaces `_uv_policy_cwd`; `_venv_pip_install(policy=)` defaults to core (ensure/LAZY_DEPS), `install_specs(policy=)` defaults to plugin. - hermes_cli/plugin_python_deps.py: `resolve()` passes policy="plugin". - Docs: developer guide "Dependency security policy" section, catalog README admission rule 9, AGENTS.md pinning policy — plugin authors are responsible for their deps and strongly recommended to pin upper bounds, floor on the oldest API-compatible version and run their own release quarantine (`uv --exclude-newer` in their CI); operators can set UV_EXCLUDE_NEWER. - Tests: the #118841 cwd test is replaced by two invariants — a plugin install carries `--no-config` and no checkout cwd (red on base), a core lazy install keeps the checkout cwd and no `--no-config`.
…licy Hermes's 14-day `[tool.uv] exclude-newer` quarantine applies to Hermes's own dependencies only (uv lock/sync, `hermes update`, LAZY_DEPS extras via `ensure()`). A plugin's declared `python_dependencies` install under the PLUGIN's policy: `install_specs(policy="plugin")` runs uv with `--no-config` from any cwd, still inside the core constraints file. Reverses item 3 of #118841, which ran the uv tier with cwd=<checkout> for every install so the quarantine reached plugin deps from any cwd. That made catalog re-pins floored on a <14-day release uninstallable (#120076: "only hindsight-client<=0.9.2 is available"; #114530 held on the same gate). Maintainer ruling (Teknium): "plugins dont have to abide by our 14 day rule btw. They can have their own security policy on that. Only hermes' dependencies themselves have to. We should recommend that they do this for their plugins and we should give guidance to plugin devs that they should though." - tools/lazy_deps.py: INSTALL_POLICIES ("core" | "plugin"); `_uv_policy_args` replaces `_uv_policy_cwd`; `_venv_pip_install(policy=)` defaults to core (ensure/LAZY_DEPS), `install_specs(policy=)` defaults to plugin. - hermes_cli/plugin_python_deps.py: `resolve()` passes policy="plugin". - Docs: developer guide "Dependency security policy" section, catalog README admission rule 9, AGENTS.md pinning policy — plugin authors are responsible for their deps and strongly recommended to pin upper bounds, floor on the oldest API-compatible version and run their own release quarantine (`uv --exclude-newer` in their CI); operators can set UV_EXCLUDE_NEWER. - Tests: the #118841 cwd test is replaced by two invariants — a plugin install carries `--no-config` and no checkout cwd (red on base), a core lazy install keeps the checkout cwd and no `--no-config`.
|
Merged — thanks @nicoloboschi. Landed as 2ae5584 ( Proof on merged main (after #120231, plugin deps now follow the plugin's own policy): from a bare venv holding only hermes-agent, One non-blocking note for future bumps: we recommend (not require) the oldest API-compatible floor with an exclusion for the known-broken release (e.g. |
Follow-up to #119767, and the SHA-bump @teknium1 asked for at the end of vectorize-io/hindsight#4640.
shadc75038→f7a153d,version1.0.0→1.0.1.What moved
The two post-handoff fixes from #4640 (vectorize-io/hindsight#4655), ported from your commits rather than reimplemented:
6e1de4850e6) —sync_turnnow clears_session_turnsafter an append retain instead of advancing the watermark to its length. Overwrite mode untouched.cd3de040ab9) —initialize()recordswarning_callback/platform;_start_embedded_daemonroutes the "cannot run as root" notice through the host sink, falling back togateway.warning_notifications.render_notification.hooks:key fromplugin.yaml(the nit —72ee40fa680).A dependency floor, which is the part worth your attention:
hindsight-embed/hindsight-clientnow floor at>=0.10.1instead of>=0.6.1. Our 0.10.0 (on PyPI 2026-09-14 → 09-21) shipped a probe that ranasyncio.runon the caller's thread, clearing its event loop, so the next client call hit an aiohttp session bound to a dead loop andlocal_embeddedfailed outright withTimeout context manager should be used inside a task. Anyone who installed in that window is pinned to the broken release until a floor moves them off it. Fixed in 0.10.1; the floor is what carries the fix to them.One thing you may want to know about the buffer fix
6e1de4850e6also removes a duplicate write we hadn't spotted:on_session_switchflushes the whole buffer under the old document id, so after an append retain it re-shipped turns that were already stored. Our test was pinning that second retain as correct — it now expects one retain per session. The pre-fix bundled copy has the same shape, so it was double-writing on every session switch too.Checks
scripts/validate_plugin_catalog.py plugin-catalog/hindsight.yaml→OK: 1 file(s) validf7a153dis the tip ofvectorize-io/hindsightmain; the plugin at that commit declaresversion: 1.0.1inplugin.yaml, so the catalog label and the manifest agreehermes plugins validatepasses at this commit — our CI runs it againsthermes-agent@mainon every change to the plugin, along with a fullMemoryProviderround-trip (load →is_available→initialize→sync_turn→prefetch→ recall tool →on_session_end) on a real embedded daemon