Skip to content

Bot Screen ships on hosted images via -desktop tags (salvage #112381) - #120914

Merged
teknium1 merged 2 commits into
mainfrom
feat/bot-screen-hosted-image
Sep 24, 2026
Merged

teknium1 merged 2 commits into
mainfrom
feat/bot-screen-hosted-image

Conversation

@teknium1

Copy link
Copy Markdown
Collaborator

Hosted and immutable Hermes deployments get Bot Screen by pulling a -desktop image tag: the published image ships without Xvnc/Xfce and cannot install at run time (unprivileged hermes, no sudo, sealed /opt/hermes), so the image layer is the only delivery path.

Salvage of #112381 by @IAvecilla, which GitHub auto-closed when its base branch merged as #108914; none of it had reached main. Applied onto origin/main with authorship preserved, @pefontana's review fixes included.

Changes

  • docker.yml: variant: [slim, desktop] axis. :latest / :main / :v* are the image they are today; :latest-desktop / :main-desktop / :v*-desktop add the packages and Playwright's headed Chromium. Slim owns the build-cache scope (desktop reads it, writes nothing; the cache is already at the 10 GB cap). One manifest per variant, so a desktop publish failure cannot skip slim's :latest; a short digest set fails the merge instead of publishing a single-arch tag.
  • Dockerfile / docker/stage2-hook.sh: XDG_RUNTIME_DIR=/tmp/hermes-runtime seeded 0700 as hermes at boot (containers have no logind; the $HOME/.cache fallback was the shared /opt/data volume, so two instances would contend for one display lock). Refuses a foreign-owned or symlinked directory rather than chowning it. Deterministic Chromium discovery: the headless shell is exported for ordinary browsing, the headed build exists only on desktop images.
  • tools/bot_desktop: memory gate reads the cgroup working set (memory.current − inactive_file) so it stops tightening over uptime and cannot refuse to restart the screen that idle-stop just stopped; installable() yields three distinct dead-end messages instead of a sudo line nobody on a hosted instance can run; env_for_agent() replaces a headless-shell pin so agent and dock share one Chromium over one --user-data-dir (otherwise Chromium's singleton swallowed the dock's launch into the windowless process).
  • Docs: -desktop tags, measured sizes, and the note that the Cloud provisioner does not select -desktop yet.

Nothing starts at boot; bot_desktop.auto_start stays off. A plain docker build . stays lean.

Validation (live, amd64, both images built from this branch)

Check Result
Lean image no Xvnc; only chromium_headless_shell-1243; 4.06 GB
Desktop image all 10 required binaries resolve as UID 10000; chromium-1243 + shell; 5.45 GB (+1.39 GB)
stage2 boot AGENT_BROWSER_EXECUTABLE_PATH → headless shell; /tmp/hermes-runtime drwx------ 10000:10000
screen start as hermes, --memory=4g Xvnc :20 up, RFB Unix socket published, unprivileged
Start again on a running screen returns status, still one Xvnc (gate guards allocation, not the session)
Agent + dock binary, screen up both resolve to chromium-1243/chrome-linux64/chrome
screen start, --memory=1g refused: "965 MB available of 1024 MB, 1536 MB needed (bot_desktop.min_free_memory_mb)"
Lean image screen start "this host cannot install them: the process is unprivileged and there is no sudo … needs a newer image"
Working set across start+stop, --memory=2g raw memory.current 232→238 MB, gate available 1881→1879 MB: no tightening
Unit test_bot_desktop_{runtime,resources,browser}, tests/docker/, config defaults: 48 passed

Outstanding on the portal side (per @pefontana): the release-target filter must not treat vX-desktop as the fleet's newest tag, and the provisioner must opt in to -desktop for the tier that offers a screen. Neither is in this repo.

Closes #112381 (superseded, same content). Related: #92524.

Infographic

Bot Screen on hosted images

The published image had no Xvnc/Xfce because nothing set the Dockerfile's
HERMES_BOT_DESKTOP argument, and a hosted instance (unprivileged, no sudo,
sealed /opt/hermes) cannot install at run time. The image layer is the only
delivery path.

- docker.yml: variant axis [slim, desktop]. :latest / :main / :v* stay the
  image they are today; :latest-desktop / :main-desktop / :v*-desktop carry
  the packages plus Playwright's headed Chromium. Slim owns the build cache
  scope; one manifest per variant so a desktop publish failure never skips
  slim's :latest.
- Dockerfile / stage2-hook.sh: XDG_RUNTIME_DIR=/tmp/hermes-runtime seeded
  0700 as hermes (containers have no logind; the $HOME/.cache fallback was
  the shared /opt/data volume), refused when foreign-owned; deterministic
  Chromium discovery exporting the headless shell for ordinary browsing.
- bot_desktop: memory gate reads the cgroup working set (usage minus
  inactive_file) so it cannot tighten over uptime and refuse to restart a
  screen idle-stop just stopped; installable() gives three distinct dead-end
  messages instead of a sudo line nobody there can run; env_for_agent
  replaces a headless-shell pin so agent and dock share one Chromium.

Squash of IAvecilla/hermes-agent:bot-desktop-cloud-image (#112381, 13
commits), which GitHub auto-closed when its base branch merged as #108914.
Review fixes from pefontana (cache scope, per-variant merge, red browser
test) are included.

Co-authored-by: pefontana <pefontana@users.noreply.github.com>
@teknium1
teknium1 requested a review from a team September 24, 2026 02:11
@teknium1 teknium1 added the ci-reviewed applied to manually approve dangerous changes label Sep 24, 2026
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 54caf52 — test: allowlist installable()'s sudo probe for the command-r

ℹ️ Info

CI-sensitive file review · View job

PR touches sensitive files, but the ci-reviewed label has been added, approving them.

Sensitive files changed:


debug info

CI timings

CI timings · View report · View job

Wall time 5m26s vs 5m30s (-1.2%). 11 job(s) slower, 8 faster, 2 unchanged.

  • JS & TS checks / JS & TS checks: +60.0s
  • Docs Site / docs-site-checks: -44.0s
  • Python tests / Run tests: +36.0s
  • Rust tests / cargo test (bootstrap installer): +30.0s
  • Desktop core E2E / Desktop core E2E (Linux): -30.0s

… ratchet

installable() asks whether the gateway host can run the package manager at all
(root, or sudo present) so a hosted instance gets 'needs a newer image' instead
of a sudo line it cannot run. The probe is on the control host and never
installs or starts anything.
@alt-glitch alt-glitch added type/feature New feature or request P3 Low — cosmetic, nice to have comp/tools Tool registry, model_tools, toolsets tool/browser Browser automation (CDP, Playwright) area/docker Docker image, Compose, packaging area/config Config system, migrations, profiles sweeper:risk-automation Sweeper risk: may affect CI, automerge, label sync, or maintainer automation sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades sweeper:risk-security-boundary Sweeper risk: may affect sandboxing, auth, credentials, or sensitive data labels Sep 24, 2026
@teknium1
teknium1 merged commit 65d01a7 into main Sep 24, 2026
43 checks passed
@teknium1
teknium1 deleted the feat/bot-screen-hosted-image branch September 24, 2026 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/config Config system, migrations, profiles area/docker Docker image, Compose, packaging ci-reviewed applied to manually approve dangerous changes comp/tools Tool registry, model_tools, toolsets P3 Low — cosmetic, nice to have sweeper:risk-automation Sweeper risk: may affect CI, automerge, label sync, or maintainer automation sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades sweeper:risk-security-boundary Sweeper risk: may affect sandboxing, auth, credentials, or sensitive data tool/browser Browser automation (CDP, Playwright) type/feature New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants