Repository navigation
Config hooks and outbound webhooks fire for external-worker cron jobs (salvage #131831) - #132438
Merged
kshitijk4poor merged 2 commits intoOct 3, 2026
Merged
kshitijk4poor merged 2 commits into
kshitijk4poor merged 2 commits into
Conversation
… worker The restart-safe external worker (python -m cron.scheduler --external-worker-file) called discover_plugins() under the payload's home override but never agent.shell_hooks.register_from_config() nor agent.outbound_webhooks.register_from_config(), so hooks: blocks in the owning profile's config.yaml silently stopped firing for cron sessions once gateway fires were handed to the worker instead of running in-process. Plugin hooks kept working, which made the gap invisible. Register both right after plugin discovery + secret hydration, under the same home override, with the gateway's never-raise shape (NousResearch#102504): consent resolves non-interactively from the owning profile's allowlist / HERMES_ACCEPT_HOOKS / hooks_auto_accept, and a broken hooks block logs a warning instead of taking the cron execution down. Fixes NousResearch#131764 (cherry picked from commit d1971c6)
…cret scope The external worker now calls GatewayStartupMixin._register_config_hooks (the helper gateway startup and each multiplexed profile already use) instead of a copied load_config/register_from_config sequence, and calls it after set_secret_scope rather than before. Registered outside the scope, a hooks.outbound target with secret_env hits get_secret with no scope while multiplexing, which raises UnscopedSecretError; the never-raise guard swallowed it, so that profile's outbound webhooks were silently dropped again. Both registries are idempotent per (home, event, ...) so a worker running several payloads registers each hook once. The kept test gains a secret_env target on a multiplexed payload to pin the ordering; the broken-config test is dropped (register_from_config never raises on a malformed block, and the helper's guard is already covered by the gateway path). Refs NousResearch#131764
kshitijk4poor
enabled auto-merge (rebase)
October 3, 2026 20:16
This was referenced Oct 3, 2026
1 task
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Cron jobs run by the restart-safe external worker now fire the profile's config
hooks:(shell hooks andhooks.outboundwebhooks), the same as jobs run in-process.Fixes #131764
What happened
The external cron worker (
cron/scheduler.py::_run_external_worker_payload, added in #101940) discovered plugins (since411c0405b6) but never registered config hooks, sohooks:andhooks.outboundsilently did nothing for worker-run jobs while plugin hooks still fired — which hid the gap.Change
cron/scheduler.py::_run_external_worker_payload: after plugin discovery and inside the payload's home override and secret scope, call the gateway's ownGatewayStartupMixin._register_config_hooks(the helper the gateway uses per profile at startup). Registration happens once per worker process; both registries are keyed per home and idempotent.tests/cron/test_external_worker_config_hooks.py(new): a multiplexed payload registers the owning profile's shell hook and asecret_envoutbound webhook under that profile's home key.Credit
@liuhao1024 (#131831, draft) — commit
7c3dc30b57cherry-picked with authorship kept (-x d1971c698a). Our follow-up018d9130a1reuses the gateway helper instead of a copied registration sequence and moves registration inside the secret scope: in the original ordering, an outbound webhook withsecret_envraisedUnscopedSecretErroron a multiplexed gateway and was silently dropped.@drafie found the same gap first in #119421 (shell hooks only).
Verification
_run_external_worker_payload, 2 payloads per workerhooks:(neighbour), main and branchgateway.run_startupimport in the one-shot worker: 2–3 ms (does not importgateway.run).Independent review: correctness, tests/probe/mutation, reuse, quality and efficiency passes approved.
Maintainer notes
register_config_hooks()shared withcli.pyandhermes_cli/main.py, which hand-write the same sequence.tui_gateway/server.pyre-registers shell hooks per session but not outbound webhooks — separate, out of scope here._run_external_worker_payload.