Conversation
# Conflicts: # tests/hermes_cli/test_desktop_exe_integrity.py
|
Thanks for extending the existing Windows post-build gate rather than changing the deliberate Suggested changes
The implementation otherwise fits the existing rollback gate: it validates both the newly built package and the backup before restoration. This is an automated hermes-sweeper review. |
SummaryThree PRs address or reference this issue complex across two related Windows failure modes. #69234 adds pack-time PE architecture validation for the corrupted or wrong-architecture executable reported in #69179; #70976 removes the deliberate Windows executable-editing configuration; #71523 extends the existing gate to validate the Electron application payload implicated by #70825's help-text symptom. Related pull requests
DuplicatesNo substantive duplicates: #69234 covers PE architecture, #70976 proposes a build-configuration change, and #71523 covers the packaged Electron payload and rollback gate. Suggested consolidationKeep #71523 open with a salvage path: preserve its payload and rollback checks, then add the branch-level regression coverage requested by the maintainer-bot keep_open review. Keep #69234 and #70976 closed rather than merging them: #69234 is superseded by the recovery implementation recorded in the #69179 discussion via #71119 and #71218, while #70976 conflicts with the documented deliberate local-rebuild configuration; no PR is merge-lane eligible here. Complex graphflowchart LR
classDef open fill:#dbeafe,stroke:#1d4ed8,color:#1e3a8a
classDef merged fill:#dcfce7,stroke:#15803d,color:#14532d
classDef closed fill:#e5e7eb,stroke:#6b7280,color:#1f2937
classDef unverified fill:#f3f4f6,stroke:#9ca3af,color:#374151
classDef best stroke-width:3px,stroke:#b45309
classDef target stroke-width:3px,stroke:#4338ca
I70825(["issue #70825 (open)"])
P71523["PR #71523 (open)"]
P71523 -->|best fix| I70825
class I70825 open
class P71523 open
class P71523 best
class P71523 target
click I70825 "https://github.com/NousResearch/hermes-agent/issues/70825"
click P71523 "https://github.com/NousResearch/hermes-agent/pull/71523"
Graph: solid arrow = fixes / best fix, dashed arrow = partial or unverified (see edge label); boxed group = PRs duplicating each other; amber border = best fix; indigo border = target; gray node = closed (state tag in the node label). Cross-PR triage: Reviewed 3 pull requests and 2 issues in this complex. Each diff was read against this issue; Assessment working set: 14 kB of PR diffs, 14 kB of issue/PR text, 9 kB of discussion (6 comments), 4 verify verdicts. verdicts reflect diff content, not PR titles. Part of an automated triage batch. |
Summary
resources/app.asar, missing archive entry metadata, or missing unpacked runtime entry files before the update is stamped or launched;signAndEditExecutable: falseconfiguration and its directrceditbranding path.Fixes #70825.
Root cause
A structurally valid
Hermes.execan still launch Electron's help screen when its packaged application is absent. The existing #71119 gate validates the PE header, architecture, and truncation, but it cannot detect the reporter's second failure shape: a 176-byteapp.asarwith no usable package entry point.signAndEditExecutableis not the app archive builder and remains intentionally disabled to avoid electron-builder's winCodeSign extraction path. The missing invariant was package validation after the build.Validation performed
The gate now requires:
resources/app.asar;package.jsonandelectron-main.mjsentry metadata in the ASAR header;app.asar.unpacked/dist/electron-main.mjsanddist/index.html, matching the committedasarUnpack: ["dist/**"]contract.Verification
main: a valid PE with a five-byte app archive was accepted;py_compile, Windows-footgun scan, andgit diff --check: clean.