Skip to content

fix: post-merge audit follow-ups for estop, cron monitor/notepad, delegation batch gate - #81696

Merged
teknium1 merged 1 commit into
mainfrom
hermes/hermes-2091240a
Aug 8, 2026
Merged

teknium1 merged 1 commit into
mainfrom
hermes/hermes-2091240a

Conversation

@teknium1

@teknium1 teknium1 commented Aug 8, 2026

Copy link
Copy Markdown
Collaborator

Summary

Fixes the four fix-forward findings from the adversarial post-merge audit of the Aug 7 unreviewed merge batch (#81138, #81139, #81141, #81148) — no reverts needed, each gap closed in place.

Changes

  • estop / feat(cli): global emergency stop \u2014 /  #81148 (agent/estop.py, gateway/run.py, hermes_cli/commands.py):
    • is_engaged() now fails safe (engaged) on stat errors, matching the module's own corrupt-sentinel doctrine — previously a permission/I/O error silently lifted the pause.
    • The gateway estop gate no longer swallows control traffic: recognized slash commands and replies owned by in-flight work (pending update prompts, clarify, slash-confirm, dangerous-command approvals, running sessions) pass through; only new agent turns get the paused notice.
    • New gateway /pause [reason | off] command — the in-band engage/resume path for messaging-only operators who have no host shell (busy_policy="dispatch" so it works mid-run). Slack routes it via /hermes pause (50-slash cap).
  • cron monitor mode / feat(cron): monitor-mode jobs \u2014 hash-suppressed change detection #81138 (cron/jobs.py): execution-mode invariants (monitor×no_agent, monitor_script×monitor_url, no_agent-requires-script) extracted to one owner _validate_job_mode_invariants() called from both create_job and update_job — flipping no_agent=True on a monitor job via update previously disabled the monitor silently (the scheduler's no_agent short-circuit runs before the monitor gate). Scoped to changed fields so legacy records keep loading; clearing the monitor and flipping no_agent in one update stays valid.
  • cron notepad / feat(cron): per-job durable notepad \u2014 KV scratchpad surviving scheduled runs #81139 (cron/jobs.py, cron/notepad.py): remove_job now calls clear_notepad (it was dead code — deleted jobs orphaned their KV rows in notepad.db forever). Best-effort: a notepad failure never blocks removal, and clearing no-ops without creating the DB.
  • delegation batch gate / feat(delegation): validate batch task quality before spawning children #81141 (tools/delegate_tool.py): template-marker regex narrowed to multi-word placeholder shapes only (<feature_name>, {file path}, <FEATURE-NAME>) — generics (Vec<T>), HTML tags, JSON snippets, glob braces, and f-string style no longer reject legitimate batches. Duplicate-goal rejection removed entirely: identical-goal fan-outs (best-of-N / ensemble sampling) are legitimate.

Validation

Before After
estop stat OSError pause silently lifted stays engaged (fail safe)
/status while paused consumed by paused notice dispatched normally
Messaging-only resume impossible (host shell required) /pause off
cronjob update no_agent=True on monitor job accepted, monitor silently dead ValueError
cronjob remove with notepad rows rows orphaned forever cleared (sibling jobs untouched)
Batch goal Refactor to Vec<T> rejected as "template marker" accepted
Best-of-N duplicate goals rejected accepted

Targeted suites: 133/133 (tests/test_estop.py +5 new, tests/cron/test_monitor_kind.py +5 new, tests/cron/test_notepad.py +3 new, tests/tools/test_delegate_batch_validation.py reshaped, tests/hermes_cli/test_commands.py), plus 549/549 across tests/cron/ + delegate tool suites and 26/26 gateway slash-access/busy suites. E2E with real files in a temp HERMES_HOME: estop roundtrip, regex accept/reject sets, update-path invariant, remove→notepad cleanup.

Infographic

post-merge audit fixes

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
@github-actions

github-actions Bot commented Aug 8, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on c7da396

⚠️ Warnings

CI timings · View report · View job

Wall time 9m1s vs 6m52s (+31.3%). 10 job(s) slower, 11 faster, 2 unchanged.

  • Python tests / Run tests slice 4/12: +20.0s
  • Python tests / Run tests slice 5/12: +17.0s
  • Python tests / Run tests slice 10/12: -17.0s
  • Python tests / Run tests slice 7/12: -13.0s
  • Python tests / Run tests slice 11/12: -9.0s

OSV vulnerability scan · View job

56 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.

@alt-glitch alt-glitch added type/bug Something isn't working P2 Medium — degraded but workaround exists comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cron Cron scheduler and job management comp/gateway Gateway runner, session dispatch, delivery comp/cli CLI entry point, hermes_cli/, setup wizard tool/delegate Subagent delegation sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages labels Aug 8, 2026
@teknium1
teknium1 merged commit 5dc0fa3 into main Aug 8, 2026
86 of 89 checks passed
@teknium1
teknium1 deleted the hermes/hermes-2091240a branch August 8, 2026 12:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cli CLI entry point, hermes_cli/, setup wizard comp/cron Cron scheduler and job management comp/gateway Gateway runner, session dispatch, delivery P2 Medium — degraded but workaround exists sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages tool/delegate Subagent delegation type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants