fix(update): dependency sync works on pip/site-packages installs — stale VIRTUAL_ENV no longer crashes uv (salvage #83434) - #92824
Merged
Merged
Conversation
…ENV is stale When Hermes is installed via pip / site-packages (e.g. the Windows installer), PROJECT_ROOT is the interpreter's site-packages directory and PROJECT_ROOT/venv is never created. The update and interrupted-install recovery paths still set VIRTUAL_ENV=PROJECT_ROOT/venv, so uv fails with 'Failed to inspect Python interpreter from active virtual environment' before installing anything — leaving the install partially updated. Detect the nonexistent VIRTUAL_ENV in the shared dependency-install helper and pin uv to the running interpreter (uv pip install --python sys.executable) instead, matching the fix already applied to lazy-deps (#83335) and the ZIP update path (#71510).
- _is_uv_command: detect 'python -m uv'/'python -m uvx' and launcher wrappers, not just a uv basename (review: naive check missed module form) - _insert_python_pin: never duplicate a caller-supplied --python (review: last-wins ambiguity) - _interpreter_scripts_dir: when pinning to sys.executable on Windows with no project venv, quarantine the running interpreter's Scripts dir so the hermes.exe shims uv rewrites are actually unlocked (review: quarantine path diverged from pinned interpreter) - tests: rewritten to repo English convention; added python -m uv, --python-guard and Windows quarantine-target cases (5 total)
Sibling-test blast radius from #92617: the salvaged fixture's fake _run_quarantined_install predates the strict_quarantine kwarg the update sync now passes.
૮ >ﻌ< ა ci reviewran on 3ca84dc — fix: derive the pinned interpreter's Scripts dir via venv_bi
|
teknium1
force-pushed
the
hermes/hermes-83bfdb1e
branch
from
August 23, 2026 09:01
b10bbaf to
76c7343
Compare
…6105 lint) The salvaged _interpreter_scripts_dir hand-rolled the Scripts/bin layout, which the AST lint-test in test_update_zip_two_phase forbids — route it through the canonical hermes_constants.venv_bin_dir instead, with the interpreter's own dir as fallback for non-venv layouts.
This was referenced Aug 23, 2026
teknium1
added a commit
that referenced
this pull request
Aug 23, 2026
The salvaged fix covered the git-path sync; the same raw-os.environ construction existed at the main update path and the interrupted-install recovery path. All three now build their uv env via managed_python_env() (#83914 class — same bug, all sites). A/B-proven with real uv: poisoned UV_PYTHON/UV_SYSTEM_PYTHON steers the merge-base construction into the hijacker's interpreter (VERDICT: HIJACKED); the managed construction installs into the install's venv (VERDICT: ISOLATED). Compose-checked with #92824's stale-VIRTUAL_ENV pin: isolation + pin together install into the running interpreter on the site-packages shape.
melon-xf
added a commit
to melon-xf/hermes-agent
that referenced
this pull request
Sep 3, 2026
The salvaged fix covered the git-path sync; the same raw-os.environ construction existed at the main update path and the interrupted-install recovery path. All three now build their uv env via managed_python_env() (NousResearch#83914 class — same bug, all sites). A/B-proven with real uv: poisoned UV_PYTHON/UV_SYSTEM_PYTHON steers the merge-base construction into the hijacker's interpreter (VERDICT: HIJACKED); the managed construction installs into the install's venv (VERDICT: ISOLATED). Compose-checked with NousResearch#92824's stale-VIRTUAL_ENV pin: isolation + pin together install into the running interpreter on the site-packages shape.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
hermes update's dependency sync no longer crashes on pip/site-packages installs — when the exportedVIRTUAL_ENVpoints at the nonexistentPROJECT_ROOT/venv(which is never created on those installs), the shared install helper now drops the stale pointer and pins--python sys.executable, so uv installs into the running interpreter instead of refusing with "Failed to inspect Python interpreter from active virtual environment" (salvage of #83434 by @mrmixx-max).Same bug class already fixed piecemeal at two other sites (#71510 ZIP path, #83335 lazy-deps); this closes the shared helper that the main update path, interrupted-install recovery, and git update path all route through.
Changes
hermes_cli/main.py(@mrmixx-max, 2 commits): stale-VIRTUAL_ENVdetection in_install_python_dependencies_with_optional_fallback;_is_uv_command(handlespython -m uvand launcher wrappers, not just basename);_insert_python_pin(caller-supplied--pythonwins); Windows shim quarantine retargeted at the pinned interpreter's real Scripts dir (quarantining the nonexistent venv's dir would leave the runninghermes.exelocked — the original bug in a different coat).strict_quarantinekwarg the update sync passes since fix(update): a contended Windows venv is never mutated — failed shim quarantine refuses instead of warning (#87331) #92617 (sibling-test blast radius).Validation
test_cmd_update.pyfailure setVERDICT: CRASHED("Failed to inspect Python interpreter…" propagated from real uv) · Phase B PR head, identical scenario →VERDICT: INSTALLED(package imports from the pinned interpreter)cwd/.venvwhen one exists; the repro was corrected to the true site-packages layout (no.venvunder PROJECT_ROOT), where the bug fires 100%. The gate catching an imprecise repro is the gate working.Phase-2 salvage queue item 2 (#91277).
Infographic