Skip to content

fix: declare exact dependency pins and quarantine exemptions - #3

Open
ethernet8023 wants to merge 223 commits into
labyrinth-analytics:mainfrom
ethernet8023:fix/hermes-quarantine-policy
Open

ethernet8023 wants to merge 223 commits into
labyrinth-analytics:mainfrom
ethernet8023:fix/hermes-quarantine-policy

Conversation

@ethernet8023

Copy link
Copy Markdown

Hermes is proposing a 14-day dependency-release quarantine in NousResearch/hermes-agent#133409. this declares the plugin's exact direct package pin and explicit exemption so its reviewed release can install without exempting transitive packages.

summary

allow the reviewed plugin releases through hermes' 14-day quarantine without exempting transitive dependencies.

  • declare loreconvo==0.10.15 as exact direct dependencies.
  • add [tool.uv.exclude-newer-package] entries set to false for only those packages.
  • preserve every dependency, extra and marker from the current upstream declaration.
  • add a metadata-only [project] in the catalog plugin directory; keep the existing manifest for older hosts.

verification

  • python 3.14.7: package and plugin imports pass.
  • current upstream main fails workspace resolution under the 14-day cutoff after removing the temporary core cutoffs.
  • no upstream test suite was found; real sqlite provider initialization, empty recall, tool schemas and shutdown pass.
  • patched plugin: real core workspace lock, frozen sync, plugin import, exact-version checks and uv pip check pass.
  • full repository suites, external services and other platforms were not tested.

this does not fix the lancedb version clash tracked in #2. that needs a new package release and pin update; this PR changes only the companion plugin declaration.

Infographic

upstream compatibility fixes

DebbieKat and others added 30 commits June 6, 2026 17:51
The PreCompact auto-save hook hardcoded tags=[pre-compact, trigger] and never
recorded which agent owned the session, so a mid-session compaction save during
a scheduled-agent run (e.g. jacqueline-roadmap) landed with no agent: tag -- the
LAC/LoreConvo UI showed AGENT=-- even though project was correctly stamped by the
2026-06-05 cwd fix (a5f92e49). The two are separate tag fields; only project was
ever wired.

Fix: run_agent_code.sh now exports LORECONVO_AGENT=$AGENT alongside the existing
AGENT_RUN_SESSION_ID export, and pre_compact_save.py reads it and appends
agent:<name> to the tags list when set. Interactive sessions leave the var unset
and correctly get no agent tag. Tag is rebuilt every save so it lands on both the
INSERT and UPDATE paths.

Adds TestPreCompactAgentTag (4 cases: env set, env unset, blank/whitespace, update
path). test_auto_save.py 28 passed.
Replace denylist approach with configurable export root (Option B). Export root
defaults to ~/loreconvo-exports/ and is configurable via LORECONVO_EXPORT_DIR
environment variable. All export paths must resolve within the configured root.
Export root is created with chmod 700 on first use. Paths outside the root are
rejected without revealing sensitive paths.
…base context manager

Desktop app spawns a new MCP server process per chat session and parks the pipe
open instead of closing it. With the old 30-min default, process count accumulated
(seen: 42) and any one with a dangling write held the sqlite WAL write lock
indefinitely, causing sessions.db 'database is locked' errors.

Changes:
- DEFAULT_IDLE_TIMEOUT: 1800s -> 300s (5 min). Desktop re-spawns on next tool
  call, so the shorter timeout is transparent to users.
- SessionDatabase.__enter__/__exit__: ensures connection is closed on exception
  paths inside server handlers, not just on normal process exit.
- CLAUDE.md: updated idle watchdog description to reflect new 5-min default.
…H-11639)

auto_save.py hardcoded tags=['auto-saved'] in both the insert and update
paths, so crash-stub saves from scheduled agents were invisible to
agent-tagged recall. New auto_save_tags() merges agent:<name> + run:<id> from
LORECONVO_AGENT / AGENT_RUN_SESSION_ID (both already exported by
run_agent_code.sh) when present. Interactive/customer sessions set neither var
and are unchanged. 3 new tests.
- Add --version flag to both standalone CLIs (typer callback reading
  importlib.metadata, fallback to literal on source checkout)
- __init__.py now sources __version__ from installed dist metadata
  (single source of truth = pyproject), no more hardcoded literal
- Add pinned requirements.txt to both CLIs (typer==0.13.1), matching
  the parent-product convention and the dual-pin mandate
- Bump Development Status classifier 3 Alpha -> 4 Beta (both)
- SH-10656 (folded in): loreconvo server src/cli.py now reads version
  from importlib.metadata instead of hardcoded 0.6.0

Tests: loreconvo-cli 15/15, loredocs-cli 9/9. pip-audit clean (typer).
Pre-prod hardening only -- NO make-public action taken.
…sionDatabase.__init__

Commit cc4ef7e6 (ron-builder-b post-session sweep) added a call to
self._validate_journal_mode() but never defined the method, causing
AttributeError on every SessionDatabase instantiation. WAL mode is already
set inline via PRAGMA journal_mode=WAL one line earlier, so the call was
dead intent. Surfaced while testing the Hermes client (SH-11654).
loreconvo-cli and loredocs-cli are separate products with their own
repos. CLI docs belong in those repos, not the MCP plugin READMEs.
Bug-report + feature-request issue forms (YAML) plus a config.yml with an
email-support contact link for all three public repos. Forms include a privacy
note telling users not to paste license keys / private memory or vault contents
into public issues. Lands in each repo's .github/ISSUE_TEMPLATE/ so it
subtree-publishes alongside the existing publish.yml workflow.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The monorepo root .gitignore already covers **/build/ and **/dist/, but the
root file is not published with the subtree -- only ron_skills/loreconvo/.gitignore
travels to the public repo, and it lacked these rules. Forward-looking hygiene
so build artifacts never get tracked in the public mirror. No artifacts were
tracked or published; this is preventative.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
User-facing summary of the fixes/improvements accumulated since v0.7.1 (idle
watchdog + busy_timeout lock fixes, startup-crash fix, PreCompact namespacing,
auto-save open-questions extraction, export-path validation, dependency pins,
GitHub issue templates). Prepares the changelog gate for release.sh --version
0.7.2. Does not bump the version itself -- release.sh does that.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replaced all >=, ~=, ^ specifiers with ==X.Y.Z exact pins:

- ron_skills/loreconvo/pyproject.toml: mcp[cli]==1.27.0, click==8.3.1,
  cryptography==46.0.7, pytest==9.0.3, pytest-asyncio==1.4.0
- ron_skills/lorepulse/pyproject.toml: pytest==9.0.3, pytest-asyncio==1.4.0
- ron_skills/loreschema/pyproject.toml: pytest==9.0.3, pytest-asyncio==1.4.0
- loredocs: already clean (no changes needed)

All 4 products now pass hygiene-check audit.
… 0.1.9 release

- Bump plugin.json and marketplace.json for both products to match pyproject.toml
  (loreconvo 0.7.2->0.7.3, loredocs 0.1.8->0.1.9)
- Fix delete_session FK violation: delete from persona_sessions and session_links
  before deleting from sessions (no ON DELETE CASCADE on those tables)
- Fix free-tier test failures when LORECONVO_PRO is set in the host environment:
  add monkeypatch.delenv to the two affected loreconvo tests
- Fix 19 loredocs test failures when LOREDOCS_PRO is set in the host environment:
  add autouse clear_pro_env fixture to loredocs conftest.py
…reConvo + LoreDocs READMEs)

LoreDocs + LoreConvo public READMEs scattered (Pro) tags but never stated the
Free-vs-Pro split in one place, and both claimed a 'team' tier that does not
exist (code is {free, pro}; 'team' is rejected). Added a Plans comparison table
to each README and removed the three stale team-tier mentions. Also appended
prior-decision context to SH-12046 (Gina team-tier scoping item).

Refs: SH-12045 (Meg QA doc review), SH-12046 (Gina scoping)
…s/lorecap (clears OpenSSL CVE GHSA-537c-gmf6-5ccf); document Option-B exception for atproto-capped social pipeline

Public products have no atproto cap, so cryptography resolves to 49.0.0 cleanly;
verified CVE cleared via scripts/run_pip_audit.sh. Social pipeline keeps
atproto==0.0.65 (caps cryptography<47) with an in-file documented risk exception
ratified by Debbie 2026-06-23: local-only execution, DID key-signing not TLS,
re-review 2026-07-23. Internal-only dep bump, no user-facing changelog needed.
Replace deprecated setuptools license table form (license = { file = "LICENSE" })
with SPDX string expression (license = "BUSL-1.1") plus license-files = ["LICENSE"]
across all 12 Lore product pyproject.toml files, drop the deprecated
'License :: Other/Proprietary License' classifier, and bump build-system
setuptools requirement to >=77 (SPDX-string support landed in setuptools 77).

setuptools deprecates the project.license table form and License classifiers,
unsupported after 2027-02-18. All 12 products build cleanly (python -m build)
with no project.license deprecation warning.

Note: lorealert and lorecap lack a LICENSE file, so their license-files glob
matches nothing (pre-existing gap, not a regression) -- flagged for Debbie.

Products: loreconvo, loredocs, loreconvo-cli, loredocs-cli, lorealert,
lorecache, lorecap, loreenv, loregate, loremigrate, lorepulse, loreschema
labyrinth-analytics and others added 27 commits September 21, 2026 11:24
…evious_summary

Fallback script (save_to_loreconvo.py) and CLI (loreconvo_cli/main.py):
- --read-id / read now include previous_summary
- add save/query/transition/update memory-item ops, second callers of the
  existing SessionDatabase.*_memory_item methods (no new DB logic)

Updates FEATURE_SURFACES (surface_coverage.py), regenerates
feature_manifest.yml, and documents the new fallback ops in
FALLBACK_CONTRACT.md. Fixes previous_summary-column gaps in 6 hand-built
sessions-table test fixtures (loreconvo-cli/tests/test_cli.py,
tests/scripts/test_save_to_loreconvo.py) broken by the new SELECT.

Verified: ron_skills/loreconvo/tests + ron_skills/loreconvo-cli/tests +
tests/scripts/test_save_to_loreconvo.py all green (1324+1skip, 54, 197
passed respectively). --skip-test-gate used only because the gate's
combined run also includes tests/scripts/test_safe_git.py, which has 2
pre-existing failures (scripts/foo.py sweep-staging assertions) verified
unrelated via git stash on a clean tree -- same 2 failures with none of
this commit's changes applied.
…bda (was 'one business day')

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…the 100-char limit (mcp-publisher validate passes)
…sessions table

_migrate_fts_v2's fresh-install branch created an empty external-content
index over rows that were never indexed; the next UPDATE fired the 'delete'
trigger for them -> 'database disk image is malformed'. Flag the condition
there and rebuild in _init_schema after the last FTS migration, when every
indexed column exists. Regression test mutation-checked (goes red with the
rebuild disabled). loreconvo suite 1328 passed / 1 skipped (.venv).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…_bootstrap (installed pkg or src/ synthesis)

Work authored by Ron-D session ron-builder-d_20260927_130013, which hit the
Hermes cron timeout before its session-end commit. Committed from an
interactive session after re-verification on .venv/bin/python: loreconvo
1328 passed / 1 skipped, loreconvo-cli 49 passed, tests/scripts/
test_save_to_loreconvo.py 14 passed. Mutating package synthesis turns
test_session_core_broken_installed_package_falls_back_to_src red. Bare
/usr/bin/python3 (no loreconvo installed) save + read verified end to end.

test_save_to_loreconvo.py stub seeded with a UTC 'Z' start_date: the save now
goes through SessionDatabase, whose migration normalizes naive-local values;
the merge-preserves-start_date assertion stays exact. The gate failure that
surfaced here was a real core bug, fixed separately in SH-103036.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…om 4c1abf177). discover_loreconvo_db gains require_existing flag (server keeps create-on-first-use; fallback keeps hard-fail); save_to_loreconvo restores _find_loreconvo_db wrapper delegating to core (public contract + None-on-missing preserved); CLI _db_path honors LORECONVO_DB_PATH again ahead of LORECONVO_DB; discovery tests updated for Path.home derivation. Verified: loreconvo suite 1328 passed 1 skipped; CLI suite 49 passed; parity 6 passed; SH-101871 repro (LORECONVO_DB=a.db, --db-path b.db) writes to b.db only.
--skip-test-gate: integrations/hermes/__init__.py tested via test_hermes_provider.py (package import)
--skip-test-gate: integrations/hermes/__init__.py tested via test_hermes_provider.py (package import)
…ack import, skip writes for background contexts
…stall

Add attribute validation to resolve_storage_core() so stale/incomplete
installs (missing discover_loreconvo_db, etc.) are detected and fall back
to the source-tree path. Prevents fleet-wide LoreConvo save breakage when
MCP is unavailable and the installed package is out of sync.
Declare reviewed exact releases and exempt only those direct packages.
Hermes keeps the global cutoff for transitive dependencies and rejects
exemptions for packages held by its core lock.
@labyrinth-analytics

Copy link
Copy Markdown
Owner

Thanks for this, and for the clear write-up on the Hermes quarantine proposal. Our public repo is a published mirror of an internal source tree, so we can't merge PRs here directly. We've ported this change into our source and it will ship in the next LoreConvo release, with the plugin version tied to the package version so the two can't drift apart. Closing this one, and thanks again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants