Commit graph

38 commits

Author SHA1 Message Date
rasyidan
955cc61f82 fix: robustify tag dereferencing and hash extraction in update-pins.sh 2026-06-08 01:51:52 +07:00
Rasyidan A F
4f3060ea08
Merge pull request #3 from RationallyPrime/fix/apscheduler-tests
fix: disable apscheduler tests (processpool failures in nix sandbox)
2026-03-30 11:58:57 +07:00
Hákon Freyr
247b520641 fix: disable apscheduler tests (processpool failures in nix sandbox)
The processpool executor tests assert specific signal exit codes that
differ inside the nix build sandbox. Same class of issue as the existing
sanic/cherrypy/pytest-services overrides.

Fixes #2

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-28 12:37:28 +00:00
4f787c78f3 fix: handle upstream rename of minisweagent_path.py → mini_swe_runner.py
Upstream removed minisweagent_path.py in favor of mini_swe_runner.py,
breaking the nightly-package-contents check. Accept either module name
in checks and ensure both are patched into pyproject.toml py-modules.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 11:31:43 +07:00
f6ae751bff fix: bump tenacity, firecrawl-py, fal-client to satisfy hermes-agent 0.4.0 deps
Upstream hermes-agent 0.4.0 requires tenacity>=9.1.4, firecrawl-py>=4.16.0,
and fal-client>=0.13.1. Override nixpkgs versions for tenacity (9.1.2→9.1.4)
and firecrawl-py (GitHub→PyPI 4.16.0), bump fal-client (0.4.0→0.13.1).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 09:52:10 +07:00
76d1677e94 fix: bump hermes-agent 0.3.0 → 0.4.0, fix CI update script targeting wrong fields
- Stable: pinVersion 0.3.0 → 0.4.0 (v2026.3.23, commit 8416bc2)
- Nightly: 0.3.0-unstable-2026-03-22 → 0.4.0-unstable-2026-03-25 (commit e5691ee)
- Fix update-pins.sh: target pinVersion/pinRev/pinHash instead of generic
  version/rev/hash which incorrectly matched fal-client fields
- Add cherrypy test override for macOS Nix sandbox compatibility
- No litellm: pythonRemoveDeps still strips it from wheel metadata

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-26 07:17:18 +07:00
3a9dc709f7 fix: add parallel-web declaratively for package update, pytest nix sandbox fix 2026-03-25 14:54:59 +07:00
51c4fafe37 fix: remove compromised litellm dependency
litellm on PyPI has been reported as compromised. The upstream
hermes-agent v0.4.0 already dropped it from its dependencies.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-25 12:24:10 +07:00
nix-hermes-agent-bot
207e6c1cdb 🤖 bump hermes-agent → 0.4.0 (v2026.3.23)
Upstream: https://github.com/NousResearch/hermes-agent/releases/tag/v2026.3.23

Tests: nix build .#hermes-agent (passed)
2026-03-24 06:47:25 +00:00
nix-hermes-agent-bot
324a6e050e 🤖 bump hermes-agent → 0.3.0 (v2026.3.17)
Upstream: https://github.com/NousResearch/hermes-agent/releases/tag/v2026.3.17

Tests: nix build .#hermes-agent (passed)
2026-03-22 12:33:41 +00:00
0116dbe7e8 style: use inherit instead of assignment for pkgs.lib
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 16:04:34 +07:00
027881ced6 style: fix nixfmt formatting in flake.nix
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 15:37:57 +07:00
22fb4d0195 feat: add hermes-agent-nightly version 2026-03-22 15:33:38 +07:00
b307e92b09 feat: add github ci for nightly version 2026-03-22 15:33:25 +07:00
7ff52678e1 test: pin nightly hash and test build 2026-03-22 15:33:08 +07:00
0c5c5425a0 test: nightly build, pull latest hash and test 2026-03-22 15:32:53 +07:00
f64b73730e fix(module): use string interpolation for custom skill source paths
`toString` converts a Nix path to a string without registering it as a
build input, causing "custom skill source not found" errors in the Nix
sandbox. String interpolation properly copies the path to the store.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 02:31:48 +07:00
59bd0a0547 fix: chmod DESCRIPTION.md before overwrite in Nix sandbox
copytree makes files read-only in Nix sandbox; rglob("DESCRIPTION.md")
then tries to overwrite skill-level copies → PermissionError. chmod
0o644 before copy2 to handle already-existing read-only targets.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-22 02:00:02 +07:00
Ciphercat
880796fc0e feat(skills): add bundled.include for cherry-picking bundled skills
When bundled.include is set to a non-empty list, only the listed skills
are installed from the upstream bundled skills directory. When empty
(default), all bundled skills are installed (existing behavior).

Invalid include paths cause a build error with available skills listed.
DESCRIPTION.md files are only copied for categories that have at least
one included skill.
2026-03-18 22:03:07 +00:00
Rasyidan A F
ad607ee4dc
Merge pull request #1 from 0xrsydn/feat/skills 2026-03-18 11:23:37 +07:00
Ciphercat
0512a81eb9 fix: disable sanic test suite to unbreak CI
sanic 25.12.0 in nixpkgs has a flaky test_keep_alive_client_timeout
that fails in sandbox builds. Override the python package set to skip
sanic's tests — they're upstream's problem, not ours.

Cascade was: sanic → sanic-testing → slack-bolt → hermes-agent → all checks.
2026-03-18 02:57:19 +00:00
Ciphercat
0a03c43f90 docs: remove superseded skills PRD 2026-03-18 02:38:52 +00:00
Ciphercat
1a1f06aaa5 test: add skills coexistence e2e coverage 2026-03-18 02:32:27 +00:00
Ciphercat
481c62c568 docs: clarify declarative and native skills coexistence 2026-03-18 02:31:46 +00:00
Ciphercat
a1b9295c8e feat: add declarative Hermes skills phase 1 2026-03-18 02:31:46 +00:00
Ciphercat
c2966d2515 docs: add declarative skills PRD 2026-03-18 02:30:20 +00:00
Ciphercat
ba6c63e9bf ci: fix lint glob + format nix files 2026-03-18 02:24:18 +00:00
Ciphercat
c3da68363c ci: add lint + flake check workflow 2026-03-18 02:20:36 +00:00
Ciphercat
010a1b6644 feat: bump hermes-agent 0.2.0 → 0.3.0 + auto-update CI
- Update package.nix to v0.3.0 (NousResearch/hermes-agent v2026.3.17)
- Add scripts/update-pins.sh — checks latest stable release, prefetches, validates build
- Add .github/workflows/update-pins.yml — runs every 6h + manual dispatch
- Pattern follows nix-openclaw's yolo-update approach
2026-03-17 19:10:01 +00:00
Ciphercat
e7b70a7b4d feat: persistent auth — seed-once, never overwrite on rebuild
- authFile now only copies to auth.json if it doesn't already exist
- Runtime token refreshes (OAuth rotate) survive nixos-rebuild
- Added authFileForceOverwrite option (default false) as escape hatch
- Committed AUTH-ANALYSIS.md documenting full auth architecture
2026-03-16 11:45:02 +00:00
Ciphercat
6024741356 test: add hermes-agent import check
Verifies hermes-agent starts without ModuleNotFoundError.
Exits cleanly with 'Failed to initialize OpenAI client' (expected — no API key in test).
2026-03-16 01:21:10 +00:00
Ciphercat
1d95780fff fix: missing minisweagent_path module + add nix checks
- Patch upstream pyproject.toml to include minisweagent_path in py-modules
- Copy mini-swe-agent/src/minisweagent into package for importability
- Add 3 nix checks: package-contents, cli-commands, doctor
- All binaries tested: hermes, hermes-agent, hermes-acp
- hermes gateway, config, status, claw migrate all verified working
2026-03-16 01:15:24 +00:00
Rasyidan A F
742b6d541c
docs: reclarify lol 2026-03-16 07:49:17 +07:00
Ciphercat
32b624783a docs: add golden paths for supported deployment topologies 2026-03-16 00:46:23 +00:00
Ciphercat
5b49310049 chore: rename to nix-hermes-agent 2026-03-16 00:40:30 +00:00
Ciphercat
5930ea925d feat: add authFile option + sops-nix documentation
- authFile option for declarative OAuth token management
- sops-nix integration examples in README
- Plain file secrets example in README
2026-03-16 00:36:12 +00:00
Ciphercat
3dd03ba2ae feat: declarative NixOS module following nix-openclaw patterns
- Deep-merge config attrset → cli-config.yaml (like nix-openclaw's JSON config)
- Declarative documents option (SOUL.md, AGENTS.md, USER.md — inline or file paths)
- MCP servers as structured Nix options (merged into config)
- Environment files for secrets (systemd EnvironmentFile, outside Nix store)
- Non-secret environment vars (separate from secrets)
- Proper tmpfiles rules, activation scripts for config + document linking
- systemd hardening (NoNewPrivileges, ProtectSystem, PrivateTmp)
- Comprehensive README with full usage examples
2026-03-15 23:59:09 +00:00
Ciphercat
f70dc0f39b feat: initial nix package and NixOS module for hermes-agent v0.2.0
- buildPythonApplication with Python 3.12
- All extras included (messaging, cron, tts, voice, mcp, honcho, acp)
- Custom PyPI packages: fal-client, honcho-ai, agent-client-protocol
- NixOS module with systemd service for gateway mode
- Runtime deps wrapped: nodejs 22, ripgrep, ffmpeg, git
- Flake-based with overlay support
2026-03-15 23:49:39 +00:00