Repository navigation
Install Hermes once; contained sessions run the pre-built environment - #435
Merged
Merged
Conversation
Contained Hermes sessions ran `uv run --project <clone>`, which reinstalled Hermes's dependencies into the per-run home on every session (minutes of setup) and could not start at all: uv tried to install hermes-agent itself as an editable package into the read-only clone. The installer now builds the environment once per pinned commit, beside the source (`<repo>.runtime/<sha>/`: a uv-managed standalone Python and a venv). Sessions run that interpreter directly with the source and runtime bound read-only; a missing runtime is an error that names the installer. `init` installs Hermes when a judge lens uses it. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Round 1 — reviewed head a553ba2c — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.
terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.
Verdict: nothing blocking — 1 advisory note.
1 finding attached to the lines below.
Merged 1 finding. Rejected findings: none; the remaining lenses reported no findings.
- CI workflows provision Hermes with the kernel's installer (source and runtime); a failed install stays advisory and never fails the job. - Installer: one source lock before any clone or re-pin; Python lookup ignores active virtualenvs; note that runtimes are built in place. - Tick preflight requires a ready runtime, naming the installer. - Full init keeps REVIEW_MODEL and REVIEW_HERMES_PROVIDER (a drop that predates this change). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Member
Author
|
Compatibility statement (added for the 0.3.0rc1 release audit, per RELEASING.md).
|
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Contained Hermes sessions ran
uv run --project <clone>, so every session reinstalled Hermes's dependency tree into its per-run home before the model saw a token (measured: about 2–4 minutes per session on a cluster filesystem). They also could not start at all:uv run --projectinstalls hermes-agent itself as an editable package, which writes build metadata into the clone, and the clone is bound read-only.Claude Code and Codex are pinned binaries installed once and bound read-only; this makes Hermes the same.
Changes
scripts/install_hermes.sh: after pinning and verifying the source, builds the runtime once per pinned commit at<repo>.runtime/<sha>/: a uv-managed standalone Python (so the interpreter resolves at the same path inside the container) and a venv (uv sync --frozen --no-install-project). A completion marker makes reruns a no-op; a lock refuses concurrent installs; the download cache is removed afterwards.HermesHarness: runs<runtime>/venv/bin/python -B <repo>/run_agent.pydirectly. No uv at session time. Contained sessions bind the source and the runtime read-only. A missing or incomplete runtime is an error result naming the installer; there is no per-session fallback.outerloop init: installs Hermes when a judge lens uses it (respecting--no-install-harness) and recordsREVIEW_HERMES_REPO.Upgrading: existing Hermes deployments rerun
bash scripts/install_hermes.shonce to build the runtime; until then Hermes lenses return the installer error instead of starting.Verified
🤖 Generated with Claude Code