Skip to content

Install Hermes once; contained sessions run the pre-built environment - #435

Merged
renmengye merged 2 commits into
mainfrom
feat/hermes-prebuilt-env
Sep 28, 2026
Merged

renmengye merged 2 commits into
mainfrom
feat/hermes-prebuilt-env

Conversation

@renmengye

Copy link
Copy Markdown
Member

Contained Hermes sessions ran uv run --project <clone>, so every session reinstalled Hermes's dependency tree into its per-run home before the model saw a token (measured: about 2–4 minutes per session on a cluster filesystem). They also could not start at all: uv run --project installs hermes-agent itself as an editable package, which writes build metadata into the clone, and the clone is bound read-only.

Claude Code and Codex are pinned binaries installed once and bound read-only; this makes Hermes the same.

Changes

  • scripts/install_hermes.sh: after pinning and verifying the source, builds the runtime once per pinned commit at <repo>.runtime/<sha>/: a uv-managed standalone Python (so the interpreter resolves at the same path inside the container) and a venv (uv sync --frozen --no-install-project). A completion marker makes reruns a no-op; a lock refuses concurrent installs; the download cache is removed afterwards.
  • HermesHarness: runs <runtime>/venv/bin/python -B <repo>/run_agent.py directly. No uv at session time. Contained sessions bind the source and the runtime read-only. A missing or incomplete runtime is an error result naming the installer; there is no per-session fallback.
  • outerloop init: installs Hermes when a judge lens uses it (respecting --no-install-harness) and records REVIEW_HERMES_REPO.
  • Docs and CHANGELOG updated.

Upgrading: existing Hermes deployments rerun bash scripts/install_hermes.sh once to build the runtime; until then Hermes lenses return the installer error instead of starting.

Verified

  • Full gate: 2158 passed, 2 skipped; ruff, format, mypy clean.
  • On a Slurm cluster: install built the runtime in about 4 minutes (rerun: 5 s); a contained verify session through this branch ran with no install step and filed its verdict. The same case with per-session installs took about 160 s longer.

🤖 Generated with Claude Code

Contained Hermes sessions ran `uv run --project <clone>`, which reinstalled
Hermes's dependencies into the per-run home on every session (minutes of
setup) and could not start at all: uv tried to install hermes-agent itself as
an editable package into the read-only clone.

The installer now builds the environment once per pinned commit, beside the
source (`<repo>.runtime/<sha>/`: a uv-managed standalone Python and a venv).
Sessions run that interpreter directly with the source and runtime bound
read-only; a missing runtime is an error that names the installer. `init`
installs Hermes when a judge lens uses it.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head a553ba2c — reviewer summarizer:hermes/gpt-5.6-terra over coverage+credentials+deployment+general+lifecycle+prose.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: nothing blocking — 1 advisory note.

1 finding attached to the lines below.

Merged 1 finding. Rejected findings: none; the remaining lenses reported no findings.

Comment thread src/outerloop/harness.py
- CI workflows provision Hermes with the kernel's installer (source and
  runtime); a failed install stays advisory and never fails the job.
- Installer: one source lock before any clone or re-pin; Python lookup
  ignores active virtualenvs; note that runtimes are built in place.
- Tick preflight requires a ready runtime, naming the installer.
- Full init keeps REVIEW_MODEL and REVIEW_HERMES_PROVIDER (a drop that
  predates this change).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@renmengye renmengye added the outerloop:review re-request the advisory review label Sep 28, 2026

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Round 1 — reviewed head 0379c005 — reviewer hermes/gpt-5.6-terra.

terra
Advisory findings from outerloop — the code owner decides. Reply to disagree; the outerloop:no-review label opts this PR out.

Verdict: no defects found.

@renmengye
renmengye merged commit 9f66be3 into main Sep 28, 2026
5 checks passed
@renmengye
renmengye deleted the feat/hermes-prebuilt-env branch September 28, 2026 03:02
@renmengye

Copy link
Copy Markdown
Member Author

Compatibility statement (added for the 0.3.0rc1 release audit, per RELEASING.md).

  • Surfaces: the persisted Hermes runtime layout and its completion marker; the launch-time runtime reader.
  • Oldest state read: a source-only (v0.2.1) Hermes checkout is not used until the runtime is installed; a missing runtime fails clearly at preflight rather than mid-session.
  • First tick after upgrade: run outerloop harness upgrade hermes before Hermes sessions launch; other backends are unaffected.
  • Rollback: older kernels ignore the runtime directory and use the source checkout.
  • Fixtures: source-only installation, failure, retry and reuse (F16).

@renmengye renmengye mentioned this pull request Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

outerloop:review re-request the advisory review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant