Commit Graph
23 Commits
Author SHA1 Message Date
d2d79ce8fd Stop the Hermes Desktop launcher reconciling a mise install
The launcher called omarchy-install-hermes-cli with no arguments on every start to remove a mise-built Hermes left beside the app. Omarchy no longer builds Hermes through mise: it sets the app's runtime up before the app is opened, and the installer now only answers a named --check or --now, so the call had nothing left to reconcile and only printed usage. The launch check keeps a forbidden stand-in for that command on its PATH, so a launcher that reaches for it again fails the build.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-21 18:04:29 -05:00
Spencer Bull ff6264f633 Move Hermes Desktop out of the fast release ring 2026-09-08 14:43:28 -05:00
Spencer Bull 9c7f00351c Update hermes-desktop to 2026.9.7 2026-09-08 12:17:07 -05:00
Spencer BullandCodex XHigh f69f6ce364 Fix Hermes desktop launch settings and sandbox consistency
Release 2026.8.31-3 preserves upstream desktop settings and explicit launch environment without invoking the CLI sandbox setup. Keep incomplete runtimes from blocking the packaged fallback, and use the namespace sandbox consistently in both locations.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-09-07 04:10:07 -05:00
Spencer Bull 0c2fa676f6 Use the next Hermes package release number 2026-09-07 03:35:15 -05:00
Spencer BullandGPT-6 Codex 2fb9ab2ba9 Launch native Hermes without privileged sandbox setup
Use the same direct executable path for menu launches and URLs, require working user namespaces, and retain only the first-update relaunch gate backport. This avoids the upstream CLI fallback that makes a helper in the user runtime setuid-root.

Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-07 03:17:42 -05:00
Spencer BullandGPT-6 Codex 9588b28cf6 Prepare packaged Hermes for native in-app updates
Track main while pinning the initial release commit. Ship the matching upstream installer and Linux namespace sandbox backport, and launch the native user build prepared by Omarchy.

Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-07 02:55:06 -05:00
Spencer Bull 3356e8c04c Restore packaged Hermes Desktop at 2026.8.31-2
Revert the native installer and updater packaging introduced by #325. Keep the prebuilt desktop and existing launcher, updating only the release tag, commit and archive checksum from the previous recipe.
2026-09-07 02:01:52 -05:00
Spencer Bull b36bfce109 Restore Hermes PKGBUILD formatting 2026-09-06 22:53:12 -05:00
Spencer Bull beb164a9a2 Resolve Hermes profile homes before package setup 2026-09-06 22:29:49 -05:00
Spencer BullandGPT-6 Codex 351f188d02 Register Hermes Desktop only after publishing its native CLI
Keep build-time registration private, verify the published launcher, and then let the native command register the final desktop entry. Keep that launcher first on the desktop environment PATH for subsequent registrations.

Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-06 02:21:16 -05:00
Spencer BullandClaude Opus 5 f4adf308f9 Make native Hermes setup retryable without a late sudo step
Stage the initial clone before publishing its ownership marker and build the desktop through the same native CLI used by updates. Keep a concurrent checkout intact and reset pkgrel for the version change.

Co-Authored-By: Claude Opus 5 (default) <noreply@anthropic.com>
2026-09-06 02:17:27 -05:00
Spencer Bull 2b1edd47b2 Revert "Keep in-app updates on the verified Hermes CLI"
This reverts commit 68a4a6cc22.
2026-09-06 02:02:52 -05:00
Spencer Bull 68a4a6cc22 Keep in-app updates on the verified Hermes CLI 2026-09-06 01:59:58 -05:00
Spencer BullandGPT-6 Codex 341299f477 Let the Hermes package bootstrap native desktop updates
Install Hermes into its writable native layout instead of shipping a frozen /opt desktop. Preserve the native update path, migrate tagged bootstraps, and keep existing CLI launchers until the desktop is ready.

Co-Authored-By: GPT-6 Codex (xhigh) <noreply@openai.com>
2026-09-06 01:56:23 -05:00
Ryan Hughes 246eea9620 Fix Hermes Desktop keyring detection on Hyprland
Default Electron to the gnome-libsecret password store so Hermes can use GNOME Keyring for secure remote tokens. Declare libsecret as a runtime dependency.
2026-08-30 23:49:02 -04:00
OmabotandCodex XHigh 9dc71c39cc Reconcile Hermes ownership on every launch
Tidying the terminal agent's Hermes away only happened in the menu installer,
so `pacman -S hermes-desktop` on its own, or an install interrupted after the
package landed, left two Hermeses -- and by then the menu entry that would
have noticed is disabled, because we are installed.

Co-Authored-By: Codex XHigh <noreply@openai.com>
2026-08-22 08:33:05 -07:00
Omabot 9b0dd041f8 Let the app own its Hermes runtime
Pairing the app with the mise CLI does not work, and pinning the app back to
the tag behind PyPI's release does not rescue it: v2026.7.20's desktop reaches
"backend is ready" and then hangs without ever opening a window, against its
own matching runtime. Only the newest app against a runtime built from its own
commit starts, which is the arrangement upstream ships.

So the package returns to the newest tag and the launcher sets
HERMES_DESKTOP_IGNORE_EXISTING, which keeps the app off whatever hermes is on
PATH -- on Omarchy that is the mise CLI installed for the terminal agent, a
different release, and the version gap is what produced the 401. The app
provisions ~/.hermes itself on first launch instead.

mise and uv are no longer dependencies, since the launcher no longer installs
anything; git and curl are, because the app's own bootstrap needs them.
2026-08-19 06:12:11 -07:00
Omabot 1a394eae60 Track PyPI's release rather than the newest tag
Built from v2026.8.18 against the CLI on PyPI, the app never starts: it
resolves the CLI, launches the backend, and then fails its readiness probe
with 401 Unauthorized. The two have to agree on the dashboard session-token
handshake -- the app scrapes window.__HERMES_SESSION_TOKEN__ out of the served
HTML, and web_server.py falls back to a random token when it cannot agree, so
every probe after that is rejected. A month separated the two: the tag was
2026-08-18, hermes-agent 0.19.0 on PyPI was 2026-07-20.

Upstream never meets this because their installer builds the app from the same
checkout it installs the CLI from. Pinning the CLI forward to the app's commit
is not open to us either -- Hermes refuses a non-editable install from a git
checkout and tells you to use `uv sync` instead. So the app is pinned back
instead, to the tag PyPI's current release was cut from.

Verified on a worker: the desktop reaches "Hermes backend is ready" and maps
its window, where the newer build stopped at the 401 every time.
2026-08-19 05:21:53 -07:00
Omabot cd005e8d9d Guarantee the CLI rather than warning about it
The launcher only delegated to omarchy-install-hermes-cli and, when that was
absent, printed a warning to stderr -- which nothing sees under a graphical
launch -- and started the app anyway. The app then offered to install Hermes
itself, and that copy wins permanently: it checks ~/.hermes/hermes-agent
before it checks PATH, so installing the CLI afterwards changes nothing until
that directory is deleted.

So install it here when omarchy's script isn't around, with the same
interpreter pin and the same exported cooldown, and hand the app the real
executable by putting the mise install's bin directory on PATH instead of
leaving it to search. Its probe allows 15 seconds; resolving this way takes
0.2. mise and uv become dependencies, which is what makes the package
self-sufficient on a machine without Omarchy.
2026-08-19 03:25:36 -07:00
Omabot 4ebb07b267 Fix what the review found in the desktop package
Pin the build stamp. write-build-stamp.mjs resolves the commit the app pins
its first-launch bootstrap to, preferring $GITHUB_SHA and otherwise running
`git rev-parse`. That fallback is wrong under makepkg: the build happens
inside this repository, so git ascends out of srcdir and stamps the app with
an omarchy-pkgs commit that means nothing upstream. Confirmed by rebuilding --
the stamp now reads the tag's own commit rather than this repo's HEAD.

Ship upstream's MIT licence. The package declares MIT and was installing only
Electron's licence text.

Repair a drifted CLI before launching rather than only a missing one. `mise
up` can leave Hermes rebuilt against the system Python, and a stub can be
there but cold; either way the wrapper's own repair takes minutes while the
app allows 15 seconds before bootstrapping its own copy. Running the installer
unconditionally costs nothing when Hermes is healthy.

Register the hermes:// scheme. The desktop entry took %U while declaring no
MimeType, so the scheme electron-builder configures went unhandled.
2026-08-19 03:08:40 -07:00
Omabot d2247aa363 Ask for Wayland directly in the Hermes launcher
Chromium falls back to XWayland often enough to matter, and the result is a
blurry window on every scaled display -- the same reason the ChatGPT and Grok
Bot launchers set this. Skipped when the caller has already named a platform.
2026-08-19 02:51:49 -07:00
Omabot a57f63914f Build Hermes Desktop from source instead of packaging the CLI
Install > AI is for GUI apps, so the package becomes the desktop shell and the
terminal agent moves to a lazy mise stub that omarchy installs itself.

Nous builds Hermes Desktop for macOS and Windows only -- their download page
offers a .dmg and an .exe and points Linux users at a terminal install -- so
there is no vendor binary to repackage the way grok-bot repackages xAI's deb.
Their electron-builder config does carry a Linux target though, untested by
upstream but working: npm ci at the workspace root, npm run pack in
apps/desktop, and electron-builder stages node-pty and get-windows for
linux-x64 on its own. 337 MB unpacked, 129 MB packaged.

The app is only a shell -- it runs `hermes serve` against a CLI it does not
ship, and clones its own unpinned copy into ~/.hermes when it finds none. So
/usr/bin/hermes-desktop makes sure the CLI is there before handing over, and
says so plainly rather than bootstrapping a second Hermes where Omarchy's
installer isn't around to do it properly.
2026-08-19 02:42:15 -07:00