Skip to content

fix: restore immutable update visibility - #3

Merged
Dannyxlm merged 6 commits into
mainfrom
fix/immutable-update-visibility
Jul 29, 2026
Merged

fix: restore immutable update visibility#3
Dannyxlm merged 6 commits into
mainfrom
fix/immutable-update-visibility

Conversation

@Dannyxlm

Copy link
Copy Markdown
Owner

Summary

  • restore the backend (+N) update count for CloudSeed's immutable managed runtime
  • surface source-monitor freshness, blockers, candidate state, and release lineage in Hermes Desktop
  • keep immutable updates request-only: the dashboard never runs hermes update against production
  • harden the status contract against stale fetch receipts and make candidate requests atomic/idempotent

Root cause

CloudSeed intentionally disabled the stock in-place updater when it moved to immutable releases. The replacement source monitor was already live through Dannyxlm/cloudseed-infra#61, but the running Hermes backend did not expose that receipt to Desktop. Desktop therefore received the old suppression payload and rendered no count.

Cross-repo compatibility

Security/correctness follow-up

Independent review found and this PR closes two P1s:

  1. freshness now uses the older of generated_at and last_fetched_at, so a freshly rewritten receipt cannot authorize stale upstream state;
  2. candidate markers use atomic no-clobber publication, exact repeats are idempotent, and conflicting pending requests fail closed.

Verification

  • tests/hermes_cli/test_dashboard_admin_endpoints.py + Codex app-server tests: 140 passed
  • tests/hermes_cli/test_web_server.py: 523 passed
  • Desktop managed-update UI/store tests: 31 passed
  • Desktop TypeScript typecheck: passed
  • Desktop production build: passed
  • Ruff over all touched Python paths: passed
  • git diff --check: passed
  • scoped secret scan: zero findings

Automated by Ava on Danny's behalf.

@Dannyxlm
Dannyxlm merged commit b7eed3c into main Jul 29, 2026
88 of 93 checks passed
@Dannyxlm
Dannyxlm deleted the fix/immutable-update-visibility branch July 29, 2026 06:02
Dannyxlm pushed a commit that referenced this pull request Aug 21, 2026
…age_id)

Live-canary finding #3 (Alice, staging): the relay inbound leg is
at-least-once. On WS re-handshake the connector replays its durable
per-instance buffer; a long multi-tool turn (60-100s) straddling a quiet
socket drop got its ORIGINAL inbound replayed after the turn finished,
re-running the entire turn — the user saw the final answer posted 2-5x
(each a separate execution, hence slightly different texts). Receipts:
same msg text at history=0 in back-to-back sessions 121647/121840, no
Slack-side retry on the connector (envelope dedupe never fired).

Consumer-side idempotency: bounded FIFO seen-set (512) keyed by platform
message identity; events without a message_id never dedupe (fail-open —
dropping a real message is worse than rerunning one). No wire change;
contract v1 untouched.

Transplanted-from: victor-fork/feat/relay-slack-live-cards@73ce04ae75 (extracted for the rc.4 relay-fixes train; tests moved to a standalone file with no live-cards dependencies)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant