fix: restore immutable update visibility - #3
Merged
Conversation
…table-update-visibility
Dannyxlm
pushed a commit
that referenced
this pull request
Aug 21, 2026
…age_id) Live-canary finding #3 (Alice, staging): the relay inbound leg is at-least-once. On WS re-handshake the connector replays its durable per-instance buffer; a long multi-tool turn (60-100s) straddling a quiet socket drop got its ORIGINAL inbound replayed after the turn finished, re-running the entire turn — the user saw the final answer posted 2-5x (each a separate execution, hence slightly different texts). Receipts: same msg text at history=0 in back-to-back sessions 121647/121840, no Slack-side retry on the connector (envelope dedupe never fired). Consumer-side idempotency: bounded FIFO seen-set (512) keyed by platform message identity; events without a message_id never dedupe (fail-open — dropping a real message is worse than rerunning one). No wire change; contract v1 untouched. Transplanted-from: victor-fork/feat/relay-slack-live-cards@73ce04ae75 (extracted for the rc.4 relay-fixes train; tests moved to a standalone file with no live-cards dependencies)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
(+N)update count for CloudSeed's immutable managed runtimehermes updateagainst productionRoot cause
CloudSeed intentionally disabled the stock in-place updater when it moved to immutable releases. The replacement source monitor was already live through
Dannyxlm/cloudseed-infra#61, but the running Hermes backend did not expose that receipt to Desktop. Desktop therefore received the old suppression payload and rendered no count.Cross-repo compatibility
hermes-update-status.v1produced by merged CloudSeed PR fix: resolve symlink bypass in write deny list on macOS NousResearch/hermes-agent#61NousResearch/hermes-agentmainSecurity/correctness follow-up
Independent review found and this PR closes two P1s:
generated_atandlast_fetched_at, so a freshly rewritten receipt cannot authorize stale upstream state;Verification
tests/hermes_cli/test_dashboard_admin_endpoints.py+ Codex app-server tests: 140 passedtests/hermes_cli/test_web_server.py: 523 passedgit diff --check: passedAutomated by Ava on Danny's behalf.