Merge pull request #512 from Codename-11/fix/android-compaction-watchdog #162
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # Hermes-Relay — Vanilla-Upstream Route Contract (ADR 34) | |
| # | |
| # Proves the Android *standard path* (no-plugin) route surface exists on | |
| # UNMODIFIED NousResearch/hermes-agent — the invariant CLAUDE.md asserts but | |
| # that was never tested. Source-parses upstream's declared routes (no server | |
| # boot, no pip install, no model keys); see scripts/check-upstream-route-contract.py | |
| # for the design + tradeoff (catches renamed/removed routes; not runtime auth). | |
| # | |
| # Required-PR and direct push runs check a pinned ref (non-flaky); the weekly | |
| # schedule tracks upstream `main` as a drift siren. | |
| name: CI — Upstream Contract | |
| permissions: | |
| contents: read | |
| on: | |
| workflow_call: | |
| push: | |
| branches: [main, dev] | |
| paths: | |
| - "scripts/check-upstream-route-contract.py" | |
| - ".github/workflows/ci-contract.yml" | |
| - "app/src/main/kotlin/com/hermesandroid/relay/network/upstream/**" | |
| schedule: | |
| - cron: "0 6 * * 1" # Mondays 06:00 UTC — upstream-drift siren (tracks main) | |
| workflow_dispatch: | |
| inputs: | |
| upstream_ref: | |
| description: "NousResearch/hermes-agent ref to check (branch, tag, or SHA)" | |
| required: false | |
| default: "" | |
| concurrency: | |
| group: ci-contract-${{ github.ref }} | |
| cancel-in-progress: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }} | |
| jobs: | |
| route-contract: | |
| name: Vanilla-upstream route contract | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 10 | |
| steps: | |
| - name: Checkout hermes-relay | |
| uses: actions/checkout@v7 | |
| with: | |
| persist-credentials: false | |
| - name: Resolve upstream ref | |
| id: ref | |
| env: | |
| REQUESTED_REF: ${{ github.event.inputs.upstream_ref }} | |
| run: | | |
| set -euo pipefail | |
| # PR/push runs use a known-good NousResearch/hermes-agent commit so | |
| # normal CI is stable. The weekly schedule below intentionally tracks | |
| # main as the upstream-drift siren. | |
| DEFAULT_REF="ef4b897a1843cd32c4f141f55db60f0f0602cc98" | |
| if [ "${{ github.event_name }}" = "schedule" ]; then | |
| REF="main" # weekly drift siren | |
| elif [ -n "$REQUESTED_REF" ]; then | |
| REF="$REQUESTED_REF" # manual override | |
| else | |
| REF="$DEFAULT_REF" | |
| fi | |
| # The ref is passed to git below, so reject option-like or malformed | |
| # values before it reaches that boundary. Full commit IDs and normal | |
| # branch/tag names remain supported for manual contract checks. | |
| if [[ "$REF" == -* ]] || | |
| ! git check-ref-format --allow-onelevel "$REF" >/dev/null; then | |
| echo "FAIL: invalid upstream branch or tag name." >&2 | |
| exit 1 | |
| fi | |
| echo "ref=$REF" >> "$GITHUB_OUTPUT" | |
| echo "Checking standard-path route contract against upstream ref: $REF" | |
| - name: Extract trusted upstream contract sources | |
| env: | |
| UPSTREAM_REF: ${{ steps.ref.outputs.ref }} | |
| run: | | |
| set -euo pipefail | |
| UPSTREAM_GIT="$RUNNER_TEMP/hermes-agent-contract.git" | |
| git init --bare "$UPSTREAM_GIT" | |
| git -C "$UPSTREAM_GIT" remote add origin \ | |
| "https://github.com/NousResearch/hermes-agent.git" | |
| git -C "$UPSTREAM_GIT" fetch --no-tags --depth=1 origin -- "$UPSTREAM_REF" | |
| UPSTREAM_COMMIT="$(git -C "$UPSTREAM_GIT" rev-parse 'FETCH_HEAD^{commit}')" | |
| mkdir -p _upstream/gateway/platforms _upstream/hermes_cli | |
| git -C "$UPSTREAM_GIT" show \ | |
| "$UPSTREAM_COMMIT:gateway/platforms/api_server.py" \ | |
| > _upstream/gateway/platforms/api_server.py | |
| git -C "$UPSTREAM_GIT" show \ | |
| "$UPSTREAM_COMMIT:hermes_cli/web_server.py" \ | |
| > _upstream/hermes_cli/web_server.py | |
| echo "Extracted contract sources from upstream commit: $UPSTREAM_COMMIT" | |
| - name: Set up Python 3.11 | |
| uses: actions/setup-python@v7 | |
| with: | |
| python-version: "3.11" | |
| - name: Run route-surface contract | |
| run: python scripts/check-upstream-route-contract.py "_upstream" |