Last updated: 17 September 2026, 10:20 AEST
Hermes updated from v0.20.6 to v0.21.3 with a verified full backup. The gateway is running current code, Telegram is healthy, all eight configs are schema 45, six customised bundled skills and all seven worker links were preserved, and the main custom integrations passed. The custom-safeguards review found nothing that should be removed. The static publish vault move, paid auxiliary-model decision, role-skill cleanup and cron delivery-proof migration are complete. Connections remains the open decision.
The update is operationally successful. Hermes, launchd, Telegram, Photon, Camofox, Computer Use, Context7, memory-gate, Kanban handlers, cron inventory and the session database all passed their named checks. The automatic updater restart failed because its old process mixed old and new Python modules, but a fresh process loaded correctly and BB restarted the gateway. The old updater emitted no native receipt, so the verified full ZIP and direct runtime evidence are the rollback and completion proof for this run. One later Desktop-only cosmetic commit remains for the next normal update.
Gateway PID 86501 is stable; Telegram and Photon connect; config schema 45 passes across the fleet.
Six customised bundled skills, seven worker symlinks, Camofox, Context7, memory-gate and the external Claude/Codex work-verification wrapper remain functional.
Static vault relocation, paid auxiliary routing, role-skill lifecycle cleanup and exact cron delivery proof are complete. Connections remains open.
Claude and Anthropic were untouched. No paid-provider generation smoke ran. Curator remains disabled and no cleanup, delete, prune or automatic replacement ran.
Installed: v0.20.6 at 10b38830 moved to v0.21.3 at 64a9b432. The checkout is clean; one later Desktop-only cosmetic commit is parked for the next normal update.
Rollback: Full backup /Users/boydbowker/.hermes/backups/pre-update-2026-09-16-170022.zip is 3,635,175,036 bytes and passed unzip -t with no compressed-data errors.
Gateway: The updater restart failed from mixed old/new modules. A fresh Hermes process worked, BB restarted the gateway, launchd became current, and PID 86501 remained stable with Telegram and Photon connected.
Configuration: Default profile migrated 39 to 45; seven worker profiles migrated 38 to 45. Exact default-profile change count: six.
Receipt limitation: No update_receipts/latest.json was written by the old updater process. Verified backup plus direct runtime evidence are the completion proof for this run.
Camofox live proof: After a separate session logged one malformed 400 request, a direct post-update browser_navigate to https://example.com succeeded and returned the expected page snapshot. The integration is functional.
What was checked: We compared Boyd's custom safeguards and workflows with the new built-in Hermes features to see whether any custom piece had become redundant.
Monitored worker, in English: It is a wrapper for external Claude Code or Codex jobs. Native Hermes tracks whether the process started, finished, failed or disappeared. The wrapper also checks whether the promised files or Git changes appeared and whether verification passed. Process completion is not work completion.
What changed on 17 September: Seven role manuals stopped repeating native Kanban lifecycle mechanics. B1, B2 and B4 delivery verifiers now require an exact delivered cron execution row. The custom safeguards and Obsidian marker repair remain.
Native Kanban: No Kanban default, config, dispatcher, database, task state or source code changed. Normal sessions still do not receive Kanban tools unless explicitly configured, and dispatched workers continue using Hermes's native behavior.
Curator: Skill housekeeping remains disabled. If considered later, run a dry-run and inspect every candidate before enabling.
Evidence: Full audit: 80-Logs/hermes-updates/2026-09-16-v0.21.3-native-replacement-audit.md. SHA-256 a0685301c3c55ef8572c23a20000769862ae3c1011b030d7261afeb9b582c94e.
What changed: The full 32 MB publish vault was copied with 53 file hashes verified, then live skills, cron prompts, report tooling and system references were moved to the new path.
Verification: The report passed 18 of 18 checks and deployed successfully from the new directory. Both the immutable Cloudflare preview and stable URL returned the updated content.
Obsidian Vault: The 424-line umbrella became a 133-line Vault OS router with specialist detail behind references. Live v2.1.0 SHA-256: 1e7da2d7c769161b3f1e73402b834266af0399242d0da365551818c5eb14b55d.
External writing checks: anti-ai-writing-checklist now activates at the external boundary rather than during ordinary chat, internal notes, plans or AI handoffs. Live v2.0.0 SHA-256: 6abfe77ddf574d3d752d9b2c8dd7720846ce7c36bfd437431a9f75ceb1b07049.
Claude Code execution: autonomous-coding-agents is now a 75-line local Claude Code execution adapter. SOUL and native Hermes own general routing and delegation. Live v2.0.0 SHA-256: afb6f9f3c70bf1a4130e9fbc219b6a48e21278e586d2b70b65c75ef88813d04c.
Model route resolution: model-routing is now a 61-line compatibility adapter for model-tier resolution. Direct-versus-delegate judgement remains in SOUL. Live v2.0.0 SHA-256: d66044526ffb8e85eaa66de5cc2989614aa719b136159ce74cd7ab6b634459bb.
Communication boundaries: communicating-with-bb was reduced from 296 lines to a 44-line boundary skill. Ordinary plain-English style remains in SOUL, USER and MEMORY; MEDIA delivery and wait-state rules now live in SOUL. Live v3.1.0 SHA-256: 00df457dee197e2d0829af29cab02a9baff66fec3c7b30ba9530b4f7783ff349.
Project audits: forensic-project-audit was reduced from a compulsory 408-line investigation to a 91-line project-truth router. All 20 specialist references remain available on demand. Live v2.0.0 SHA-256: 4659a6aa9ec14d4be4cb1fe00e78ceca08ab2c83af0661d281b0dd4d82a4f9ea.
Review discipline: Each review now starts with a whole-system verdict: unique job, removal impact, existing owner, evidenced failures and smallest valid form. Clause mapping follows as an intent-loss check, not a rule-replication exercise.
Verification and scope: All six live hashes were re-read on 6 September. Named mechanical, routing and post-install checks passed for each closeout. No unapproved provider, config, cron, deployment or gateway change was included.
Evidence and rollback: Canonical review evidence lives under 20-Knowledge/Prompts/model-knowledge/skill-modernisation/. Each live replacement has a dated backup and closeout receipt.
Cause: Normal Google Workspace use imported `_hermes_home.py`, causing Python 3.11 to regenerate a `.pyc` file that Hermes counted as source drift.
Action: Moved only `_hermes_home.cpython-311.pyc` to `~/.Trash/hermes-google-workspace-pycache-item7-20260831-074804/`.
Verification: Google Workspace matches stock by CLI diff and full file-hash comparison. Weekly Review Planning and the bundled manifest are unchanged.
What changed: Updated the canonical Infra record, remediation handoff, dated closeout log, structured report and rendered local HTML. No runtime, skill or manifest change ran during Item 7.
Verification: Hermes v0.20.6 at 10b38830; clean source tree; config schema 39; quick backups; built-in memory; current gateway definition; Telegram and Photon connected; Context7, Camofox and Computer Use healthy; 7 profile skill links intact.
Google Workspace: All source and reference files match stock. BB approved moving the regenerated Python bytecode cache to Trash; Google Workspace no longer appears modified.
Excluded: No Hermes update, model or provider smoke, credential file inspection, credential change, skill reset, gateway restart, report deployment or MemPalace work.
Security follow-up: Stopping the temporary loopback verifier unexpectedly echoed inherited environment values into internal tool output. BB confirmed the affected X/Twitter credentials were manually rotated on 1 September 2026. No values are stored in this report.
What changed: Renamed the morning, midday, evening, weekly, follow-up, safety-net, learning-review and delivery-check cron surfaces. Updated the three delivery-verifier fallback names.
What stayed unchanged: Stable job IDs, schedules, delivery targets, providers, models, filenames and JSON keys did not change. Necessary Condition keeps its existing name.
Verification: Read-back confirmed all 11 live names and prompts. The three verifier scripts compiled and passed synthetic successful-delivery dry runs. No gateway restart was required.
What changed: Main fallback order is kimi-coding / kimi-k3, then opencode-go / deepseek-v4-pro. Sol and Luna remain unchanged.
Delegation limit: Hermes delegates inherit the shared main fallback chain. A separate Luna to MiniMax M3 fallback is not supported, so MiniMax was left parked.
Verification: Config schema 39, typed YAML read-back and hermes fallback list passed. No model calls and no gateway restart were performed.
gpt-5.6-sol -> kimi-k3 -> deepseek-v4-pro. Delegation remains gpt-5.6-luna and inherits that shared fallback chain.Rollback: Dated rollback bundle: `~/.hermes/backups/v0205-maintenance-20260823-200339`.
Config and security: Default schema 33 and 7 profile schema 23 configs migrated to 38. Concurrency re-pinned to 3. Destructive permanent approvals stripped. Disk cleanup, curator and lazy installs disabled.
Memory and compression: Memory-gate v3 plus fail-closed passed 28 durable tests across all configs. Duplicate memory/skill reviews are off. Compression is in-place, uses the 5,000-message safety threshold and routes to verified OpenAI Codex GPT-5.6.
Providers and cron: Blank, self, Kimi and unused GLM routes removed without deleting credentials or Ollama models. Linear MCP removed while API-key capability remains. Three cron prompts use canonical Vault OS paths; Matt sweep is pinned to GPT-5.6.
Skills: Stock Hermes, Google Workspace, OCR and coder Claude skills restored after BB overlays were verified. Orchestrator and Ops lifecycle drift fixed.
Storage: `state.db` reduced from 5,537.0 MB to 1,922.5 MB, reclaiming 3,614.5 MB. SQLite quick-check returned `ok`.
Runtime closeout: Launchd service definition matches. Wrapper PID 20572 supervises gateway child PID 20578 at v0.20.5 / 8804e783. Telegram and Photon connected, cron ticks, Camofox returns HTTP 200 and Computer Use performs live app discovery.
What changed: Ran `hermes update --backup --yes` from d71033a4 to 8804e783. Hermes reports v0.20.5. Two later Desktop-only commits remain for the next normal update.
Backup proof: The updater printed the full-backup banner before mutation. `/Users/boydbowker/.hermes/backups/pre-update-2026-08-23-174745.zip` is 5.3 GB and passed full compressed-data integrity.
Maintenance result: All 8 configs are schema 38 with concurrency 3. Memory-gate v3, stock skills, cron routes, compact session storage, launchd supervision, Camofox and Computer Use passed.
Result: Rebuilt the external-content search index and vacuumed the database. Size fell from 5,537.0 MB to 1,922.5 MB.
Integrity: No conversation data was deleted. SQLite `PRAGMA quick_check` returned `ok`.
Google Workspace: BB service-account and read-only scope policy lives in `workspace-api-operations`; bundled Google Workspace matches stock v1.2. The later generated bytecode cache moved to Trash with BB approval.
Hermes Agent: BB operations policy now lives in `bb-hermes-ops`; bundled Hermes Agent matches stock v3.2.
OCR and coder Claude: Stock OCR is restored in root plus all 7 profiles. Coder Claude policy moved to `autonomous-coding-agents`; coder `claude-code` matches stock.
Ownership: Orchestrator 2.1.2 comments the worker target, blocks only its own task at the revision cap and escalates.
Status: Ops SKILL, anomaly catalog, examples and starter prompt use native `running` status.
Review choice: BB downstream reviewer cards remain supported. Native same-card review is optional.
What changed: Ran hermes update --backup --yes from b9b463f3 to d71033a4. Hermes now reports v0.19.0 and up to date.
Validation: Repo clean; Camofox localhost-only and healthy; all seven role-skill symlinks intact; Context7 and Linear MCP connected; Computer Use doctor passed; Telegram and Photon reached ready state.
Open maintenance: The launchd plist is stale relative to v0.19.0. Updating it requires a separately approved gateway restart.
Problem: The reviewer skill instructed a dispatcher-spawned reviewer to complete or block the producer's task. v0.19.0 rejects foreign lifecycle mutations and has no reviewer exception.
Fix: Orchestrator 2.1.1, reviewer 2.2.0, linked role guidance and coder success exits now use cross-task comments for evidence and the reviewer's own task as the gate. Revise creates a correction card and blocks the reviewer's own gate.
Proof: Temporary real Kanban databases confirmed foreign complete/block are rejected, foreign comment succeeds, approve completes the reviewer gate, and revise creates a ready correction card while leaving the producer done.
Path gate: Memory-gate v3 parses V4A Add, Update, Delete and both Move endpoints and gates the full patch when any protected target appears.
Session gate: Interactive CLI and Telegram lineage is allowed; cron, subagent, missing and unknown sources block.
Approval gate: One-shot approval is bound to exact content via `yes save <scope> <sha12>`. Changed content cannot reuse old approval.
Proof: `fail_closed: true` is active across all 8 configs. Every hook doctor and the durable 28-test verifier pass.
What changed: Ran hermes update --backup from 449706cb to b9b463f3 after precheck found 183 upstream commits.
Validation: Repo clean, gateway launchd-supervised, Context7 and Linear MCP connected, Camofox health OK on 127.0.0.1, worker skill symlinks OK.
DB maintenance: hermes sessions optimize completed and SQLite PRAGMA quick_check returned ok; database stayed around 3.28 GB.
Evidence: Files appeared under apps/desktop/src and apps/shared/src around update time and matched generated JavaScript output.
Cleanup: Moved to ~/.Trash/hermes-generated-js-post-update-20260710-191358; git status is clean afterward.
Delivery protection: v0.19.0 adds a durable delivery-obligation ledger so finished replies can survive a gateway restart. This run did not perform a destructive crash test.
Current model: Default model is now openai-codex gpt-5.6-sol. The configured fallback entries are blank, so Hermes reports no active fallback providers.
What changed: The update includes perf(skills): speed up snapshot prompt builds, dashboard/session query offloading, and state-query compact rows.
What this means: Less waiting around the parts of Hermes that build prompts, list sessions, and render dashboard/status surfaces.
Recommended use: No behaviour change. Treat it as background speed.
What changed: Fallback providers reload for live sessions, fallback-chain refresh hardening, delegation completion/session-boundary fixes, webhook route scripts off the event loop, and webhook payload filters.
Local check: Gateway is supervised by launchd at PID 4420. Fresh logs show Telegram connected, Photon sidecar listening on 127.0.0.1:8789, and gateway running with 2 platforms.
What changed: Compression now has a 75% trigger floor under 512K, no summary output cap, and reasoning-trace exclusion. Session message API pagination and offset handling were fixed.
What this means: Long chats should be less likely to churn or lose useful shape during compaction.
What happened: During lazy backend refresh, platform.matrix failed its pip install/build refresh. Hermes kept the previous installed version.
What this means: Not a blocker for Boyd’s active Telegram/Photon setup. It matters only if Matrix is used.
Action: No action. Broad Terminal Full Disk Access was not granted and is not recommended under BB security policy.
What remains custom: BB-specific message content, Obsidian delivery markers and policy checks still sit above the native ledger.
Action: No repair required.
Why it fits: This Mac runs a launchd gateway plus seven profiles. `hermes update --plan` now inventories the install, running supervisor and intended restart path before mutation.
Current proof: The plan detected the launchd gateway and named `launchctl kickstart` as the intended restart route. No receipt exists for this run because the command started on v0.19 code before the receipt feature was installed.
--plan` before future updates and verify `logs/update_receipts/latest.json` afterward.Why it fits: Scheduled research and verification jobs have different cost and reasoning needs. Per-job reasoning can keep simple checks cheap and reserve higher effort for analysis.
Safety boundary: Inference pins and reasoning levels are user-owned. Review jobs individually rather than changing all 19 at once.
Current state: Gateway v0.20.5 is live under current launchd supervision. Test through ordinary use.
Why it fits: This setup has many local and modified skills. Install-time evaluation reduces the chance that a weak or unsafe skill enters the active prompt.
Current proof: `hermes worktree list --repo ~/.hermes/hermes-agent` returned nothing to reclaim.
Fit: Useful only if BB deliberately moves specialist profiles into Bot Mode or the Desktop app.
What changed: The update adds grok-4.5 GA to the model catalog, with context lengths and reasoning-effort allowlist.
What changed: Gateway gained webhook payload filters and docs coverage for filters plus route scripts.
v0.20.6 at 10b38830 to v0.21.3 at 64a9b432.Context7, isolated Kanban handlers and SQLite quick_check.Installed v0.21.3, upgraded Computer Use, migrated all eight configs to schema 45, refreshed gateway launchd state and enabled schema-default Connections entries.
Telegram, Photon, Camofox, Context7, memory-gate, worker profiles, cron inventory, Kanban mechanics and session DB integrity passed. No rollback is needed.
pre-update-2026-09-16-170022.zip passed compressed-data integrity.Restored safe automatic update backups, repaired the gateway service definition, removed stale Stitch current-state documentation, disabled unavailable Hindsight, reconciled the native memory proposal, reviewed modified bundled skills, and completed live closeout checks.
ImpactHermes is v0.20.6 at 10b38830. Config, gateway state, Telegram, Photon, Context7, Camofox, Computer Use and the required profile skill links passed. No update ran during remediation.
v0.20.6 at 10b38830.Context7, Camofox and Computer Use passed.v0.20.6 and 10b38830 markers.6,379 commits installed. The release includes safer update planning and receipts, mid-turn steering, session storage compaction, per-job cron reasoning, worktree cleanup, install-time skill evaluation, Bot Mode improvements and broad runtime reliability work.
ImpactHermes is v0.20.5 at 8804e783. Config fleet schema 38, concurrency 3, memory-gate v3, stock-tracking bundled skills, compact session storage, current launchd supervision, Telegram, Photon, cron, Camofox and Computer Use all passed.
v0.19.0 at d71033a4, clean tree and 6,377 commits behind.8804e783 after a verified 5.3 GB full backup.v0.20.5; Telegram and Photon connected.Context7 and Computer Use passed.3,145 commits installed across the Quicksilver release and 1,712 later mainline commits. Major areas include startup speed, durable delivery, delegation lifecycle, multi-profile gateways, provider routing, secret sources, approvals, security and desktop/TUI performance.
ImpactHermes is v0.19.0 at d71033a4 with a clean repo. Camofox, role-skill symlinks, Context7, Linear, Computer Use, Telegram and Photon passed. Orchestrator 2.1.1, reviewer 2.2.0 and linked guidance now match the v0.19 ownership guard; direct approve and revise runtime tests passed. Memory-gate still has an unpatched V4A bypass and session-lineage false block. The gateway service definition needs a quiet-window refresh.
v0.18.2 at b9b463f3, clean tree, 3,145 commits behind d71033a4.~/.hermes/backups/pre-update-2026-07-27-120649.zip, 5.8 GB.v0.19.0 at d71033a4 and up to date.Context7 and Linear MCP connected. Computer Use doctor passed.716 commits pulled. Notable changes include faster skill snapshot prompt builds, fallback-provider reload hardening, dashboard/session DB responsiveness, compression-thrash protection, webhook payload filters, session-message pagination fixes, Grok 4.5 catalog support, and broad gateway/MCP/runtime hardening.
ImpactLocal system is healthy after update: repo clean, gateway supervised and freshly restarted, Telegram and Photon connected, Camofox localhost-only and healthy, all worker profile symlinks intact, Context7 and Linear MCP enabled. Matrix backend refresh warning is the only watch item.
v0.18.0 at upstream 30e947e0; repo clean; update available.~/.hermes/backups/pre-update-2026-07-08-222918.zip (4.6 GB). Restore command: hermes import /Users/boydbowker/.hermes/backups/pre-update-2026-07-08-222918.zip.hermes-agent==0.18.2 at upstream 449706cb.v0.18.2 (2026.7.7.2), upstream 449706cb, up to date, repo clean.context7 and linear enabled; Dropbox MCP disabled by config.v0.18.0 is the Judgment Release: P0/P1 cleanup, first-class Mixture-of-Agents, completion contracts and verification evidence, /learn and /journey, background delegation fan-out, desktop coding Projects, gateway scale-to-zero and drain coordination, Vertex AI support, and a broad security hardening round.
The local system is on v0.18.0 at upstream 30e947e0. Repo is clean. Gateway is supervised by launchd and Telegram is live. Camofox remains bound to 127.0.0.1. All seven worker profile skill symlinks survived. OpenAI Codex and Kimi smokes returned OK. The practical work now is to decide which new v0.18 capabilities are worth piloting, without turning the tool into the mission.
v0.18.0 (2026.7.1) at upstream 30e947e0.v0.17.0 at 2ecca1e7d.v2026.7.1 present.gpt-5.5 returned OK; kimi-coding / kimi-k2.6 returned OK.Upstream Kanban added typed block reasons and loop protection. Backups now include project databases, Kanban boards, sibling stores, response store, memory store, and verification evidence. Gateway model-switching no longer blocks the event loop. Security redaction expanded. CuaDriver upgraded from 0.6.5 to 0.6.8.
ImpactKanban patch kept and verified. Rollback coverage is now more complete. No other process changes.
Decisions and Actions3e99ec0ff to 2ecca1e7d. Public version remains v0.17.0.~/.hermes/backups/hermes-update-20260627-225918/local-kanban-diff.patch.~/.hermes/backups/pre-update-2026-06-27-225937.zip, 3.9 GB. Snapshot 20260627-220547-pre-update.v0.17.0 at upstream 2ecca1e7d, Camofox localhost bind intact, profile symlinks intact, gateway launchd supervision healthy, Telegram connected, Context7 MCP passed, Linear MCP passed, Kanban patch compiles and imports.361 commits pulled. Package-lock.json was dirty pre-update. Incoming changes touched the Anthropic adapter. CuaDriver upgraded to 0.6.5. Python dependencies refreshed, web UI and desktop app rebuilt.
ImpactNo local patches affected. Cron runs from before this update showed network timeouts. Reassessment scheduled after next cron runs.
Decisions and Actions5a53e0f0f to 5ecf3bf0e. Public version remains v0.17.0.~/.hermes/backups/pre-update-2026-06-23-160840.zip, 2.7 GB. Snapshot 20260623-151120-pre-update.v0.17.0 at upstream 5ecf3bf0, repo clean, Camofox localhost bind intact, Camofox health OK, profile symlinks intact, gateway restarted under launchd, Telegram connected, Context7 MCP lookup passed, local MCP list passed.Released hermes-agent==0.17.0. 509 commits pulled. Web UI rebuilt. Desktop packaged app rebuilt. CuaDriver upgraded to 0.5.7. SOP hook-table drift found and fixed. SOP updated to exclude Claude/Anthropic unless BB explicitly requests.
Major version jump. No breaking changes to Boyd's setup. OpenAI Codex and Kimi provider checks passed. Follow-up fixes completed in the same session.
Decisions and Actionsv2026.6.19.gpt-5.5. Manual snapshot 20260619-215158-pre-update.~/.hermes/backups/pre-update-2026-06-19-225453.zip.hermes-agent==0.17.0, web UI built, desktop packaged app rebuilt, CuaDriver upgraded to 0.5.7, gateway restarted.v0.17.0, repo clean, Camofox localhost bind intact, profile symlinks intact, gateway loaded and Telegram connected, delegation smoke passed, Context7 MCP lookup passed, Kanban schema scan clean.gpt-5.5 returned OK. Kimi kimi-k2.6 returned OK. OpenRouter smoke skipped (per-token, not required by SOP).416 commits, same version tag, fast-forward from 6110aed9b to 4e6d05c6a. Pre-update zip backup created.
Camofox localhost patch intact, 7 profile symlinks intact, gateway service loaded, Telegram connected. Stitch MCP was not configured at this point.
Decisions and Actions6110aed9b to 4e6d05c6a.~/.hermes/backups/pre-update-2026-06-14-202134.zip.Context7 passed. Stitch MCP was not configured.530 commits between 5af899c7c and 6110aed9b. Gateway fell back to background process because launchd bootstrap hit exit 5. Telegram reconnected and cron ticker ran.
Drift discovered: launchd plist stale, Telegram pause patch clobbered, degraded-send-path patch absorbed upstream. All resolved by the 2026-06-14 update session. SOP changed to make Claude smokes opt-in.
Decisions and Actions5af899c7c and 6110aed9b.20260610-191100-pre-update2 saved.227 commits, tag v2026.6.5. Claude OAuth expired, only env-var credential active. Dirty repo had prompt_caching.py and package-lock noise.
Interactive Claude login ran during update. SOP-001 rewritten to use interactive login path and drop setup-token. Kanban orchestrator drift found but resolved: stock playbook load was correct, no full merge needed.
v2026.6.5.SOP-001 rewritten to use that path and drop setup-token.40-Projects/claude-oauth-safety-guardrails/sops/update-gate.md. The stable URL is https://hermes-vault.pages.dev/briefs/hermes-update/.