Compare commits

..

3 Commits

Author SHA1 Message Date
f4dd57fa60 fix: add start-hermes.sh baked into image, replace broken ENTRYPOINT
Some checks failed
Build Hermes agent / build (pull_request) Has been cancelled
Build ollama (gfx906) / build (pull_request) Has been cancelled
- New start-hermes.sh: multi-profile launcher that works with s6-overlay's
  main-program model (replaces bash->tini->entrypoint.sh chain)
- Dockerfile: COPY start-hermes.sh into /usr/local/bin/ alongside
  run-multi-gateways.sh (which is now unused but kept for reference)
- compose.yml: remove entrypoint override, CMD now points at
  /usr/local/bin/start-hermes.sh via the image default ENTRYPOINT

Fixes the SIGTERM crash loop caused by S6_CMD_ARG0 being unset when the
deprecated entrypoint.sh shim bypassed s6-overlay's /init.
2026-07-07 21:58:41 -04:00
a6b25ee84d fix: replace broken ENTRYPOINT override with s6-overlay compatible CMD
The custom ENTRYPOINT chained bash -> tini -g -> deprecated entrypoint.sh,
bypassing s6-overlay's /init entirely. This left S6_CMD_ARG0 unset and the
orphan -g flag crashed rc.init with '-g: not found' -> SIGTERM -> restart loop.

Fix:
- Remove the ENTRYPOINT override so the image default is used:
  ENTRYPOINT ['/init', '/opt/hermes/docker/main-wrapper.sh']
- Change CMD to point at /opt/data/start-hermes.sh, a new launcher
  that starts per-profile gateways in background then the default
  gateway in foreground (via s6-overlay's main-program model).

The old /usr/local/bin/run-multi-gateways.sh is no longer called.
2026-07-07 21:56:33 -04:00
54e0661396 fix: add missing USER hermes at end of Dockerfile
The Dockerfile was switching to USER root for the final chown but never
switched back to USER hermes. This caused ALL container processes to run
as root (uid 0) instead of the hermes user (uid 10000).

The entrypoint's gosu privilege drop only caught the main exec chain,
leaving backgrounded subprocesses (dashboard PTY sessions, workers with
start_new_session=True) running as root — creating files owned by root
in ExoKortex and breaking Syncthing sync.

Adding USER hermes at the end ensures the container runs unprivileged
and ALL child processes inherit uid 10000 from the start.
2026-07-07 14:58:44 -04:00
3 changed files with 54 additions and 6 deletions

View File

@@ -6,19 +6,19 @@ services:
ssh:
- default
container_name: hermes
entrypoint: ["/bin/bash", "-c",
"bash /usr/local/bin/run-multi-gateways.sh && exec /usr/bin/tini -g -- /opt/hermes/docker/entrypoint.sh \"$@\"",
"hermes-entrypoint"]
restart: always
# Gateway run enables the internal API server on port 8642
command: gateway run
# Use the image default ENTRYPOINT ["/init", "/opt/hermes/docker/main-wrapper.sh"]
# for proper s6-overlay supervision. The CMD runs our multi-profile launcher
# which spawns per-profile gateways in background, then the default gateway
# in foreground (keeps the container alive).
command: ["/usr/local/bin/start-hermes.sh"]
environment:
- HERMES_UID=10000
- HERMES_GID=10000
- OLLAMA_HOST=http://ollama:11434
- HERMES_DASHBOARD=1
# Multi-profile: comma-separated list of profiles to run as gateways.
# The entrypoint reads this and starts one gateway per profile.
# start-hermes.sh reads this and starts one gateway per profile.
# Add profiles here when they exist on disk (e.g. default,researcher,writer)
- HERMES_PROFILES=ashley,claire,finn,matt,paul
- API_SERVER_ENABLED=true

View File

@@ -62,6 +62,11 @@ PYEOF
# Launches one gateway process per profile (HERMES_PROFILES env var)
COPY --chmod=0755 run-multi-gateways.sh /usr/local/bin/run-multi-gateways.sh
# ---------- Install s6-overlay compatible startup script ----------
# Runs as the CMD via s6-overlay's main-program model.
# Replaces the old bash->tini->entrypoint.sh chain that caused SIGTERM crash loops.
COPY --chmod=0755 start-hermes.sh /usr/local/bin/start-hermes.sh
# ---------- Runtime ----------
USER hermes
ENV HERMES_HOME=/opt/data
@@ -75,3 +80,8 @@ USER root
RUN chown -R hermes:hermes /opt/hermes/tools /opt/hermes/toolsets.py
VOLUME [ "/opt/data" ]
# Switch to the hermes user so the container runs unprivileged.
# All child processes inherit this user — no more orphan root processes
# that escape gosu privilege drops in the entrypoint.
USER hermes

38
ai/hermes/start-hermes.sh Normal file
View File

@@ -0,0 +1,38 @@
#!/bin/bash
# Multi-profile + default gateway launcher — runs as the CMD via s6-overlay.
#
# The image's default ENTRYPOINT ["/init", "/opt/hermes/docker/main-wrapper.sh"]
# starts the s6 supervision tree, then exec's main-wrapper.sh with the CMD args.
# main-wrapper.sh sources the venv, drops to the hermes user via s6-setuidgid,
# and exec's this script.
#
# This script:
# 1. Launches per-profile background gateways (HERMES_PROFILES env var)
# 2. Starts the default gateway in foreground (keeps the container alive)
#
# Replaces the old approach of chaining bash -> tini -g -> deprecated entrypoint.sh
# which bypassed s6-overlay and caused the SIGTERM crash loop.
set -e
HERMES_BIN="/opt/hermes/.venv/bin/hermes"
# --- Multi-profile gateways (background) ---
if [ -n "${HERMES_PROFILES:-}" ]; then
echo "[start-hermes] Launching per-profile gateways: ${HERMES_PROFILES}"
IFS=',' read -ra PROFILES <<< "${HERMES_PROFILES}"
for profile in "${PROFILES[@]}"; do
profile="$(echo "${profile}" | xargs)" # trim whitespace
[ -z "${profile}" ] && continue
echo "[start-hermes] -> background gateway for profile '${profile}'"
# No gosu/s6-setuidgid needed — we're already running as the hermes user
# (main-wrapper.sh drops privileges before exec'ing this script).
nohup "${HERMES_BIN}" --profile "${profile}" gateway run \
>> "/opt/data/logs/gateway-${profile}.log" 2>&1 &
done
echo "[start-hermes] All profile gateways launched"
fi
# --- Default gateway (foreground — keeps container alive) ---
echo "[start-hermes] Starting default gateway (foreground)"
exec "${HERMES_BIN}" gateway run