Two fixes from the verify lane retro review, independently confirmed by firstmate.
F1 — THE FALSE POSITIVE
agent-health-check.py hardcoded /root/ when looking for the Hermes CLI wrapper, so it reported wrapper-missing:tanko for an agent that has a perfectly good wrapper at /home/jerome/.local/bin/hermes.
Fix: Added get_user_home(user) helper that resolves the home directory from the agent user field. Used in every leg that touches a user home (wrapper, hermes-real, .env, config.yaml).
Proof: Old code reported wrapper-missing:tanko. New code reports tanko healthy.
F2 — STALE REFERENCES
tanko is HYBRID (DSH + Hermes) since 2026-08-27, but four files still said otherwise:
hermes-zulip-restore.prose.md (3 lines)
hermes-zulip-plugin.prose.md (3 lines)
infrastructure-control.prose.md (1 line)
docs/probe-drift-round2-evidence.md (6 lines)
Fix: Updated each to describe tanko as hybrid. For the evidence doc, added a historical note explaining that the DSH-only observations reflected the /root/ hardcoding bug, not the underlying truth — a silently-updated evidence doc is worse than a stale one.
Out of scope
tanko runtime value unchanged (hybrid is correct)
nothing installed on tanko
koby hosts read-only
## Summary
Two fixes from the verify lane retro review, independently confirmed by firstmate.
### F1 — THE FALSE POSITIVE
agent-health-check.py hardcoded /root/ when looking for the Hermes CLI wrapper, so it reported wrapper-missing:tanko for an agent that has a perfectly good wrapper at /home/jerome/.local/bin/hermes.
**Fix:** Added get_user_home(user) helper that resolves the home directory from the agent user field. Used in every leg that touches a user home (wrapper, hermes-real, .env, config.yaml).
**Proof:** Old code reported wrapper-missing:tanko. New code reports tanko healthy.
### F2 — STALE REFERENCES
tanko is HYBRID (DSH + Hermes) since 2026-08-27, but four files still said otherwise:
- hermes-zulip-restore.prose.md (3 lines)
- hermes-zulip-plugin.prose.md (3 lines)
- infrastructure-control.prose.md (1 line)
- docs/probe-drift-round2-evidence.md (6 lines)
**Fix:** Updated each to describe tanko as hybrid. For the evidence doc, added a historical note explaining that the DSH-only observations reflected the /root/ hardcoding bug, not the underlying truth — a silently-updated evidence doc is worse than a stale one.
## Out of scope
- tanko runtime value unchanged (hybrid is correct)
- nothing installed on tanko
- koby hosts read-only
F1: agent-health-check.py now resolves the home directory from the agent's
user field via a shared helper (get_user_home) instead of hardcoding /root/.
This fixes the false-positive wrapper-missing:tanko report — tanko has a
working wrapper at /home/jerome/.local/bin/hermes, but the check was looking
in /root/.local/bin/.
F2: Updated stale references that described tanko as DSH-only:
- hermes-zulip-restore.prose.md: tanko excluded — hybrid (DSH + Hermes)
- hermes-zulip-plugin.prose.md: tanko excluded — hybrid (DSH + Hermes)
- infrastructure-control.prose.md: tanko is hybrid (DSH + Hermes) agent
- docs/probe-drift-round2-evidence.md: marked as historical record with
dated note explaining that the DSH-only observations reflected the
/root/ hardcoding bug, not the underlying truth
Refs: fix/agent-health-root-hardcoding-20260928
- Fixed line 537: f-string now uses single quotes inside double-quoted shell
command to avoid nested quote collision
- Added home = get_user_home(user) to check_config_integrity loop scope so
the config check can resolve the correct home directory
The fleet's wrappers do not all use a hermes-real indirection. Some (tanko,
mumuni) exec the venv module directly. This check now:
1. Tries hermes-real at {home}/.local/bin (koonimo's shape)
2. Tries the venv under {home}/.hermes/hermes-agent/venv (tanko/mumuni shape)
3. Tries /usr/local/lib/hermes-agent/venv (legacy system-wide shape)
Each match is reported with which shape it matched, so a genuinely broken
wrapper is still a failure while a different-but-valid shape is not.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Summary
Two fixes from the verify lane retro review, independently confirmed by firstmate.
F1 — THE FALSE POSITIVE
agent-health-check.py hardcoded /root/ when looking for the Hermes CLI wrapper, so it reported wrapper-missing:tanko for an agent that has a perfectly good wrapper at /home/jerome/.local/bin/hermes.
Fix: Added get_user_home(user) helper that resolves the home directory from the agent user field. Used in every leg that touches a user home (wrapper, hermes-real, .env, config.yaml).
Proof: Old code reported wrapper-missing:tanko. New code reports tanko healthy.
F2 — STALE REFERENCES
tanko is HYBRID (DSH + Hermes) since 2026-08-27, but four files still said otherwise:
Fix: Updated each to describe tanko as hybrid. For the evidence doc, added a historical note explaining that the DSH-only observations reflected the /root/ hardcoding bug, not the underlying truth — a silently-updated evidence doc is worse than a stale one.
Out of scope
The fleet's wrappers do not all use a hermes-real indirection. Some (tanko, mumuni) exec the venv module directly. This check now: 1. Tries hermes-real at {home}/.local/bin (koonimo's shape) 2. Tries the venv under {home}/.hermes/hermes-agent/venv (tanko/mumuni shape) 3. Tries /usr/local/lib/hermes-agent/venv (legacy system-wide shape) Each match is reported with which shape it matched, so a genuinely broken wrapper is still a failure while a different-but-valid shape is not.