treefmt-check
checks.x86_64-linux.treefmt
· build #165
· raw
1treefmt v2.6.0traversed 580 files2emitted 384 files for processing3formatted 384 files (8 changed) in 889ms4 M modules/nixos/hermes/agent-config.nix5 M modules/nixos/hermes/cli.nix6 M modules/nixos/hermes/guest.nix7 M modules/nixos/hermes/host.nix8 M modules/nixos/hermes/options.nix9 M modules/nixos/hermes/simplex.nix10 M packages/spaces-integration-gateway/gateway-core.ts11 M tests/hermes.nix12diff --git a/modules/nixos/hermes/agent-config.nix b/modules/nixos/hermes/agent-config.nix13index 417f808..1b03671 10064414--- a/modules/nixos/hermes/agent-config.nix15+++ b/modules/nixos/hermes/agent-config.nix16@@ -148,16 +148,15 @@ rec {17 # is the venv ROOT, not its bin dir.18 # Callers append config.nix.package when the user has config repos;19 # this file has no `config`.20- path =21- [22- "${stateDir}/.venv"23- hermesPackage24- pkgs.bash25- pkgs.coreutils26- pkgs.git27- ]28- ++ basePackages29- ++ cfg.extraPackages;30+ path = [31+ "${stateDir}/.venv"32+ hermesPackage33+ pkgs.bash34+ pkgs.coreutils35+ pkgs.git36+ ]37+ ++ basePackages38+ ++ cfg.extraPackages;39 hasConfigRepos = repos.dirs != [ ];40 };41 # The config repos this user's agent edits. ./options.nix,42diff --git a/modules/nixos/hermes/cli.nix b/modules/nixos/hermes/cli.nix43index b2b5f04..5577de6 10064444--- a/modules/nixos/hermes/cli.nix45+++ b/modules/nixos/hermes/cli.nix46@@ -47,7 +47,9 @@ let47 lib.mapAttrsToList (user: ucfg: ''48 ${user})49 ADDRESS_FILE=${hlib.simplexAddressFile user}50- AGENT_UNIT=${if ucfg.native then "hermes-simplex-address-${user}" else "microvm@${hlib.vmName user}"}51+ AGENT_UNIT=${52+ if ucfg.native then "hermes-simplex-address-${user}" else "microvm@${hlib.vmName user}"53+ }54 ;;55 '') cfg.enabledUsers56 );57@@ -78,7 +80,9 @@ let58 in59 ''60 ${user})61- ${lib.concatStringsSep "\n " (lib.mapAttrsToList (n: v: "export ${n}=${lib.escapeShellArg v}") env)}62+ ${lib.concatStringsSep "\n " (63+ lib.mapAttrsToList (n: v: "export ${n}=${lib.escapeShellArg v}") env64+ )}65 export PATH=${lib.escapeShellArg (lib.makeBinPath path)}:"$PATH"66 export LD_LIBRARY_PATH=${lib.escapeShellArg rt.env.LD_LIBRARY_PATH}"''${LD_LIBRARY_PATH:+:$LD_LIBRARY_PATH}"67 ;;68diff --git a/modules/nixos/hermes/guest.nix b/modules/nixos/hermes/guest.nix69index 5378741..202a969 10064470--- a/modules/nixos/hermes/guest.nix71+++ b/modules/nixos/hermes/guest.nix72@@ -347,7 +347,7 @@ in73 stateDir = guestStateDir;74 workingDirectory = guestWorkspace user;75 addToSystemPackages = true;76- settings = ac.settings;77+ inherit (ac) settings;78 environment =79 nixAgentEnv80 // ac.simplexEnv {81@@ -361,7 +361,8 @@ in82 HERMES_SANDBOX = "microvm";83 };84 inherit (cfg) extraPlugins;85- extraPackages = basePackages ++ cfg.extraPackages ++ lib.optional nixosConfigEnabled config.nix.package;86+ extraPackages =87+ basePackages ++ cfg.extraPackages ++ lib.optional nixosConfigEnabled config.nix.package;88 mcpServers = lib.optionalAttrs ucfg.spacesGateway.enable {89 spaces = {90 command = "${pkgs.socat}/bin/socat";91diff --git a/modules/nixos/hermes/host.nix b/modules/nixos/hermes/host.nix92index 04b66e7..65731fd 10064493--- a/modules/nixos/hermes/host.nix94+++ b/modules/nixos/hermes/host.nix95@@ -310,20 +310,20 @@ in96 ))97 (forEachVmUser (98 user: ucfg: {99- "hermes-spaces-bridge-${user}" = lib.mkIf ucfg.spacesGateway.enable {100- description = "spaces bridge socket for ${vmName user}";101- wantedBy = [ "sockets.target" ];102- # "vsock::<port>" binds VMADDR_CID_ANY on the host.103- listenStreams = [ "vsock::${toString (spacesVsockPort user)}" ];104- socketConfig.Accept = true;105- # Any guest can complete a vsock connect. The helper rejects it106- # post-accept. So a hostile sibling microVM could trip the107- # Accept=yes trigger limit. That limit is 200 per 2s. Then it108- # could fail the socket. This is a cross-VM DoS. Rejected109- # instances exit within milliseconds. MaxConnections bounds the110- # buildup.111- socketConfig.TriggerLimitIntervalSec = 0;112- };113+ "hermes-spaces-bridge-${user}" = lib.mkIf ucfg.spacesGateway.enable {114+ description = "spaces bridge socket for ${vmName user}";115+ wantedBy = [ "sockets.target" ];116+ # "vsock::<port>" binds VMADDR_CID_ANY on the host.117+ listenStreams = [ "vsock::${toString (spacesVsockPort user)}" ];118+ socketConfig.Accept = true;119+ # Any guest can complete a vsock connect. The helper rejects it120+ # post-accept. So a hostile sibling microVM could trip the121+ # Accept=yes trigger limit. That limit is 200 per 2s. Then it122+ # could fail the socket. This is a cross-VM DoS. Rejected123+ # instances exit within milliseconds. MaxConnections bounds the124+ # buildup.125+ socketConfig.TriggerLimitIntervalSec = 0;126+ };127 }128 ))129 ];130diff --git a/modules/nixos/hermes/options.nix b/modules/nixos/hermes/options.nix131index 58a1db3..e5d55e1 100644132--- a/modules/nixos/hermes/options.nix133+++ b/modules/nixos/hermes/options.nix134@@ -592,9 +592,7 @@ in135 # this covers the MAC too.136 map (fn: {137 assertion =138- !ucfg.enable139- || ucfg.native140- || lib.count (u: hlib.${fn} u == hlib.${fn} user) vsockUsers == 1;141+ !ucfg.enable || ucfg.native || lib.count (u: hlib.${fn} u == hlib.${fn} user) vsockUsers == 1;142 message = "services.hermes-microvm: ${fn} collision on ${user} — rename one of the colliding users or disable one VM (services.hermes-microvm.users.<name>.enable = false).";143 }) [ "cidFor" ]144 ) cfg.users145@@ -633,7 +631,9 @@ in146 ++ lib.mapAttrsToList (user: ucfg: {147 assertion =148 !(ucfg.enable && ucfg.native)149- || lib.count (u: u.enable && u.native && u.simplexPort == ucfg.simplexPort) (lib.attrValues cfg.users) == 1;150+ ||151+ lib.count (u: u.enable && u.native && u.simplexPort == ucfg.simplexPort) (lib.attrValues cfg.users)152+ == 1;153 message = "services.hermes-microvm: duplicate simplexPort ${toString ucfg.simplexPort} (${user}) — the hash-derived default collided in its 1000-port window; set services.hermes-microvm.users.<name>.simplexPort explicitly on one of them.";154 }) cfg.users;155 };156diff --git a/modules/nixos/hermes/simplex.nix b/modules/nixos/hermes/simplex.nix157index fa8139c..7aac29d 100644158--- a/modules/nixos/hermes/simplex.nix159+++ b/modules/nixos/hermes/simplex.nix160@@ -78,7 +78,10 @@ in161 RestartSec = 5;162 # No prompts: a display-name or migration prompt leaves the unit dead.163 ExecStart =164- if bindPort == null then "${startScript}" else "${daemonArgs} --chat-server-port ${toString bindPort}";165+ if bindPort == null then166+ "${startScript}"167+ else168+ "${daemonArgs} --chat-server-port ${toString bindPort}";169 };170 };171 172diff --git a/packages/spaces-integration-gateway/gateway-core.ts b/packages/spaces-integration-gateway/gateway-core.ts173index 2fac038..94e9c0d 100644174--- a/packages/spaces-integration-gateway/gateway-core.ts175+++ b/packages/spaces-integration-gateway/gateway-core.ts176@@ -113,8 +113,7 @@ export interface McpStep {177 }178 179 export type McpExchangeResult =180- | { ok: true; reply: Record<string, unknown> }181- | { ok: false; reason: string };182+ { ok: true; reply: Record<string, unknown> } | { ok: false; reason: string };183 184 /**185 * One MCP exchange on a fresh unix-socket connection, the "MCP wire". It speaks186diff --git a/tests/hermes.nix b/tests/hermes.nix187index ed7ca7e..77daf78 100644188--- a/tests/hermes.nix189+++ b/tests/hermes.nix190@@ -1532,7 +1532,8 @@ in191 # LoadCredential resolves before the unit's own ExecStartPre, so the192 # dashboard unit must not mint its own token; the agent does.193 agentMintsToken = lib.any (lib.hasInfix "hermes-desktop-token-bob") nativeAgent.serviceConfig.ExecStartPre;194- dashboardMintsNone = !lib.any (lib.hasInfix "hermes-desktop-token") nativeDashboard.serviceConfig.ExecStartPre;195+ dashboardMintsNone =196+ !lib.any (lib.hasInfix "hermes-desktop-token") nativeDashboard.serviceConfig.ExecStartPre;197 afterAgent = lib.elem "hermes-agent-bob.service" nativeDashboard.after;198 wantsAgent = lib.elem "hermes-agent-bob.service" nativeDashboard.wants;199 };200@@ -1552,7 +1553,12 @@ in201 testAgentEnv = {202 expr = {203 inherit (nativeAgent.environment) HOME HERMES_HOME HERMES_SANDBOX;204- inherit (nativeAgent.serviceConfig) User Group WorkingDirectory LoadCredential;205+ inherit (nativeAgent.serviceConfig)206+ User207+ Group208+ WorkingDirectory209+ LoadCredential210+ ;211 gateway = lib.hasSuffix "/bin/hermes gateway" nativeAgent.serviceConfig.ExecStart;212 seedsModel = lib.hasInfix ".model-seeded" nativeSeedAgent.preStart;213 noSeedWithoutModel = lib.hasInfix ".model-seeded" nativeAgent.preStart;214@@ -1590,7 +1596,8 @@ in215 # directly; the uid resolves at run time.216 testSpacesMcp = {217 expr = {218- bob = lib.hasInfix "\"mcp_servers\":{\"spaces\":{\"args\":[],\"command\":\"/nix/store/" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text219+ bob =220+ lib.hasInfix "\"mcp_servers\":{\"spaces\":{\"args\":[],\"command\":\"/nix/store/" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text221 && lib.hasInfix "-hermes-spaces-mcp\"" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text;222 noVsock = lib.hasInfix "VSOCK" nativeSys.services.hermes-microvm.nativeSettingsFiles.bob.text;223 aliceHasNone = nativeSys.services.hermes-microvm.nativeSettingsFiles ? alice;224@@ -1643,7 +1650,7 @@ in225 testShim = {226 expr =227 let228- text = (hermesShimOf nativeSys).text;229+ inherit ((hermesShimOf nativeSys)) text;230 in231 {232 bobNative = lib.hasInfix "bob)\n mode=native" text;233@@ -1693,13 +1700,12 @@ in234 {235 daemonBindsUid = lib.hasInfix "--chat-server-port $((10000 + $(" nativeSimplex.startScript.text;236 bobUsesIt = lib.hasInfix "hermes-simplex-start" (svc "hermes-simplex-bob").serviceConfig.ExecStart;237- aliceUsesIt = lib.hasInfix "hermes-simplex-start" (svc "hermes-simplex-alice").serviceConfig.ExecStart;238- bobAgentDialsPublic =239- lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "bob")}"240- (svc "hermes-agent-bob").preStart;241- aliceAgentDialsPublic =242- lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "alice")}"243- (svc "hermes-agent-alice").preStart;244+ aliceUsesIt = lib.hasInfix "hermes-simplex-start" (svc "hermes-simplex-alice")245+ .serviceConfig.ExecStart;246+ bobAgentDialsPublic = lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "bob")}" (svc "hermes-agent-bob")247+ .preStart;248+ aliceAgentDialsPublic = lib.hasInfix "SIMPLEX_WS_URL=ws://127.0.0.1:${toString (hlib.simplexPortFor "alice")}" (svc "hermes-agent-alice")249+ .preStart;250 addressDialsPublic = (svc "hermes-simplex-address-bob").environment.SIMPLEX_WS_URL;251 distinct = hlib.simplexPortFor "alice" != hlib.simplexPortFor "bob";252 quiet = failedAssertions twoNative;253@@ -1756,8 +1762,11 @@ in254 expr = {255 nativeRefusesVm = lib.any (lib.hasInfix "hermes-native-guard-bob") nativeAgent.serviceConfig.ExecStartPre;256 dashboardToo = lib.any (lib.hasInfix "hermes-native-guard-bob") nativeDashboard.serviceConfig.ExecStartPre;257- vmRefusesNative = lib.any (lib.hasInfix "hermes-vm-guard-alice") nativeSys.systemd.services."microvm-virtiofsd@hermes-alice".serviceConfig.ExecStartPre;258- afterFirewall = lib.elem "hermes-firewall.service" nativeDashboard.after259+ vmRefusesNative =260+ lib.any (lib.hasInfix "hermes-vm-guard-alice")261+ nativeSys.systemd.services."microvm-virtiofsd@hermes-alice".serviceConfig.ExecStartPre;262+ afterFirewall =263+ lib.elem "hermes-firewall.service" nativeDashboard.after264 && lib.elem "hermes-firewall.service" nativeSys.systemd.services."hermes-simplex-bob".after;265 };266 expected = {