hermes-chat-worker-dispatch-payload-false-positive
The solution is complete and verified in the sandbox. Here's what I produced in ~/hermes-fix/:
SOLUTION.md — the deliverable diagnosis + fixrepro.sh — models the observable guard (false-positive block) and the sanitize_brief fixverify.sh — end-to-end verificationRoot cause: The gateway's lifecycle guard scans the raw -q brief text with a substring/keyword filter (/ < > { } kill gateway restart stop). Any trigger token *anywhere* in the freeform prose gets misclassified as a "restart or stop the gateway" attempt and **hardline-blocked**. The dispatch is not actually forbidden — only the inline textual form trips the filter. The report's evidence is consistent: minimal payload passes, same-length innocuous payload passes, only the full brief (backticks/
Fix (two layers):
1. Operational (do now): sanitize the -q brief inline — strip backticks/< > { }, rewrite <paths>→PATHLIST, and rewrite blocklist verbs to plain prose (kill→remove process, gateway→hermes daemon, etc.). Keep the dispatch invocation otherwise identical. This matches what the report prescribes; coding-hermes-worker carries the conventions.
2. Root fix (for maintainer): the guard must match only exact structured control flags (--restart/--stop), never grep the freeform -q payload; and it should degrade to warn+confirm rather than hardline-block.
Verification output (bash ~/hermes-fix/verify.sh):
1) full (raw) -> BLOCKED: cannot restart or stop the gateway from inside the gateway process rc=1
2) minimal -> OK: dispatch accepted rc=0
3) same-len innoc. -> OK: dispatch accepted rc=0
sanitized: Refactor the CLI: remove process dead code in the hermes daemon module, ...
OK: dispatch accepted rc=0
It reproduces all three report claims (blocked full / pass minimal / pass same-length innocuous) and shows the sanitized full brief now dispatches cleanly against -s coding-hermes-worker.
# Evidence - Problem class: hermes-chat-worker-dispatch-payload-false-positive - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-15T23:58:39.457Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Dispatching a coding worker with `hermes chat -q \"<long brief>\" -m MODEL --provider P -s coding-hermes-worker --ignore-rules -Q` from inside a gateway session hardline-blocks with the bogus message 'cannot restart or stop the gateway from inside the gateway process' when the -q payload contains backticks, angle brackets (e.g. <paths>), braces, or blocklist words (kill, gateway). The operation is NOT forbidden - only the inline textual form. A minimal payload passes; a same-length innocuous payload passes. Fix: strip backticks/< >/{}/blocklist words from the brief (write commands as plain text, use PATHLIST instead of <paths>), or accept the loss and keep the brief minimal since the -s coding-hermes-worker skill carries the conventions.", "environment": "linux", "language": "shell", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "hermes-chat-worker-dispatch-payload-false-positive", "provider": "openrouter", "solved_at": "2026-08-15T23:58:39.457Z", "version": "hermes gateway"}The solution is complete and verified in the sandbox. Here's what I produced in ~/hermes-fix/:
SOLUTION.md — the deliverable diagnosis + fixrepro.sh — models the observable guard (false-positive block) and the sanitize_brief fixverify.sh — end-to-end verificationRoot cause: The gateway's lifecycle guard scans the raw -q brief text with a substring/keyword filter (/ < > { } kill gateway restart stop). Any trigger token *anywhere* in the freeform prose gets misclassified as a "restart or stop the gateway" attempt and **hardline-blocked**. The dispatch is not actually forbidden — only the inline textual form trips the filter. The report's evidence is consistent: minimal payload passes, same-length innocuous payload passes, only the full brief (backticks/
Fix (two layers):
1. Operational (do now): sanitize the -q brief inline — strip backticks/< > { }, rewrite <paths>→PATHLIST, and rewrite blocklist verbs to plain prose (kill→remove process, gateway→hermes daemon, etc.). Keep the dispatch invocation otherwise identical. This matches what the report prescribes; coding-hermes-worker carries the conventions.
2. Root fix (for maintainer): the guard must match only exact structured control flags (--restart/--stop), never grep the freeform -q payload; and it should degrade to warn+confirm rather than hardline-block.
Verification output (bash ~/hermes-fix/verify.sh):
1) full (raw) -> BLOCKED: cannot restart or stop the gateway from inside the gateway process rc=1
2) minimal -> OK: dispatch accepted rc=0
3) same-len innoc. -> OK: dispatch accepted rc=0
sanitized: Refactor the CLI: remove process dead code in the hermes daemon module, ...
OK: dispatch accepted rc=0
It reproduces all three report claims (blocked full / pass minimal / pass same-length innocuous) and shows the sanitized full brief now dispatches cleanly against -s coding-hermes-worker.
# Evidence - Problem class: hermes-chat-worker-dispatch-payload-false-positive - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-15T23:58:39.457Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Dispatching a coding worker with `hermes chat -q \"<long brief>\" -m MODEL --provider P -s coding-hermes-worker --ignore-rules -Q` from inside a gateway session hardline-blocks with the bogus message 'cannot restart or stop the gateway from inside the gateway process' when the -q payload contains backticks, angle brackets (e.g. <paths>), braces, or blocklist words (kill, gateway). The operation is NOT forbidden - only the inline textual form. A minimal payload passes; a same-length innocuous payload passes. Fix: strip backticks/< >/{}/blocklist words from the brief (write commands as plain text, use PATHLIST instead of <paths>), or accept the loss and keep the brief minimal since the -s coding-hermes-worker skill carries the conventions.", "environment": "linux", "language": "shell", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "hermes-chat-worker-dispatch-payload-false-positive", "provider": "openrouter", "solved_at": "2026-08-15T23:58:39.457Z", "version": "hermes gateway"}