- Inbox -> archives/inbox_processed: ari_followup (Sardius), remarkable_inbox, tic_tac_toe_state - Inbox images -> resources/kids-os (KidsOS UI 2026-07-28) - Archives/travel/2026: Aeromexico HCYDNU confirmation + Hertz BOS L670EDC05D8 - Exports/calendars: all_flights, chiapas TGZ, maine BOS ICS - Areas: chiapas_trip_2026-09 (HCYDNU booked), trump_accounts_and_emi_board_2026 (Trump accounts + EMI FL board), operations audits (hermes migration + Apple Mail local research) - Projects new (enriched stubs from MEMORY.md): xiao_epaper 400x300 (5-pass grayscale), mac_privacy_migrations (Xcode signing), remarkable_pro workflow (132 + watchdog + art), tactility_humation_avatars (320x240 pre-render), voice_dev_infra (network map .102/.110/.150) - Paper-apps: restored detailed README (181 lines porting guide) + enriched paper_apps_golf_galaxy_zero project with full mechanics cross-ref - Maine wedding: Hertz rental 63 L670EDC05D8 + tolls (PlatePass vs SunPass PRO) — intentional addition kept - 220 Emerald: removed duplicate consolidated junk appended at end (142 lines clean) - Removed runtime logs: chrome.err (288 lines), chrome.log tracked -> now ignored per .gitignore - Clean empty inbox
7.3 KiB
title, status, date, source
| title | status | date | source |
|---|---|---|---|
| Hermes migration audit — Mac mini | in_progress | 2026-08-02 | Live audit on Mac-mini-M4.local |
Hermes migration audit — Mac mini
Verified working
- Hermes Agent
v0.19.1is installed at/Users/adolforeyna/.hermes/hermes-agent. - Primary state database passed
PRAGMA quick_checkand contains 1,456 sessions. - Brain access is available at
/Users/adolforeyna/brainwith read/write/traverse access. - Migrated Hermes assets exist:
- 32 skills
- 33 scripts
- 4 memory files
- profiles:
emi,kids,voice
- All 10 scheduled cron jobs are present and their referenced local scripts exist.
- A persistent macOS launchd gateway was installed at:
/Users/adolforeyna/Library/LaunchAgents/ai.hermes.gateway.plist - Gateway cron ticker was verified healthy after installation; scheduled jobs will fire automatically.
- MCP
macminiconnected successfully in 40 ms and exposed 48 tools.
Restored during audit
- WhatsApp credentials were absent locally but present on the old Pi (
pi5, hostnameaeropi5). - Restored the credential into the canonical Mac path:
/Users/adolforeyna/.hermes/platforms/whatsapp/session/creds.json - Set credential permissions to
0600. - After the restore, the Mac gateway connected to WhatsApp.
Outstanding migration work
1. WhatsApp handoff
The Mac gateway can connect to WhatsApp, but outgoing messages failed with Not connected to WhatsApp.
Likely contributing factors:
- The old Pi gateway may still be operating the same WhatsApp linked-device session.
- The old Pi is still reachable as SSH alias
pi5/ hostnameaeropi5.
An attempt to stop the old Pi gateway was denied by the user approval system, so no workaround or retry was performed.
2. Local session-lock ownership
/Users/adolforeyna/.local/state is owned by root. Hermes consequently cannot create:
/Users/adolforeyna/.local/state/hermes
Gateway log warning:
Could not acquire session lock (non-fatal): [Errno 13] Permission denied
This should be repaired before relying on the WhatsApp bridge long-term.
3. OpenSCAD iMac MCP
The configured openscad_imac MCP fails initial connection because SSH host-key verification fails. The macmini MCP is healthy.
4. ESP32 voice routes
The esp32-voice-gateway plugin detected that its routes are missing after the Hermes update. Its saved patch no longer applies cleanly to the current gateway/platforms/api_server.py.
The ESP32 voice API must be updated to the current Hermes source and verified before use.
5. Gateway model credentials
Gateway logs show the configured custom Meta model muse-spark-1.1 receives HTTP 401 Unauthorized. The model credential must be refreshed or the gateway model/provider changed, then tested with an inbound message.
Optional capability gaps (not migration failures)
- Nous Portal authentication is not configured.
- Web-search provider keys are not configured.
- Docker is not installed.
These do not block the core agent, brain, cron, or healthy Mac mini MCP.
Migration sequence
- Resolve Pi → Mac WhatsApp ownership and verify a real outbound reply.
- Repair the Mac local Hermes-state directory ownership and confirm lock acquisition.
- Repair and test the OpenSCAD iMac MCP SSH trust relationship.
- Restore and test ESP32 voice gateway routes.
- Repair/test gateway model credentials.
- Complete end-to-end checks: WhatsApp inbound/outbound, cron heartbeat, MCPs, voice endpoints, and model calls.
Progress update — WhatsApp routing and full session-state recovery
Channel routing correction
The first post-migration WhatsApp responses were incorrectly sent into the group named EMI Assistant (120363409068274776@g.us). This group is reserved for EMI conversations and is not the family/home channel.
Live bridge inspection identified these WhatsApp groups:
EMI Assistant— separate EMI groupFamReynaBot— family group, with the bot plus Adolfo and his wifeReynaO— separate group
The default/home route was corrected so scheduled/default WhatsApp delivery uses the original Pi WhatsApp home-channel configuration rather than EMI.
User registration and policy
- Family group policy remains
allowlistwith no mention requirement. - The original Pi WhatsApp allowlist was restored rather than using temporary Mac-only configuration overrides.
- The original bot mode, user allowlist, home channel, owner-message forwarding setting, and enabled setting were copied from the Pi runtime
.envinto the Mac.env. - The Mac bridge now starts in
botmode. It had mistakenly started inself-chatmode before restoration; that mode ignores ordinary DM traffic and explained the DM non-responses.
Full WhatsApp session recovery
Initial recovery copied only creds.json. That was insufficient for inbound-message handling: the Pi WhatsApp session directory contains encrypted multi-file authentication/session state.
On 2026-08-02:
- Verified the Pi session had 1,592 files:
creds.jsonplus 1,591 key/state files. - Stopped the Mac gateway briefly.
- Copied the entire Pi session directory to:
/Users/adolforeyna/.hermes/platforms/whatsapp/session/ - Applied restrictive permissions (
0700directories,0600files). - Restarted the Mac launchd gateway.
After restart:
- WhatsApp bridge reported
status=connected. - Cron gateway ticker was healthy.
- The gateway processed a recovered inbound WhatsApp event and generated a response.
Current verification status
A fresh user-authored DM test after the full session-state restore is still required to prove live inbound DM processing end-to-end. An automated recovery-probe DM was attempted but denied by the user approval system, so it was not retried.
Progress update — browser automation restored on Mac mini
The iMac is kids-only and must not host Hermes browser automation or private browser state. On 2026-08-03, a dedicated visible Chrome automation profile was created on the Mac mini at:
~/Library/Application Support/Google/Chrome-Hermes/
- The source Chrome profile was copied once with caches and lock files excluded, preserving the available same-Mac browser session material without operating on the iMac.
- Chrome is running as a separate visible instance with CDP bound only to
127.0.0.1:9222, using theReynaFamilyBotChrome profile (reynafamilybot@gmail.com) by default. Live Gemini verification confirmed that bot account is signed in. agent-browseris connected to that instance under sessionhermes-visible; its dashboard is healthy on127.0.0.1:4848.- A LAN observer proxy is verified on
192.168.68.112:4849. The dashboard hard-codedws://localhost:<port>, so laptop viewers sawDisconnected; the proxy now rewrites that endpoint to a narrow LAN stream bridge (:4851) and normalizes its WebSocket Origin before forwarding to the localhost-only stream (:4850). A LAN URL load verifiedOnlinerather thanDisconnected. - Local helpers:
~/bin/hermes-browser(start/status) and~/bin/hermes-browser-dashboard-proxy.py.
The durable launchd plist was written at ~/Library/LaunchAgents/com.reyna.hermes-browser-dashboard-proxy.plist, but its registration was blocked by Hermes' gateway safety guard. It requires a one-time explicit launchctl bootstrap from a separate Mac mini Terminal session before relying on the LAN observer proxy across restarts.