Loopback :8642
Running from the shared patched installation with the default profile.
A reversible first separation spike that preserves the useful shared foundation, isolates product behavior and memory, and establishes the contracts that future gateway candidates must meet.
The target retains existing public contracts and ports. Shadow processes use unused ports and temporary state, so nothing competes with the live profiles.
Running from the shared patched installation with the default profile.
Running from the same installation with isolated game-assist state.
Not listening at discovery time. Scheduled task exists; last result indicates failure.
Tool service, portal, search, and capacity coordination are listening on their established local ports.
Free and reserved by this blueprint for the provider-neutral Featherless proxy.
Free and reserved for personal and Nagato separation tests using disposable homes.
Runtime releases are immutable directories selected by a small current pointer. Existing profile state stays in place for the first spike; state migration is a later, separately reversible concern.
| Role | Runtime location | State authority | Command/service identity |
|---|---|---|---|
| Personal | %LOCALAPPDATA%\HermesRuntimes\personal\releases\<build> | Existing default Hermes home | hermes + Hermes_Personal_Gateway |
| Nagato | %LOCALAPPDATA%\HermesRuntimes\nagato\releases\<build> | Existing game-assist profile home | nagato-hermes + Nagato_Hermes_Gateway |
| Candidate | Worktree-owned build or package cache | Test-owned temporary directory only | Harness controller; no login autostart |
| Plans | Versioned gaem-proxy application | %LOCALAPPDATA%\gaem-plans, outside the static webroot | Gaem_Plans_Service behind HTTPS proxy |
Patch ownership is classified by behavior, not history. Mixed commits must be re-authored into coherent slices before either runtime is built.
| Class | Current patches | Destination | Exit condition |
|---|---|---|---|
| Shared Featherless | 0001, 0006, 0008, 0010, 0012, 0017 | Temporary shared-foundation branch for both durable runtimes | Scheduler parity allows client-side reservation logic to be removed |
| Nagato product | 0002, 0003, 0004, 0011, 0014, 0015 | Nagato runtime only | Retained while Hermes is the selected product gateway |
| Must split | 0005, 0007, 0013 | Featherless/tool-wire pieces shared; Runs/trace/GTC pieces product-only | No mixed patch remains in either manifest |
| General Windows test infrastructure | 0009, 0016 | Build/test overlay; propose upstream separately | Drop locally when upstream contains equivalent coverage |
Personal manifest: exact upstream release + shared Featherless slices + justified general tool-wire/Windows fixes. Nagato manifest: the same shared base + Runs/trace/artifact/privacy/GTC product slices. Both manifests pin source, tree, dependencies, tests, and rollback build.
The scheduler is an OpenAI-compatible loopback proxy. It owns the provider credential and actual request queue; clients stop reserving capacity independently.
Interactive project work. Uses scheduler base URL and a personal workload identity.
Weighted fairness, concurrency, deadlines, safe retry boundaries, model metadata, capacity state, and body-free observability.
Foreground game turns, background Recall review, tests, and future gateway implementations.
POST /v1/chat/completions, streaming SSE, and GET /v1/models. Existing clients switch by base URL, not core patches.
/healthz and authenticated /v1/scheduler/status; never prompts, responses, credentials, or memory content.
Bounded workload class, profile ID, request ID, and absolute deadline headers. Unknown values use safe defaults.
Weighted queues for interactive, Nagato foreground, background, and maintenance; per-client caps prevent starvation or monopolization.
Retry only before provider acceptance/stream output. Once bytes stream, failure is explicit—never silently replay a billable generation.
Streaming, auxiliary calls, context metadata, capacity refresh, deadlines, and recovery must match before old reservation code is removed from both Hermes runtimes and GTC.
Nagato should install with research and active memory ready to use. “Baked in” means pinned, configured, health-checked, and covered by compatibility tests while each dependency retains its own downstream update channel.
gtc_* functions, Valkey coordination, and safe result shapesHealth, capability/version handshake, tool schemas, malformed-call refusal, bounded results, research citations, image handling, timeout/retry behavior, and scheduler integration.
Availability, initialize, prefetch, completed-turn sync, session switch, pre-compression, tools, shutdown, backup/export/delete, profile isolation, and failure-soft behavior.
GTC and the selected memory provider may move faster than the trimmed Nagato Hermes runtime. Their update pipelines therefore produce independently testable artifacts and compatibility evidence; Nagato consumes an approved version range or exact pin instead of absorbing their source histories.
Personal Hermes can be an excellent Nagato developer and operator while its memory remains distinct from the product’s player/game knowledge.
game_idRepository and Forgejo access stay normal. Runtime inspection goes through authenticated loopback bridge/gateway APIs and explicit development tools: health, bounded configuration metadata, run/trace inspection, test commands, and validated mutations. Direct SQLite/JSON writes remain outside the agent contract.
License, Windows support, local/cloud posture, Hermes integration cost, maintenance activity, data portability, isolation model, and dependency weight.
Run the same capture/recall/correction/negative-relevance/restart corpus; do not accept project benchmarks or README claims as product evidence.
Trace the selected memory IDs and injected byte budget, then verify that recalled context materially changes the agent’s correct plan without leaking irrelevant memory.
Provider-specific tools stay behind an allowlist and canonical adapter vocabulary where needed; export and migration are tested before production adoption.
The current public static directory remains legacy/sanitized during migration. The new surface uses capability links and has no public index.
POST /api/v1/plans with local publisher authentication, bounded files, title, and TTLGET /p/<capability>/… with noindex, CSP, MIME allowlist, and no directory listingDELETE /api/v1/plans/<id> requires the management secret and immediately revokes the viewBefore proxy behavior changes, move gaem-proxy into a private Forgejo repository with tests, a locked dependency graph, configuration documentation, and a rollbackable service definition. The live folder is currently not version-controlled.
R1–R5 are recovery, build, integration, shadow, and memory-proof work. R6 is the only live cutover and requires a short agreed maintenance window. Scheduler extraction follows the first proven separation, as requested.
Diagnose the currently failed bridge task, restore health, inventory safe state, create checksummed backups, and prove the current rollback commands.
Re-author mixed patches, produce personal and Nagato manifests, build immutable release directories, and independently review exact outputs.
Pin GTC’s current verified service contract, build its downstream-update test lane, inventory the memory-provider list, and turn Hermes’ provider lifecycle into a reusable conformance suite.
Run personal and Nagato builds on :8742/:8743 with disposable homes, fake providers by default, required GTC adapter checks, then bounded live Featherless smoke.
Screen the 25+ options, fully test a short list, install the selected provider per durable runtime, run canary/negative/correction/isolation/restart tests, and prove candidates receive temporary stores.
Stop old gateways, switch task/alias pointers, reuse existing state homes, start new binaries on :8642/:8643, restore bridge :8765, and run human acceptance.
Build :8650 proxy, migrate one client at a time, compare billing/stream/deadline/capacity behavior, then retire duplicated patches.
Evaluate pi, OAL, Turnstone, stripped Hermes, and ground-up against the now-real runtime, memory, scheduler, and replay contracts.
No migration deletes the prior installation or rewrites live state in place. Destructive cleanup waits until post-cutover acceptance and backup expiry.
Stop the shadow process and delete only its verified temporary home. Live ports and tasks were never touched.
Repoint the personal task/alias to the old shared executable and restart :8642 against the unchanged default home.
Repoint the Nagato task to the old shared executable, restart :8643, then restore bridge health on :8765.
Disable the external provider per affected runtime and return to built-in memory; never delete provider data during rollback.
Return each client base URL to its previous direct Featherless path while the shared patch set still exists.
Disable the new /p and API routes; legacy sanitized static /plans remains independently served.
The next state-changing action is R1: diagnose/restore the existing bridge, create backups, and prepare isolated worktrees/build directories. Before R6, the live gateway cutover will pause for an agreed maintenance window and explicit human approval.