Files
iris_x_hermes/docs
ARIA 597a28050f
CI / Gateway plugin tests (push) Successful in 5m29s
CI / Kotlin tests (android host + desktop) (push) Successful in 7m22s
TLS: fingerprint-confirm flow for self-signed gateway certs (issue #14)
docs/09 §9.4 promised a SSH-host-key-style fingerprint confirm on first
pair, but the app built a default OkHttpClient with no certificate
handling — self-signed gateway certs were simply rejected.

Build the flow:
- TlsPinning.kt: PinningTrustManager wraps the platform default trust
  manager; a rejected cert is accepted only when its SHA-256 fingerprint
  matches the user-confirmed pin, anything else fails with
  TlsFingerprintRequired (hostname verification still applies).
- SecureStore.pinnedCertFingerprint (Android EncryptedSharedPreferences +
  desktop settings.json), cleared on forget().
- GatewayClient: pinning socket factory on the shared client (all legs
  inherit it), new terminal State.TlsConfirmRequired, unwrap the nested
  TlsFingerprintRequired in connect loop / watchdog / SSE / poll /
  testHello.
- ConnectScreen: confirm dialog showing the fingerprint ("Confirm &
  pin" re-runs the connect); IrisApp routes TlsConfirmRequired there;
  ChatScreen + desktop tray handle the new state.
- Docs: §9.4 now describes the real flow (incl. SAN requirement), gap
  table item 6 → implemented, setup.md limitation note updated.
- Tests: TlsPinningTest (fingerprint vs openssl, pin accept/reject,
  live pin read, unwrap) + TlsPinningIntegrationTest (real TLS
  handshake: unpinned → confirm data, pinned → 200).

Live E2E verified on the phone: first pair against a self-signed
IRIS_HTTP_CERT gateway shows the dialog, confirm pins, chat works,
auto-reconnect after gateway restart uses the pin.
2026-08-24 21:30:42 +02:00
..

Iris × Hermes — Implementation Reference Library

A coder-facing reference library for building a native Android + Desktop experience for hermes-agent, connected through a gateway platform plugin.

This folder is the single source of truth for what to build and why. Read it top-to-bottom once, then use the numbered docs as a lookup while implementing.

⚠️ READ FIRST — two hard rules

  1. hermes-agent/ (sibling of this folder) is a read-only research reference. It must NEVER be committed, pushed, or shipped. It is git-ignored at the repo root. We only install our plugin into a live hermes install (~/.hermes/plugins/); we never modify hermes core.
  2. ADB is installed and a device is connected (a5ca2a4b, Xiaomi MIX 2S, Android 10 / API 29). Use it to install/launch/debug the app on-device.

Reading order

# File When to read
0 00-overview.md Always first. Vision, scope, disclaimers, locked decisions.
1 01-architecture.md Before touching code. System shape + rationale.
2 02-monorepo.md When scaffolding the repo.
3 03-gateway-plugin.md When building the Python plugin.
4 04-wire-protocol.md When implementing either side of the WS.
5 05-streaming.md Streaming / reasoning / tools / intermediate.
6 06-channels-cron-search.md Channels, threads, cron delivery, search.
7 07-media.md Media upload/download + playback.
8 08-push.md Push (ntfy default + FCM optional), outbox, sync.
9 09-pairing-security.md Pairing, auth, security model.
10 10-android-app.md When building the Android app.
11 11-desktop-app.md When building the Desktop app.
12 12-toolchain.md First time on a machine (JDK/SDK/uv/Firebase).
13 13-testing.md Writing tests + on-device ADB workflow.
14 14-milestones.md Planning work / tracking progress.
15 15-hermes-reference.md Cheat-sheet of hermes-agent source to read.
16 16-open-questions.md Decisions made + open items.
17 17-future-control-surface.md Backlog — what the app could control beyond chat (cron, kanban, models, …).
19 19-http-fallback-transport.md Design — HTTP fallback leg (POST + SSE/long-poll) so the app can send/receive when the WS is down.
20 20-qr-pairing.md Terminal QR at gateway setup + in-app QR scanner (Android) + iris://pair deep link.

Machine-readable / diagrams:


The three deliverables (one monorepo)

  1. gateway-plugin/ — a Python hermes platform plugin named iris. Runs inside the hermes gateway process. Opens a WebSocket server the apps connect to. Implements the full BasePlatformAdapter contract. Zero new Python dependencies, zero hermes-core changes.
  2. app/androidApp — native Kotlin + Jetpack Compose client.
  3. app/desktopApp — Kotlin + Compose Multiplatform client that shares the Android app's code and is "tweaked" for a big screen.

The Android and Desktop clients live in one Compose Multiplatform Gradle project (app/) with a shared KMP module (app/shared).


Status

  • Phase: M0–M6 complete; M7 (polish + E2E + docs) in progress.
  • Owner decisions locked: see 16-open-questions.md.
  • Last updated: 2026-08-19.