{
  "evidence_schema": 1,
  "scope": "Actual Hermes Python API backup/import round-trip; service startup stubbed. Not full CLI/service or cron execution proof.",
  "image_channel": "main",
  "image": "nousresearch/hermes-agent@sha256:4ab33c59d8ae5a1660f24b3065626853d09a2b42f28e77e85de99798be08a663",
  "host": {
    "provider_trial": "Railway free VM",
    "os": "Ubuntu 26.04.1 LTS",
    "architecture": "x86_64",
    "docker": "29.1.2"
  },
  "container_exit_code": 0,
  "isolation": {
    "network": "none",
    "read_only_rootfs": true,
    "published_ports": {},
    "privileged": false,
    "dropped_capabilities": [
      "ALL"
    ],
    "no_new_privileges": true,
    "memory_bytes": 1258291200,
    "cpus": 1,
    "pids_limit": 128,
    "no_host_docker_socket": true,
    "no_real_profile_or_credentials": true,
    "image_entrypoint_bypassed": true
  },
  "result": {
    "archive": {
      "members": [
        "SOUL.md",
        "config.yaml",
        "state.db.quarantine.lock",
        "state.db",
        "state.db.fts_rebuild.lock",
        "cron/.jobs.lock",
        "cron/jobs.json",
        "workspace/sentinel.txt",
        "scripts/sentinel.py"
      ],
      "path": "/lab/api-roundtrip/synthetic-full-backup.zip",
      "sha256": "594c1292910be20d9ffd5d5db3be953ac4bb45fde5ce365306835a89f10c28b1"
    },
    "blocked_operations": [],
    "limitations": [
      "Python API round-trip only; CLI, Docker restart/reboot, dashboard and gateway not tested",
      "Service start was explicitly stubbed; no gateway or scheduler ran",
      "Cron job definition persisted and stayed paused; task execution was not tested",
      "Only the inspected core source files were hash-pinned; record the actual image digest separately",
      "Synthetic data only; credentials, external delivery and duplicate-effect recovery not tested"
    ],
    "passed": true,
    "python": "3.14.7 (main, Sep  1 2026, 14:18:09) [Clang 22.1.3 ]",
    "restored": {
      "database": {
        "integrity_check": [
          [
            "ok"
          ]
        ],
        "messages": 2,
        "sessions": 1,
        "user_version": 0
      },
      "job_id": "f306ea79f5f3",
      "messages": [
        [
          "user",
          "synthetic question",
          "4febb42553df4861b73225dedac0961f"
        ],
        [
          "assistant",
          "synthetic answer",
          "2f3d4e97c9a34bcf9a0bcc7270589156"
        ]
      ],
      "workspace_and_script_hashes_match": true
    },
    "root": "/lab/api-roundtrip",
    "scope": "Real Hermes Python API round-trip; NOT full CLI or service proof",
    "service_start_stub_calls": [
      {
        "context": "import"
      }
    ],
    "source": {
      "database": {
        "integrity_check": [
          [
            "ok"
          ]
        ],
        "messages": 2,
        "sessions": 1,
        "user_version": 0
      },
      "file_sha256": {
        "scripts/sentinel.py": "afcf000b43c564bd03ee6ce9f811ceb2ef5807209a58c8400b33adf28bb2552a",
        "workspace/sentinel.txt": "482b7019e695e8d7b05e3bf0daa8a6f801b124aaf2f9ba59a30570596caf1138"
      },
      "job": {
        "deliver": "local",
        "enabled": false,
        "id": "f306ea79f5f3",
        "last_run_at": null,
        "name": "deploymanual-inert-job",
        "next_run_at": null,
        "no_agent": true,
        "script": "sentinel.py",
        "state": "paused"
      },
      "messages": [
        [
          "user",
          "synthetic question",
          "4febb42553df4861b73225dedac0961f"
        ],
        [
          "assistant",
          "synthetic answer",
          "2f3d4e97c9a34bcf9a0bcc7270589156"
        ]
      ]
    },
    "sqlite": "3.53.1",
    "started_utc": "2026-10-04T01:58:28Z",
    "upstream_reference": "158fd638da1629c8e62caf9ade1515d162def8ab",
    "verified_core_git_blobs": {
      "cron/jobs.py": "2e421c7af328f7e9e259713e03c8880e35ccf793",
      "hermes_cli/backup.py": "3ee30a826010bd07e37c8229c5d1a0b70510655b",
      "hermes_cli/backup_restore.py": "e54dd44e5f55be548d0371628c558b0f42965904",
      "hermes_cli/backup_sqlite.py": "1f0177b1db4175451a64b42968d86376e5b7cfcb",
      "hermes_cli/gateway.py": "4730718d3d8d0b6a45fb50662a212582227a9ec1",
      "hermes_constants.py": "bbdf2e9ea49f1e5cceb7791a0f1941bf2ed1e5d5",
      "hermes_state.py": "7ae87ae2ecdce76d6f9bcaf1dd38ba59e00966f9",
      "hermes_state_messages.py": "de97d964718a275091e475e035744f21ebab0e50",
      "hermes_state_sessions.py": "7e137ea3ecfae89cde4db8fe16040667f88283af"
    }
  },
  "console": "Scanning /lab/api-roundtrip/source ...\nBacking up 9 files ...\n\nBackup complete: /lab/api-roundtrip/synthetic-full-backup.zip\n  Files:       9\n  Original:    270.0 KB\n  Compressed:  11.5 KB\n  Time:        0.0s\n\n  Excluded directories:\n    backups/\n\nRestore with: hermes import synthetic-full-backup.zip\nBackup contains 9 files\nTarget: /lab/api-roundtrip/restored\n\nChecking archive integrity ...\n\nImporting 9 files ...\n\nImport complete: 9 files restored in 0.0s\n  Target: /lab/api-roundtrip/restored\n\nNote: The hermes-agent codebase was not included in the backup.\n  If this is a fresh install, run: hermes update\n\nDone. Your Hermes configuration has been restored.\nPASS: real Hermes API round-trip; service start stubbed; no cron execution\n/lab/api-roundtrip/result.json\n",
  "not_tested": [
    "Full CLI entrypoint and automatic service startup",
    "Cron execution and scheduler behavior",
    "Duplicate external effects or idempotency",
    "Dashboard authentication and SSH forwarding",
    "External port reachability",
    "Host reboot and recovery",
    "Model-provider calls"
  ],
  "provenance": {
    "input_zip_sha256": "03a46634b0d6d95a6122de2e47f193b30f43b62d00add572d720291b57d68a0b",
    "validation": "Evidence ZIP integrity, actual result, exit code, archive SHA256, source/restored fixture hashes and container isolation independently checked during editorial integration.",
    "redactions": "Public record omits host temporary directory, container identifiers and infrastructure claim/access details. Synthetic session/message/job IDs and /lab paths retained."
  },
  "independent_editorial_checks": {
    "source_restored_jobs_json_bytes_match": true,
    "cron_jobs_json_sha256": "e477ed70cee87409098f4becbabd6d1426e52afddde67091bece002c984822c2",
    "fixture_file_hashes_match": true,
    "backup_zip_sha256_matches": true
  }
}
