Release info

Hermes Agent v0.21.2/v0.21.3 Patch Pair: The state.db Campaign Closes 44 Issues, and Cloud Refresh Bursts Stop Revoking Sessions

Nous Research shipped two patch releases in mid-September. v0.21.2, "The state.db Patch Release", fixes the fragile-database class that v0.21.0's session-store rewrite introduced (second writers, WAL false-corruption, one bad row killing sessions list, sessions bound to another profile's database) across six PRs closing 44 issues — 947 commits / 312 PRs / 140 contributors in the window. v0.21.3 rolls up 338 PRs, chiefly to bring the remote-gateway sign-in fix to auto-updating Cloud agents: a refresh burst can no longer replay a rotated refresh token into the Portal's reuse detection and revoke the whole session; a long-lived state.db writer-handle leak is also fixed. Same window: DeepSeek Harness dsh-v0.1.6-alpha.1 lands config changes self-hosters must act on (DeepSeek endpoint migration, E2B removal, PTC rename).

Direct answer: Nous Research shipped two Hermes Agent patch releases in mid-September: v0.21.2 (Sept 11) is "The state.db Patch Release" — six PRs close 44 issues and kill the fragile-database class that v0.21.0's session-store rewrite introduced: no more second writers cancelling each other's locks, healthy WAL databases no longer reported corrupt, one bad row no longer kills sessions list, sessions never bind to another profile's database, and opening state.db read-only takes 0.01 s instead of stalling 4–20 s behind a live gateway. v0.21.3 (Sept 14) rolls up 338 PRs, existing so the remote-gateway sign-in fix reaches Cloud agents that auto-update: a Desktop refresh burst can no longer replay an already-rotated refresh token into the Portal's reuse detection and revoke the whole session; long-lived processes stop leaking duplicate state.db writer handles. Both notes say full curated release notes ship with v0.22.0.

v0.21.2: the state.db reliability campaign

v0.21.0's big rewrite of session-store connection handling made state.db fragile on some installs. v0.21.2 fixes root causes rather than symptoms, six PRs closing 44 issues:

  • Second writers are gone. Profile gateways no longer write hosted-room state into the root state.db every 5 seconds (it moves to shared-state.db); the dashboard opens read-only first; cron's lifecycle guard goes through the tracked connection registry instead of a raw open() on a live database; doctor --fix refuses a checkpoint it can't prove is safe.
  • Healthy WAL databases stop wedging. OpenZFS (deleted) dentries and a close() racing an append_message both produced a sticky DeletedWalGenerationError on a good store; a transient WSL2 disk I/O error no longer kills get_session.
  • FTS damage no longer kills your turn. A full-text-search-index error used to be classified as whole-file corruption and fail-close the conversation; now search degrades, the index rebuilds later, the transcript store is untouched.
  • One corrupt row no longer kills sessions list, export or insights. A TEXT timestamp or a 1e30 epoch used to crash the whole listing; bad rows now render ? with a WARNING naming the session.
  • Sessions never bind to or read another profile's database. The Desktop launch backend could pin to the wrong profile's state.db under a HERMES_HOME race; session_search by bare ID silently scanned every profile.
  • Opening state.db no longer takes the write lock when nothing needs writing — a one-shot hermes behind a busy gateway stalled 4–20 s; now 0.01 s.

Beyond the campaign: multi-profile isolation hardening (secondary-profile bots no longer inherit the default profile's allow-lists; stdio MCP servers no longer receive the default profile's vault secrets; MEDIA: delivery can't attach another profile's .env/auth.json/state.db), a password-blind credential vault (1Password/Bitwarden/local — the agent signs in and pays without ever seeing a secret), a curated SHA-pinned plugin catalog with one Desktop Plugins page, the Nous free tier with guided first launch, and the end of Desktop backend spawn storms. Window volume (the full v0.21.0→v0.21.2 window, not the six-PR campaign itself): 947 non-merge commits / 312 PRs / 140 contributors. If your state.db was already damaged by 0.21.0/0.21.1, run hermes doctor first — it now names structural vs index damage honestly.

v0.21.3: the Cloud sign-in fix, rolled to everyone

A patch rollup of 338 PRs (1,036 commits / 2,642 files) that exists for one main reason: remote Desktop and Cloud agents auto-update to the newest release tag, so the gateway sign-in fix had to ship in a tag. Both refresh paths (cookie gate and the desktop's native bearer route) now coalesce concurrent requests carrying the same rotating refresh token — a Desktop wake burst can no longer replay an already-rotated token into the Portal's reuse detection and revoke the whole session. Pairs with a Portal-side sliding 30-day idle horizon. Also fixed: long-lived processes stop leaking duplicate state.db writer handles (the N live SessionDB handles precursor stops firing on healthy topologies). The rest of the window (reasoning-effort selectors, OpenRouter OAuth PKCE, HEIF/AVIF decoding, new FAL models and more) is undocumented here on purpose — the official notes state full curated release notes for this window ship with v0.22.0.

Same window: DeepSeek Harness dsh-v0.1.6-alpha.1 (self-hoster action required)

The alpha that landed Sept 15 brings Web-sidebar terminals (multi-tab, shell selection, recovery after refresh), MCP on the official SDK v2, headless stdin / --session-id / --json, SSH remote workspaces, and experimental Browser/Computer Use and Auto review. But three changes require self-hosters to touch config: DeepSeek now defaults to the Messages protocol (if you manually configured the old official root address, switch it to https://api.deepseek.com/anthropic), the built-in E2B execution backend is removed, and the PTC package/service names unify to ptc-runtime with no old aliases; the workflow executor becomes workflow-ptc. Ralph is off by default now.

How to read it

For teams running Hermes where it hurts — long-lived gateways, cron-heavy automation, multiplexed profiles — v0.21.2 is the "stop losing sessions" patch and v0.21.3 is the "stop losing Cloud logins" patch; both are safe, targeted updates rather than feature drops. Start from the Hermes product page and the architecture deep dive; comparing ecosystems, see Hermes Agent vs OpenClaw, migrating see the OpenClaw-to-Hermes migration guide. DeepSeek Harness watchers, the glossary and compare hub cover the adjacent ecosystem.

Sources