Skip to content

fix(kanban): pin write_safe_root to task workspace and profile scope - #111168

Open
jjjorgenson wants to merge 6 commits into
NousResearch:mainfrom
jjjorgenson:cursor/kanban-file-isolation-9a3f
Open

jjjorgenson wants to merge 6 commits into
NousResearch:mainfrom
jjjorgenson:cursor/kanban-file-isolation-9a3f

Conversation

@jjjorgenson

Copy link
Copy Markdown

Summary

Closes #70688.

Pins HERMES_WRITE_SAFE_ROOT (with TERMINAL_CWD) on kanban worker spawn so tasks cannot write outside their workspace (sibling / symlink / .. denied).

Adds a ContextVar profile scope (tools/write_safe_root_scope.py) for desktop / multiplex / session turns so a secondary profile cannot inherit the launch process vault — including the empty-secondary + launch-env-set hole (matrix M2).

Security / hard gate

Under a routed scope, writes outside the intended root (foreign vault, launch vault, parent-outside-child) are denied. Spawn pin unchanged. WSR does not gate reads (same as before).

Test plan

  • tests/hermes_cli/test_kanban_worker_terminal_cwd.py (11)
  • tests/tui_gateway/test_write_safe_root_profile_desktop.py
  • tests/tools/test_write_safe_root_profile_isolation.py
  • tests/tools/test_write_safe_root_profile_matrix.py (M1–M6)

@alt-glitch alt-glitch added type/bug Something isn't working P3 Low — cosmetic, nice to have comp/cron Cron scheduler and job management comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/tui Terminal UI (ui-tui/ + tui_gateway/) comp/gateway Gateway runner, session dispatch, delivery tool/file File tools (read, write, patch, search) area/profiles Multi-profile isolation, HERMES_HOME scoping sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades labels Sep 14, 2026
@alt-glitch

Copy link
Copy Markdown

This was generated by AI during triage.

Related: #76317 is an earlier open fix for the same issue (#70688) that pins the write-safe root at kanban spawn only. This PR covers that plus a ContextVar profile scope for desktop/multiplex turns across gateway/run.py and tui_gateway. Flagging so reviewers can compare scope before merging either.

@jjjorgenson

Copy link
Copy Markdown
Author

Thanks @alt-glitch — good catch linking #76317.

We knew about that earlier open fix and should have cited it in the PR body. Short comparison for reviewers:

#76317 — pins HERMES_WRITE_SAFE_ROOT / TERMINAL_CWD at kanban worker spawn and preserves that task root through worker dotenv / delegation. Spawn-path coverage for #70688.
This PR — same spawn-pin class of fix, plus a ContextVar profile scope (write_safe_root_scope) for desktop / multiplex / session turns (gateway + tui_gateway), including the empty-secondary + launch-env-set case (matrix M2 / fluxkapacitor Sep 11 repro on #70688).

cursoragent and others added 6 commits September 17, 2026 17:52
…ch#70688)

Salvaged from NousResearch/hermes-agent PR NousResearch#76317, adapted for the
kanban_db_dispatch facade split.

- _default_spawn: derive realpath of the claimed workspace and set both
  TERMINAL_CWD and HERMES_WRITE_SAFE_ROOT, replacing any inherited
  deployment-wide write root; fail closed on unusable paths (no / export)
- HERMES_KANBAN_SAFE_ROOT_ACTIVE lineage marker survives delegate scrub
- env_loader: task-scoped safe root outranks profile/managed dotenv reload
- Tests: own-workspace OK; sibling/.. /symlink escape denied; scratch
  dispatch scoped; spawn failure path unchanged
- Docs: file-tool pin is not an OS sandbox; global kanban path env vars
  collapse multi-board isolation

Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…e on desktop/multiplex path

Models secondary-profile turns in tui_gateway and multiplex gateway where
HERMES_WRITE_SAFE_ROOT stays on the launch profile's process env. Tests
fail until write-safe-root gets profile-scoped resolution like TERMINAL_*.

Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…ousResearch#70688)

Add focused regression test for fluxkapacitor Sep 11 repro: a desktop-hosted
non-default profile session still reads write-safe roots from process env
after _session_profile_runtime_scope, not from the routed profile .env.

Test documents inverted permissions (own vault denied, default vault allowed)
and prints expected-vs-actual for every check. Left failing until WSR gets
profile-scoped binding like terminal_scope.

Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…tiplex (NousResearch#70688)

Add tools/write_safe_root_scope ContextVar (parallel to terminal_scope) and bind
it at routed profile turn boundaries: TUI session scope, prompt turn, and gateway
_profile_runtime_scope. get_safe_write_roots() resolves from the scope when bound
so a secondary profile no longer inherits the launch profile vault from os.environ.

Turns fluxkapacitor regression tests green; kanban spawn isolation unchanged.

Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…when scoped empty (NousResearch#70688)

Add desktop/multiplex matrix cases for launch/secondary WSR combinations.
Fix M2 hole: when a routed profile scope is bound with no profile vault,
deny writes under launch-process HERMES_WRITE_SAFE_ROOT instead of treating
empty bound scope as unrestricted.

Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
… Phase A)

Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
@cursor
cursor Bot force-pushed the cursor/kanban-file-isolation-9a3f branch from 42c0958 to e438115 Compare September 17, 2026 17:54

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/profiles Multi-profile isolation, HERMES_HOME scoping comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint comp/cron Cron scheduler and job management comp/gateway Gateway runner, session dispatch, delivery comp/tui Terminal UI (ui-tui/ + tui_gateway/) P3 Low — cosmetic, nice to have sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades tool/file File tools (read, write, patch, search) type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Dispatcher-spawned kanban workers inherit the deployment-wide HERMES_WRITE_SAFE_ROOT instead of a task-workspace-scoped one

3 participants