Repository navigation
fix(kanban): pin write_safe_root to task workspace and profile scope - #111168
jjjorgenson wants to merge 6 commits into
Conversation
Related: #76317 is an earlier open fix for the same issue (#70688) that pins the write-safe root at kanban spawn only. This PR covers that plus a ContextVar profile scope for desktop/multiplex turns across gateway/run.py and tui_gateway. Flagging so reviewers can compare scope before merging either. |
|
Thanks @alt-glitch — good catch linking #76317. We knew about that earlier open fix and should have cited it in the PR body. Short comparison for reviewers: #76317 — pins HERMES_WRITE_SAFE_ROOT / TERMINAL_CWD at kanban worker spawn and preserves that task root through worker dotenv / delegation. Spawn-path coverage for #70688. |
…ch#70688) Salvaged from NousResearch/hermes-agent PR NousResearch#76317, adapted for the kanban_db_dispatch facade split. - _default_spawn: derive realpath of the claimed workspace and set both TERMINAL_CWD and HERMES_WRITE_SAFE_ROOT, replacing any inherited deployment-wide write root; fail closed on unusable paths (no / export) - HERMES_KANBAN_SAFE_ROOT_ACTIVE lineage marker survives delegate scrub - env_loader: task-scoped safe root outranks profile/managed dotenv reload - Tests: own-workspace OK; sibling/.. /symlink escape denied; scratch dispatch scoped; spawn failure path unchanged - Docs: file-tool pin is not an OS sandbox; global kanban path env vars collapse multi-board isolation Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…e on desktop/multiplex path Models secondary-profile turns in tui_gateway and multiplex gateway where HERMES_WRITE_SAFE_ROOT stays on the launch profile's process env. Tests fail until write-safe-root gets profile-scoped resolution like TERMINAL_*. Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…ousResearch#70688) Add focused regression test for fluxkapacitor Sep 11 repro: a desktop-hosted non-default profile session still reads write-safe roots from process env after _session_profile_runtime_scope, not from the routed profile .env. Test documents inverted permissions (own vault denied, default vault allowed) and prints expected-vs-actual for every check. Left failing until WSR gets profile-scoped binding like terminal_scope. Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…tiplex (NousResearch#70688) Add tools/write_safe_root_scope ContextVar (parallel to terminal_scope) and bind it at routed profile turn boundaries: TUI session scope, prompt turn, and gateway _profile_runtime_scope. get_safe_write_roots() resolves from the scope when bound so a secondary profile no longer inherits the launch profile vault from os.environ. Turns fluxkapacitor regression tests green; kanban spawn isolation unchanged. Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
…when scoped empty (NousResearch#70688) Add desktop/multiplex matrix cases for launch/secondary WSR combinations. Fix M2 hole: when a routed profile scope is bound with no profile vault, deny writes under launch-process HERMES_WRITE_SAFE_ROOT instead of treating empty bound scope as unrestricted. Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
… Phase A) Co-authored-by: JJ Jorgenson <jjjorgenson@users.noreply.github.com>
42c0958 to
e438115
Compare
Summary
Closes #70688.
Pins
HERMES_WRITE_SAFE_ROOT(withTERMINAL_CWD) on kanban worker spawn so tasks cannot write outside their workspace (sibling / symlink /..denied).Adds a ContextVar profile scope (
tools/write_safe_root_scope.py) for desktop / multiplex / session turns so a secondary profile cannot inherit the launch process vault — including the empty-secondary + launch-env-set hole (matrix M2).Security / hard gate
Under a routed scope, writes outside the intended root (foreign vault, launch vault, parent-outside-child) are denied. Spawn pin unchanged. WSR does not gate reads (same as before).
Test plan
tests/hermes_cli/test_kanban_worker_terminal_cwd.py(11)tests/tui_gateway/test_write_safe_root_profile_desktop.pytests/tools/test_write_safe_root_profile_isolation.pytests/tools/test_write_safe_root_profile_matrix.py(M1–M6)