Skip to content

fix(gateway): scope routed memory and skill writes 🩷 - #75729

Closed
kingrubic wants to merge 1 commit into
NousResearch:mainfrom
kingrubic:fix/75684-routed-profile-storage
Closed

kingrubic wants to merge 1 commit into
NousResearch:mainfrom
kingrubic:fix/75684-routed-profile-storage

Conversation

@kingrubic

Copy link
Copy Markdown

What does this PR do?

Fixes a profile-isolation bug in multiplexed gateway slash commands. When /memory or /skills was dispatched for a routed profile, the command handlers could read/write the gateway process's default HERMES_HOME instead of the routed profile home. This could expose pending writes across profiles or persist approval changes to the wrong config.

Related Issue

Fixes #75684

Type of Change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • 🔒 Security fix

Changes Made

  • Scope /memory and /skills dispatch through _profile_runtime_scope() when multiplexing is active.
  • Resolve handler config paths through the runtime get_hermes_home() context rather than the module-level gateway home.
  • Add end-to-end regressions for both subsystems covering routed dispatch, config toggles, and profile-local pending queues.

How to Test

  • Red phase on current main: 4 failures demonstrating default-home dispatch/config leakage.
  • Focused canonical environment (uv run --extra dev --extra messaging python -m pytest ...): 36 passed.
  • Independent audit: approved; profile-local approve/pending probes passed.
  • Ruff: passed.
  • git diff --check: passed.
  • Broad tests/gateway: 4,421 passed, 24 skipped, 18 unrelated baseline/environment failures in API/Discord/Telegram/WeCom/readiness/systemd/session-prune tests. No failures were in the changed files or Multiplex /memory and /skills use default profile home instead of routed profile #75684 tests.

Tested on macOS with Python 3.13.11.

Checklist

  • I've read the Contributing Guide
  • My commit messages follow Conventional Commits
  • I searched for existing PRs to make sure this isn't a duplicate
  • My PR contains only changes related to this fix
  • I've added tests for the bug
  • I've tested on macOS
  • I've considered cross-platform impact — single-profile behavior remains unchanged

@alt-glitch alt-glitch added type/bug Something isn't working P2 Medium — degraded but workaround exists comp/gateway Gateway runner, session dispatch, delivery tool/memory Memory tool and memory providers tool/skills Skills system (list, view, manage) area/profiles Multi-profile isolation, HERMES_HOME scoping area/config Config system, migrations, profiles sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state labels Aug 1, 2026
@teknium1

teknium1 commented Aug 1, 2026

Copy link
Copy Markdown
Collaborator

Thanks for the focused profile-isolation fix. Current main invokes /memory and /skills outside the routed runtime scope (gateway/run.py:14359-14363), even though normal multiplexed agent turns enter it (gateway/run.py:23046-23055). Both handlers also use the process-level _hermes_home for config writes (gateway/slash_commands.py:3429-3437, gateway/slash_commands.py:3478-3485), while pending approval storage uses runtime get_hermes_home() (tools/write_approval.py:110-111).

The changes in e35315184771 address both causes and add coverage for dispatch scope, profile-local config toggles, and pending-queue isolation. No correctness or completeness defect was identified in the reviewed diff.

Automated hermes-sweeper review.

@teknium1 teknium1 added sweeper:risk-security-boundary Sweeper risk: may affect sandboxing, auth, credentials, or sensitive data sweeper:blast-moderate Sweeper blast radius: moderate — a subsystem or single platform area/memory Memory subsystem: store, providers, sync, background reviews labels Aug 1, 2026
@GottZ

GottZ commented Aug 3, 2026

Copy link
Copy Markdown

This was generated by AI during triage.

Summary

One PR addresses issue #75684. #75729 scopes /memory and /skills dispatch to the routed profile and replaces process-level _hermes_home configuration lookup with runtime-scoped get_hermes_home(), covering both reported causes.

Related pull requests

  • fix(gateway): scope routed memory and skill writes 🩷 #75729 best fix — (+186/-4) — keep open with a salvage path: Consistent with the maintainer-bot keep_open review, the diff routes both commands through _profile_runtime_scope(), uses get_hermes_home() for profile-local configuration, and adds regression tests for routed dispatch, approval toggles, and pending-queue isolation.

Suggested consolidation

Keep #75729 open with a salvage path: preserve its complete profile-isolation fix and focused regression coverage while it proceeds through review. It is the only PR in this complex, so there are no duplicate PRs to close.

Complex graph

flowchart LR
    classDef open fill:#dbeafe,stroke:#1d4ed8,color:#1e3a8a
    classDef merged fill:#dcfce7,stroke:#15803d,color:#14532d
    classDef closed fill:#e5e7eb,stroke:#6b7280,color:#1f2937
    classDef unverified fill:#f3f4f6,stroke:#9ca3af,color:#374151
    classDef best stroke-width:3px,stroke:#b45309
    classDef target stroke-width:3px,stroke:#4338ca
    I75684(["issue #75684 (open)"])
    P75729["PR #75729 (open)"]
    P75729 -->|best fix| I75684
    class I75684 open
    class P75729 open
    class P75729 best
    class P75729 target
    click I75684 "https://github.com/NousResearch/hermes-agent/issues/75684"
    click P75729 "https://github.com/NousResearch/hermes-agent/pull/75729"
Loading

Graph: solid arrow = fixes / best fix, dashed arrow = partial or unverified (see edge label); boxed group = PRs duplicating each other; amber border = best fix; indigo border = target; gray node = closed (state tag in the node label).

Cross-PR triage: Reviewed 1 pull request and 1 issue in this complex. Each diff was read against this issue; Assessment working set: 10 kB of PR diffs, 5 kB of issue/PR text, 2 verify verdicts. verdicts reflect diff content, not PR titles. Part of an automated triage batch.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/config Config system, migrations, profiles area/memory Memory subsystem: store, providers, sync, background reviews area/profiles Multi-profile isolation, HERMES_HOME scoping comp/gateway Gateway runner, session dispatch, delivery P2 Medium — degraded but workaround exists sweeper:blast-moderate Sweeper blast radius: moderate — a subsystem or single platform sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages sweeper:risk-security-boundary Sweeper risk: may affect sandboxing, auth, credentials, or sensitive data sweeper:risk-session-state Sweeper risk: may lose/corrupt/mis-associate session or context state tool/memory Memory tool and memory providers tool/skills Skills system (list, view, manage) type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Multiplex /memory and /skills use default profile home instead of routed profile

4 participants