fix(myah): derive allowed media roots from terminal.cwd + env var - #11
Merged
Merged
Conversation
Replaces the hardcoded list of four cache directories with a derived
list that includes:
1. The canonical Hermes cache dirs (always)
2. Hermes' configured terminal.cwd (for hosted Myah this auto-includes
/root; for OSS deployments this auto-includes whatever the user
configured, e.g. ~/workspace)
3. Optional MYAH_MEDIA_ALLOWED_ROOTS env var (colon-separated paths)
Topology-agnostic: works identically for hosted and OSS Myah without
hardcoding either's path conventions.
Spec ref: myah/docs/superpowers/specs/2026-04-28-cron-and-files-fixes-design.md §6.B2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Replaces the hardcoded allowlist in
_myah_allowed_media_rootswith a derived list that covers the agent's actual working directory.Problem: The previous allowlist contained only four Hermes cache subdirectories. Files written by the agent to its working directory (e.g.
/root/, the Docker default forterminal.cwd) returned 403 from the media endpoint even when the platform detected the path correctly. The platform-side regex widening (myah PR NousResearch#63) detects the path; this change makes the agent actually serve it.Fix: The allowlist is now derived from three sources:
terminal.cwdfromconfig.yaml— loaded viahermes_cli.config.load_config(). For hosted Myah the Docker image setsterminal.cwd: /rootso/rootis auto-included. For OSS deployments whatever the user configured (e.g.~/workspace) is auto-included without any code changes.MYAH_MEDIA_ALLOWED_ROOTSenv var (colon-separated paths) for any additional explicit additions.Paths that fail to resolve (don't exist yet on disk) are silently dropped rather than crashing the endpoint.
ImportErrorfromhermes_cli.configis caught with a graceful fallback to the env-var-only path.All Myah additions are wrapped in the standard
# ── Myah: ... ──/# ────markers.Pairs with
T3-Venture-Labs-Limited/myahPR NousResearch#63 (platform-side regex widening for/rootand/Users).