Skip to content

fix(myah): derive allowed media roots from terminal.cwd + env var - #11

Merged
deestax merged 1 commit into
mainfrom
fix/derive-media-roots-from-config
Apr 28, 2026
Merged

deestax merged 1 commit into
mainfrom
fix/derive-media-roots-from-config

Conversation

@deestax

@deestax deestax commented Apr 28, 2026

Copy link
Copy Markdown
Member

Replaces the hardcoded allowlist in _myah_allowed_media_roots with a derived list that covers the agent's actual working directory.

Problem: The previous allowlist contained only four Hermes cache subdirectories. Files written by the agent to its working directory (e.g. /root/, the Docker default for terminal.cwd) returned 403 from the media endpoint even when the platform detected the path correctly. The platform-side regex widening (myah PR NousResearch#63) detects the path; this change makes the agent actually serve it.

Fix: The allowlist is now derived from three sources:

  1. Canonical Hermes cache dirs (always included, back-compat with existing behaviour)
  2. terminal.cwd from config.yaml — loaded via hermes_cli.config.load_config(). For hosted Myah the Docker image sets terminal.cwd: /root so /root is auto-included. For OSS deployments whatever the user configured (e.g. ~/workspace) is auto-included without any code changes.
  3. MYAH_MEDIA_ALLOWED_ROOTS env var (colon-separated paths) for any additional explicit additions.

Paths that fail to resolve (don't exist yet on disk) are silently dropped rather than crashing the endpoint. ImportError from hermes_cli.config is caught with a graceful fallback to the env-var-only path.

All Myah additions are wrapped in the standard # ── Myah: ... ── / # ──── markers.

Pairs with T3-Venture-Labs-Limited/myah PR NousResearch#63 (platform-side regex widening for /root and /Users).

Replaces the hardcoded list of four cache directories with a derived
list that includes:
  1. The canonical Hermes cache dirs (always)
  2. Hermes' configured terminal.cwd (for hosted Myah this auto-includes
     /root; for OSS deployments this auto-includes whatever the user
     configured, e.g. ~/workspace)
  3. Optional MYAH_MEDIA_ALLOWED_ROOTS env var (colon-separated paths)

Topology-agnostic: works identically for hosted and OSS Myah without
hardcoding either's path conventions.

Spec ref: myah/docs/superpowers/specs/2026-04-28-cron-and-files-fixes-design.md §6.B2
@deestax
deestax merged commit 6f406a0 into main Apr 28, 2026
6 of 7 checks passed
@deestax
deestax deleted the fix/derive-media-roots-from-config branch April 28, 2026 08:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant