Files
hermes-agent/apps
teknium1 485979ddf4 fix(review): validate the logsRoot owner name; scope the whole palette and fail 4064 on an unknown profile
Independent-review findings on #126159:

- MAJOR: `hermes:fs:logsRoot` joined a renderer-supplied profile name into
  `profiles/<name>` unvalidated (session-owner data; from the remote backend in
  remote mode), so `..`/absolute values escaped the profiles root, were created
  and revealed. `localPluginsRoot` now accepts only `default` or a
  `DESKTOP_PROFILE_NAME_RE` match — the gate `localSkinProfileKey` and main.ts
  already apply — and otherwise falls back to the active Desktop profile.
- MINOR (b): `commands.catalog` scoped skill discovery to the routed profile but
  read quick_commands and plugin commands unscoped, listing the LAUNCH profile's
  quick commands in a profile-routed palette. All loaders run inside the one
  `_session_home_scope` block.
- MINOR (c): `commands.catalog` swallowed ProfileUnavailableError into a warning
  (ok + empty skills) while complete.slash returned 4064; `_profile_scoped_rpc`
  re-raises it so dispatch maps it to 4064 (also fixes skills.reload's 5025).
- MINOR (a): the shared `session_gateway_runtime` reader's new merge (top-level
  base_url/api_mode + billing_provider) gets a CLI-side test; the CLI-visible
  precedence change is disclosed in the PR body.
2026-09-28 03:13:19 -07:00
..