Files
hermes-agent/hermes_cli
Brooklyn Nicholson 7a21d15c35 feat(tui): add attachments.storage config for workspace attachment staging
Desktop file attachments stage into <profile home>/attachments, which sits
outside the session workspace, so an agent with a restricted workspace can be
unable to read the very files the user attached to it (#110662).

Add a top-level `attachments.storage` config key ("hermes-home" default |
"workspace" opt-in). The gateway reads it per profile from the session's
profile config.yaml — file.attach runs before prompt.submit installs the
profile scope, so the process config still belongs to the launch profile
(same reason as _profile_configured_cwd). Opting in stages attachments under
<workspace>/.hermes/attachments, inside the allowed ref root, so the @file:
ref stays workspace-relative and the same profile's agent can always read its
own attachments back.

A remote (ssh) profile keeps the profile home dir either way: its workspace
lives on the execution host, and the bind-mounted <profile home>/attachments
is what container and remote backends receive (#76577). Traversal hardening
and staging name sanitization are unchanged.

Fixes https://github.com/NousResearch/hermes-agent/issues/110662
2026-09-27 19:07:07 -05:00
..
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…
…