Skip to content

fix(config): allow HERMES_HOME permissions override via HERMES_HOME_M…#6994

Closed
devorun wants to merge 1 commit into
NousResearch:mainfrom
devorun:patch-42
Closed

fix(config): allow HERMES_HOME permissions override via HERMES_HOME_M…#6994
devorun wants to merge 1 commit into
NousResearch:mainfrom
devorun:patch-42

Conversation

@devorun

@devorun devorun commented Apr 10, 2026

Copy link
Copy Markdown
Contributor

…ODE (#6991)

What does this PR do?

Fixes #6991

The Bug

_secure_dir() in config.py unconditionally applies 0o700 permissions to directories on every gateway startup. This removes the other-execute bit (o+x), preventing web servers (like nginx) from traversing into HERMES_HOME subdirectories to serve content, resulting in persistent 403 Forbidden errors.

The Fix

Introduced the HERMES_HOME_MODE environment variable to _secure_dir().

  • Defaults to 0700 to maintain strict owner-only access for standard installations.
  • Deployments requiring directory traversal can now explicitly opt-in by setting HERMES_HOME_MODE=0701 (or similar).
  • Preserved the existing is_managed() carve-out for NixOS setups.
  • Included graceful handling of ValueError if an invalid octal string is provided.

Related Issue

Fixes #

Type of Change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 🔒 Security fix
  • 📝 Documentation update
  • ✅ Tests (adding or improving test coverage)
  • ♻️ Refactor (no behavior change)
  • 🎯 New skill (bundled or hub)

Changes Made

How to Test

Checklist

Code

  • I've read the Contributing Guide
  • My commit messages follow Conventional Commits (fix(scope):, feat(scope):, etc.)
  • I searched for existing PRs to make sure this isn't a duplicate
  • My PR contains only changes related to this fix/feature (no unrelated commits)
  • I've run pytest tests/ -q and all tests pass
  • I've added tests for my changes (required for bug fixes, strongly encouraged for features)
  • I've tested on my platform:

Documentation & Housekeeping

  • I've updated relevant documentation (README, docs/, docstrings) — or N/A
  • I've updated cli-config.yaml.example if I added/changed config keys — or N/A
  • I've updated CONTRIBUTING.md or AGENTS.md if I changed architecture or workflows — or N/A
  • I've considered cross-platform impact (Windows, macOS) per the compatibility guide — or N/A
  • I've updated tool descriptions/schemas if I changed tool behavior — or N/A

For New Skills

  • This skill is broadly useful to most users (if bundled) — see Contributing Guide
  • SKILL.md follows the standard format (frontmatter, trigger conditions, steps, pitfalls)
  • No external dependencies that aren't already available (prefer stdlib, curl, existing Hermes tools)
  • I've tested the skill end-to-end: hermes --toolsets skills -q "Use the X skill to do Y"

Screenshots / Logs

@teknium1

Copy link
Copy Markdown
Contributor

Closed in favor of #6993 which includes the same fix plus a docstring update explaining the web server traversal use case. Your fix was correct and identical in approach — thanks for the contribution, @devorun!

@teknium1 teknium1 closed this Apr 10, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug]: _secure_dir() resets ~/.hermes to 0700 on every gateway start, breaking nginx serving from subdirectories

2 participants