fix(approval): deterministic approvals.single_query_mode for -q sessions
hermes chat -q sets HERMES_INTERACTIVE=1 (for interactive sudo prompts) but
runs one turn with no user waiting to answer approval prompts. Previously a
dangerous command triggered the interactive gate, waited the full 300s
timeout, then failed closed — and the agent was effectively forced to work
around the block, often silently auto-approving via execute_code (which
auto-approves in non-gateway mode).
Add approvals.single_query_mode (default deny, mirror of cron_mode):
deny — block dangerous commands and execute_code deterministically with
a clear 'no user present' message (no 300s wait)
approve — auto-approve dangerous commands/execute_code in -q mode
cli.py marks the session with HERMES_SINGLE_QUERY_SESSION; the shared gate
(_run_approval_gate, check_all_command_guards, check_execute_code_guard)
treats -q as a deterministic non-interactive context when that marker is set.
execute_code, the -q escape hatch, now honors single_query_mode instead of
auto-approving headlessly. Includes tirith parity in the combined guard and
docs. Fixes #86878.
This commit is contained in:
@@ -19889,6 +19889,14 @@ def main(
|
||||
# agent must wait the full MCP cold-start bound before its first
|
||||
# (and only) tool snapshot. See #51316.
|
||||
cli._single_query_mode = True
|
||||
# Mark single-query for the approval gate. cli.py sets
|
||||
# HERMES_INTERACTIVE earlier for interactive sudo prompts, but a -q
|
||||
# run has NO user waiting to answer approval prompts. The gate reads
|
||||
# this marker (via gateway.session_context.get_session_env, which falls
|
||||
# back to os.environ when the session-context layer isn't engaged) and
|
||||
# takes the deterministic approvals.single_query_mode path instead of
|
||||
# waiting the full timeout. See #86878.
|
||||
os.environ["HERMES_SINGLE_QUERY_SESSION"] = "1"
|
||||
if not cli._claim_active_session("cli", stderr=bool(quiet)):
|
||||
sys.exit(1)
|
||||
try:
|
||||
|
||||
Reference in New Issue
Block a user