docs: update secure_parent_dir docstring and caller comments for the install-tree exclusion

The docstring and all four caller comments still said the helper
refuses only / and top-level directories. Since #93757 it also refuses
the entire hermes-agent install tree. Bring the docstring and the
comments at the four credential-write call sites in line with the
actual behavior so future changes are not misled by a stale safety
description.

Follow-up to #93757.
This commit is contained in:
Ben Barclay
2026-08-25 10:55:53 +10:00
parent 8b48f621c5
commit 98f0e0df07
3 changed files with 15 additions and 5 deletions
+6 -3
View File
@@ -1424,7 +1424,8 @@ def _save_auth_store(auth_store: Dict[str, Any], target_path: Optional[Path] = N
auth_file.parent.mkdir(parents=True, exist_ok=True)
# Tighten parent dir to 0o700 so siblings can't traverse to creds.
# No-op on Windows (POSIX mode bits not enforced); ignore failures.
# secure_parent_dir refuses to chmod / or top-level dirs (#25821).
# secure_parent_dir refuses to chmod /, top-level dirs, or the
# hermes-agent install tree (#25821, #93050).
secure_parent_dir(auth_file)
auth_store["version"] = AUTH_STORE_VERSION
auth_store["updated_at"] = datetime.now(timezone.utc).isoformat()
@@ -2812,7 +2813,8 @@ def _read_qwen_cli_tokens() -> Dict[str, Any]:
def _save_qwen_cli_tokens(tokens: Dict[str, Any]) -> Path:
auth_path = _qwen_cli_auth_path()
auth_path.parent.mkdir(parents=True, exist_ok=True)
# secure_parent_dir refuses to chmod / or top-level dirs (#25821).
# secure_parent_dir refuses to chmod /, top-level dirs, or the
# hermes-agent install tree (#25821, #93050).
secure_parent_dir(auth_path)
# Per-process random temp suffix avoids collisions between concurrent
# writers and stale leftovers from a crashed prior write.
@@ -5628,7 +5630,8 @@ def _write_shared_nous_state(state: Dict[str, Any]) -> None:
with _nous_shared_store_lock():
path = _nous_shared_store_path()
path.parent.mkdir(parents=True, exist_ok=True)
# secure_parent_dir refuses to chmod / or top-level dirs (#25821).
# secure_parent_dir refuses to chmod /, top-level dirs, or the
# hermes-agent install tree (#25821, #93050).
secure_parent_dir(path)
tmp = path.with_name(f"{path.name}.tmp.{os.getpid()}.{uuid.uuid4().hex}")
# Create with 0o600 atomically via os.open(O_EXCL) — closes the TOCTOU
+7 -1
View File
@@ -1022,7 +1022,13 @@ def secure_parent_dir(path: Path) -> None:
prevent catastrophic host bricking when ``HERMES_HOME`` or other path
env vars resolve to an unexpected location.
See https://github.com/NousResearch/hermes-agent/issues/25821.
Also refuses to chmod the hermes-agent install tree (the directory this
module lives in, and anything below it): restricting the install dir to
0700 locks the runtime user out of traversing it when it does not own
the dir, as in the Docker image. A warning is logged when this happens.
See https://github.com/NousResearch/hermes-agent/issues/25821 and
https://github.com/NousResearch/hermes-agent/pull/93050.
"""
parent = path.parent.resolve()
# Refuse root and its direct children (/usr, /home, /var, /tmp, …).
+2 -1
View File
@@ -424,7 +424,8 @@ def _write_json(path: Path, data: dict) -> None:
path.parent.mkdir(parents=True, exist_ok=True)
# Tighten parent dir to 0o700 so siblings can't traverse to the creds.
# No-op on Windows (POSIX mode bits aren't enforced); ignore failures.
# secure_parent_dir refuses to chmod / or top-level dirs (#25821).
# secure_parent_dir refuses to chmod /, top-level dirs, or the
# hermes-agent install tree (#25821, #93050).
secure_parent_dir(path)
# Per-process random suffix avoids collisions between concurrent
# writers and stale leftovers from a prior crashed write.