Files
hermes-agent/tools
Tarek Belkahia 70a64db532 feat(gateway): deliver MEDIA files that live inside a remote terminal sandbox (#466)
`MEDIA:/path` only delivered when the file existed on the gateway host.
With the ssh / modal / daytona / singularity / vercel backends the agent's
artifact sits on another filesystem, so `validate_media_delivery_path`
rejected it and the attachment vanished with a "Skipping unsafe" log line —
the #1 gap for sandboxed deployments.

`BaseEnvironment.fetch_file` pulls a regular file out of any backend over
the exec channel (base64, marker-fenced, size-bounded INSIDE the sandbox so
/dev/zero cannot flood host memory — the same shape image_source already
uses). `gateway/media_fetch.py` runs only when a remote backend is active
and the host lookup failed: the sandbox path is screened against the SAME
denylist as host deliveries, again after `readlink -f`, then copied into
the document cache (an allowlisted root) and validated like any host file.
No new tool; the existing `MEDIA:` tag is the interface.

Salvaged from #68506 by @tokou (design and denylist mirroring); redone on
current main without the send_file tool, the per-backend transports and
the undeliverable-notice plumbing (the #66797 failure notice already covers
that surface).
2026-09-05 16:09:46 +05:30
..