e444d16580
* fix(vision): mount images/ upload dir into sandboxes and permit host read (#69575) Desktop, clipboard, and PDF uploads land in the flat top-level HERMES_HOME/images/ dir, but Docker sandboxes only mounted the cache/ subtree and the vision resolver only permitted host reads from the media caches. So vision_analyze on any desktop-app upload failed under a Docker backend with "not reachable inside the sandbox". - Add ("images", "images") to _CACHE_DIRS so the uploads dir is bind-mounted into sandbox containers through the existing profile-scoped cache-mount and reverse-mapping mechanism. - Add home/"images" to _media_cache_roots() so the non-local host-read allowlist permits reading uploads directly from the host filesystem. - Cover the mount entry, the container path mapping, and the Docker-mode resolver read for a profile-scoped upload. Co-authored-by: JonthanaHanh <92574114+JonthanaHanh@users.noreply.github.com> Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com> * fix(tui_gateway): write image uploads under the session's profile home (#69575) The attach RPCs (image.attach_bytes, clipboard.paste, pdf.attach) wrote uploads to the gateway's module-cached launch home via _hermes_home/"images". Those RPCs run before prompt.submit installs the session's profile HERMES_HOME override, so in a multi-profile / root-gateway deployment the file landed in the launch home while the sandbox mount and the vision host-read allowlist both resolve the session profile's images/ at run time — the agent could never see the upload it was handed. Add _session_images_dir(session), which anchors the write on the session's stored profile_home when present (matching the mount/read scope) and falls back to the launch home otherwise. Route both write sites through it, keeping per-profile isolation. Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com> --------- Co-authored-by: JonthanaHanh <92574114+JonthanaHanh@users.noreply.github.com> Co-authored-by: webtecnica <75556242+webtecnica@users.noreply.github.com>