Files
hermes-agent/hermes_cli
fangliquanflq 1c37b9c457 fix(approval): approvals.deny applies inside isolated containers too (#91002)
Both shell-command guard entry points returned approval from the isolated-container fast
path before the operator's approvals.deny rules were evaluated, so a Docker sandbox with
no host mounts (or singularity/modal/daytona/vercel) skipped the entire user deny list.
The deny list is documented as never bypassable: it states what the agent may DO, not
what it can reach. Evaluate it before the container skip; the built-in dangerous-command
heuristics keep skipping there. hermes approvals test mirrors the new order.

Salvaged from #91029 by @fangliquanflq.
2026-09-05 18:08:00 +05:30
..