hermes-agent/agent
snav 0b8e81996f fix(codex-app-server): honor approvals.mode/yolo for gateway-context approval routing
On gateway/cron/non-CLI contexts the codex app-server runtime has no UI to
surface codex's exec/apply_patch approval requests, so they fail closed
(silently decline) — the bot appears responsive but cannot write files, with
no approval prompt anywhere ("patch rejected by user").

When the user has explicitly opted out of Hermes approvals (approvals.mode: off,
the /yolo session toggle, or HERMES_YOLO_MODE=1), collapse to codex's own
sandbox permission profile (~/.codex/config.toml) as the policy gate by passing
_ServerRequestRouting(auto_approve_exec=True, auto_approve_apply_patch=True) to
the session. Defaults (manual/smart/unset) preserve the current fail-closed
behavior — a no-op for users who have not opted out.

Reads the mode via the canonical tools.approval._get_approval_mode() (which
already normalizes the YAML-1.1 bare-'off'->False case) at session-build time,
so a mid-session /yolo toggle is honored too.

5 integration tests: each opt-out mechanism (config off, YAML False, env var,
session yolo) plus the default fail-closed regression guard.

Closes #26530

Co-authored-by: snav <jake@nousresearch.com>
2026-07-01 22:58:37 +05:30
..
lsp fix(tui): prevent killpg suicide during MCP shutdown 2026-07-01 04:54:46 -07:00
pet fix(pet): snap kitty frames to whole cells 2026-06-30 15:41:44 -05:00
secret_sources
…
transports fix(security): strip dynamic Hermes secrets from all subprocess spawn env 2026-07-01 14:37:22 +05:30
__init__.py
…
account_usage.py
…
agent_init.py fix(review): isolate the background-review fork from the canonical session 2026-07-01 16:21:39 +05:30
agent_runtime_helpers.py revert: back out prompt_caching.enabled toggle (#56105) for re-evaluation (#56126) 2026-07-01 00:20:32 -07:00
anthropic_adapter.py fix(anthropic): use claude-code/ UA prefix for OAuth to avoid 404 (#48534) 2026-07-01 15:42:15 +05:30
async_utils.py
…
auxiliary_client.py fix(moa): raise aux timeouts to 900s and give the Codex aux path a stable prompt_cache_key (#56395) 2026-07-01 06:02:40 -07:00
azure_identity_adapter.py
…
background_review.py fix(review): isolate the background-review fork from the canonical session 2026-07-01 16:21:39 +05:30
bedrock_adapter.py
…
billing_view.py
…
browser_provider.py
…
browser_registry.py
…
chat_completion_helpers.py fix: make Nous Portal access token resolution resilient 2026-07-01 05:06:00 -07:00
codex_responses_adapter.py
…
codex_runtime.py fix(codex-app-server): honor approvals.mode/yolo for gateway-context approval routing 2026-07-01 22:58:37 +05:30
coding_context.py feat(agent): add configurable coding_instructions 2026-06-30 00:59:59 -05:00
context_breakdown.py feat(desktop): add context usage breakdown popover 2026-06-29 09:18:10 -04:00
context_compressor.py fix(compaction): detect and strip merge-into-tail summaries past the delimiter 2026-07-01 18:23:01 +05:30
context_engine.py fix(context): clamp -1 post-compression sentinel in sibling status paths 2026-07-01 13:36:50 +05:30
context_references.py fix(security): anchor @file context refs to canonical read deny-list 2026-07-01 02:43:49 -07:00
conversation_compression.py fix(agent): make compression lock-lease refresher tolerate transient DB blips 2026-06-30 13:36:29 +05:30
conversation_loop.py fix(moa): price aggregator turn at its real model so session cost isn't advisor-only (#56394) 2026-07-01 06:02:33 -07:00
copilot_acp_client.py fix(agent): stream copilot ACP chat completions 2026-06-28 22:52:51 -07:00
credential_persistence.py
…
credential_pool.py fix(auth): serialize Codex OAuth pool refresh under the auth-store lock (#56233) 2026-07-01 02:45:07 -07:00
credential_sources.py
…
credits_tracker.py
…
curator.py fix(curator): never archive cron-referenced skills + floor use=0 pruning (#54443) 2026-06-28 15:10:21 -07:00
curator_backup.py
…
display.py feat(display): friendly human-phrased tool labels for built-in tools (#55166) 2026-06-29 20:31:17 -07:00
error_classifier.py fix(error-classifier): route 5xx context-overflow into compression 2026-07-01 16:14:16 +05:30
errors.py
…
file_safety.py fix(file): block credential paths from search results 2026-07-01 01:02:35 -07:00
gemini_native_adapter.py Merge consecutive same-role contents for native Gemini 2026-06-30 11:51:22 -07:00
gemini_schema.py
…
i18n.py
…
image_gen_provider.py
…
image_gen_registry.py
…
image_routing.py fix(vision): detect Ollama vision models via /api/show (#54511) 2026-06-28 22:52:59 -07:00
insights.py
…
iteration_budget.py
…
jiter_preload.py
…
learn_prompt.py fix(learn): honor requirements mixed with sources in /learn requests (#55956) 2026-06-30 16:56:01 -07:00
learning_graph.py fix(desktop): scope memory graph cache by profile 2026-06-30 03:44:41 -05:00
learning_graph_render.py fix(journey): swap skill/memory inks so drillable rows read as clickable 2026-06-30 11:54:16 -05:00
learning_mutations.py refactor(journey): route memory mutations through MemoryStore atomic I/O 2026-06-30 15:16:21 -05:00
lmstudio_reasoning.py
…
manual_compression_feedback.py
…
markdown_tables.py
…
memory_manager.py
…
memory_provider.py
…
message_content.py
…
message_sanitization.py
…
moa_loop.py fix(moa): price aggregator turn at its real model so session cost isn't advisor-only (#56394) 2026-07-01 06:02:33 -07:00
moa_trace.py fix(moa): capture streamed aggregator output into full-turn traces (#56312) 2026-07-01 04:07:46 -07:00
model_metadata.py fix(context): parse vLLM's token-based output-cap error format 2026-07-01 03:17:48 -07:00
models_dev.py
…
moonshot_schema.py
…
nous_rate_guard.py
…
onboarding.py
…
oneshot.py
…
plugin_llm.py
…
portal_tags.py
…
process_bootstrap.py
…
prompt_builder.py fix(agent): limit .hermes.md parent walk to git repos only 2026-06-28 20:46:32 -07:00
prompt_caching.py
…
rate_limit_tracker.py
…
reasoning_timeouts.py
…
redact.py security(agent): redact Slack App-Level (xapp-) tokens 2026-07-01 02:45:22 -07:00
replay_cleanup.py
…
retry_utils.py
…
runtime_cwd.py
…
secret_scope.py
…
shell_hooks.py feat(agent): add pre_verify hook and verify-on-stop coding guidance 2026-06-30 00:59:29 -05:00
skill_bundles.py
…
skill_commands.py
…
skill_preprocessing.py fix(windows): hide console-window flash on backend git/gh/wmic/bash subprocess spawns 2026-06-28 05:28:45 -07:00
skill_utils.py
…
ssl_guard.py
…
stream_diag.py
…
subdirectory_hints.py fix(subdirectory_hints): catch RuntimeError from Path.expanduser() 2026-07-01 04:55:15 -07:00
system_prompt.py
…
think_scrubber.py
…
thinking_timeout_guidance.py
…
thread_scoped_output.py fix(bg-review): scope stdout/stderr silencing to the worker thread (#55966) 2026-06-30 17:28:33 -07:00
title_generator.py fix(title_generator): strip think blocks from LLM output before extracting title 2026-07-01 04:18:48 -07:00
tool_dispatch_helpers.py fix(agent): wrap list-type untrusted content in untrusted_tool_result 2026-07-01 02:44:09 -07:00
tool_executor.py fix(agent): prefer late-completing real result over timeout message (review) 2026-07-01 14:56:52 +05:30
tool_guardrails.py
…
tool_result_classification.py
…
trajectory.py
…
transcription_provider.py
…
transcription_registry.py
…
tts_provider.py
…
tts_registry.py
…
turn_context.py fix(memory): degrade gracefully after repeated at-capacity consolidation failures (#42405) 2026-06-30 20:01:16 +05:30
turn_finalizer.py fix(agent): persist recovered final responses 2026-07-01 03:34:49 -07:00
turn_retry_state.py feat(vertex): add Google Vertex AI provider for Gemini (OAuth2) 2026-07-01 05:25:33 -07:00
usage_pricing.py feat(vertex): add Google Vertex AI provider for Gemini (OAuth2) 2026-07-01 05:25:33 -07:00
verification_evidence.py
…
verification_stop.py feat(agent): restore surface-aware "auto" default for verify_on_stop 2026-06-30 01:43:08 -05:00
verify_hooks.py feat(agent): add pre_verify hook and verify-on-stop coding guidance 2026-06-30 00:59:29 -05:00
vertex_adapter.py feat(vertex): add Google Vertex AI provider for Gemini (OAuth2) 2026-07-01 05:25:33 -07:00
video_gen_provider.py
…
video_gen_registry.py
…
web_search_provider.py
…
web_search_registry.py
…