Repository navigation
Conversation
Packaged Desktop on Linux/NixOS often inherits a stripped PATH without the nix profile shims where `hermes` is installed after `hermes setup`. Fall back to `sh -lc 'command -v hermes'` before triggering bootstrap. Fixes NousResearch#42923
Reorder backend-probes docs/functions and restrict login-shell PATH resolution to an allowlisted command name so the sh -lc probe cannot be abused for shell injection.
|
Verification comment — security-reviewed by scheduled code review bot Reviewed the login-shell PATH probe implementation. The approach is solid:
One minor observation: No issues found. Clean security fix for NixOS/Linux PATH resolution. |
teknium1
left a comment
There was a problem hiding this comment.
Thanks for tracing the NixOS packaged-PATH failure. The premise is still present on current main: apps/desktop/electron/main.ts:3416 only calls findOnPath('hermes'), so a CLI available solely through the login-shell profile is not considered.
Problems
- This branch targets Electron
.cjsfiles that no longer exist on main. Commit39d09453fmigrated the relevant code toapps/desktop/electron/main.tsandapps/desktop/electron/backend-probes.ts; GitHub consequently reports the PR as conflicting. - The new tests in
apps/desktop/electron/backend-probes.test.cjs:84-101cover only rejected/no-op inputs. They do not verify a successful login-shell lookup or theresolveHermesBackendfallback.
Suggested changes
- Salvage the allowlisted probe into the current TypeScript files and insert it after
findOnPath('hermes')atapps/desktop/electron/main.ts:3416, preserving the existingverifyHermesClicheck at line 3442. - Add controlled success and resolver-fallback coverage rather than relying on a host-installed CLI.
Automated hermes-sweeper review.
| assert.equal(verifyHermesCli('/definitely/not/a/real/binary/anywhere'), false) | ||
| }) | ||
|
|
||
| test('findCommandOnLoginShell returns null for falsy command', () => { |
There was a problem hiding this comment.
These tests cover only early-return guard paths. Please add controlled coverage that proves a successful login-shell lookup is used by the resolver after findOnPath('hermes') misses.
|
Closing this older point fix as superseded by the merged #69696 ( |
Summary
On Linux/NixOS, Hermes Desktop can inherit a stripped
PATHthat omits nix profile shims wherehermesis installed afterhermes setup. The resolver then falls through to first-launch bootstrap even though the CLI works in the user's shell.Fix
When
findOnPath('hermes')misses on non-Windows hosts, fall back tosh -lc 'command -v hermes'before bootstrap.Fixes #42923
Notes
This addresses PATH visibility for packaged Desktop launches. The separate "pick existing folder" validation for
~/.hermeswithout a checkout tree may still need follow-up if that UI path remains broken on Nix.Verification