From f5200a4c10d4a0c563cb1693b9f616ba79889c31 Mon Sep 17 00:00:00 2001 From: fangliquanflq Date: Thu, 13 Aug 2026 03:31:26 +0800 Subject: [PATCH] fix(config): declare shared Docker container key --- cli.py | 1 + hermes_cli/config_defaults.py | 3 +++ tests/hermes_cli/test_set_config_value.py | 14 ++++++++++++++ 3 files changed, 18 insertions(+) diff --git a/cli.py b/cli.py index c0a02a3cba..2600a5845c 100644 --- a/cli.py +++ b/cli.py @@ -458,6 +458,7 @@ def load_cli_config() -> Dict[str, Any]: "daytona_image": "nikolaik/python-nodejs:python3.11-nodejs20", "docker_volumes": [], # host:container volume mounts for Docker backend "docker_mount_cwd_to_workspace": False, # explicit opt-in only; default off for sandbox isolation + "docker_shared_container_key": "", }, "browser": { "inactivity_timeout": 120, # Auto-cleanup inactive browser sessions after 2 min diff --git a/hermes_cli/config_defaults.py b/hermes_cli/config_defaults.py index 8d68834a9b..e270042131 100644 --- a/hermes_cli/config_defaults.py +++ b/hermes_cli/config_defaults.py @@ -495,6 +495,9 @@ DEFAULT_CONFIG = { # When on, SETUID/SETGID caps are omitted from the container since # no privilege drop is needed. "docker_run_as_host_user": False, + # Explicit opt-in for trusted profiles to reuse the same Docker + # container identity. Empty preserves the active-profile boundary. + "docker_shared_container_key": "", # Persistent shell — keep a long-lived bash shell across execute() calls # so cwd/env vars/shell variables survive between commands. # Enabled by default for non-local backends (SSH); local is always opt-in diff --git a/tests/hermes_cli/test_set_config_value.py b/tests/hermes_cli/test_set_config_value.py index cd62cda456..264aa29708 100644 --- a/tests/hermes_cli/test_set_config_value.py +++ b/tests/hermes_cli/test_set_config_value.py @@ -128,6 +128,20 @@ class TestConfigYamlRouting: or "TERMINAL_DOCKER_MOUNT_CWD_TO_WORKSPACE=True" in env_content ) + def test_terminal_docker_shared_key_preserves_string_values( + self, _isolated_hermes_home, capsys + ): + set_config_value("terminal.docker_shared_container_key", "off") + + import yaml + + saved = yaml.safe_load(_read_config(_isolated_hermes_home)) + assert saved["terminal"]["docker_shared_container_key"] == "off" + assert "TERMINAL_DOCKER_SHARED_CONTAINER_KEY=off" in _read_env( + _isolated_hermes_home + ) + assert "not a recognized config key" not in capsys.readouterr().out + def test_terminal_vercel_runtime_goes_to_config_and_env(self, _isolated_hermes_home): set_config_value("terminal.vercel_runtime", "python3.13") config = _read_config(_isolated_hermes_home)