Commit Graph

8 Commits

Author SHA1 Message Date
Ruichen Zhou 50b54bb18f fix(ssh): isolate prompt backend probes from file sync
The prompt-time backend probe built a normal SSHEnvironment just to run a
one-line `uname`. That constructor detects the remote home, creates the
~/.hermes tree, force-uploads every sync file and snapshots a login session;
when the throwaway object was later garbage-collected, __del__ -> cleanup()
ran sync_back() and `ssh -O exit` against the ControlMaster socket the
agent's real environment shares (keyed by user@host:port).

Add an internal probe_only construction path for SSH: an isolated,
same-length ControlMaster socket (keyed by the instance's session id), no
remote dir setup, no FileSyncManager, no session snapshot. The probe now
tears its own connection down explicitly on success, non-zero exit and
exception, without replacing the probe result when cleanup fails. Normal
SSH callers and non-SSH backends are unchanged.

Salvaged from #77933 onto the facade/sibling layout (the probe body moved to
_run_backend_probe, _create_environment to tools/terminal_tool_backends.py).
2026-09-06 13:32:51 +05:30
kshitijk4poor 256bd1adc9 feat(docker): terminal.docker_snap_compat opt-out for snap-packaged Docker under AppArmor (#9730)
On hosts where Docker ships as a snap (Ubuntu cloud images / Azure VMs), the
snap's AppArmor confinement turns two sandbox hardening flags into a dead
container at start: `--init` fails with "exec /sbin/docker-init: operation not
permitted" and `--security-opt no-new-privileges` then fails every exec the
same way ("exec /usr/bin/sleep: operation not permitted"). This is snapd
LP#1908448 — not probeable from the client, and docker_extra_args cannot remove
flags we add.

`terminal.docker_snap_compat: true` drops exactly those two flags; cap-drop ALL,
the tmpfs hardening, PID limits and the privdrop caps are unchanged, and a
warning is logged at container start. Bridged everywhere the other docker_*
keys are (CLI env map, gateway env map, `hermes config set` sync, terminal_tool
env read, the shared container_config shaper, DEFAULT_CONFIG).
2026-09-05 21:00:19 +05:30
Teknium 98c140bc4b simplify(compat): code_execution_tool/environments.local — drop 36 re-exports, repoint 5 callers + 14 test files 2026-09-03 13:24:04 -07:00
Teknium 97700e2ac1 refactor(terminal): drop dead per-backend _check_* aliases (table entries are the callers) 2026-09-02 20:50:23 -07:00
Teknium 5e3c9e215c refactor(terminal): fold vercel checks into spec, table docker kwargs, compact to 329 LOC 2026-09-02 20:30:20 -07:00
Teknium df6921b0d9 refactor(terminal): spec-table requirement checkers, shared modal reason, tabled sandbox builders 2026-09-02 20:14:17 -07:00
Teknium d320d5f741 refactor(termhub): compact re-export blocks and wrap companion-module docstrings 2026-09-02 15:59:18 -07:00
Teknium 21c7037975 refactor(terminal): extract sudo/shell-rewrite cluster to terminal_tool_sudo and backend builders/checkers to terminal_tool_backends 2026-09-02 15:31:31 -07:00