23526148d1
terminal_tool reads all settings from TERMINAL_* env vars, bridged from config.yaml by the CLI, gateway, and TUI-PTY launchers. Processes that skip every launcher bridge — hermes serve / the Desktop app backend's in-process agents, the desktop cron ticker — saw an unset TERMINAL_ENV and silently ran every command on the host even when config.yaml selects terminal.backend: docker. A user who configured Docker isolation got unsandboxed host execution with no warning. Two layers: - _ensure_terminal_env_bridged() in _get_env_config(): when TERMINAL_ENV is unset, backfill TERMINAL_* from config.yaml via apply_terminal_config_to_env(override=False). Explicit env always wins (honor explicit choice; only fix the accidental fallback). One-shot, fail-open to the historical local default. - cmd_dashboard/serve: run the same bridge at startup so every consumer in the backend process (in-process agents, desktop cron ticker, tui_gateway cwd resolution) sees the bridged env directly. Fixes #63141, #54449, #61115, #65696.