Repository navigation
fix(agent): agent notifications and Herdr state in the Docker sandbox - #63
Merged
Merged
Conversation
Agents in a Docker-sandboxed run sent no desktop notifications when a turn finished or they needed input: only TERM and COLORTERM reached the container, and Claude Code and Codex choose OSC 9/777/99 or the bell from TERM_PROGRAM. TERM_PROGRAM, TERM_PROGRAM_VERSION and LC_TERMINAL are now forwarded too, so the terminal or multiplexer wrapping the pane gets the same signals as outside the sandbox. Profile env vars still win.
Herdr identifies an agent by the pane's foreground process, which for a Docker-sandboxed run is the host docker CLI, so it showed no agent state. Inside a Herdr pane the docker process now gets HERDR_AGENT=<agent>, Herdr's documented hint for wrappers. It is set only on the host process, never in the container, and a HERDR_AGENT the user exported is kept.
A HERDR_AGENT set by the profile (an env var or binding) is applied to the host docker process, but the inferred hint replaced it, so Herdr could use the wrong agent's detection rules. The hint is now skipped when env_vars already has HERDR_AGENT, as it already was for one the user exported. Also moves herdr_agent_hint above the doc comment of codex_args_forcing_full_access, which it had split off.
…r sandbox The README's Docker section and a new docs/sandboxing.md section say that cmux, herdr and other terminals get agent notifications in the sandbox with no setup, and that herdr also shows the agent's state. The section lists the forwarded terminal vars, the HERDR_AGENT override, and why the apps' own hook integrations don't run in the container.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
TERM_PROGRAM, but onlyTERMandCOLORTERMreached the container.TERM_PROGRAM,TERM_PROGRAM_VERSIONandLC_TERMINALare now forwarded too. The escape sequences already pass throughdocker run -t, so whatever wraps the pane (Ghostty, iTerm2, kitty, cmux, herdr, tmux) gets the same signals as outside the sandbox. Profile env vars still win.dockerCLI. Inside a Herdr pane (HERDR_ENV=1) thedockerprocess now getsHERDR_AGENT=<agent>, Herdr's documented hint for wrappers, so it applies that agent's screen rules. AHERDR_AGENTthe user already exported is kept.docs/sandboxing.mdsection ("Notifications, herdr and cmux") say this works with no setup, list the forwarded vars and theHERDR_AGENToverride, and explain why the apps' own hook integrations don't run in the container.Safety
HERDR_AGENTis set on the hostdockerprocess after the container's-eargs are built, so it never reaches the container.Test plan
HERDR_AGENThint (inside/outside Herdr, user-exported value kept)cargo fmt --checkpassescargo testpasses (533 + 25 + 33)