Skip to content

fix(gateway): bridge terminal config when multiplexing profiles - #78289

Closed
Baophan00 wants to merge 1 commit into
NousResearch:mainfrom
Baophan00:fix/multiplex-terminal-backend
Closed

Baophan00 wants to merge 1 commit into
NousResearch:mainfrom
Baophan00:fix/multiplex-terminal-backend

Conversation

@Baophan00

Copy link
Copy Markdown

Bug

When a multiplexed gateway routes a turn to a secondary profile, only hermes_home and the secret scope were switched. The TERMINAL_* env vars still carried the gateway profile's backend. A routed profile with terminal.backend: docker silently ran commands on the gateway's local backend — the sandbox was never entered.

Fix

Bridge the routed profile's terminal: section from its config.yaml into os.environ inside _profile_runtime_scope. Save the original TERMINAL_* values before bridging and restore them when the scope exits, so the next turn's profile sees its own terminal config.

When a multiplexed gateway routes a turn to a secondary profile,
only hermes_home and secret scope were switched — TERMINAL_* env
vars still carried the gateway profile's backend. A profile with
terminal.backend: docker silently ran commands on the gateway's
local backend.

Bridge the routed profile's terminal: section into os.environ
inside _profile_runtime_scope, save the originals, and restore
them when the scope exits so the next turn's profile sees its
own terminal config.
@alt-glitch alt-glitch added type/bug Something isn't working comp/gateway Gateway runner, session dispatch, delivery backend/docker Docker container execution area/config Config system, migrations, profiles area/profiles Multi-profile isolation, HERMES_HOME scoping P2 Medium — degraded but workaround exists sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades labels Aug 4, 2026
@100yenadmin

Copy link
Copy Markdown

Heads up — this and #79117 both target #68559 (terminal config leaking across routed profiles), and a reviewer asked us to consolidate around one approach.

I've folded the coverage here into #79117: it uses a ContextVar terminal-config scope and routes every TERMINAL_ENV/TERMINAL_CWD read through a single accessor (including the env_probe cache and prompt_builder backend-probe paths), with a guard test that fails on any new direct env read. Your bridge approach is lighter; the ContextVar one covers a few more read sites and the cross-profile probe-cache case. Not trying to step on this — flagging so a maintainer can pick one rather than merge overlapping fixes, and happy to align on naming either way. Thanks for digging into the same bug.

@teknium1

teknium1 commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator

Thanks for this PR. Merged via #101242 (4a7f228) on current main — routed multiplex profiles get their own terminal cwd/backend/docker config; container boot honors config multiplex_profiles.

#101242 won as the consolidated fix because it covers the whole multiplex-profile bug class in one change (with tests) rather than the single symptom addressed here; this PR is superseded by it.
Your PR is referenced in #101242's body as prior work on this bug.

If anything from your original change is still missing on main >= 4a7f228, please open a fresh PR/issue against main and tag it. Thanks again.

@teknium1 teknium1 closed this Sep 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/config Config system, migrations, profiles area/profiles Multi-profile isolation, HERMES_HOME scoping backend/docker Docker container execution comp/gateway Gateway runner, session dispatch, delivery P2 Medium — degraded but workaround exists sweeper:risk-compatibility Sweeper risk: may break existing users, config, migrations, defaults, or upgrades sweeper:risk-message-delivery Sweeper risk: may drop, duplicate, misroute, or suppress messages type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants