docker: turn the agent loose — detached /loop, with the first-run gates handled
`./sylph-agent loose [task]` starts Claude Code detached with
--dangerously-skip-permissions, running /loop on loop-task.md: work the RE
backlog one item at a time, commit to auto/* branches, never push, record
withdrawn results rather than deleting them. `logs`/`attach`/`stop` to watch and
end it. Runs -d WITHOUT --rm so the transcript survives the container exiting —
for an unattended run that is the only record of what happened.
Two things had to be fixed for an agent to survive being left alone.
MEMORY CONTINUITY. The project is now bind-mounted twice: at /work, and at its
own host path. Claude Code derives its per-project state key from the working
directory, so running at /work handed the agent an empty project instead of the
accumulated one. Verified: a loose run now reports MEMORY=yes and reads back the
same branch and backlog as the host.
FOUR INTERACTIVE GATES, each a silent permanent hang with nobody at the keyboard
-- no error, no log line, just a container that looks healthy and does nothing:
theme picker hasCompletedOnboarding + lastOnboardingVersion. Re-fires
whenever the container's Claude Code is a different version
to the host's, which is the normal case.
folder trust projects.<path>.hasTrustDialogAccepted
bypass disclaimer answered in a pty by bin/claude-autonomous. It has no config
key by design -- it wants a person to accept once, and the
person did so by launching this.
fullscreen upsell fullscreenUpsellSeenCount. This one fires MID-SESSION, after
the pty wrapper has already handed over, so it cannot be
answered the same way.
Config key names were read out of the shipped binary's own strings, not guessed.
The pty wrapper matches SINGLE WORDS. Claude Code draws its UI with
absolute-column escapes between words, so the prompt arrives as
`Yes,\x1b[13GI\x1b[15Gaccept` and a multi-word pattern never matches -- failing
in a way indistinguishable from the wrapper not running at all. It stops
matching once the session is live so nothing later is answered by accident.
~/.claude.json is now mounted read-only at a staging path and copied in, so the
container cannot rewrite the host config. Credentials stay shared read-write in
~/.claude, which is what token refresh and memory continuity need.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -51,6 +51,9 @@ RUN apt-get update && apt-get install -y --no-install-recommends \
|
||||
python3 python3-numpy python3-pil python3-pip \
|
||||
gdb strace ltrace binutils file xxd ripgrep jq unzip zip p7zip-full \
|
||||
procps psmisc lsof less nano tini sudo \
|
||||
# expect drives Claude Code's one-time interactive gates for an
|
||||
# unattended run — see bin/claude-autonomous.
|
||||
expect \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
# Pin the unversioned tool names to 19 so CMake, and anything that shells out to
|
||||
|
||||
Reference in New Issue
Block a user