feat(terminal): pluggable terminal environment backends via plugin registry
Third-party sandbox vendors can now ship a terminal backend as a standalone
plugin instead of landing in core. Adds the five-piece pluggable-subsystem
pattern for terminal environments:
- agent/terminal_env_provider.py — TerminalEnvironmentProvider ABC with
declarative classification flags (is_remote, is_container,
skip_container_guards, cache_path_base, strip_env_keys,
session_isolated_when_nonpersistent) so every historical
frozenset-of-names classification site consults the registry instead
- agent/terminal_env_registry.py — thread-safe scoped registry; built-in
backend names are reserved and unregistrable
- PluginContext.register_terminal_environment_provider() mirroring
register_browser_provider
- _create_environment falls through to registered providers; unknown-backend
errors list plugin names
- Classification sites wired: approval guard skip, container path/cwd
handling (terminal/file/code-exec), prompt-builder env hints + probe,
host env probe suppression, skills remote-env note, cache path
translation, subprocess secret stripping (both spawn paths),
per-session isolation for name-resumed sandboxes
- Surfaces: hermes setup picker + doctor + status rows, dashboard
terminal-backend picker rows/probe/validation, terminal.backend schema
options recomputed per request
- Docs: developer-guide/terminal-environment-plugin.md + sidebar + plugins
capability table