Description
When an agent session executes shell commands on Linux, the command is not run directly by the system interpreter: the exec layer routes it through the ZCode AppImage binary itself. Instead of executing the requested program, the AppImage boots a full desktop-app instance (Electron main process, crash reporter init, zcode:// deep-link protocol registration, user-level desktop-file and icon installation) - repeatedly - and the requested command may never actually run. Each boot raises the ZCode window over the user's other work (focus stealing), making the machine unusable while an agent session runs.
Steps to Reproduce
- Install ZCode 3.14.4 as the linux-x64 AppImage, run an agent session on Linux (KDE Plasma / CachyOS here).
- Have the agent run a shell command, e.g.
python3 tools/foo.py.
- Inspect with
ps: the process is python3 /home/<user>/.local/bin/ZCode-3.14.4-linux-x64.AppImage tools/foo.py - the AppImage file was interposed into the interpreter's arguments.
- Capture the command's stdout/stderr.
Expected Behavior
Agent shell commands execute directly with the system binaries; no app instance is booted per command, no desktop-integration side effects occur, and the ZCode window never raises itself over other windows.
Actual Behavior
ps shows the AppImage binary interposed into the command line (argv rewrite) for commands run by the agent.
- A single command's output contained 9,000+ lines (~280 KB) of ZCode app boot logs instead of the command's output, from multiple waves of new PIDs over several minutes:
[main] [crash-capture] configured remoteCrashReporterEnabled=true, [deep-link] 注册协议成功 { scheme: 'zcode' }, [deep-link] Linux AppImage 用户级图标安装完成, [arms] electron initialized env=prod version=3.14.4.
- In that case the requested long-running script produced zero output - it never executed.
- The app window raises itself over other applications on command execution (focus stealing the user can see; reported and reproduced repeatedly during one session).
Environment
- OS: CachyOS (Arch-based), KDE Plasma, X11
- ZCode 3.14.4 linux-x64 AppImage (
~/.local/bin/ZCode-3.14.4-linux-x64.AppImage)
- Not a system-level shim:
/usr/bin and /usr/sbin coreutils have identical checksums, and no shell aliases/functions shadow the interpreter; the rewrite happens in ZCode's command-exec layer.
Suggested fix
Do not route agent shell-command execution through the AppImage binary. Resolve the real system interpreter/binary (or a dedicated runner path) for command execution, and confine desktop-integration (protocol/desktop-file/icon registration) and any window raise to the interactive GUI session only.
Description
When an agent session executes shell commands on Linux, the command is not run directly by the system interpreter: the exec layer routes it through the ZCode AppImage binary itself. Instead of executing the requested program, the AppImage boots a full desktop-app instance (Electron main process, crash reporter init,
zcode://deep-link protocol registration, user-level desktop-file and icon installation) - repeatedly - and the requested command may never actually run. Each boot raises the ZCode window over the user's other work (focus stealing), making the machine unusable while an agent session runs.Steps to Reproduce
python3 tools/foo.py.ps: the process ispython3 /home/<user>/.local/bin/ZCode-3.14.4-linux-x64.AppImage tools/foo.py- the AppImage file was interposed into the interpreter's arguments.Expected Behavior
Agent shell commands execute directly with the system binaries; no app instance is booted per command, no desktop-integration side effects occur, and the ZCode window never raises itself over other windows.
Actual Behavior
psshows the AppImage binary interposed into the command line (argv rewrite) for commands run by the agent.[main] [crash-capture] configured remoteCrashReporterEnabled=true,[deep-link] 注册协议成功 { scheme: 'zcode' },[deep-link] Linux AppImage 用户级图标安装完成,[arms] electron initialized env=prod version=3.14.4.Environment
~/.local/bin/ZCode-3.14.4-linux-x64.AppImage)/usr/binand/usr/sbincoreutils have identical checksums, and no shell aliases/functions shadow the interpreter; the rewrite happens in ZCode's command-exec layer.Suggested fix
Do not route agent shell-command execution through the AppImage binary. Resolve the real system interpreter/binary (or a dedicated runner path) for command execution, and confine desktop-integration (protocol/desktop-file/icon registration) and any window raise to the interactive GUI session only.