Skip to content

fix: sandbox temp dir fallback - #1662

Merged
kevincodex1 merged 2 commits into
Twigpine:mainfrom
jatmn:issue-1649
Jun 16, 2026
Merged

kevincodex1 merged 2 commits into
Twigpine:mainfrom
jatmn:issue-1649

Conversation

@jatmn

@jatmn jatmn commented Jun 16, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Probe the Claude temp directory before returning it, and fall back to verified writable temp locations when the primary base is inaccessible or read-only.
  • Use the resolved Claude temp dir for sandboxed shell cwd tracking and TMPDIR/CLAUDE_CODE_TMPDIR/CLAUDE_TMPDIR propagation so the sandbox allowlist and shell providers agree.
  • Update @anthropic-ai/sandbox-runtime to 0.0.55 and refresh bun.lock.
  • Fix the PR typecheck failures with narrow type annotations and inference hints.

Impact

  • Sandboxed Bash and PowerShell commands can continue to use writable temp storage in restricted /tmp, private tmp, or read-only tmp environments.
  • Temp directory permission decisions are validated up front instead of memoizing an unusable path.

Permission policy notes

  • Sandboxed processes now receive CLAUDE_TMPDIR alongside TMPDIR and CLAUDE_CODE_TMPDIR.
  • Fallback temp roots are still under policy-controlled temp/config locations:
    • {tmpdir()}/claude-code/{claude temp dir name}/
    • {getClaudeConfigHomeDir()}/tmp/{claude temp dir name}/

Fixes #1649

Checks run

  • bun install (passed after network/filesystem escalation; initial sandboxed run hit EPERM copying packages)
  • bun run build (passed)
  • python -m pytest -q python/tests (passed: 44 passed; pytest cache warning due access denied writing .pytest_cache)
  • bun run typecheck (passed)
  • bun run typecheck:type-tests (passed)
  • git diff --check (passed; CRLF warnings only)
  • bun run check (build/smoke/deadcode ran, but test:full still reports 11 full-suite failures that pass in focused reruns)
  • ANTHROPIC_API_KEY=test-key bun test --max-concurrency=1 src/commands/export/export.test.ts (passed)
  • Focused rerun of the other reported failing files passed: src/commands/lsp/lsp.test.ts, src/utils/plugins/marketplaceManager.test.ts, src/utils/secureStorage/platformStorage.test.ts
  • bun run security:pr-scan (fails before scanning: null is not an object evaluating mergeBase.stderr.trim)

Notes

  • No UI or provider behavior changed; screenshots not applicable.
  • Full-suite test failures appear order/global-state related in this local environment because the same reported files pass when run directly.

Summary by CodeRabbit

  • Bug Fixes
    • Improved sandbox temporary directory resolution with added usability probing and safer fallback locations.
    • Updated environment overrides so the sandbox temp directory is consistently honored in shell providers.
    • Strengthened recursive directory creation error handling (e.g., existing directory and access cases).
    • Refined caching and health-check failure output to reduce ambiguous/over-detailed results.
  • Chores
    • Updated the sandbox runtime dependency to a newer compatible version.

Probe Claude temp directories before returning them and fall back through platform temp and config-home temp paths when the primary temp base is inaccessible.

Use the resolved Claude temp dir for sandboxed shell cwd tracking and TMPDIR/CLAUDE_TMPDIR propagation so the sandbox allowlist, Bash, and PowerShell providers agree on the writable temp path.

Update @anthropic-ai/sandbox-runtime to 0.0.55 and refresh bun.lock.

Validation: bun install passed after escalation; bun run build passed; python -m pytest -q python/tests passed; bun run typecheck:type-tests passed; git diff --check passed. bun run check still reports full-suite order/global-state failures; focused reruns of the reported failing files passed with a dummy ANTHROPIC_API_KEY. bun run typecheck has pre-existing unrelated repo-wide strictness failures; security:pr-scan fails before scanning on mergeBase.stderr.
@coderabbitai

coderabbitai Bot commented Jun 16, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: cce05a54-079c-4493-94d4-9e60c6cf9363

📥 Commits

Reviewing files that changed from the base of the PR and between fdce1fc and 93efd34.

📒 Files selected for processing (16)
  • src/commands/plugin/BrowseMarketplace.tsx
  • src/components/Settings/Config.tsx
  • src/components/StatusNotices.tsx
  • src/components/memory/MemoryFileSelector.tsx
  • src/constants/outputStyles.ts
  • src/hooks/useManagePlugins.ts
  • src/main.tsx
  • src/services/api/grove.ts
  • src/services/mcp/config.ts
  • src/services/mcp/doctor.ts
  • src/utils/analyzeContext.ts
  • src/utils/errors.ts
  • src/utils/permissions/pathValidation.ts
  • src/utils/plugins/loadPluginCommands.ts
  • src/utils/plugins/refresh.ts
  • src/utils/sessionStorage.ts
📜 Recent review details
🧰 Additional context used
📓 Path-based instructions (7)
**/*.{ts,tsx,js,jsx,py}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Keep comments useful and concise in code

Files:

  • src/components/StatusNotices.tsx
  • src/components/memory/MemoryFileSelector.tsx
  • src/services/api/grove.ts
  • src/utils/analyzeContext.ts
  • src/utils/plugins/refresh.ts
  • src/main.tsx
  • src/components/Settings/Config.tsx
  • src/constants/outputStyles.ts
  • src/commands/plugin/BrowseMarketplace.tsx
  • src/utils/errors.ts
  • src/utils/permissions/pathValidation.ts
  • src/services/mcp/doctor.ts
  • src/utils/plugins/loadPluginCommands.ts
  • src/hooks/useManagePlugins.ts
  • src/services/mcp/config.ts
  • src/utils/sessionStorage.ts
**/*

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • src/components/StatusNotices.tsx
  • src/components/memory/MemoryFileSelector.tsx
  • src/services/api/grove.ts
  • src/utils/analyzeContext.ts
  • src/utils/plugins/refresh.ts
  • src/main.tsx
  • src/components/Settings/Config.tsx
  • src/constants/outputStyles.ts
  • src/commands/plugin/BrowseMarketplace.tsx
  • src/utils/errors.ts
  • src/utils/permissions/pathValidation.ts
  • src/services/mcp/doctor.ts
  • src/utils/plugins/loadPluginCommands.ts
  • src/hooks/useManagePlugins.ts
  • src/services/mcp/config.ts
  • src/utils/sessionStorage.ts
**

⚙️ CodeRabbit configuration file

**: # Contributing to OpenClaude

Thanks for contributing.

OpenClaude is a fast-moving open-source coding-agent CLI with support for multiple providers, local backends, MCP, and a terminal-first workflow. The best contributions here are focused, well-tested, and easy to review.

Before You Start

  • Search existing issues and discussions before opening a new thread.
  • Check open pull requests for work that overlaps with your contribution. If a PR already exists that addresses the same change, open an issue or discussion first to align on direction — duplicate PRs may be closed without review.
  • Use issues for confirmed bugs and actionable feature work.
  • Use discussions for setup help, ideas, and general community conversation.
  • For larger changes, open an issue first so the scope is clear before implementation.
  • For security reports, follow SECURITY.md.

Pull Requests

Every PR needs a reason. Your PR description must include:

  • what changed and why
  • the user or developer impact
  • the exact checks you ran
  • a linked issue when one exists, using Fixes fix: skip assertMinVersion for third-party providers #123, `Closes `#123, or another clear link
  • screenshots when the PR touches UI, terminal presentation, or the VS Code extension
  • which provider path was tested when the PR changes provider behavior

The PR author is responsible for ensuring their PR is merge-ready. PRs with merge conflicts will not be reviewed or approved until the conflicts are resolved.

Issues are the recommended starting point for anything non-trivial — opening one first helps avoid wasted effort if the change is out of scope or already being worked on. Small fixes, doc corrections, and obvious improvements can stand on their own without a linked issue, as long as the PR description explains the intent.

What Gets Closed Without Review

PRs may be closed without review...

Files:

  • src/components/StatusNotices.tsx
  • src/components/memory/MemoryFileSelector.tsx
  • src/services/api/grove.ts
  • src/utils/analyzeContext.ts
  • src/utils/plugins/refresh.ts
  • src/main.tsx
  • src/components/Settings/Config.tsx
  • src/constants/outputStyles.ts
  • src/commands/plugin/BrowseMarketplace.tsx
  • src/utils/errors.ts
  • src/utils/permissions/pathValidation.ts
  • src/services/mcp/doctor.ts
  • src/utils/plugins/loadPluginCommands.ts
  • src/hooks/useManagePlugins.ts
  • src/services/mcp/config.ts
  • src/utils/sessionStorage.ts
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}

⚙️ CodeRabbit configuration file

{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}: Review provider routing, model selection, env precedence, auth/token handling, OpenAI-compatible shims, retries, proxy behavior, and outbound HTTP behavior with high scrutiny. Block on silent default changes, hidden fallback expansion, credential reuse mistakes, hardcoded provider assumptions, or new network reach that is not intentional and documented.

Files:

  • src/services/api/grove.ts
src/{skills,utils/plugins,services/mcp}/**

⚙️ CodeRabbit configuration file

src/{skills,utils/plugins,services/mcp}/**: Review skill/plugin/MCP behavior as a trust boundary. Check registry fetches, local and remote installs, path normalization, hash verification, revocation/trust metadata, tools_required handling, config-home behavior, and startup-time loading. Block on path traversal risk, unverified downloads, silent trust promotion, or unexpected code/tool activation.

Files:

  • src/utils/plugins/refresh.ts
  • src/services/mcp/doctor.ts
  • src/utils/plugins/loadPluginCommands.ts
  • src/services/mcp/config.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • src/main.tsx
src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**

⚙️ CodeRabbit configuration file

src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**: Review permission prompts, auto-allow logic, sandbox behavior, SDK permission schemas, shell/PowerShell execution, and background execution paths as security-sensitive. Block on bypasses, unclear trust boundaries, unsafe path handling, missing user visibility, or changes that broaden allowed behavior without an explicit maintainer decision.

Files:

  • src/utils/permissions/pathValidation.ts
🔇 Additional comments (16)
src/utils/errors.ts (1)

182-183: LGTM!

Also applies to: 193-193

src/services/api/grove.ts (1)

207-208: LGTM!

src/services/mcp/doctor.ts (1)

470-470: LGTM!

src/utils/permissions/pathValidation.ts (1)

115-116: LGTM!

src/utils/sessionStorage.ts (1)

107-109: LGTM!

src/hooks/useManagePlugins.ts (1)

16-16: LGTM!

Also applies to: 30-30, 67-67, 136-137, 152-153, 189-190, 198-199, 202-203, 206-208, 217-220

src/commands/plugin/BrowseMarketplace.tsx (1)

21-21: LGTM!

Also applies to: 143-149

src/utils/analyzeContext.ts (1)

310-310: LGTM!

src/utils/plugins/loadPluginCommands.ts (1)

526-528: LGTM!

Also applies to: 611-613

src/utils/plugins/refresh.ts (1)

38-38: LGTM!

Also applies to: 170-172

src/components/Settings/Config.tsx (1)

30-30: LGTM!

Also applies to: 201-201

src/components/memory/MemoryFileSelector.tsx (1)

51-51: LGTM!

src/components/StatusNotices.tsx (1)

23-29: LGTM!

src/constants/outputStyles.ts (1)

185-185: LGTM!

src/main.tsx (1)

1454-1457: LGTM!

src/services/mcp/config.ts (1)

1274-1276: LGTM!


📝 Walkthrough

Walkthrough

Fixes EACCES temp directory errors by adding a writability probe and two-level fallback in getClaudeTempDir, tolerating EACCES in mkdir/mkdirSync when the target directory already exists, propagating CLAUDE_TMPDIR through bash and PowerShell sandbox env overrides, and simplifying Shell.ts to call getClaudeTempDir() directly. Also adds comprehensive TypeScript type safety across plugin management, memory files, MCP configs, and utilities, and hardens error handling for filesystem access, cache logic, MCP health checks, and session storage. @anthropic-ai/sandbox-runtime is bumped to 0.0.55.

Changes

Temp Dir EACCES Fix and CLAUDE_TMPDIR Propagation

Layer / File(s) Summary
mkdir/mkdirSync EACCES tolerance
src/utils/fsOperations.ts
Both mkdir and mkdirSync catch blocks now extract errno codes: EEXIST is always ignored; EACCES is ignored only when the target path already exists; all other cases rethrow.
getClaudeTempDir usability probe and fallback chain
src/utils/permissions/filesystem.ts
New ensureUsableTempDir helper creates the directory and a probe subdir to confirm writability. getClaudeTempDir runs this probe on the primary path; on isFsInaccessible errors it tries a path under tmpdir() then under getClaudeConfigHomeDir(), logging each fallback step.
Shell wiring: direct getClaudeTempDir and CLAUDE_TMPDIR env propagation
src/utils/Shell.ts, src/utils/shell/bashProvider.ts, src/utils/shell/powershellProvider.ts, package.json
Shell.ts drops manual path construction and calls getClaudeTempDir() directly for sandboxTmpDir. Both shell providers add CLAUDE_TMPDIR to sandbox env overrides. @anthropic-ai/sandbox-runtime bumped 0.0.46 → 0.0.55.

TypeScript Type Safety Improvements

Layer / File(s) Summary
Plugin management and hooks type safety
src/hooks/useManagePlugins.ts, src/commands/plugin/BrowseMarketplace.tsx
Introduces LoadedPlugin, HookMatcher, HooksSettings, and PluginMarketplaceEntry type imports; creates typed enabledPlugins list used consistently for MCP/LSP server counting, hook aggregation, and returned metrics. Marketplace loading casts plugins array to typed shape for installed count and total calculations.
Memory file and settings config typing
src/components/Settings/Config.tsx, src/components/memory/MemoryFileSelector.tsx, src/components/StatusNotices.tsx
Config.tsx and MemoryFileSelector.tsx import and cast MemoryFileInfo[] type for memory file arrays. StatusNotices.tsx refactors loadMemoryFiles to store and return in-flight promises, maintaining cache behavior while improving promise-handling control flow.
Utility and service type assertions
src/constants/outputStyles.ts, src/main.tsx, src/services/mcp/config.ts, src/utils/analyzeContext.ts, src/utils/plugins/loadPluginCommands.ts, src/utils/plugins/refresh.ts
OutputStyles casts Object.values(allStyles) to Array<OutputStyleConfig | null>. main.tsx and mcp/config casts MCP config objects to Record<string, ScopedMcpServerConfig>. analyzeContext casts Object.entries(systemContext) to Array<[string, string]>. Plugin loaders and refresh utilities cast Object.entries results and apply hook type assertions.

Behavioral Robustness Fixes

Layer / File(s) Summary
Error classification and cache logic tightening
src/utils/errors.ts, src/services/api/grove.ts
isFsInaccessible now treats EROFS (read-only filesystem) as an inaccessible error. fetchAndStoreGroveConfig tightens cache-hit guard with explicit cachedEntry !== undefined check before accessing its grove_enabled property, avoiding optional-chaining side effects.
MCP health check and path validation refactoring
src/services/mcp/doctor.ts, src/utils/permissions/pathValidation.ts
getLiveCheck removes the error field from failed health check results, returning only attempted, result, and durationMs. isPathInSandboxWriteAllowlist wraps getResolvedSandboxConfigPath in an explicit flatMap callback to ensure correct argument passing to the memoized resolver.
Session storage refactor
src/utils/sessionStorage.ts
getBuiltInCommandNames() assigns the result to a local names variable, stores it in cache, and returns the variable directly instead of returning the cache variable.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~25 minutes

Suggested reviewers

  • kevincodex1
🚥 Pre-merge checks | ✅ 6 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 36.36% which is insufficient. The required threshold is 80.00%. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (6 passed)
Check name Status Explanation
Title check ✅ Passed The title 'fix: sandbox temp dir fallback' is concise and accurately describes the primary change: implementing fallback logic for sandbox temporary directory handling.
Description check ✅ Passed The PR description covers all required template sections with substantial detail: Summary (what/why changed), Impact (user and developer effects), and Notes (testing, limitations). All major checklist items are addressed.
Linked Issues check ✅ Passed The PR successfully addresses issue #1649 by implementing fallback temp directory logic that handles EACCES and EROFS permission errors, allowing sandboxed operations to use alternative writable locations instead of failing.
Out of Scope Changes check ✅ Passed All changes remain scoped to the sandbox temp directory fallback objective: temp dir resolution, shell provider env vars, error handling, and type corrections. No unrelated functional changes detected.
Risk Surface Disclosed ✅ Passed PR properly discloses risk surface: code includes comprehensive docstrings and comments documenting the permission handling changes (EACCES/EPERM/EROFS), usability probing mechanism, fallback strat...
No Hidden Policy Change ✅ Passed PR implements explicit permission-policy enhancement for temp directory fallback with no hidden policy changes. All modifications are deliberate and documented: temp dir probing with fallbacks, mem...

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Comment @coderabbitai help to get the list of available commands and usage tips.

@jatmn jatmn self-assigned this Jun 16, 2026
@jatmn jatmn changed the title Fix sandbox temp dir fallback fix: sandbox temp dir fallback Jun 16, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@src/utils/permissions/filesystem.ts`:
- Around line 389-407: The fallback directory logic gated by isFsInaccessible(e)
at the beginning of the block does not account for EROFS (read-only filesystem)
errors, which can be thrown by ensureUsableTempDir when the fallback directory
is mounted read-only. Modify the condition at line 389 to also check for EROFS
errors in addition to isFsInaccessible(e), or update the error handling in the
catch block at line 401 to allow EROFS errors to continue iterating through
fallback directories instead of rethrowing immediately. This ensures that
read-only filesystem errors trigger the fallback mechanism rather than aborting.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: fc7c7749-4af4-4b88-927d-512ec11bcb2f

📥 Commits

Reviewing files that changed from the base of the PR and between a36ef46 and fdce1fc.

⛔ Files ignored due to path filters (1)
  • bun.lock is excluded by !**/*.lock
📒 Files selected for processing (6)
  • package.json
  • src/utils/Shell.ts
  • src/utils/fsOperations.ts
  • src/utils/permissions/filesystem.ts
  • src/utils/shell/bashProvider.ts
  • src/utils/shell/powershellProvider.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (5)
**/*

⚙️ CodeRabbit configuration file

**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.

Files:

  • package.json
  • src/utils/shell/bashProvider.ts
  • src/utils/shell/powershellProvider.ts
  • src/utils/fsOperations.ts
  • src/utils/permissions/filesystem.ts
  • src/utils/Shell.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}

⚙️ CodeRabbit configuration file

{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.

Files:

  • package.json
**

⚙️ CodeRabbit configuration file

**: # Contributing to OpenClaude

Thanks for contributing.

OpenClaude is a fast-moving open-source coding-agent CLI with support for multiple providers, local backends, MCP, and a terminal-first workflow. The best contributions here are focused, well-tested, and easy to review.

Before You Start

  • Search existing issues and discussions before opening a new thread.
  • Check open pull requests for work that overlaps with your contribution. If a PR already exists that addresses the same change, open an issue or discussion first to align on direction — duplicate PRs may be closed without review.
  • Use issues for confirmed bugs and actionable feature work.
  • Use discussions for setup help, ideas, and general community conversation.
  • For larger changes, open an issue first so the scope is clear before implementation.
  • For security reports, follow SECURITY.md.

Pull Requests

Every PR needs a reason. Your PR description must include:

  • what changed and why
  • the user or developer impact
  • the exact checks you ran
  • a linked issue when one exists, using Fixes #123, `Closes `#123, or another clear link
  • screenshots when the PR touches UI, terminal presentation, or the VS Code extension
  • which provider path was tested when the PR changes provider behavior

The PR author is responsible for ensuring their PR is merge-ready. PRs with merge conflicts will not be reviewed or approved until the conflicts are resolved.

Issues are the recommended starting point for anything non-trivial — opening one first helps avoid wasted effort if the change is out of scope or already being worked on. Small fixes, doc corrections, and obvious improvements can stand on their own without a linked issue, as long as the PR description explains the intent.

What Gets Closed Without Review

PRs may be closed without review...

Files:

  • package.json
  • src/utils/shell/bashProvider.ts
  • src/utils/shell/powershellProvider.ts
  • src/utils/fsOperations.ts
  • src/utils/permissions/filesystem.ts
  • src/utils/Shell.ts
**/*.{ts,tsx,js,jsx,py}

📄 CodeRabbit inference engine (CONTRIBUTING.md)

Keep comments useful and concise in code

Files:

  • src/utils/shell/bashProvider.ts
  • src/utils/shell/powershellProvider.ts
  • src/utils/fsOperations.ts
  • src/utils/permissions/filesystem.ts
  • src/utils/Shell.ts
src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**

⚙️ CodeRabbit configuration file

src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**: Review permission prompts, auto-allow logic, sandbox behavior, SDK permission schemas, shell/PowerShell execution, and background execution paths as security-sensitive. Block on bypasses, unclear trust boundaries, unsafe path handling, missing user visibility, or changes that broaden allowed behavior without an explicit maintainer decision.

Files:

  • src/utils/permissions/filesystem.ts
🔇 Additional comments (5)
src/utils/fsOperations.ts (1)

425-438: LGTM!

Also applies to: 558-570

src/utils/Shell.ts (1)

32-33: LGTM!

Also applies to: 223-224

src/utils/shell/bashProvider.ts (1)

242-242: LGTM!

src/utils/shell/powershellProvider.ts (1)

119-119: LGTM!

package.json (1)

80-80: LGTM!

Comment thread src/utils/permissions/filesystem.ts
Handle EROFS as an inaccessible filesystem error for sandbox temp fallback behavior.

Add narrow type annotations and inference fixes so the stricter typecheck job passes.
@jatmn
jatmn marked this pull request as ready for review June 16, 2026 03:24
@jatmn
jatmn requested a review from kevincodex1 June 16, 2026 03:45

@kevincodex1 kevincodex1 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me

@kevincodex1
kevincodex1 merged commit c3db798 into Twigpine:main Jun 16, 2026
4 checks passed
@jatmn
jatmn deleted the issue-1649 branch June 16, 2026 13:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Error: EACCES: permission denied, mkdir '/tmp/claude-10369'

2 participants