fix: sandbox temp dir fallback - #1662
Conversation
Probe Claude temp directories before returning them and fall back through platform temp and config-home temp paths when the primary temp base is inaccessible. Use the resolved Claude temp dir for sandboxed shell cwd tracking and TMPDIR/CLAUDE_TMPDIR propagation so the sandbox allowlist, Bash, and PowerShell providers agree on the writable temp path. Update @anthropic-ai/sandbox-runtime to 0.0.55 and refresh bun.lock. Validation: bun install passed after escalation; bun run build passed; python -m pytest -q python/tests passed; bun run typecheck:type-tests passed; git diff --check passed. bun run check still reports full-suite order/global-state failures; focused reruns of the reported failing files passed with a dummy ANTHROPIC_API_KEY. bun run typecheck has pre-existing unrelated repo-wide strictness failures; security:pr-scan fails before scanning on mergeBase.stderr.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (16)
📜 Recent review details🧰 Additional context used📓 Path-based instructions (7)**/*.{ts,tsx,js,jsx,py}📄 CodeRabbit inference engine (CONTRIBUTING.md)
Files:
**/*⚙️ CodeRabbit configuration file
Files:
**⚙️ CodeRabbit configuration file
Files:
{src/services/api/**,src/integrations/**,src/utils/model/**,src/utils/provider*.ts,src/commands/provider/**}⚙️ CodeRabbit configuration file
Files:
src/{skills,utils/plugins,services/mcp}/**⚙️ CodeRabbit configuration file
Files:
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}⚙️ CodeRabbit configuration file
Files:
src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**⚙️ CodeRabbit configuration file
Files:
🔇 Additional comments (16)
📝 WalkthroughWalkthroughFixes EACCES temp directory errors by adding a writability probe and two-level fallback in ChangesTemp Dir EACCES Fix and CLAUDE_TMPDIR Propagation
TypeScript Type Safety Improvements
Behavioral Robustness Fixes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Suggested reviewers
🚥 Pre-merge checks | ✅ 6 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (6 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@src/utils/permissions/filesystem.ts`:
- Around line 389-407: The fallback directory logic gated by isFsInaccessible(e)
at the beginning of the block does not account for EROFS (read-only filesystem)
errors, which can be thrown by ensureUsableTempDir when the fallback directory
is mounted read-only. Modify the condition at line 389 to also check for EROFS
errors in addition to isFsInaccessible(e), or update the error handling in the
catch block at line 401 to allow EROFS errors to continue iterating through
fallback directories instead of rethrowing immediately. This ensures that
read-only filesystem errors trigger the fallback mechanism rather than aborting.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: ASSERTIVE
Plan: Pro Plus
Run ID: fc7c7749-4af4-4b88-927d-512ec11bcb2f
⛔ Files ignored due to path filters (1)
bun.lockis excluded by!**/*.lock
📒 Files selected for processing (6)
package.jsonsrc/utils/Shell.tssrc/utils/fsOperations.tssrc/utils/permissions/filesystem.tssrc/utils/shell/bashProvider.tssrc/utils/shell/powershellProvider.ts
📜 Review details
🧰 Additional context used
📓 Path-based instructions (5)
**/*
⚙️ CodeRabbit configuration file
**/*: Apply the OpenClaude maintainer review rubric from AGENTS.md. Review the current diff, not stale discussion context. Separate real blockers from suggestions. Do not request changes for vague style churn. Treat approval as merge-ready from CodeRabbit's side, pending required human review and GitHub Checks. If checks are failing or unavailable, say so clearly instead of implying the PR is fully ready.
Files:
package.jsonsrc/utils/shell/bashProvider.tssrc/utils/shell/powershellProvider.tssrc/utils/fsOperations.tssrc/utils/permissions/filesystem.tssrc/utils/Shell.ts
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}
⚙️ CodeRabbit configuration file
{bin/**,scripts/**,package.json,src/setup.ts,src/main.tsx,src/entrypoints/**}: Review install, launcher, build, packaging, startup, and entrypoint changes for cross-platform compatibility, tracked-source rewrites, env/config precedence, and release safety. Block on changes that can break Windows/macOS/Linux startup or publish unexpected artifacts.
Files:
package.json
**
⚙️ CodeRabbit configuration file
**: # Contributing to OpenClaudeThanks for contributing.
OpenClaude is a fast-moving open-source coding-agent CLI with support for multiple providers, local backends, MCP, and a terminal-first workflow. The best contributions here are focused, well-tested, and easy to review.
Before You Start
- Search existing issues and discussions before opening a new thread.
- Check open pull requests for work that overlaps with your contribution. If a PR already exists that addresses the same change, open an issue or discussion first to align on direction — duplicate PRs may be closed without review.
- Use issues for confirmed bugs and actionable feature work.
- Use discussions for setup help, ideas, and general community conversation.
- For larger changes, open an issue first so the scope is clear before implementation.
- For security reports, follow SECURITY.md.
Pull Requests
Every PR needs a reason. Your PR description must include:
- what changed and why
- the user or developer impact
- the exact checks you ran
- a linked issue when one exists, using
Fixes#123, `Closes `#123, or another clear link- screenshots when the PR touches UI, terminal presentation, or the VS Code extension
- which provider path was tested when the PR changes provider behavior
The PR author is responsible for ensuring their PR is merge-ready. PRs with merge conflicts will not be reviewed or approved until the conflicts are resolved.
Issues are the recommended starting point for anything non-trivial — opening one first helps avoid wasted effort if the change is out of scope or already being worked on. Small fixes, doc corrections, and obvious improvements can stand on their own without a linked issue, as long as the PR description explains the intent.
What Gets Closed Without Review
PRs may be closed without review...
Files:
package.jsonsrc/utils/shell/bashProvider.tssrc/utils/shell/powershellProvider.tssrc/utils/fsOperations.tssrc/utils/permissions/filesystem.tssrc/utils/Shell.ts
**/*.{ts,tsx,js,jsx,py}
📄 CodeRabbit inference engine (CONTRIBUTING.md)
Keep comments useful and concise in code
Files:
src/utils/shell/bashProvider.tssrc/utils/shell/powershellProvider.tssrc/utils/fsOperations.tssrc/utils/permissions/filesystem.tssrc/utils/Shell.ts
src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**
⚙️ CodeRabbit configuration file
src/{components/permissions,utils/permissions,hooks/toolPermission,tools,entrypoints/sdk}/**: Review permission prompts, auto-allow logic, sandbox behavior, SDK permission schemas, shell/PowerShell execution, and background execution paths as security-sensitive. Block on bypasses, unclear trust boundaries, unsafe path handling, missing user visibility, or changes that broaden allowed behavior without an explicit maintainer decision.
Files:
src/utils/permissions/filesystem.ts
🔇 Additional comments (5)
src/utils/fsOperations.ts (1)
425-438: LGTM!Also applies to: 558-570
src/utils/Shell.ts (1)
32-33: LGTM!Also applies to: 223-224
src/utils/shell/bashProvider.ts (1)
242-242: LGTM!src/utils/shell/powershellProvider.ts (1)
119-119: LGTM!package.json (1)
80-80: LGTM!
Handle EROFS as an inaccessible filesystem error for sandbox temp fallback behavior. Add narrow type annotations and inference fixes so the stricter typecheck job passes.
Summary
Impact
Permission policy notes
{tmpdir()}/claude-code/{claude temp dir name}/{getClaudeConfigHomeDir()}/tmp/{claude temp dir name}/Fixes #1649
Checks run
Notes
Summary by CodeRabbit