feat(shell) add saved output refs for Reborn shell - #4154
Merged
Merged
Conversation
Contributor
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
…eborn-shell-output-files # Conflicts: # crates/ironclaw_host_runtime/src/lib.rs # crates/ironclaw_host_runtime/src/process_port.rs
theredspoon
pushed a commit
to theredspoon/ironclaw
that referenced
this pull request
Jun 21, 2026
* Add saved output refs for Reborn shell * Tighten Reborn shell output capture * Harden Reborn shell output capture lifecycle * Sanitize Reborn shell previews before saving * fix(reborn): tenant-scope shell saved-output dir + GC (nearai#4154 review blockers #1, #4) Saved shell-command output files previously landed directly in shared std::env::temp_dir() (per-file 0o600, but the parent dir was world-listable), and cleanup_stale_command_outputs() walked all of /tmp and unlinked any entry that matched the well-known prefixes — both ambient surfaces let one principal on the same host enumerate or delete another principal's saved output. Route every saved output through a per-scope subdirectory derived from RebornSandboxScopeKey (the same SHA-256-of-tenant/user/agent/project digest the Reborn sandbox transport uses for workspace_path) under <tempdir>/ironclaw-command-outputs/<scope_digest>/, created with owner-only 0o700. Both scratch streams and final sanitized outputs live inside that directory, and the 24h GC scan is scoped to it — so two distinct (tenant, user, agent, project) tuples produce disjoint, non-enumerable directories and the cross-principal-delete surface closes by construction. Closes blockers #1 and #4 from the PR-nearai#4154 review. Blocker #2 (typed saved_output_read capability) and finding #3 (24h GC vs never-delete retention) remain serrrfirat-owned design decisions and are intentionally out of scope here. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * fix: address saved shell output review findings * fix: publish shell saved output through file_read --------- Co-authored-by: Zaki <zaki@manian.org> Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Verification
Note