Skip to content

Gate sandboxed terminal tempdir to local projects - #58240

Merged
Veykril merged 1 commit into
mainfrom
AI-348/gate-sandbox-tempdir-local
Jun 1, 2026
Merged

Gate sandboxed terminal tempdir to local projects#58240
Veykril merged 1 commit into
mainfrom
AI-348/gate-sandbox-tempdir-local

Conversation

@rtfeldman

Copy link
Copy Markdown
Contributor

PR #57878 introduced a per-thread sandboxing temp directory that, for every terminal command, overrode TMPDIR/TMP/TEMP and pushed the directory into the sandbox writable scope. For remote projects this temp directory is created on the client while the terminal actually runs on the remote host, so it leaked client-side environment variables into the remote terminal and pointed $TMPDIR at a path that doesn't exist there.

This gates the temp-directory logic behind project.is_local(), so remote projects no longer get their terminal environment infected. This doesn't restore the per-thread tempdir behavior for remoting, but it undoes the regression.

Closes AI-348

Release Notes:

  • Fixed remote terminals having their environment overridden by client-side temp directory variables

@rtfeldman rtfeldman self-assigned this Jun 1, 2026
@cla-bot cla-bot Bot added the cla-signed The user has signed the Contributor License Agreement label Jun 1, 2026
@zed-community-bot zed-community-bot Bot added the staff Pull requests authored by a current member of Zed staff label Jun 1, 2026
@rtfeldman
rtfeldman requested a review from Veykril June 1, 2026 15:52
@rtfeldman
rtfeldman marked this pull request as ready for review June 1, 2026 15:52
@Veykril
Veykril added this pull request to the merge queue Jun 1, 2026
Merged via the queue into main with commit 513e2b2 Jun 1, 2026
45 checks passed
@Veykril
Veykril deleted the AI-348/gate-sandbox-tempdir-local branch June 1, 2026 16:03
TomPlanche pushed a commit to TomPlanche/zed that referenced this pull request Jun 2, 2026
[PR zed-industries#57878](zed-industries#57878) introduced
a per-thread sandboxing temp directory that, for every terminal command,
overrode `TMPDIR`/`TMP`/`TEMP` and pushed the directory into the sandbox
writable scope. For remote projects this temp directory is created on
the client while the terminal actually runs on the remote host, so it
leaked client-side environment variables into the remote terminal and
pointed `$TMPDIR` at a path that doesn't exist there.

This gates the temp-directory logic behind `project.is_local()`, so
remote projects no longer get their terminal environment infected. This
doesn't restore the per-thread tempdir behavior for remoting, but it
undoes the regression.

Closes AI-348

Release Notes:

- Fixed remote terminals having their environment overridden by
client-side temp directory variables
This was referenced Jun 18, 2026
jonx pushed a commit to jonx/zed-aros that referenced this pull request Jul 17, 2026
[PR zed-industries#57878](zed-industries#57878) introduced
a per-thread sandboxing temp directory that, for every terminal command,
overrode `TMPDIR`/`TMP`/`TEMP` and pushed the directory into the sandbox
writable scope. For remote projects this temp directory is created on
the client while the terminal actually runs on the remote host, so it
leaked client-side environment variables into the remote terminal and
pointed `$TMPDIR` at a path that doesn't exist there.

This gates the temp-directory logic behind `project.is_local()`, so
remote projects no longer get their terminal environment infected. This
doesn't restore the per-thread tempdir behavior for remoting, but it
undoes the regression.

Closes AI-348

Release Notes:

- Fixed remote terminals having their environment overridden by
client-side temp directory variables
jolutz pushed a commit to jolutz/zed that referenced this pull request Aug 8, 2026
[PR zed-industries#57878](zed-industries#57878) introduced
a per-thread sandboxing temp directory that, for every terminal command,
overrode `TMPDIR`/`TMP`/`TEMP` and pushed the directory into the sandbox
writable scope. For remote projects this temp directory is created on
the client while the terminal actually runs on the remote host, so it
leaked client-side environment variables into the remote terminal and
pointed `$TMPDIR` at a path that doesn't exist there.

This gates the temp-directory logic behind `project.is_local()`, so
remote projects no longer get their terminal environment infected. This
doesn't restore the per-thread tempdir behavior for remoting, but it
undoes the regression.

Closes AI-348

Release Notes:

- Fixed remote terminals having their environment overridden by
client-side temp directory variables
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cla-signed The user has signed the Contributor License Agreement staff Pull requests authored by a current member of Zed staff

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants