Gate sandboxed terminal tempdir to local projects - #58240
Merged
Conversation
rtfeldman
marked this pull request as ready for review
June 1, 2026 15:52
Veykril
approved these changes
Jun 1, 2026
TomPlanche
pushed a commit
to TomPlanche/zed
that referenced
this pull request
Jun 2, 2026
[PR zed-industries#57878](zed-industries#57878) introduced a per-thread sandboxing temp directory that, for every terminal command, overrode `TMPDIR`/`TMP`/`TEMP` and pushed the directory into the sandbox writable scope. For remote projects this temp directory is created on the client while the terminal actually runs on the remote host, so it leaked client-side environment variables into the remote terminal and pointed `$TMPDIR` at a path that doesn't exist there. This gates the temp-directory logic behind `project.is_local()`, so remote projects no longer get their terminal environment infected. This doesn't restore the per-thread tempdir behavior for remoting, but it undoes the regression. Closes AI-348 Release Notes: - Fixed remote terminals having their environment overridden by client-side temp directory variables
This was referenced Jun 10, 2026
This was referenced Jun 18, 2026
Closed
This was referenced Jul 1, 2026
This was referenced Jul 10, 2026
jonx
pushed a commit
to jonx/zed-aros
that referenced
this pull request
Jul 17, 2026
[PR zed-industries#57878](zed-industries#57878) introduced a per-thread sandboxing temp directory that, for every terminal command, overrode `TMPDIR`/`TMP`/`TEMP` and pushed the directory into the sandbox writable scope. For remote projects this temp directory is created on the client while the terminal actually runs on the remote host, so it leaked client-side environment variables into the remote terminal and pointed `$TMPDIR` at a path that doesn't exist there. This gates the temp-directory logic behind `project.is_local()`, so remote projects no longer get their terminal environment infected. This doesn't restore the per-thread tempdir behavior for remoting, but it undoes the regression. Closes AI-348 Release Notes: - Fixed remote terminals having their environment overridden by client-side temp directory variables
jolutz
pushed a commit
to jolutz/zed
that referenced
this pull request
Aug 8, 2026
[PR zed-industries#57878](zed-industries#57878) introduced a per-thread sandboxing temp directory that, for every terminal command, overrode `TMPDIR`/`TMP`/`TEMP` and pushed the directory into the sandbox writable scope. For remote projects this temp directory is created on the client while the terminal actually runs on the remote host, so it leaked client-side environment variables into the remote terminal and pointed `$TMPDIR` at a path that doesn't exist there. This gates the temp-directory logic behind `project.is_local()`, so remote projects no longer get their terminal environment infected. This doesn't restore the per-thread tempdir behavior for remoting, but it undoes the regression. Closes AI-348 Release Notes: - Fixed remote terminals having their environment overridden by client-side temp directory variables
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR #57878 introduced a per-thread sandboxing temp directory that, for every terminal command, overrode
TMPDIR/TMP/TEMPand pushed the directory into the sandbox writable scope. For remote projects this temp directory is created on the client while the terminal actually runs on the remote host, so it leaked client-side environment variables into the remote terminal and pointed$TMPDIRat a path that doesn't exist there.This gates the temp-directory logic behind
project.is_local(), so remote projects no longer get their terminal environment infected. This doesn't restore the per-thread tempdir behavior for remoting, but it undoes the regression.Closes AI-348
Release Notes: