Skip to content

Tell the child its temporary directory is /tmp - #39

Merged
O6lvl4 merged 1 commit into
developfrom
fix/tmpdir-38
Sep 28, 2026
Merged

O6lvl4 merged 1 commit into
developfrom
fix/tmpdir-38

Conversation

@O6lvl4

@O6lvl4 O6lvl4 commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Closes #38

On macOS, porta didn't give the child a TMPDIR. So a program that works out its temp directory from the OS (Rust's std::env::temp_dir, and with it every Almide program) went to the per-user /var/folders/…/T and was refused. That directory stays closed on purpose.

  • The child's environment now gets TMPDIR=/tmp, the temp directory the sandbox grants. This applies on Linux too. An explicit -e TMPDIR=… still wins.
  • porta explain's environment line lists it.
  • docs/enforcement.md: the Environment row says so.
  • scripts/integration.py:
    • The child's TMPDIR is /tmp even when the caller's TMPDIR points under /var/folders, and it can make a temp file.
    • -e overrides it.

Verified (macOS, pinned Almide 0.63.0)

  • almide test --ci: 145 tests pass.
  • scripts/integration.py: all PASS, including the new one.
    • Run from a checkout outside /tmp. A checkout under /tmp fails the existing "a write outside the grants is refused" test, because /tmp is always granted. That has nothing to do with this change.
  • scripts/escapes.py: "Every attempt this host could make was held."
  • Real run: inside O6lvl4/onogoro, golemide's solve goes from "failed all 6 attempts" to "solved on the first attempt".

Found alongside

With Almide 0.64, process.exit refuses anything outside 0..=125. That breaks porta's 126 / 127 and the passthrough of a child killed by a signal (almide/almide#2780). porta pins 0.63.0-rc1, so today's CI is unaffected, but it will be a problem at the next Almide upgrade.

🤖 Generated with Claude Code

The child's environment starts empty, and the caller's TMPDIR stays out on
purpose: on macOS it is the per-user /var/folders/.../T, which the profile
keeps closed. But a program with no TMPDIR asks the OS instead, and Rust's
std::env::temp_dir on macOS gets that same closed directory. So every
temporary file an Almide or Rust program made under porta was refused.
golemide's solve failed all six attempts that way inside onogoro.

The child now gets TMPDIR=/tmp, the temporary directory the run is granted,
on both platforms; -e TMPDIR=... still overrides it. explain lists it, and
an integration test checks both.

Closes #38

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@O6lvl4
O6lvl4 merged commit 0da7d18 into develop Sep 28, 2026
4 checks passed
@O6lvl4
O6lvl4 deleted the fix/tmpdir-38 branch September 28, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

On macOS the child gets no TMPDIR, so Rust programs and mktemp reach for /var/folders and are refused

1 participant