Tell the child its temporary directory is /tmp - #39
Merged
Merged
Conversation
The child's environment starts empty, and the caller's TMPDIR stays out on purpose: on macOS it is the per-user /var/folders/.../T, which the profile keeps closed. But a program with no TMPDIR asks the OS instead, and Rust's std::env::temp_dir on macOS gets that same closed directory. So every temporary file an Almide or Rust program made under porta was refused. golemide's solve failed all six attempts that way inside onogoro. The child now gets TMPDIR=/tmp, the temporary directory the run is granted, on both platforms; -e TMPDIR=... still overrides it. explain lists it, and an integration test checks both. Closes #38 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #38
On macOS, porta didn't give the child a
TMPDIR. So a program that works out its temp directory from the OS (Rust'sstd::env::temp_dir, and with it every Almide program) went to the per-user/var/folders/…/Tand was refused. That directory stays closed on purpose.TMPDIR=/tmp, the temp directory the sandbox grants. This applies on Linux too. An explicit-e TMPDIR=…still wins.porta explain'senvironmentline lists it.docs/enforcement.md: the Environment row says so.scripts/integration.py:TMPDIRis/tmpeven when the caller'sTMPDIRpoints under/var/folders, and it can make a temp file.-eoverrides it.Verified (macOS, pinned Almide 0.63.0)
almide test --ci: 145 tests pass.scripts/integration.py: all PASS, including the new one./tmp. A checkout under/tmpfails the existing "a write outside the grants is refused" test, because/tmpis always granted. That has nothing to do with this change.scripts/escapes.py: "Every attempt this host could make was held."solvegoes from "failed all 6 attempts" to "solved on the first attempt".Found alongside
With Almide 0.64,
process.exitrefuses anything outside 0..=125. That breaks porta's 126 / 127 and the passthrough of a child killed by a signal (almide/almide#2780). porta pins 0.63.0-rc1, so today's CI is unaffected, but it will be a problem at the next Almide upgrade.🤖 Generated with Claude Code