fix(runtime): refuse an unsafe agent provider home before planning, and let doctor --fix tighten it (#1265) - #1267
Open
mrthankyou wants to merge 5 commits into
Open
mrthankyou wants to merge 5 commits into
mrthankyou wants to merge 5 commits into
Conversation
…nd let doctor --fix tighten it (#1265) Claude Code and Codex create ~/.claude and ~/.codex from the umask (0755 or 0775), and the agent adapters accept only 0700. Any such home failed the launch only when the engine rendered the workflow, after planning and the execution snapshot, as an INTERNAL_ERROR naming no directory. This hit the default Codex setup on macOS and Linux, and Claude on Linux. validate (and so run) now predicts each selected agent's provider home with the adapters' rules and reports PROVIDER_HOME_UNSAFE with the directory and the fix. doctor reports a provider-homes check, and doctor --fix sets each such home that is a real directory the operator owns to 0700. A directory above a provider home is reported but never changed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
… and pin the directory doctor --fix changes (#1265) From review: - The adapters require the provider-home root (~/.ultrafuzz-provider-homes or ULTRAFUZZ_PROVIDER_HOME_ROOT) to be private too, not only the home. It is now checked, and doctor --fix repeats until root and home are both tightened. - A relative ULTRAFUZZ_PROVIDER_HOME_ROOT, which the adapters reject, is reported. - A component that cannot be inspected for any reason other than ENOENT is reported instead of passing, as the adapter fails on it. - doctor --fix opens the directory without following a link and changes it through that descriptor, only if it is still the directory checked. - A caller that passes no environment is checked against the process's own, which the engine then uses. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…dable homes, and documents the root (#1265) From review: - A provider-home root shared by several agents is tightened once, and a directory already at 0700 is not reported as tightened. - A home its owner cannot read (e.g. 0300) cannot be opened; it is changed by path instead, right after confirming it is still the same directory. - The docs said --fix never changes a directory above a provider home, but it tightens the Ultrafuzz provider-home root; they now say so. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Collaborator
|
Thanks, the preflight is the right fix. Failing at One change before we merge: please drop Concretely:
We'll take care of the smaller items ourselves in a follow-up after merge, so no need to handle them here:
|
…OVIDER_HOME_UNSAFE (#1265) Per review, doctor stays report-only: drop doctor --fix and everything that supported it (fixProviderHomes, the fd-pinned fchmod and its EACCES path fallback, the multi-pass loop, DoctorInput.fix, the CLI flag, PROVIDER_HOME_FIXED / PROVIDER_HOME_FIX_FAILED, the fixable field and the fix-only tests), and the separate provider-homes doctor check, since doctor already reports PROVIDER_HOME_UNSAFE through validate. Each problem now carries the remedy the diagnostic prints: `chmod 700 <dir>` for a home or provider-home root with the wrong mode, `chmod go-w <dir>` for a writable ancestor, and what to change otherwise. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
…-home-preflight # Conflicts: # CHANGELOG.md
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1265.
Problem
The agent adapters (
templates/smithers/agents/provider-home.tsx) accept a provider home only if it is a directory the operator owns, with mode exactly0700, below directories only the operator can write. Claude Code and Codex create their own homes from the umask, so the result is usually0755or0775:~/.claude755~/.claude775~/.codex755~/.codex755The Codex adapter uses its provider home in both
subscriptionandapi-keymode, andultrafuzz initdefaults to Codex. So a default Codex run fails for anyone whose Codex CLI created~/.codex, on macOS or Linux, and a Claude run fails on Linux. It fails only when the engine renders the workflow, after about 2 minutes of planning and execution-snapshot preparation, asINTERNAL_ERROR: render frame: provider homes must be operator-owned with private 0700 permissions, with no directory named. CI misses it because the e2e campaign setsCODEX_HOMEto a fresh 0700 directory.Change
provider-home-preflight.ts:predictedProviderHomemirrors the adapters' resolution order:config_dirorULTRAFUZZ_PROVIDER_HOME_ROOT, thenCLAUDE_CONFIG_DIR/CODEX_HOME/KIMI_*, then~/.claude/~/.codex/~/.kimi-code, and~/.ultrafuzz-provider-homes/<provider>for the rest.providerHomeProblemsapplies the adapters' checks to each selected agent's home.resolveProviderHomeunder Bun and checks the prediction matches it.validate(and sorun, which validates before planning) reportsPROVIDER_HOME_UNSAFEin the agents check, naming the directory and the fix:ultrafuzz doctorgains aprovider-homescheck.ultrafuzz doctor --fixapplies the repair first, then checks:0700, and reportsPROVIDER_HOME_FIXED(tightened <dir> from mode 755 to 700);ULTRAFUZZ_PROVIDER_HOME_ROOTat a private directory.HOME, as the engine does. A launch withoutHOME, such as the unit tests' empty environments, isn't checked, so the suite never reads a developer's real~/.codex.doctor,--fix),docs/config.md, CHANGELOG.Not done: tightening the directory automatically during launch
Ultrafuzz could also
chmod 700an operator-owned~/.codexor~/.claudesilently whenever it launches. That would need no user action, and it's arguably correct, since those directories hold credentials and both CLIs run as the same user. This PR deliberately doesn't do it. Per Chesterton's fence, the0700rule and the decision not to change other tools' directories should be reviewed first:doctor --fixgives the same result with the operator's consent. If maintainers agree automatic tightening is safe, it can be added on top of this change. A related option is to accept an operator-owned home that isn't group- or world-writable (such as0755), as the checks on parent directories already do. That also changes the security rule, so it also needs review.Verification
validateagainst the realHOMEreports the maintainer's real~/.codex(755) asPROVIDER_HOME_UNSAFE(read only; not modified).HOMEwhose.codexis 755:doctorreportsprovider-homes: error;doctor --fixreportsPROVIDER_HOME_FIXED … from mode 755 to 700;validatethen passes.provider-home-preflight.test.ts:--fixtightens only the operator's own home and leaves an ancestor alone;validaterefuses before launch and passes once fixed;resolveProviderHomerun under Bun.doctor/validatetests (12) and the CLIdoctortests pass. Strict eslint, prettier and the docs check are clean.🤖 Generated with Claude Code
The PR should not merge while its advertised provider-home repair command is unavailable.
Summary
The PR adds provider-home validation before planning and changes doctor to report manual remedies. Changes since the previous review also add early duplicate-run detection, timeout-shadowing warnings, and retry handling for failed optional producers, including Modal resume decisions.
doctor --fixrepair is no longer available.Diagram
%%{init: {'theme': 'neutral'}}%% flowchart LR A[validate or run] --> B[Check selected provider homes] B -->|unsafe| C[PROVIDER_HOME_UNSAFE] C --> D[Manual permission repair] B -->|safe| E[Plan and launch] F[doctor] --> BReviews (4) · Last reviewed commit: "Merge remote-tracking branch 'origin/uns..."