From 5ce0979836647380ed6f7e6aaf1c23f4684c1987 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Radim=20H=C3=B6fer?= Date: Sat, 26 Sep 2026 10:37:49 +0200 Subject: [PATCH 1/2] feat(docker): enhance mount handling in Docker sandbox to skip nonexistent paths and add corresponding tests --- src/handlers/run/docker_sandbox.rs | 40 +++++++++++++++++++++++++++--- 1 file changed, 37 insertions(+), 3 deletions(-) diff --git a/src/handlers/run/docker_sandbox.rs b/src/handlers/run/docker_sandbox.rs index f2a506e3..31ae56d5 100644 --- a/src/handlers/run/docker_sandbox.rs +++ b/src/handlers/run/docker_sandbox.rs @@ -1,4 +1,4 @@ -use std::path::PathBuf; +use std::path::{Path, PathBuf}; pub(crate) fn docker_binary_available() -> bool { std::env::var_os("PATH") @@ -925,7 +925,11 @@ fn append_filesystem_mounts( } for path in &read_paths { - if !is_nested_under(path, cwd) { + // A missing mount target inside the cwd bind mount makes Docker + // create an empty placeholder at that path on the host, which then + // reappears every session even after the user deletes it. Nothing + // to hide if it doesn't exist. + if !is_nested_under(path, cwd) || !Path::new(path).exists() { continue; } // `--tmpfs` only accepts a directory target; a file target fails @@ -952,7 +956,8 @@ fn append_filesystem_mounts( } for path in &write_paths { - if path == cwd || !is_nested_under(path, cwd) { + // Same as above: a missing source would be created on the host. + if path == cwd || !is_nested_under(path, cwd) || !Path::new(path).exists() { continue; } if read_paths @@ -1710,6 +1715,35 @@ mod tests { assert_eq!(nested_mount[1], format!("{nested}:{nested}:ro")); } + #[test] + fn docker_run_command_skips_mounts_for_nonexistent_denied_paths() { + let network = DockerRunNetwork { + name: "n".to_owned(), + gateway_ip: "172.30.0.1".to_owned(), + }; + let cwd = std::env::current_dir().unwrap(); + let missing = cwd + .join("definitely-missing-denied-path") + .to_string_lossy() + .into_owned(); + let (_, args) = docker_run_command( + "claude", + &network, + std::slice::from_ref(&missing), + std::slice::from_ref(&missing), + &std::collections::HashMap::new(), + false, + DEFAULT_SANDBOX_IMAGE, + None, + None, + ) + .unwrap(); + assert!( + !args.iter().any(|arg| arg.contains(&missing)), + "nonexistent denied path must not be mounted: {args:?}" + ); + } + #[test] fn docker_run_command_mounts_cwd_readonly_when_cwd_itself_is_denied_write() { let network = DockerRunNetwork { From 1a9c18bc78b83ce7b24312ca4ea3b9a1a3b857b9 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Radim=20H=C3=B6fer?= Date: Sat, 26 Sep 2026 10:39:53 +0200 Subject: [PATCH 2/2] refactor(tests): improve formatting of remote command invocation for better readability --- src/handlers/entry/root.rs | 7 +++---- 1 file changed, 3 insertions(+), 4 deletions(-) diff --git a/src/handlers/entry/root.rs b/src/handlers/entry/root.rs index a442349e..d2107452 100644 --- a/src/handlers/entry/root.rs +++ b/src/handlers/entry/root.rs @@ -2340,10 +2340,9 @@ mod tests { let child_env = HashMap::from([("GH_TOKEN".to_owned(), "GITHUB_PAT_TOKEN".to_owned())]); let command = vec!["codex".to_owned()]; - let native_result = remote_codex_command_with_mcp_binding_headers( - &command, &bindings, &child_env, None, - ) - .unwrap(); + let native_result = + remote_codex_command_with_mcp_binding_headers(&command, &bindings, &child_env, None) + .unwrap(); assert!( native_result .iter()