Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 3 additions & 4 deletions src/handlers/entry/root.rs
Original file line number Diff line number Diff line change
Expand Up @@ -2340,10 +2340,9 @@ mod tests {
let child_env = HashMap::from([("GH_TOKEN".to_owned(), "GITHUB_PAT_TOKEN".to_owned())]);
let command = vec!["codex".to_owned()];

let native_result = remote_codex_command_with_mcp_binding_headers(
&command, &bindings, &child_env, None,
)
.unwrap();
let native_result =
remote_codex_command_with_mcp_binding_headers(&command, &bindings, &child_env, None)
.unwrap();
assert!(
native_result
.iter()
Expand Down
40 changes: 37 additions & 3 deletions src/handlers/run/docker_sandbox.rs
Original file line number Diff line number Diff line change
@@ -1,4 +1,4 @@
use std::path::PathBuf;
use std::path::{Path, PathBuf};

pub(crate) fn docker_binary_available() -> bool {
std::env::var_os("PATH")
Expand Down Expand Up @@ -925,7 +925,11 @@ fn append_filesystem_mounts(
}

for path in &read_paths {
if !is_nested_under(path, cwd) {
// A missing mount target inside the cwd bind mount makes Docker
// create an empty placeholder at that path on the host, which then
// reappears every session even after the user deletes it. Nothing
// to hide if it doesn't exist.
if !is_nested_under(path, cwd) || !Path::new(path).exists() {
continue;
}
// `--tmpfs` only accepts a directory target; a file target fails
Expand All @@ -952,7 +956,8 @@ fn append_filesystem_mounts(
}

for path in &write_paths {
if path == cwd || !is_nested_under(path, cwd) {
// Same as above: a missing source would be created on the host.
if path == cwd || !is_nested_under(path, cwd) || !Path::new(path).exists() {
continue;
}
if read_paths
Expand Down Expand Up @@ -1710,6 +1715,35 @@ mod tests {
assert_eq!(nested_mount[1], format!("{nested}:{nested}:ro"));
}

#[test]
fn docker_run_command_skips_mounts_for_nonexistent_denied_paths() {
let network = DockerRunNetwork {
name: "n".to_owned(),
gateway_ip: "172.30.0.1".to_owned(),
};
let cwd = std::env::current_dir().unwrap();
let missing = cwd
.join("definitely-missing-denied-path")
.to_string_lossy()
.into_owned();
let (_, args) = docker_run_command(
"claude",
&network,
std::slice::from_ref(&missing),
std::slice::from_ref(&missing),
&std::collections::HashMap::new(),
false,
DEFAULT_SANDBOX_IMAGE,
None,
None,
)
.unwrap();
assert!(
!args.iter().any(|arg| arg.contains(&missing)),
"nonexistent denied path must not be mounted: {args:?}"
);
}

#[test]
fn docker_run_command_mounts_cwd_readonly_when_cwd_itself_is_denied_write() {
let network = DockerRunNetwork {
Expand Down
Loading