Skip to content

wrapper: restore u+w on staged ~/.claude config - #29

Merged
jaxxen-dev merged 1 commit into
mainfrom
fix/readonly-staged-config
Sep 25, 2026
Merged

jaxxen-dev merged 1 commit into
mainfrom
fix/readonly-staged-config

Conversation

@jaxxen-dev

@jaxxen-dev jaxxen-dev commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

cp -aL preserves /nix/store's read-only modes, so home-manager-managed skills/agents dirs landed in the seed as 0555. That made the exit-time rm -rf of the scratch dir fail with 'Permission denied', and — worse — made the defense-in-depth find -delete of a nested .credentials.json fail silently, leaking it into the seed.

chmod -R u+w the staged copy before the strip, secure-fail if any .credentials.json survives, and chmod the scratch dir before cleanup. tests/host.sh now uses a read-only fake store so this regresses loudly.

What & why

Checklist

CI runs nix flake check (host-side guarantees, guest build, shellcheck) automatically. The
full-boot smoke test (tests/boot.sh) needs a real VM and is not in CI — so if your change
touches the guest, wrapper, or boot path, you must run it locally on a Nix+KVM box and paste
the result here. (See CLAUDE.md → "Definition of done".)

  • nix flake check is green (CI on this PR, or run locally)
  • Ran bash tests/boot.sh on a Nix+KVM box — pasted the N passed, M failed line below; or N/A (docs / CI-only change, no guest/wrapper/boot impact)
  • Touches the TTY (zsh/ZLE/terminfo/ssh -tt)? Did a human ccvm --shell pass — resize, vim, less, vi-mode — since terminal fidelity isn't automated
  • Security invariants still hold (no secret to disk/argv/seed; host key pinned; only the CWD shared) — see CLAUDE.md "Security invariants"
  • Commit trailer is the exact ccvm form: Co-authored-by: Claude <noreply@anthropic.com>

boot.sh: 47 passed, 0 failed
nix run works

cp -aL preserves /nix/store's read-only modes, so home-manager-managed
skills/agents dirs landed in the seed as 0555. That made the exit-time
rm -rf of the scratch dir fail with 'Permission denied', and — worse —
made the defense-in-depth find -delete of a nested .credentials.json
fail silently, leaking it into the seed.

chmod -R u+w the staged copy before the strip, secure-fail if any
.credentials.json survives, and chmod the scratch dir before cleanup.
tests/host.sh now uses a read-only fake store so this regresses loudly.

Co-authored-by: Claude <noreply@anthropic.com>
@jaxxen-dev
jaxxen-dev merged commit 5fbd2fa into main Sep 25, 2026
1 check passed
@jaxxen-dev
jaxxen-dev deleted the fix/readonly-staged-config branch September 25, 2026 04:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant