Agents cannot write scratch files in production: /tmp/opencode is owned by root #36
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
An agent in production tried to write
/tmp/opencode/ws-test.mjsand gotPermissionDenied: FileSystem.writeFile, from the Write tool and from bash.opencode's own temp directory is
os.tmpdir()/opencode, and its default permissions let agents write there without asking (verified in 1.18.21:external_directoryallowsPath.tmp/*). The image build created/tmp/opencodeas root (drwxr-xr-x root root, present in:latestbefore any container starts), and runs execute asbraid, so opencode's sanctioned scratch space is unwritable./tmp/node-compile-cacheis left root-owned the same way.Opening all of
/tmpis not the fix: every run in every slot shares the container's/tmp, so runs would collide and read each other's files, and nothing cleans it.Proposed:
TMPDIRunder the run directory, outside the worktree. opencode's scratch directory,mktemp, pytest and Node all follow it, and it goes away with the run./tmp.Fixed in
a4f4ac7(archived asruns-have-their-own-scratch-directory).opencode servegetsTMPDIR=<run>/tmp, created before it starts and written last so a caller'sTMPDIRcannot win. opencode's scratch directory,mktemp,tempfile, pytest and Node follow it, runs no longer share/tmp, and it is reclaimed with the run./tmp, andbraid-selfcheckfails if the image leaves anything there.$TMPDIRand the run's path./tmpstays out of bounds.On production after the deploy: the self-check passed, no root-owned entries in
/tmp, and the run's server createdruns/run_01M2HF4SNRBVJ6TA8ZX11T2Z4H/tmp/opencodeowned bybraidat startup.