fix(daemon): run a sandbox git credential helper through sh - #2799
Merged
zfy0701 merged 1 commit intoOct 5, 2026
Merged
Conversation
agentconnect-md#2794 ships dist/bin/git-credential with the daemon, but npm packs every non-bin file as 0644 and only the CLI's repairDaemonBundleModes restores modes. The CLI is installed separately and not upgraded with the daemon, so on rc.41 git still fails, now with 'Permission denied'. Reading the helper with sh makes its mode irrelevant.
Contributor
There was a problem hiding this comment.
Reviewed revision 1e6e3a6c; no blocking findings. Invoking the sandbox wrapper through sh fixes the missing executable bit while preserving helper arguments and the daemon-target invocation.
A standalone smoke check using the changed helper formatter and shipped wrapper reproduced the 0644 permission failure before the change and succeeded afterward, including paths containing spaces and apostrophes. The Vitest suite was not run here because pnpm and dependencies are absent.
sent by review-bot (Codex · gpt-6-astra) · open in session
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #2794.
Why #2794 is not enough
#2794 made the daemon build emit
dist/bin/git-credential, so a daemon installation used as a helper root hasthe helper git is pointed at. The build writes it as 0755 and
assert-self-contained.mjschecks that, but npmdrops the mode when it packs. Every non-
binfile in the tarball is 0644. On a host upgraded to 2.2.0-rc.41 withagentconnect upgrade:So a session placed on another daemon still fails every credentialed clone, now with
…/dist/bin/git-credential: Permission deniedinstead ofnot found.The CLI already works around npm's mode loss for the seccomp helpers:
repairDaemonBundleModesinpackages/cli/src/install.ts(#666). Adding the wrapper to that list would not fix this, though.@agentconnect.md/cliis installed separately, andagentconnect upgradeonly replaces the daemon payload(cli-daemon-split.md). A host keeps its CLI until the operator reinstalls it, so the fix would miss hosts with an
older CLI, and it would never reach versions already installed.
Change
quotedHelperbuilds the helper line for a sandbox target as!sh '<helper>' <agentId>, not!'<helper>' <agentId>.shreads the wrapper instead of executing it, so its mode no longer matters. Thisships with the daemon, so it reaches every host that upgrades.
/opt/agentconnect/bin/git-credential(0555) andmicrosandbox's wrapper work the same through
sh.run/shim, written 0755 on every boot) are unchanged..git/configlines written before this keep the old form. They only matter where the helper isexecutable, which it is in the image.
sh.Tests
git-injection.test.ts› "runs an installation helper that npm shipped without its executable bit".Real
git credential fillruns with the envcloneGitEnvbuilds for an agent whose helper root is a daemoninstallation, with
bin/git-credentialat 0644. Without the change it fails with the production error(
…/bin/git-credential: Permission denied); with it, git gets the helper's answer.git-injection.test.tsnow expect!sh '…'.git-injection,sandbox-credential-helper,gitea-gitcred,host-shim,shim-paths,executor-facet,executor-plane,srt-local,daemon-session-hosts,microsandbox-launch: 246 passed. The 2 failures indaemon-session-hosts(microsandbox custom TLS) fail identically onmainon macOS.Not in this PR
assert-self-contained.mjsstill checks the wrapper's executable bit indist. That check is now harmlessbut no longer needed.
repairDaemonBundleModesis unchanged. The seccomp helpers have the same old-CLI gap.🤖 Generated with Claude Code