user-local installs for claude and pi, fix sandbox mounts
Move claude and pi from sudo global installs to ~/.local. Claude binary is copied to /usr/local/bin for sandbox visibility, pi runs via node from ~/.local/lib (ro-mounted). Fix bwrap intermediate dir traversal by setting 0755 perms on auto-created HOME dirs. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -8,11 +8,9 @@ import { parseStream } from './stream-parser';
|
||||
|
||||
const SEND_TIMEOUT_MS = 5 * 60 * 1000;
|
||||
|
||||
// Resolve absolute path to claude binary
|
||||
const CLAUDE_BIN = (() => {
|
||||
const result = Bun.spawnSync({ cmd: ['which', 'claude'], stdout: 'pipe', stderr: 'ignore' });
|
||||
return result.stdout.toString().trim() || 'claude';
|
||||
})();
|
||||
// Use /usr/local/bin/claude so it's visible inside bwrap sandbox (which ro-binds /usr).
|
||||
// The actual binary lives at ~/.local/bin/claude, symlinked from /usr/local/bin/claude.
|
||||
const CLAUDE_BIN = '/usr/local/bin/claude';
|
||||
|
||||
const DATA_PATH = process.env.DATA_PATH ?? join(process.cwd(), 'data');
|
||||
|
||||
|
||||
@@ -26,7 +26,8 @@ function isPidAlive(pid: number): boolean {
|
||||
}
|
||||
}
|
||||
|
||||
// Resolve pi as [node, cli.js]
|
||||
// Resolve pi as [node, cli.js] — the real .js path lives under ~/.local/lib/node_modules
|
||||
// which is ro-mounted in the sandbox. Node is at /usr/bin/node (under /usr ro-bind).
|
||||
const PI_CMD = (() => {
|
||||
const whichResult = Bun.spawnSync({ cmd: ['which', 'pi'], stdout: 'pipe', stderr: 'ignore' });
|
||||
const piBin = whichResult.stdout.toString().trim() || 'pi';
|
||||
|
||||
@@ -65,9 +65,21 @@ export function buildSandboxPrefix(email: string): string[] {
|
||||
if (existsSync('/lib64')) args.push('--ro-bind', '/lib64', '/lib64');
|
||||
if (existsSync('/sbin')) args.push('--ro-bind', '/sbin', '/sbin');
|
||||
|
||||
// Ensure intermediate dirs under HOME are traversable after runuser drops privileges
|
||||
// (bwrap auto-creates them as root-owned drwx------)
|
||||
const homeDir = process.env.HOME!;
|
||||
args.push('--perms', '0755', '--dir', homeDir);
|
||||
|
||||
// Bun runtime (e.g. /home/pastilhas/.bun)
|
||||
args.push('--ro-bind', BUN_DIR, BUN_DIR);
|
||||
|
||||
// npm global packages (~/.local/lib) — pi and its dependencies
|
||||
const localLib = join(homeDir, '.local', 'lib');
|
||||
if (existsSync(localLib)) {
|
||||
args.push('--perms', '0755', '--dir', join(homeDir, '.local'));
|
||||
args.push('--ro-bind', localLib, localLib);
|
||||
}
|
||||
|
||||
// Project source (for MCP server)
|
||||
args.push('--ro-bind', PROJECT_ROOT, PROJECT_ROOT);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user