sandbox: leak-free placement for the .cliguard exec symlink #227
No reviewers
Labels
No labels
burndown-2026-06
sunday-sprint
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/umbra!227
Loading…
Reference in a new issue
No description provided.
Delete branch "issue-185-sandbox-leakfree"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This keeps the sandbox's
$0-sensitive exec symlink inside a private tmpfs view of the canonical tool directory, so the helper can still exec.<tool>.cliguardwithout leaving a host-side artifact..<tool>.cliguardbehind on the host.go test -vet=off -p 1 ./cli/sandbox ./cli/shell; fullmake testhit container scratch-space limits in this environment.closes #185
ward.workflow: pull-request-and-merge