diff options
| author | Joe Mou <dev@mou.fo> | 2026-07-16 20:36:38 -0400 |
|---|---|---|
| committer | Joe Mou <dev@mou.fo> | 2026-07-16 20:46:06 -0400 |
| commit | 9750fbbc9e827e3e5b83f8cba17eb4aa5f7aa1a1 (patch) | |
| tree | 338e8fb6e88f83302c4c21ebd4e071214ef07792 /hostnix/mojo/packages/claude-code/claude.sb | |
| parent | ba8205f11c82792ab0679a3c36f39e00364f3d7e (diff) | |
mojo: Allow git/jj to access their repo dirs from sandboxed claude
/usr/bin/git is an xcode-select shim that needs to stat
/Library/Developer/CommandLineTools to find the real git binary; the
sandbox denied that path by default, breaking git entirely.
Separately, when TARGET_DIR is a subdirectory of a larger repo, the
real .git/.jj directories live above TARGET_DIR and were unwritable,
breaking commits from within the subdirectory. default.nix now
resolves the real git/jj dirs at launch and passes them through as
GIT_DIR/JJ_DIR sandbox params.
Diffstat (limited to 'hostnix/mojo/packages/claude-code/claude.sb')
| -rw-r--r-- | hostnix/mojo/packages/claude-code/claude.sb | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/hostnix/mojo/packages/claude-code/claude.sb b/hostnix/mojo/packages/claude-code/claude.sb index 1117b18..3adb074 100644 --- a/hostnix/mojo/packages/claude-code/claude.sb +++ b/hostnix/mojo/packages/claude-code/claude.sb @@ -114,6 +114,10 @@ ;; Project directory - primary workspace (subpath (param "TARGET_DIR")) + ;; Include .git and .jj directories in case the root is above TARGET_DIR. + (subpath (param "GIT_DIR")) + (subpath (param "JJ_DIR")) + ;; Temporary directories (subpath (param "TMP_DIR")) (subpath "/tmp") @@ -287,6 +291,12 @@ (subpath "/Library/Java") ) +;; Xcode Command Line Tools - needed so /usr/bin/git (an xcode-select shim) +;; can locate the real git binary +(allow file-read* + (subpath "/Library/Developer/CommandLineTools") +) + ;; Generated allow-read rules for: /Users/joe/src ;; for some reason claude-code needs list access to all parent directories of TARGET_DIR ;; - it doesn't need access to read the contents of directories, only the directories |
