summaryrefslogtreecommitdiff
path: root/hostnix/mojo/packages/claude-code
diff options
context:
space:
mode:
authorJoe Mou <dev@mou.fo>2026-07-16 20:36:38 -0400
committerJoe Mou <dev@mou.fo>2026-07-16 20:46:06 -0400
commit9750fbbc9e827e3e5b83f8cba17eb4aa5f7aa1a1 (patch)
tree338e8fb6e88f83302c4c21ebd4e071214ef07792 /hostnix/mojo/packages/claude-code
parentba8205f11c82792ab0679a3c36f39e00364f3d7e (diff)
mojo: Allow git/jj to access their repo dirs from sandboxed claude
/usr/bin/git is an xcode-select shim that needs to stat /Library/Developer/CommandLineTools to find the real git binary; the sandbox denied that path by default, breaking git entirely. Separately, when TARGET_DIR is a subdirectory of a larger repo, the real .git/.jj directories live above TARGET_DIR and were unwritable, breaking commits from within the subdirectory. default.nix now resolves the real git/jj dirs at launch and passes them through as GIT_DIR/JJ_DIR sandbox params.
Diffstat (limited to 'hostnix/mojo/packages/claude-code')
-rw-r--r--hostnix/mojo/packages/claude-code/claude.sb10
-rw-r--r--hostnix/mojo/packages/claude-code/default.nix5
2 files changed, 15 insertions, 0 deletions
diff --git a/hostnix/mojo/packages/claude-code/claude.sb b/hostnix/mojo/packages/claude-code/claude.sb
index 1117b18..3adb074 100644
--- a/hostnix/mojo/packages/claude-code/claude.sb
+++ b/hostnix/mojo/packages/claude-code/claude.sb
@@ -114,6 +114,10 @@
;; Project directory - primary workspace
(subpath (param "TARGET_DIR"))
+ ;; Include .git and .jj directories in case the root is above TARGET_DIR.
+ (subpath (param "GIT_DIR"))
+ (subpath (param "JJ_DIR"))
+
;; Temporary directories
(subpath (param "TMP_DIR"))
(subpath "/tmp")
@@ -287,6 +291,12 @@
(subpath "/Library/Java")
)
+;; Xcode Command Line Tools - needed so /usr/bin/git (an xcode-select shim)
+;; can locate the real git binary
+(allow file-read*
+ (subpath "/Library/Developer/CommandLineTools")
+)
+
;; Generated allow-read rules for: /Users/joe/src
;; for some reason claude-code needs list access to all parent directories of TARGET_DIR
;; - it doesn't need access to read the contents of directories, only the directories
diff --git a/hostnix/mojo/packages/claude-code/default.nix b/hostnix/mojo/packages/claude-code/default.nix
index a9798fd..2e3fd35 100644
--- a/hostnix/mojo/packages/claude-code/default.nix
+++ b/hostnix/mojo/packages/claude-code/default.nix
@@ -6,11 +6,16 @@ writeShellScriptBin "claude" ''
exit 1
fi
+ git_dir="$(git rev-parse --absolute-git-dir 2>/dev/null)"
+ jj_root="$(jj root --ignore-working-copy 2>/dev/null)"
+
exec /usr/bin/sandbox-exec -f ${./claude.sb} \
-D TARGET_DIR="$(realpath "$PWD")" \
-D TMP_DIR=/tmp \
-D HOME_DIR="$HOME" \
-D CACHE_DIR="$HOME/.cache" \
+ -D GIT_DIR="''${git_dir:-$PWD/.git}" \
+ -D JJ_DIR="''${jj_root:-$PWD}/.jj" \
${claude-code}/bin/claude \
--allow-dangerously-skip-permissions "$@"
''