Skip to content

fix(sed): fall back to direct write when hidden temp file is refused - #2659

Merged
chaliy merged 1 commit into
mainfrom
claude/project-thread-kex6cr
Oct 9, 2026
Merged

chaliy merged 1 commit into
mainfrom
claude/project-thread-kex6cr

Conversation

@chaliy

@chaliy chaliy commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Requested by Михайло · project thread

What changed

sed -i and yq -i now work on filesystems or embedder policies that refuse dot paths. They still stage through the hidden .bashkit-<tool>-<hex>.tmp sibling when allowed; when the backend refuses to check or write that temporary, they replace the target with a single write_file and restore its mode. Chmod and rename failures on an accepted temporary still fail with the source untouched.

Why

Framework agents with a read/write workspace (WorkspacePolicy::read_write()) deny writes to dot paths, so sed -i exited 4 and left the file unchanged. It hit 2 of 3 live runs of the repo-release agent.

Before / After

New sed_inplace_policy_tests wrap InMemoryFs in a filesystem that refuses any dot-named path.

Before (main): sed -i 's/1/2/' notes.txt exits non-zero, file unchanged; 3 of 4 tests fail.
After: file rewritten, mode preserved (0640), no temporary left; 4/4 pass. Editing a refused target itself (.env) still fails and leaves it intact, so the fallback does not bypass the policy.

Risk

  • Low
  • The fallback gives up the rename step only. Every in-tree backend's write_file is all-or-nothing (TM-FS-014 for RealFs), and the existing TM-FS-016 failpoint suites (allocate, every backend-write class, chmod, rename) still pass. Threat model row updated.

Checklist

  • Tests added or updated
  • Backward compatibility considered

sed -i and yq -i stage through a .bashkit-<tool>-<hex>.tmp sibling. Embedder
policies that refuse dot paths (e.g. a read/write workspace policy) made
sed exit 4 with the file unchanged. When the temporary cannot be checked or
written, replace the target with one all-or-nothing write_file and restore
its mode. Chmod/rename failures still fail with the source untouched.
@chaliy chaliy self-assigned this Oct 9, 2026
@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
bashkit eaad228 Commit Preview URL

Branch Preview URL
Oct 09 2026, 04:19 PM

@chaliy
chaliy merged commit 1e840fe into main Oct 9, 2026
46 checks passed
@chaliy
chaliy deleted the claude/project-thread-kex6cr branch October 9, 2026 16:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant