Repository navigation
plat 568
| Field | Value |
|---|---|
| State | fixed on main |
| Priority | P2 |
| Product | sandbox |
| Area | skills |
| Summary | Users could not install custom skills: the sandbox made the whole .agents/.claude/.codex/.cursor/.gemini/.pi folders read-only |
Excellence, 2026-10-06: an agent running as a user's slot tried to install a skill (the gws installer writing .agents/skills/gws-shared) and got "Read-only file system". pkg/common/managed_projection_guard.go made the whole .agents, .claude, .codex, .cursor, .gemini and .pi folders read-only for the coding agent's shell, so nothing could be installed under their skills/ folders (npx skills add writes .agents/skills). The folder permissions themselves were fine.
Owner decision: protect our system files, not the whole folders. The guard now blocks the root instruction files (AGENTS.md, CLAUDE.md, GEMINI.md) and each CLI's policy files by name (settings, hooks, rules, commands, prompts, config, mcp.json, ...) plus whatever else already sits in those folders, and leaves the folders and their skills/ alone. A projected skill carries an ownership marker and only those are removed by the adapters, so an installed skill survives.
- Not verified in a real sandbox: this Mac's Docker cannot create the namespaces, and the existing sandbox tests skip here. After the next deploy, as a slot user, check that
mkdir .agents/skills/xworks and that writing.claude/settings.jsonandAGENTS.mdfails. - A policy file that does not exist yet (for example
.claude/settings.local.json) is not protected on the Linux backends, which skip a missing path. Before this change the whole folder was protected. If that matters, protect it from the launcher (create it empty first). - Not deployed.
Auto-synced from docs/ on main. Edit there, not here.