anthropics / anthropics/claude-code

Sandbox blocks Go TLS on macOS: trustd Mach port inaccessible

オープン
#88,180 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
area:sandbox bug duplicate platform:macos
主要言語
Python
スター
145k
フォーク
23.1k
PR マージ指標
PR 指標を取得中

説明

## Summary

All Go binaries fail TLS verification inside the Claude Code sandbox on macOS. This affects `gh` (GitHub CLI), and would affect any Go-based CLI tool.

## Root cause

Go 1.18+ on macOS uses `//go:cgo_import_dynamic` to call Security.framework's `SecTrustEvaluateWithError` for TLS certificate verification. This is a direct dynamic symbol import — not cgo — so `CGO_ENABLED=0` has no effect. The verification requires a Mach port connection to the `trustd` system daemon, which the sandbox blocks.

Error: `tls: failed to verify certificate: x509: OSStatus -26276` (`errSecNotAvailable`)

## What works vs. what doesn't

| Tool | TLS engine | In sandbox |
|------|-----------|------------|
| `curl` | LibreSSL (reads cert files) | Works |
| `gh` (Go) | Security.framework via trustd | Fails |
| Any Go binary | Security.framework via trustd | Fails |

## Reproduction

```bash
# Inside Claude Code sandbox:
gh auth status
# => tls: failed to verify certificate: x509: OSStatus -26276

# Same command outside sandbox:
gh auth status
# => ✓ Logged in to github.com
```

## What we tried (and why it doesn't work)

- **`CGO_ENABLED=0`**: Go 1.26 uses `//go:cgo_import_dynamic`, not cgo. Build flag is irrelevant.
- **`SSL_CERT_FILE`**: Go on macOS ignores this — always uses Security.framework.
- **`GODEBUG=x509usefallbackroots=1`**: Only activates if `x509.SetFallbackRoots` was called. macOS's `loadSystemRoots()` returns a `systemPool: true` marker, so Go never triggers the fallback path.

## Suggested fix

Allow the Mach port to `trustd` (`com.apple.trustd`) in the sandbox profile. This is a read-only trust evaluation service — it doesn't modify system state. This would fix all Go-based CLI tools, not just `gh`.

## Environment

- macOS Darwin 25.5.0 (arm64)
- Go 1.26.5 (nix)
- gh 2.97.0 (nix)
- Claude Code sandbox (default settings)

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

No source files or tests are named. Start by reproducing `gh auth status` inside and outside the Claude Code sandbox, then inspect the sandbox profile and its Mach-port rules; done means Go-based TLS verification succeeds in the sandbox without weakening unrelated restrictions.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
go, macos
領域
operating-systems, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
42/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。