anthropics / anthropics/claude-code
[BUG] macOS allowUnixSockets does not match /tmp symlink path
- 主要言語
- Python
- スター
- 145k
- フォーク
- 23.1k
- PR マージ指標
- PR 指標を取得中
説明
### Summary
On macOS, allowing an existing Unix socket through its `/tmp` path does not permit a sandboxed direct connection. The connection returns `EPERM`. Using the socket's physical `/private/tmp` path works.
### Environment
- Claude Code 2.1.236
- macOS Darwin 23.6.0 (x86_64)
### Reproduction
`/tmp` is a symlink to `/private/tmp`:
```text
/tmp/mysql56.sock -> /private/tmp/mysql56.sock
```
Configure:
```json
{
"sandbox": {
"enabled": true,
"network": {
"allowUnixSockets": [
"/tmp/mysql56.sock"
]
}
}
}
```
From sandboxed Bash, connect to the existing socket:
```bash
mysql --protocol=SOCKET --socket=/tmp/mysql56.sock --user=__sandbox_probe__ --execute='SELECT 1'
```
Actual result:
```text
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/tmp/mysql56.sock' (1)
```
The equivalent PDO connection returns:
```text
SQLSTATE[HY000] [2002] Operation not permitted
```
### Workaround
Allow both path spellings and make the client use the physical path:
```json
"allowUnixSockets": [
"/tmp/mysql56.sock",
"/private/tmp/mysql56.sock"
]
```
```text
mysql:unix_socket=/private/tmp/mysql56.sock
```
After restarting Claude Code, the same sandboxed database query succeeds.
### Expected behavior
`allowUnixSockets` should handle the standard macOS `/tmp` to `/private/tmp` symlink consistently, or the documentation should require canonical socket paths.
Related: #40672 reports a similar `/tmp` path issue while binding a Unix socket. This report covers connecting to an existing socket.
コントリビューションガイド
このリポジトリのコントリビューションガイドは索引されていません
調査の方向性
Start with the sandbox network handling for the allowUnixSockets entry point and reproduce the connection using /tmp/mysql56.sock on macOS. Trace how the configured path is compared with the socket's physical /private/tmp path. Done means the documented configuration works consistently for the symlinked path, or the documentation clearly requires canonical paths.
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- bash, macos, mysql
- 領域
- databases, operating-systems, security
- issue の種類
- バグ
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 48/100