anthropics / anthropics/claude-code

[BUG] macOS allowUnixSockets does not match /tmp symlink path

未关闭
#93,576 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
area:sandbox bug has repro platform:macos
主要语言
Python
星标
145k
派生
23.1k
PR 合并指标
PR 指标待抓取

描述

### Summary

On macOS, allowing an existing Unix socket through its `/tmp` path does not permit a sandboxed direct connection. The connection returns `EPERM`. Using the socket's physical `/private/tmp` path works.

### Environment

- Claude Code 2.1.236
- macOS Darwin 23.6.0 (x86_64)

### Reproduction

`/tmp` is a symlink to `/private/tmp`:

```text
/tmp/mysql56.sock -> /private/tmp/mysql56.sock
```

Configure:

```json
{
"sandbox": {
"enabled": true,
"network": {
"allowUnixSockets": [
"/tmp/mysql56.sock"
]
}
}
}
```

From sandboxed Bash, connect to the existing socket:

```bash
mysql --protocol=SOCKET --socket=/tmp/mysql56.sock --user=__sandbox_probe__ --execute='SELECT 1'
```

Actual result:

```text
ERROR 2002 (HY000): Can't connect to local MySQL server through socket '/tmp/mysql56.sock' (1)
```

The equivalent PDO connection returns:

```text
SQLSTATE[HY000] [2002] Operation not permitted
```

### Workaround

Allow both path spellings and make the client use the physical path:

```json
"allowUnixSockets": [
"/tmp/mysql56.sock",
"/private/tmp/mysql56.sock"
]
```

```text
mysql:unix_socket=/private/tmp/mysql56.sock
```

After restarting Claude Code, the same sandboxed database query succeeds.

### Expected behavior

`allowUnixSockets` should handle the standard macOS `/tmp` to `/private/tmp` symlink consistently, or the documentation should require canonical socket paths.

Related: #40672 reports a similar `/tmp` path issue while binding a Unix socket. This report covers connecting to an existing socket.

贡献指南

这个仓库没有索引到贡献指南

调研方向

Start with the sandbox network handling for the allowUnixSockets entry point and reproduce the connection using /tmp/mysql56.sock on macOS. Trace how the configured path is compared with the socket's physical /private/tmp path. Done means the documented configuration works consistently for the symlinked path, or the documentation clearly requires canonical paths.

由索引模型根据 Issue 内容生成。

评估

技术栈
bash, macos, mysql
领域
databases, operating-systems, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
活跃
描述清晰度
基本清楚
新手友好度
48/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。