cli: --violations writes each recorded violation to a file - #601
Open
carlostapiacl wants to merge 1 commit into
Open
carlostapiacl wants to merge 1 commit into
carlostapiacl wants to merge 1 commit into
Conversation
A caller that runs the binary could not read the violation store, and on the CLI path the kernel monitors were never started, so filesystem denies were not recorded at all. --violations <path> turns the monitors on and appends each violation as a JSON line (timestamp, line, command). With the flag, srt waits 250 ms after the command exits: the monitor delivers a deny a few milliseconds after the syscall, and exiting at once lost 9 of 10 denies from commands refused on their last line (macOS). Without the flag nothing changes. Closes anthropics#582.
carlostapiacl
force-pushed
the
cli-violations-flag
branch
from
September 23, 2026 21:29
08d59c0 to
cff5344
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #582.
The problem
A caller that runs
srtcan't see what the sandbox refused. The violation store is filled, but nothing on the CLI path reads it, andcli.tscallsinitialize(runtimeConfig)without the third argument, so the kernel monitors never start and filesystem denies aren't recorded at all. The child just getsOperation not permitted.The change
--violations <path>: opt-in, one flag.enableLogMonitor = truetoinitialize(), so the existing monitors run.timestamp,line, andcommandwhen known. The store keeps only its last 100 and notifies with all of them, sogetTotalCount()decides which are new.sh -c 'echo x > outside'); deferring the exit kept 10 of 10.Without the flag nothing changes: no monitor, no subscription, same exit timing.
Measured
macOS 15.7 (x86_64), with
allowWriteholding/private/tmp/srt-demo/projectandexample.comas the only allowed host:The refused write and the kernel's mach-lookup deny come from the log monitor; the last line is the proxy's.
Linux (Debian 12, bwrap, Docker): the proxy deny is recorded; the refused write is not, because bwrap refuses it as
Read-only file systemand no monitor reports it. The README says so.Tests
Three in
test/cli.test.ts: a refused write is recorded even on the command's last line (macOS), a host the proxy refused is recorded (macOS and Linux), and no file appears when nothing is refused. All three fail without the change.typecheck,lint,prettierand the Node fallback test pass. Full suite on macOS x86_64: 1207 pass, 680 skip, 1 fail. The failure is insymlink-boundary.test.tsand fails onmaintoo on this machine (one or two of its tests, depending on timing): other processes were running undersrt, whose defaultTMPDIRis/tmp/claude, and those tests delete and recreate/tmp/claude.Exit codes are unchanged with the flag (checked
exit 0,exit 3, SIGKILL, SIGTERM against the same commands without it).Not covered: Windows. The flag still records proxy denies there;
initialize()only starts the monitors on macOS and Linux.Related but different: #597 changes what the sandboxed client is told when the proxy denies it. This is about the caller outside the sandbox.