Skip to content

🤖 feat: Artifacts scratch dir and reads on SSH, Docker and devcontainer runtimes - #5423

Merged
ThomasK33 merged 8 commits into
artifacts-1-tabfrom
artifacts-2-runtimes
Oct 2, 2026
Merged

ThomasK33 merged 8 commits into
artifacts-1-tabfrom
artifacts-2-runtimes

Conversation

@ThomasK33

Copy link
Copy Markdown
Member

Summary

Gives SSH/Coder, Docker and devcontainer workspaces a $XUM_SCRATCH_DIR so artifacts work on every runtime, and reads artifacts through the runtime.

Implementation

  • runtimeScratchDir.ts: SSH uses <xumHome>/workspace-scratch/<workspaceId> (scratch/ is already the scratch-chat folder), Docker uses a folder in the container, devcontainers bind-mount the host scratch dir when the local daemon can see it.
  • Remote reads/listing go through Runtime (one listing script, capped readFile, the same containment rules) in artifactRuntimeStore.ts.
  • Runtime scratch is deleted on workspace removal (not archive), like plan files.
  • Adds the artifact kind contract (diff, pdf, canvas) used by later layers, and closes a parent-folder symlink swap in host reads.
  • Docs: XUM_SCRATCH_DIR env var and the system prompt page.

Risks

Touches workspace removal for remote runtimes (scratch cleanup). Remote scratch creation is gated on the experiment in part 9.

Stack: part 2 of 9 of the Artifacts stack (each PR shows only its own layer). Everything is behind the Artifacts experiment (Settings → Experiments, off by default). The user-facing page lands in part 9 (docs/workspaces/artifacts.mdx).


Generated with xum • Model: anthropic:claude-opus-5-5 • Thinking: high • Cost: $98.34

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-02T14:14:04.510248Z e81e448 Manual request
🔒 Security Review ✅ Completed 2026-10-02T14:12:51.840550Z e81e448 Manual request

Security findings

Advisory findings (1)

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@ThomasK33
ThomasK33 added this pull request to stack #5431 October 1, 2026 21:01
@ThomasK33
ThomasK33 force-pushed the artifacts-2-runtimes branch from 77beb02 to 7796f98 Compare October 1, 2026 21:12

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 77beb0286d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/runtime/runtimeFactory.ts
Comment thread src/node/services/systemMessage.ts Outdated
Comment thread src/node/services/artifactsOperations.ts
Comment thread src/node/runtime/runtimeScratchDir.ts Outdated
Comment thread src/node/services/artifactRuntimeStore.ts
Comment thread src/node/runtime/runtimeScratchDir.ts Outdated
Comment thread src/common/utils/artifactKind.ts
@ThomasK33
ThomasK33 force-pushed the artifacts-2-runtimes branch from 7796f98 to 3ce3944 Compare October 2, 2026 03:14
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 3ce3944c78

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 3ce3944c78

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/runtime/runtimeScratchDir.ts
Comment thread src/node/services/artifactRuntimeStore.ts
Comment thread src/node/services/artifactsOperations.ts Outdated
Comment thread src/node/services/artifactsOperations.ts Outdated
Comment thread src/node/runtime/transports/OpenSSHTransport.ts Outdated
@ThomasK33
ThomasK33 force-pushed the artifacts-2-runtimes branch from 3ce3944 to 12ca655 Compare October 2, 2026 05:28
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 12ca65528f

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/runtime/runtimeHelpers.ts

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🛡️ Codex Security Review · Automatically triggered

Here are some automated security review suggestions for this pull request.

Reviewed commit: 12ca65528f

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

Comment thread src/node/runtime/runtimeScratchDir.ts Outdated
@ThomasK33
ThomasK33 force-pushed the artifacts-2-runtimes branch from 12ca655 to eaf753e Compare October 2, 2026 07:14
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eaf753e5b6

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/services/artifactsOperations.ts Outdated
Comment thread src/node/services/artifactStore.ts
Comment thread src/node/services/artifactRuntimeStore.ts
@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: eaf753e5b6

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

…er runtimes

- `$XUM_SCRATCH_DIR` on SSH, Docker and devcontainer runtimes (runtimeScratchDir), exported to agent bash, terminals and the system prompt
- Artifact listing and reads through the runtime on remote workspaces (artifactRuntimeStore)
- Artifact kinds for diff, pdf and canvas (contract for later layers)
- Refuse host artifact reads through a parent folder swapped for a symlink
- Remove the SSH runtime scratch dir with the workspace
- Docs for the remote scratch dir and the synced system prompt page
- Codex review round 1 fixes: fork passes the new workspace id to createRuntime, remote scratch prompt line follows whether the dir is set, devcontainer scratch mount probe (cached) in the Artifacts tab, terminal prelude exports after mkdir (plus MUX alias), pinned artifacts root on host and runtime reads, runtime listing visit budget keeping the newest 500
- Codex review round 2 fixes: the Artifacts tab runs the agent-turn scratch mkdir on SSH and Docker (cached, unavailable on failure), list and read pass the request abort signal through, remote terminals group the scratch prelude and shell under the cd
- Codex review round 3 fixes: the task startup path that reuses a materialized checkout builds its runtime with the task id (devcontainer scratch mount after a crash), the runtime scratch dir is created under umask 077 by agent turns and the terminal prelude (subshell-scoped)

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_

<!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…criptor (Codex r4 oQgVX, oQgVa)

A devcontainer writes its same-path scratch mount from inside the container
while the host lists and reads it, so pathname checks can be raced from the
container (swap a folder for a symlink after the check; swap-restore-swap
defeats the realpath + inode fallback on hosts without /proc/self/fd).

- listArtifactsInDir walks folders through held O_DIRECTORY|O_NOFOLLOW
  descriptors (/proc/self/fd/<fd>/<name>) where the host supports it.
- requireDescriptorPaths (container-written dirs) fails closed: no pathname
  listing, and reads refuse when the opened descriptor cannot be verified.
- Devcontainer mounts on hosts without descriptor paths are listed and read
  inside the container (panel and artifact_list), where a swap grants nothing.

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
@ThomasK33
ThomasK33 force-pushed the artifacts-2-runtimes branch from eaf753e to 7d7867d Compare October 2, 2026 08:36
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 7d7867d0a8

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7d7867d0a8

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/runtime/streamUtils.ts
Comment thread src/node/runtime/runtimeScratchDir.ts
…shell (Codex r5 oRvhh)

OpenSSH hands its command to the account's login shell. The scratch prelude's
subshell and the brace group added for the failed-cd fix are POSIX-only, so a
fish login shell rejected the whole line and the terminal exited instead of
opening (the previous `cd ... && exec $SHELL -i` worked in fish).

The command now runs `exec sh -c '<script>'`, quoted so sh and fish read it
back unchanged; $SHELL -i still opens the account's own shell. The test runs
the command under sh and fish with a quote, backslashes and $ in the path.

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: af0ed78477

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: af0ed78477

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/runtime/transports/SSH2Transport.ts
…y fish (Codex r6 oTZXo)

The SSH2 transport types the scratch prelude into the account's running login
shell. The round-3 owner-only fix wrapped mkdir in `(umask 077; ...)`, a
subshell fish rejects, so fish terminals printed a parse error and opened
without XUM_SCRATCH_DIR (the earlier `mkdir -p ... && export ...` form worked).

The prelude now uses `mkdir -p -m 700`, which keeps the scratch dir
owner-only without a subshell or changing the shell's umask. The new test
types the SSH2 lines into sh and fish and checks the var and the 0700 mode.

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 0c33f7475f

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

…nt and cache them

Without this, every agent turn on SSH, Docker and devcontainer runtimes ran a
remote exec (ensureScratchDirForSpec) and remote terminals got the scratch
prelude even with the Artifacts experiment off.

Ported unchanged from the L9 review-fix commit so its replay is a no-op:
- RemoteScratchDirCache (REMOTE_SCRATCH_DIR_TTL_MS = 5 min) in runtimeScratchDir
- turnRequestBuilder resolves remote scratch dirs only with the experiment, via
  the cache; local/worktree keep theirs
- TerminalService takes isArtifactsExperimentEnabled (wired in the desktop
  layer) and drops the remote prelude when it is off
- systemMessage comment

New aiService test: an SSH turn with the experiment off runs no scratch exec
and exports no XUM_SCRATCH_DIR; with it on, two turns run one exec.

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 4867b37cb0

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 281a405cab

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 281a405cab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread docs/hooks/environment-variables.mdx
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: 281a405cab

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 281a405cab

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/node/services/artifactsOperations.ts
Comment thread src/node/runtime/DevcontainerRuntime.ts
Comment thread src/node/services/artifactRuntimeStore.ts
… the daemon refuses it (Codex r10 oWlVV)

The scratch bind mount is added for every devcontainer with a workspace id,
Artifacts experiment on or off. A VM-backed local daemon (Docker Desktop,
Colima) with XUM_ROOT outside its file sharing refuses the source and failed
the whole `devcontainer up`, breaking devcontainer startup.

`devcontainer up` now retries once without the scratch mount when the failure
names the scratch dir (the daemon's refusal or the failed `docker run` command
line). Build failures do not name it and are not retried. Scratch then stays
unavailable, as the mount probe reports.

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
…rtifacts experiment (Codex r10 oWlVV)

Users who never enable Artifacts must not have devcontainer startup depend on
the daemon accepting the scratch mount source, even if the retry heuristic
misses a daemon's error text. createRuntime now passes scratchMountDir only when
the Artifacts experiment is on, through a gate the cross-cutting service layer
registers from ExperimentsService (off until registered), the same check agent
turns and terminals use. The retry without the mount stays for users with the
experiment on.

---

_Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
@ThomasK33

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

🛡️ Codex Security Review · Automatically triggered

Security review completed. No security issues were found in this pull request.

Reviewed commit: e81e448971

View security finding report

Only the user who started this review can view the report in Codex.

ℹ️ About Codex security reviews in GitHub

This is an experimental Codex feature. Security reviews are triggered when:

  • You comment "@codex security review"
  • A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review

Once complete, Codex will leave suggestions, or a comment if no findings are found.

@ThomasK33
ThomasK33 added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 2ab0b6b Oct 2, 2026
39 of 40 checks passed
@ThomasK33
ThomasK33 deleted the artifacts-2-runtimes branch October 2, 2026 15:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant