Repository navigation
🤖 feat: Artifacts scratch dir and reads on SSH, Docker and devcontainer runtimes - #5423
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
Security findingsAdvisory findings (1)
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
77beb02 to
7796f98
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 77beb0286d
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
7796f98 to
3ce3944
Compare
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 3ce3944c78
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
3ce3944 to
12ca655
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 12ca65528f
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
There was a problem hiding this comment.
🛡️ Codex Security Review · Automatically triggered
Here are some automated security review suggestions for this pull request.
Reviewed commit: 12ca65528f
ℹ️ About Codex security reviews in GitHub
This is an experimental Codex feature. Security reviews are triggered when:
- You comment "@codex security review"
- A regular code review gets triggered (for example, "@codex review" or when a PR is opened), and you’re opted in so security review runs alongside code review
Once complete, Codex will leave suggestions, or a comment if no findings are found.
12ca655 to
eaf753e
Compare
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: eaf753e5b6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
…er runtimes - `$XUM_SCRATCH_DIR` on SSH, Docker and devcontainer runtimes (runtimeScratchDir), exported to agent bash, terminals and the system prompt - Artifact listing and reads through the runtime on remote workspaces (artifactRuntimeStore) - Artifact kinds for diff, pdf and canvas (contract for later layers) - Refuse host artifact reads through a parent folder swapped for a symlink - Remove the SSH runtime scratch dir with the workspace - Docs for the remote scratch dir and the synced system prompt page - Codex review round 1 fixes: fork passes the new workspace id to createRuntime, remote scratch prompt line follows whether the dir is set, devcontainer scratch mount probe (cached) in the Artifacts tab, terminal prelude exports after mkdir (plus MUX alias), pinned artifacts root on host and runtime reads, runtime listing visit budget keeping the newest 500 - Codex review round 2 fixes: the Artifacts tab runs the agent-turn scratch mkdir on SSH and Docker (cached, unavailable on failure), list and read pass the request abort signal through, remote terminals group the scratch prelude and shell under the cd - Codex review round 3 fixes: the task startup path that reuses a materialized checkout builds its runtime with the task id (devcontainer scratch mount after a crash), the runtime scratch dir is created under umask 077 by agent turns and the terminal prelude (subshell-scoped) --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high` • Cost: `$123.74`_ <!-- mux-attribution: model=anthropic:claude-opus-5-5 thinking=high costs=123.74 -->
…criptor (Codex r4 oQgVX, oQgVa) A devcontainer writes its same-path scratch mount from inside the container while the host lists and reads it, so pathname checks can be raced from the container (swap a folder for a symlink after the check; swap-restore-swap defeats the realpath + inode fallback on hosts without /proc/self/fd). - listArtifactsInDir walks folders through held O_DIRECTORY|O_NOFOLLOW descriptors (/proc/self/fd/<fd>/<name>) where the host supports it. - requireDescriptorPaths (container-written dirs) fails closed: no pathname listing, and reads refuse when the opened descriptor cannot be verified. - Devcontainer mounts on hosts without descriptor paths are listed and read inside the container (panel and artifact_list), where a swap grants nothing. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
eaf753e to
7d7867d
Compare
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7d7867d0a8
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…shell (Codex r5 oRvhh) OpenSSH hands its command to the account's login shell. The scratch prelude's subshell and the brace group added for the failed-cd fix are POSIX-only, so a fish login shell rejected the whole line and the terminal exited instead of opening (the previous `cd ... && exec $SHELL -i` worked in fish). The command now runs `exec sh -c '<script>'`, quoted so sh and fish read it back unchanged; $SHELL -i still opens the account's own shell. The test runs the command under sh and fish with a quote, backslashes and $ in the path. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: af0ed78477
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…y fish (Codex r6 oTZXo) The SSH2 transport types the scratch prelude into the account's running login shell. The round-3 owner-only fix wrapped mkdir in `(umask 077; ...)`, a subshell fish rejects, so fish terminals printed a parse error and opened without XUM_SCRATCH_DIR (the earlier `mkdir -p ... && export ...` form worked). The prelude now uses `mkdir -p -m 700`, which keeps the scratch dir owner-only without a subshell or changing the shell's umask. The new test types the SSH2 lines into sh and fish and checks the var and the 0700 mode. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
…nt and cache them Without this, every agent turn on SSH, Docker and devcontainer runtimes ran a remote exec (ensureScratchDirForSpec) and remote terminals got the scratch prelude even with the Artifacts experiment off. Ported unchanged from the L9 review-fix commit so its replay is a no-op: - RemoteScratchDirCache (REMOTE_SCRATCH_DIR_TTL_MS = 5 min) in runtimeScratchDir - turnRequestBuilder resolves remote scratch dirs only with the experiment, via the cache; local/worktree keep theirs - TerminalService takes isArtifactsExperimentEnabled (wired in the desktop layer) and drops the remote prelude when it is off - systemMessage comment New aiService test: an SSH turn with the experiment off runs no scratch exec and exports no XUM_SCRATCH_DIR; with it on, two turns run one exec. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
|
@codex review |
…ratch-dir comment
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 281a405cab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 281a405cab
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
… the daemon refuses it (Codex r10 oWlVV) The scratch bind mount is added for every devcontainer with a workspace id, Artifacts experiment on or off. A VM-backed local daemon (Docker Desktop, Colima) with XUM_ROOT outside its file sharing refuses the source and failed the whole `devcontainer up`, breaking devcontainer startup. `devcontainer up` now retries once without the scratch mount when the failure names the scratch dir (the daemon's refusal or the failed `docker run` command line). Build failures do not name it and are not retried. Scratch then stays unavailable, as the mount probe reports. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
…rtifacts experiment (Codex r10 oWlVV) Users who never enable Artifacts must not have devcontainer startup depend on the daemon accepting the scratch mount source, even if the retry heuristic misses a daemon's error text. createRuntime now passes scratchMountDir only when the Artifacts experiment is on, through a gate the cross-cutting service layer registers from ExperimentsService (off until registered), the same check agent turns and terminals use. The retry without the mount stays for users with the experiment on. --- _Generated with `xum` • Model: `anthropic:claude-opus-5-5` • Thinking: `high`_
|
@codex review |
🛡️ Codex Security Review · Automatically triggeredSecurity review completed. No security issues were found in this pull request. Reviewed commit: Only the user who started this review can view the report in Codex. ℹ️ About Codex security reviews in GitHubThis is an experimental Codex feature. Security reviews are triggered when:
Once complete, Codex will leave suggestions, or a comment if no findings are found. |
Summary
Gives SSH/Coder, Docker and devcontainer workspaces a
$XUM_SCRATCH_DIRso artifacts work on every runtime, and reads artifacts through the runtime.Implementation
runtimeScratchDir.ts: SSH uses<xumHome>/workspace-scratch/<workspaceId>(scratch/is already the scratch-chat folder), Docker uses a folder in the container, devcontainers bind-mount the host scratch dir when the local daemon can see it.Runtime(one listing script, cappedreadFile, the same containment rules) inartifactRuntimeStore.ts.XUM_SCRATCH_DIRenv var and the system prompt page.Risks
Touches workspace removal for remote runtimes (scratch cleanup). Remote scratch creation is gated on the experiment in part 9.
Stack: part 2 of 9 of the Artifacts stack (each PR shows only its own layer). Everything is behind the Artifacts experiment (Settings → Experiments, off by default). The user-facing page lands in part 9 (
docs/workspaces/artifacts.mdx).Generated with
xum• Model:anthropic:claude-opus-5-5• Thinking:high• Cost:$98.34