Skip to content

linux: quote the socat socket addresses - #659

Open
v0ropaev wants to merge 1 commit into
anthropics:mainfrom
v0ropaev:fix/linux-quote-socat-socket-paths
Open

v0ropaev wants to merge 1 commit into
anthropics:mainfrom
v0ropaev:fix/linux-quote-socat-socket-paths

Conversation

@v0ropaev

@v0ropaev v0ropaev commented Oct 6, 2026

Copy link
Copy Markdown

buildSandboxCommand quotes the socat binary and then interpolates the two UNIX-CONNECT addresses bare into a string that the inner <shell> -c re-parses:

const socat = quote([socatPath ?? 'socat'])
const socatCommands = [
  `${socat} TCP-LISTEN:3128,fork,reuseaddr UNIX-CONNECT:${httpSocketPath} >/dev/null 2>&1 &`,

The socket paths come from join(tmpdir(), ...), and tmpdir() is whatever TMPDIR says. A space in it splits the address into two words, socat is handed a third address, refuses to start, and >/dev/null 2>&1 swallows the message. The script carries on and the command runs against a relay that never bound, so the first proxied connection is refused with nothing in the logs to say why.

A space in TMPDIR is not exotic on a Mac but it happens on Linux too, through TMPDIR pointing at a user-named directory, and the same goes for a path that holds a quote or a glob character.

I mentioned this on #616 while that one was about the listener race, which #639 has since fixed. The quoting is separate and still there, so here is the change for it: the addresses go through the same quote the binary already uses.

Tested with a socket directory named srt test dir <pid>. Without the change the new test fails on the first assertion, with it the file is 20 pass, 22 skip. bun test over the whole suite gives the same 19 failures with and without the change, all of them --control-fd and proxy cases that need Linux or a network, and npm run typecheck, prettier and eslint are clean.

The test is gated on isLinux like its neighbours, so it will only actually run on the Linux legs. I did check that it passes and fails as intended on this machine by removing the gate locally, since wrapCommandWithSandboxLinux builds the string without caring which platform it is on.

buildSandboxCommand quotes the socat binary and then interpolates the two
UNIX-CONNECT addresses bare into a string the inner shell re-parses. The
socket paths sit under tmpdir(), which is whatever TMPDIR says, so a space
there splits an address into two words. socat is then handed a third
address, refuses to start, and >/dev/null 2>&1 hides the message, leaving
the command running against a relay that never bound.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant