Skip to content

guardrails: block-windows-drive-tmp blocks correct /tmp writes on Git for Windows and misses downloader targets #4251

Description

@kyle-sexton

Observed in .claude/plugins/data/plugin-quality-melodic-software/evidence/c7ff503b-19e2-40d2-b99e-38c747f7fc0f/guardrails-hooks/20260919T205610Z/audit-notes.md, finding F3 (auditor severity: MEDIUM), with the packet's evidence-1.md addenda A1, A2 and A3 applied.

The guard blocks Bash-tool writes to /tmp, telling the caller to use the platform temp directory. On Git for Windows that premise is false: the mount table shows C:/Users/KYLESE~1/AppData/Local/Temp on /tmp type ntfs (binary,noacl,posix=0,usertemp) and cygpath -w /tmp answers C:\Users\KYLESE~1\AppData\Local\Temp. The write already lands in %TEMP%, so every Bash-lane block is a false positive costing a retry turn. PowerShell is unaffected: no MSYS mount table.

A1: /etc/fstab here is the unmodified shipped Git for Windows file, cygdrive typo intact, and dotfiles are chezmoi-managed with no entry for it, so the class applies to any Git Bash on a stock install. A2: the only host gate in hooks/block-windows-drive-tmp.sh is case "${OSTYPE:-}" in at L105, with no cygpath, mount or %TEMP% resolution. A design premise that does not hold, not a broken check.

Hit live twice before probing: a documentation fetch (mkdir -p /tmp/audit-docs && curl ...), and a probe that merely mentioned /tmp inside a quoted string argument. Two retry turns on correct commands.

Same guard, opposite gap: curl -sS -o /tmp/audit/hooks.md https://example.com and wget -O /tmp/a.html https://example.com both pass (exit 0), while mkdir, redirect, tee and cp targets are blocked (exit 2). A3: creator patterns at L115-L117 list tee|mktemp|mkdir|touch|dd|tee.exe and the writer case at L416 adds install|cp|mv|install.exe; neither curl nor wget appears, though those two are the most common way an agent creates a file at a fetched path.

Cheapest fix: gate the Bash lane on the mount: when cygpath -w /tmp or the mount line for /tmp resolves under %TEMP%, do not block a Bash-tool /tmp target. One probe, cacheable per process, PowerShell unchanged. Scope limit from A2: bare /tmp only; /c/tmp, C:\tmp, D:\tmp and drive-root \tmp stay blocked on every lane. Second: add curl -o/--output and wget -O/--output-document operands to the command-lane target extraction. If the mount gate is contested, reword the message to state the condition rather than assert the resolution.

Verification: on a stock Git for Windows host, mkdir -p /tmp/x from the Bash tool exits 0, mkdir -p /c/tmp/x and the PowerShell equivalent still exit 2, and curl -o /tmp/x exits 2 after the second change.

🤖 Generated with Claude Code

https://claude.ai/code/session_01F7GFS5autRMSaea6kSoXzx

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-readyFully specified and briefed; eligible for autonomous pickup from the frontier.priority: mediumReal value, no hard deadline; normal backlog flow.work-class: scopedA briefed fix or small feature; blast radius bounded by the brief, tests exist.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions