fix(shim): stop the re-entry guard from outliving the hand-off - #10
Merged
Merged
Conversation
The shim exports `AAS_SHIM` so `aas exec` cannot resolve its way back
into the shim through PATH. Nothing then took it back out, so the agent
ran with it set — and so did everything the agent started. A tmux server
launched from inside a shimmed `codex` holds it in its global
environment, and every shell that server will ever spawn inherits it;
each of those hits the shim's guard branch on its first line and execs
the bare CLI. `claude` and `codex` quietly stop following `aas switch`
for the rest of that server's life, which is the same shape as the
profile home a tmux server kept handing back.
Both routes into the agent need it removed, because the shim is not
always on the path taken:
- `aas exec` spawns the binary the shim recorded in `AAS_SHIM_BIN`
(b14cb0d), so the guard branch never runs and only scrubbing the
child environment helps. This is the common case.
- Without that hand-off, exec resolves the agent through PATH, finds
the shim, and the guard branch is what execs the real CLI — so the
shim has to unset it there.
`AAS_SHIM_BIN` was already dropped from the child environment for the
same reason: it describes one hop, not the launch.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
|
You have reached your Codex usage limits. You can see your limits in the Codex usage dashboard. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The bug
The shim exports
AAS_SHIMsoaas execcannot resolve its way back into the shim through PATH. Nothing took it back out, so the agent ran with it set — and so did everything the agent started.A tmux server launched from inside a shimmed
codexholdsAAS_SHIM=1in its global environment, and every shell that server will ever spawn inherits it. Each of those hits the shim's first line:…and runs the bare CLI unrouted.
claudeandcodexquietly stop followingaas switchfor the rest of that server's life — the same shape as the profile home a tmux server kept handing back (#4).Why both paths
The shim is not always on the route taken into the agent:
aas execspawns the binary the shim recorded inAAS_SHIM_BIN(b14cb0d), so the guard branch never runs and only scrubbing the child environment helps. This is the common case — and the reason anunsetin the shim alone would not have fixed it.AAS_SHIM_BINwas already dropped from the child environment for exactly this reason: it describes one hop, not the launch.AAS_SHIMnow joins it.Credit
The shim-side half of this was written by hand on one of our hosts and never committed; it is preserved at
wip/rtzr-shim-guard-unset. Reviewing it showed theAAS_SHIM_BINpath it did not cover, which is what this PR adds.Verification
exec::tests::the_shims_re_entry_guard_does_not_reach_the_agentand an assertion in the shim body test.🤖 Generated with Claude Code