fix(cli): export Java trust-store settings to all shells - #109
Merged
Merged
Conversation
Follow-up to the previous commit: SANDCAT_HOME already means "host CLI install dir" in install.sh (~/.local/share/sandcat), so reusing the same name inside the agent container for "the vscode user's home" gives one variable two meanings. Rename the test seam to SANDCAT_USER_HOME; behavior unchanged. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #102. Carries #108 by @atirna — the original commit is cherry-picked with authorship preserved; opened from an in-repo branch so CI runs without the fork-approval step. On top of it there is one cosmetic follow-up commit renaming the test-seam variable
SANDCAT_HOME→SANDCAT_USER_HOME(the former already means "host CLI install dir" ininstall.sh, so one name carried two meanings).Summary (from #108)
Java trust-store exports move out of
.bashrcinto a guarded/etc/profile.d/sandcat-java.sh. The entrypoint sources it afterapp-user-init.shrefreshes the writable trust store, so the agent process — and everything it spawns — inheritsJAVA_HOMEandJAVA_TOOL_OPTIONS. Login shells get it via/etc/profile, VS Code terminals via the existingsandcat-*.shsourcing block in/etc/bash.bashrc.Verification
--stacks java(temurin via devbox):JAVA_HOMEandJAVA_TOOL_OPTIONS(/proc/1/environ)https://example.comthrough the proxy → HTTP 200 (mitmproxy CA honored via the sandcat trust store)env -u JAVA_TOOL_OPTIONS→PKIX path building failed— the exact JAVA_TOOL_OPTIONS trust-store export is invisible to non-interactive shells (agent-spawned JVMs fail PKIX) #102 symptomcacertsrefreshed by app-user-init; baseline (GET 200 / POST 403 / no sudoers / no CA private key) unregresseddocker compose exec … printenvcan NOT observe these variables —docker execalways gets the image's Config.Env, never the entrypoint's;/proc/1/environis the correct probe.🤖 Generated with Claude Code