Skip to content

uds: /tmp long-path fallback is refused on macOS (parent dir is 0o755); auto transport hides it #252

Description

@RichardHightower

Summary

On macOS the UDS transport is unusable for any project whose canonical socket path exceeds the 104-byte limit. The server falls back to /tmp/agent-brain-<hash>.sock, then the client refuses to connect because /tmp is mode 0o755, and the server cannot chmod it. --transport auto silently falls back to HTTP, so nobody notices.

Found during the v10.7.0 integration test on 2026-09-19.

Server (.agent-brain/logs/server.err):

Long-path fallback: binding UDS at /tmp/agent-brain-bd5902fa.sock (pointer in .../e2e/sample-project/.agent-brain)
Dual-binding TCP 127.0.0.1:8001 + UDS /tmp/agent-brain-bd5902fa.sock
[WARNING] agent_brain_server.api.uds_bind: Failed to chmod parent dir /tmp: [Errno 1] Operation not permitted: '/tmp'

Client:

$ agent-brain --transport uds status
agent_brain_uds.errors.SocketPermissionError: Refusing to connect: parent directory mode is 0o755, expected 0o700. (socket: /tmp/agent-brain-bd5902fa.sock)
  -> chmod 700 /tmp and re-bind the server.

The hint is not actionable. /tmp is a shared directory. Nobody should chmod 700 /tmp.

Also: agent-brain start --uds --json prints "socket_path": null even though the server bound a socket.

Cause

agent_brain_uds/paths.py::_short_fallback_path hard-codes /tmp. The permission check in agent_brin_uds/permissions.py requires the parent to be 0o700, which /tmp can never satisfy.

Proposed fix

Change the fallback directory order to a per-user private dir:

  1. $XDG_RUNTIME_DIR when set (Linux, already 0o700).
  2. tempfile.gettempdir() when its mode is 0o700 (macOS $TMPDIR is /var/folders/.../T, per-user, short).
  3. ~/.agent-brain/run/, created with mode 0o700.

Keep the hash-based file name. Update the client to resolve the same directory. Fix start --uds --json to report socket_path. Add a test that runs the fallback with a long state dir on macOS and asserts the parent dir mode is 0o700.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions