Skip to content

Say which folder the agent works in, and warn when it's home - #804

Merged
robzolkos merged 13 commits into
mainfrom
warn-home-workdir
Sep 30, 2026
Merged

robzolkos merged 13 commits into
mainfrom
warn-home-workdir

Conversation

@robzolkos

@robzolkos robzolkos commented Sep 30, 2026 •

Copy link
Copy Markdown
Collaborator

Your agent works in the folder the connector is started from (os.Getwd(), internal/connector/dispatcher.go), and Claude Code runs there in acceptEdits mode, so it changes files without asking. Nothing said which folder that was. A connector started from a terminal that happened to be in ~ could change anything in the home directory.

basecamp connect setup and basecamp connect doctor now report a Work folder check:

  • pass: "Started from here, the agent works in /path/to/folder and may change files in it without asking".
  • warn in the home directory ("…your home folder…") or at a filesystem root ("…the root of the filesystem…": /, or a volume or UNC root on Windows, found as a path that is its own parent), with the hint "Start the connector from a folder made for the agent, or from the project it should work on." Home is recognised by identity on disk (os.SameFile), so symlinks and letter case (a Mac's filesystem ignores it) don't hide it. Roots are resolved as given, so /proc/self/root and similar still count.
  • fail when the folder can't be read (for example it was removed): the connector can't start there either, so setup and doctor mustn't call it ready.
  • The path is shown on one line through richtext.SanitizeSingleLine, since a folder name can carry newlines or terminal escapes. Comparisons use the raw path.

It's a warning, not a failure: some people will want the agent in a particular folder, and that's their call. Guided setup (#794) lists warning checks by name, so it shows there once both land.

Card: https://app.basecamp.com/2914079/buckets/48699913/card_tables/cards/10356301162


Summary by cubic

connect setup and connect doctor now report the folder the agent works in, warning when it's the home directory or filesystem root.

  • Adds a Work folder check that passes with the folder path, warns for the home folder or filesystem root (recognized by filesystem identity, so symlinks and case-insensitive filesystems don't hide them), and fails when the folder can't be read, reached, or entered.
  • Warns rather than passes when the home folder can't be determined; $HOME or the account record may say where it is.
  • Shows the path on one line, escaped, so folder names with newlines or terminal escapes can't forge output.

Written for commit 321f72c. Summary will update on new commits.

Review in cubic

Copilot AI balanced review requested due to automatic review settings September 30, 2026 13:58
@github-actions github-actions Bot added commands CLI command implementations tests Tests (unit and e2e) labels Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Root detection is incorrect across platforms, and unsanitized paths can inject terminal controls.

Review effort: Balanced
Findings: 1 High severity · 1 Medium severity

Open (2)
What changed in this PR

Adds work-folder safety reporting to connector setup and diagnostics.

Changes:

  • Reports the connector’s working folder.
  • Warns for home and filesystem-root folders.
  • Adds home, dedicated-folder, and symlink tests.

[!TIP]
If you aren't ready for review, convert to a draft PR.
Click "Convert to draft" or run gh pr ready --undo.
Click "Ready for review" or run gh pr ready to reengage.

File Description
internal/​commands/​connect.go Adds the check to connector setup.
internal/​commands/​connect_doctor.go Adds the check to connector diagnostics.
internal/​commands/​connect_workfolder.go Implements folder detection and warnings.
internal/​commands/​connect_workfolder_test.go Tests home, dedicated, and symlinked folders.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread internal/commands/connect_workfolder.go Outdated
Comment thread internal/commands/connect_workfolder.go
@robzolkos
robzolkos marked this pull request as ready for review September 30, 2026 14:01
Copilot AI balanced review requested due to automatic review settings September 30, 2026 15:04

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A failed home-directory lookup can incorrectly report the actual home folder as safe.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (2)

Comment thread internal/commands/connect_workfolder.go Outdated
Copilot AI balanced review requested due to automatic review settings September 30, 2026 18:47
Copilot AI previously approved these changes Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approved

The implementation matches the stated safety behavior and covers relevant platform and filesystem edge cases.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Workers run in the folder the connector is started from and may change
files there without asking. Nothing said so, and starting the connector
from a terminal that happened to be in the home directory put the whole
of it in reach.

`connect setup` and `connect doctor` now report a "Work folder" check:
the folder they run in, which is where the connector will work if it's
started from there. The home directory, or the filesystem root, is a
warning with a hint to start from a folder made for the agent or the
project it should work on. Symlinks to home are seen through.
The work-folder check printed the raw path, and check messages are
printed as they are, so a folder name carrying a newline or a terminal
escape could forge lines or clear the screen. The path is now shown
through SanitizeSingleLine; comparisons still use the raw path.

A filesystem root was only recognised as "/", so on Windows a volume or
UNC root passed, and "/" was called "your home folder". A root is now
any path that is its own parent, and its warning names it as the root
of the filesystem.
`cd /proc/self/root` keeps that path as the working directory, and it
isn't its own parent until resolved, so the root went unwarned. The root
check now resolves symlinks first.

The tests set USERPROFILE as well as HOME, since os.UserHomeDir reads it
on Windows, and the folder-name test skips on Windows, which forbids
newlines and escapes in names.
The connector can't start in a folder it can't read: the dispatcher
returns os.Getwd's error. The check only warned, and readiness accepts
warnings, so setup could write ready:true and doctor pass for a shell
whose folder had been removed. It is now a failure, with a hint to
change to a folder that exists.
Cleaning before resolving symlinks turned a working directory like
/proc/self/root/.. into /proc/self, which isn't where it leads, so the
root went unwarned. The root check now resolves the path as given and
cleans only when it can't.

The tests now check the message names the folder, not just a phrase
around it.
The home check compared resolved paths as text, so on a filesystem that
ignores letter case, as a Mac's does by default, /Users/Alice and
/users/alice were different folders and the home warning was missed.
samePath now asks whether the two are the same file on disk.
If os.UserHomeDir failed, HOME unset on Unix for instance, the check
had no home to compare with and passed every folder but the root, the
home folder included. It now falls back to the account's own record,
and if that says nothing either, it warns that it couldn't check rather
than passing.
getcwd can hand back a path that no longer resolves, for instance when a
parent folder lost its search permission after the shell went in. The
check passed, but workers open their folder by that path and would fail
to start. It now checks the path can be reached, and fails if not.
os.Stat on a folder succeeds without search permission on the folder
itself, so a folder whose own permissions stopped anyone entering it
still passed, while every worker, which enters it as cmd.Dir, would fail
to start. The check now stats "folder/.", which only resolves through a
folder that can be entered.
A $HOME that can't be looked at (a symlink through a folder the process
can't search, say) was compared as text and never matched, so the home
folder passed. A home that can't be looked at now counts as unknown, and
the check warns that it couldn't tell.

Appending "/." to a working directory already at the length limit made
the probe fail with ENAMETOOLONG though the folder was fine; it now
falls back to the path as given.
The "/." probe fell back to a plain stat at the length limit, and a
plain stat doesn't need search permission on the folder itself, so a
folder at the limit that couldn't be entered passed. The check now stats
the path, which needs its parents searchable, and then ".", which needs
the folder itself searchable, and never lengthens the path.
A working directory can reach / through more symlinks than EvalSymlinks
can expand within the path-length limit, leaving only the lexical check,
which then misses the root. The root check now asks first whether the
folder is / itself, the same way home is recognised.
A HOME naming a file passed the reachability test, so the account's own
record was never consulted and the real home folder passed. A home must
now be a folder that can be looked at.
Copilot AI balanced review requested due to automatic review settings September 30, 2026 19:41
Copilot AI dismissed their stale review, a newer Copilot review was requested September 30, 2026 19:41

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A filesystem root configured as the home directory is misclassified and receives the wrong warning.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)

Comment thread internal/commands/connect_workfolder.go
@robzolkos
robzolkos merged commit 68d349c into main Sep 30, 2026
31 checks passed
@robzolkos
robzolkos deleted the warn-home-workdir branch September 30, 2026 19:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

commands CLI command implementations tests Tests (unit and e2e)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants