fix(devshell): bind ~/.gnupg into bwrap sandbox for signed commits
The tmpfs overlay on $HOME hid the host GPG keyring inside the sandbox, so git commits with commit.gpgsign failed with "can't connect to the keyboxd". Bind ~/.gnupg rw, bind the gpg-agent socket dir (XDG_RUNTIME_DIR/gnupg), and propagate GPG_TTY so pinentry-tty works. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -48,6 +48,10 @@
|
|||||||
--bind "$HOME/.claude" "$HOME/.claude"
|
--bind "$HOME/.claude" "$HOME/.claude"
|
||||||
--bind "$HOME/.claude.json" "$HOME/.claude.json"
|
--bind "$HOME/.claude.json" "$HOME/.claude.json"
|
||||||
|
|
||||||
|
# Writable: GPG keyring + agent socket (commit signing)
|
||||||
|
--bind "$HOME/.gnupg" "$HOME/.gnupg"
|
||||||
|
--bind-try "''${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/gnupg" "''${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/gnupg"
|
||||||
|
|
||||||
--ro-bind "$HOME/.gitconfig" "$HOME/.gitconfig"
|
--ro-bind "$HOME/.gitconfig" "$HOME/.gitconfig"
|
||||||
--ro-bind "$HOME/.ssh" "$HOME/.ssh"
|
--ro-bind "$HOME/.ssh" "$HOME/.ssh"
|
||||||
--setenv GIT_SSH_COMMAND "ssh -F ~/.ssh/config"
|
--setenv GIT_SSH_COMMAND "ssh -F ~/.ssh/config"
|
||||||
@@ -61,6 +65,7 @@
|
|||||||
--setenv PATH "$PATH"
|
--setenv PATH "$PATH"
|
||||||
--setenv TERM "''${TERM:-xterm}"
|
--setenv TERM "''${TERM:-xterm}"
|
||||||
--setenv SANDBOX_ACTIVE "1"
|
--setenv SANDBOX_ACTIVE "1"
|
||||||
|
--setenv GPG_TTY "''${GPG_TTY:-}"
|
||||||
--chdir "$PROJECT_DIR"
|
--chdir "$PROJECT_DIR"
|
||||||
)
|
)
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user