fix(devshell): bind ~/.gnupg into bwrap sandbox for signed commits
Deploy / deploy (push) Failing after 1m38s
CI / ci (push) Successful in 11m57s

The tmpfs overlay on $HOME hid the host GPG keyring inside the sandbox, so
git commits with commit.gpgsign failed with "can't connect to the keyboxd".
Bind ~/.gnupg rw, bind the gpg-agent socket dir (XDG_RUNTIME_DIR/gnupg),
and propagate GPG_TTY so pinentry-tty works.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-05-20 11:39:43 +02:00
co-authored by Claude Opus 4.7
parent e738aeac05
commit 622531d78d
+5
View File
@@ -48,6 +48,10 @@
--bind "$HOME/.claude" "$HOME/.claude" --bind "$HOME/.claude" "$HOME/.claude"
--bind "$HOME/.claude.json" "$HOME/.claude.json" --bind "$HOME/.claude.json" "$HOME/.claude.json"
# Writable: GPG keyring + agent socket (commit signing)
--bind "$HOME/.gnupg" "$HOME/.gnupg"
--bind-try "''${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/gnupg" "''${XDG_RUNTIME_DIR:-/run/user/$(id -u)}/gnupg"
--ro-bind "$HOME/.gitconfig" "$HOME/.gitconfig" --ro-bind "$HOME/.gitconfig" "$HOME/.gitconfig"
--ro-bind "$HOME/.ssh" "$HOME/.ssh" --ro-bind "$HOME/.ssh" "$HOME/.ssh"
--setenv GIT_SSH_COMMAND "ssh -F ~/.ssh/config" --setenv GIT_SSH_COMMAND "ssh -F ~/.ssh/config"
@@ -61,6 +65,7 @@
--setenv PATH "$PATH" --setenv PATH "$PATH"
--setenv TERM "''${TERM:-xterm}" --setenv TERM "''${TERM:-xterm}"
--setenv SANDBOX_ACTIVE "1" --setenv SANDBOX_ACTIVE "1"
--setenv GPG_TTY "''${GPG_TTY:-}"
--chdir "$PROJECT_DIR" --chdir "$PROJECT_DIR"
) )