Skip to content

fix(odd-status): export the Claude credential from the shell instead of putting it on env's argument vector - #51

Merged
using-system merged 1 commit into
mainfrom
fix/claude-credential-off-argv
Sep 19, 2026
Merged

using-system merged 1 commit into
mainfrom
fix/claude-credential-off-argv

Conversation

@using-system

Copy link
Copy Markdown
Owner

What

scripts/run-claude.sh reads the setup's credential file into a variable, exports it in a subshell and execs the CLI there, instead of env "VAR=$(cat file)" claude ..., which placed the credential on env's argument vector (world-readable on Linux, recorded by execve auditing). A read that fails now fails the step. A new shared launch case puts a fake env first on PATH and asserts it is never called, that the credential still reaches the CLI's variable, and that no argument of the CLI carries it; tests/odd-status/test_launch.py replays it.

Why

Closes #46.

How to test

shellcheck, ruff and pytest (180 passed) locally; the odd-status / claude cell runs the launch for real.

Review

Review subagent: green (three minors, all applied: comment wording, the read-before-export, the test comment). Security review: no findings.

🤖 Generated with Claude Code

…of putting it on env's argument vector

Closes #46

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@using-system
using-system merged commit 6a797e1 into main Sep 19, 2026
16 checks passed
@using-system
using-system deleted the fix/claude-credential-off-argv branch September 19, 2026 21:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fix(odd-status): run-claude.sh places the credential on the argument vector of /usr/bin/env

1 participant