# Confine the agent runtime and protect service credentials Type: task Status: resolved ## Question Make the real Claude SDK/Bash execution surface uphold `AgentFileOp.Authorized`: deny sibling tenant workspaces and service files, expose only the minimum safe process environment, use SDK credential protection for secrets, and add an actual Linux sandbox test proving another workspace and every non-provider credential are unreadable while required tools still work. ## Answer The Agent subprocess now receives a replacement environment containing only named runtime values and the selected provider protocol values; PostgreSQL, Feishu and Hub session credentials never cross the process boundary. Provider credentials are additionally denied inside Bash. The SDK must sandbox every command (`failIfUnavailable=true`, `allowUnsandboxedCommands=false`), denies host reads and writes from root, and re-opens only the canonical project workspace plus the reviewed read-only system runtime needed by `cph`. SDK config/cache/home and general temp storage live inside the workspace. A short relative `CLAUDE_CODE_TMPDIR` prevents the pinned SDK from falling back to host `/tmp`, while absolute workspace-local `TMPDIR`/`TMP`/`TEMP` remain stable after Bash changes directory. Linux production and CI now require both bubblewrap and `socat`; preflight probes both as the service user. Bounded, credential-redacted SDK stderr is logged with run and project correlation. The real Linux proof runs the actual Claude SDK, Bash, bubblewrap, `socat` and release `cph` as UID 1000 with no capabilities and `no_new_privs`. It proves parent, sibling-project, `/tmp` and `/var/tmp` writes are rejected and have no host effect; sibling/service-secret reads fail; platform and provider secrets are absent from Bash; workspace temp remains anchored after `cd`; and `cph` still executes. Final local gates passed: TypeScript check/build, Prisma schema, 173 unit tests, 85 mock-provider integration tests, deployment shell syntax, and the dedicated Linux sandbox test.