Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
🧑💻What is the change being made?
The host-side IDE relay of the Claude sandbox now listens on a free loopback port chosen by the OS at each launch, instead of the fixed port 41337. The port is handed to the container through
IDE_RELAY_PORT:devcontainer.jsonpasses it toinit-sandbox.sh, which opens the egress firewall for that single port on the host, andclaude.shreads it for the lock file and thesocatforward. The sudoers rule now also accepts one numeric argument, andinit-sandbox.shonly honours the first port given after each container start.❓ Why is the change being made?
A fixed port fails whenever it is already taken on the host, for example by a second sandbox session or another program, and the IDE bridge is then silently disabled. Letting the OS pick a free port removes that collision and the need to keep three files in sync on one constant.
✅ How has this been tested?
Ran
ruff formatandruff checkonscripts/tasks/sandbox.py, andbash -nonclaude.shandinit-sandbox.sh. The pre-commit hooks pass. The sandbox was not launched end to end with an IDE attached, so that flow still needs a manual run.📚 How has this been documented?
Updated the sandbox section of
README.mdto say the relay uses a free loopback port picked at each launch. Comments in the touched scripts describe how the port travels from the host to the firewall and toclaude.sh.