Problem
After a workflow using tools.cache-memory completes inside AWF, the host-side post-agent step validateMemoryStep (gh-aw v0.89.21) fails with EACCES: permission denied writing /tmp/gh-aw/memory-validation/cache-default.ok.
Context
Originally reported in github/gh-aw#63472.
Root Cause
AWF's agent container performs UID/GID remapping in containers/agent/entrypoint.sh before running the user command, and /tmp is bind-mounted read-write into the chrooted agent (per docs on selective bind mounts). Files/directories created under /tmp/gh-aw/... by the agent process (running as the remapped UID) can end up with ownership/permissions that the host runner process (running as the original runner UID) cannot write into afterward — specifically when gh-aw's own post-agent validation step (outside AWF) tries to create memory-validation/cache-default.ok in the same path tree.
Proposed Solution
- Reproduce locally: run
awf --allow-domains github.com -- <cmd creating dirs under /tmp/gh-aw/memory-validation> and inspect resulting ownership/mode with --keep-containers.
- In
entrypoint.sh, ensure directories the agent creates under shared paths like /tmp/gh-aw retain permissive mode (e.g., umask 0002 or explicit chmod g+w) consistent with the host UID, or exclude /tmp/gh-aw from remap-affected writes.
- Document the interaction between AWF UID remapping and any host-side steps that read/write the same
/tmp subtree after the agent exits, in docs/environment.md.
Generated by Firewall Issue Dispatcher · copilot · auto · 22.3 AIC · ⊞ 9.2K · ◷
Problem
After a workflow using
tools.cache-memorycompletes inside AWF, the host-side post-agent stepvalidateMemoryStep(gh-awv0.89.21) fails withEACCES: permission deniedwriting/tmp/gh-aw/memory-validation/cache-default.ok.Context
Originally reported in github/gh-aw#63472.
Root Cause
AWF's agent container performs UID/GID remapping in
containers/agent/entrypoint.shbefore running the user command, and/tmpis bind-mounted read-write into the chrooted agent (per docs on selective bind mounts). Files/directories created under/tmp/gh-aw/...by the agent process (running as the remapped UID) can end up with ownership/permissions that the host runner process (running as the original runner UID) cannot write into afterward — specifically when gh-aw's own post-agent validation step (outside AWF) tries to creatememory-validation/cache-default.okin the same path tree.Proposed Solution
awf --allow-domains github.com -- <cmd creating dirs under /tmp/gh-aw/memory-validation>and inspect resulting ownership/mode with--keep-containers.entrypoint.sh, ensure directories the agent creates under shared paths like/tmp/gh-awretain permissive mode (e.g.,umask 0002or explicitchmod g+w) consistent with the host UID, or exclude/tmp/gh-awfrom remap-affected writes./tmpsubtree after the agent exits, indocs/environment.md.