Skip to content

fix(rtk): init the hook without /mnt/claude in ralphex-fe; close stdin at all rtk init sites - #168

Merged
gatezh merged 3 commits into
masterfrom
fix/rtk-init-hardening
Sep 23, 2026
Merged

gatezh merged 3 commits into
masterfrom
fix/rtk-init-hardening

Conversation

@gatezh

@gatezh gatezh commented Sep 23, 2026

Copy link
Copy Markdown
Owner

What

Makes the rtk rewrite hook initialize in ralphex-fe even without the host ~/.claude mount, and adds < /dev/null to all three rtk init call sites.

Why

Changes

  • ralphex-fe/init-docker.sh:
    • mkdir -p /home/app/.claude plus a non-recursive chown app:app on that directory, and the rtk init, now always run.
    • The copying from /mnt/claude, the Playwright MCP patch and the recursive chown -R stay inside the guard, where they were.
    • Local additions are marked with Local: … (#128) banners, set apart from the body copied from upstream.
  • .devcontainer/init-plugins.sh, claude-code/.devcontainer/init-plugins.sh, ralphex-fe/init-docker.sh: rtk init … < /dev/null, keeping both RTK_TELEMETRY_DISABLED=1 and timeout 10. The rationale comments are trimmed to three lines.

Notes

Fixes #128
Fixes #130

The rtk init block sat inside the `if [ -d /mnt/claude ]` guard, so a
standalone container (no host ~/.claude mount) never got the PreToolUse
rewrite hook and rtk stayed inert, silently.

Hoist `mkdir -p /home/app/.claude` (rtk init -g fails without it), the
`chown -R app:app` and the rtk init out of the guard; only the copying
from /mnt/claude and the Playwright MCP patch stay behind it. Local
additions are fenced with "Local:" banners, and the header no longer
claims the file is copied as-is from umputun/ralphex.

Fixes #128
A devcontainer postCreateCommand runs under a pseudo-TTY, so rtk's
is_terminal() check passes and its telemetry consent prompt can block.
RTK_TELEMETRY_DISABLED=1 opts out and `timeout 10` kills a hang, but a
fired timeout is swallowed by `|| true` and leaves rtk silently
unconfigured. Redirecting stdin from /dev/null makes the prompt
unreachable instead.

Applied to .devcontainer/init-plugins.sh, claude-code's init-plugins.sh
and ralphex-fe/init-docker.sh. The env var and timeout stay; the adjacent
comments now describe all three defences in three lines.

Fixes #130
The previous commit made chown -R /home/app/.claude unconditional. That
would also rewrite the owner of anything bind-mounted into the directory,
e.g. a host .credentials.json, which newer ralphex wrappers mount.

Restore chown -R to the guard, where it only touches copies this script
made, and chown just the directory itself unconditionally. rtk init runs
as app via gosu, so the files it creates are already app-owned.
@gatezh
gatezh merged commit 6341d4c into master Sep 23, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Harden the three rtk init call sites with < /dev/null ralphex-fe: rtk is never initialized when the container runs without /mnt/claude

1 participant