Eval sandbox cleanup verifies each directory as it walks so a swapped symlink can't redirect it.
What's wrong with this entry?
Cleaning up a plugin eval sandbox now walks the directory tree recursively, confirming each step is still the same file it expected before changing its permissions to owner-only, so a symlink swapped in mid-cleanup cannot redirect it.
- the recursive unlock runs on Linux and WSL, or when the directory is explicitly marked as owned by the harness; it is skipped on Windows
- the eval temp area gets its own
tmpsubdirectory created owner-only
await hu(e, 448)
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.234
plugin evalno longer swallows piped inputBoth mention eval
-
v2.1.234
Plugin eval reference documents image grading and new exit codes
Both mention eval
-
v2.1.234
claude plugin evalhandles termination signals and cleans up its outputBoth mention eval