Files

2.0 KiB

NEVER use AppData, $env:TEMP, %TEMP%, or any temp-dir API for any read, write, or shell command — all scratch/state/audit output lives INSIDE the project clone

What it says

Tier 2 autonomous execution (and any other code running in the sandboxed OpenCode session) MUST keep all scratch, state, audit-output, and intermediate files INSIDE the Tier 2 clone. AppData (*AppData\\*, *AppData\Local\Temp\*) is OFF-LIMITS. The full list of forbidden literals (matched against the command string by the bash deny rules):

  • *AppData\\*
  • *AppData\Local\Temp\*
  • *$env:TEMP*
  • *$env:TMP*
  • *%TEMP%*
  • *%TMP%*
  • *GetTempPath*
  • *gettempdir*
  • *mkstemp*

A violation halts the run at the OS level (Windows restricted token + ACLs) AND at the OpenCode bash-deny layer.

Why

The Tier 2 sandbox enforces path isolation: filesystem access is restricted to the Tier 2 clone (C:\projects\manual_slop_tier2\ on Windows). The Windows restricted token blocks reads/writes outside this path at the OS level. AppData is the historical leak site (the pre-2026-06-18 design put scratch files there); the relocations to project-relative paths (tests/artifacts/tier2_state/<track>/, tests/artifacts/tier2_failures/, scripts/tier2/artifacts/<track>/) make the AppData path obsolete and dangerous.

Default locations for Tier 2 artifacts

Artifact type Location
Failcount state tests/artifacts/tier2_state/<track>/state.json
Failure reports tests/artifacts/tier2_failures/
Throw-away scripts scripts/tier2/artifacts/<track-name>/
Test run logs tests/artifacts/tier2_state/<track>/test_run_<phase>_<task>.log
Audit outputs tests/artifacts/tier2_state/<track>/audit_<name>.json

Examples

WRONG (halted by the deny rule):

uv run python scripts/audit_exception_handling.py --json > %TEMP%\audit_initial.json

RIGHT:

uv run python scripts/audit_exception_handling.py --json > tests/artifacts/tier2_state/audit_initial.json