@@ -99,6 +99,27 @@ The configured Docker CLI remains the security boundary. OpenBitFun does not exp
9999the Docker daemon over the network or bypass the current user's Docker
100100permissions.
101101
102+ ### SFTP handle ownership
103+
104+ Whole-file SFTP transfers wait for CLOSE acknowledgement before reporting
105+ success, including reads. The file guard retains cleanup ownership after cancellation,
106+ I/O errors, or a dropped streaming reader; it also receives and closes late OPEN
107+ replies after the caller stops waiting. Writes are not replayed if their outcome
108+ is uncertain. A failed close or timed-out OPEN retires the affected SFTP subsystem
109+ so its unknown handles and client accounting cannot poison later operations.
110+
111+ Full and bounded directory enumeration use the same serialized raw SFTP path,
112+ which closes directory handles on errors as well as success. Cancellation retires
113+ that directory subsystem, and subsequent enumeration replaces it without
114+ invalidating the SSH transport or the separate file subsystem. No persisted
115+ profile, workspace, or wire shape changes are required.
116+
117+ The locked russh-sftp 2.3 dependency sends CLOSE on ordinary file drop without
118+ reducing its client-side handle count. Relying on that drop alone can therefore
119+ produce ` Limit exceeded: handle limit reached ` even after the server has closed
120+ every file. See [ Desktop troubleshooting] ( ../../src/apps/desktop/README.md#remote-ssh-file-handle-errors )
121+ for recovery guidance.
122+
102123## Search on hosts without ripgrep
103124
104125Agent Grep keeps one matching and result-processing implementation. For
0 commit comments