9eb13d07b6
On macOS with TCC (Transparency, Consent, and Control), os.getcwd() raises PermissionError: [Errno 1] Operation not permitted — not FileNotFoundError — when the process CWD is under a protected location (~/Documents, ~/Desktop, ~/Downloads) and the calling process lacks Full Disk Access. _safe_getcwd() only caught FileNotFoundError (deleted CWD), so the terminal-tool cleanup thread, which calls _get_env_config() → _safe_getcwd() every 60 s, logged a full stack trace on every tick. This accumulated hundreds of MB of noise in mcp-stderr.log (observed 184 MB on a single-day session) without breaking functionality — the cleanup thread's outer try/except swallowed the exception, but exc_info=True kept emitting the traceback. Fix: add PermissionError to the existing except clause so the fallback chain (TERMINAL_CWD → $HOME) runs, matching the existing pattern for deleted-CWD recovery (#17558). Complements #66306, which handles PermissionError from subprocess.Popen(cwd=...) for an inaccessible configured cwd on Linux; this handles the distinct case where the live process CWD itself is TCC-blocked. Tests cover: PermissionError fallback to $HOME, TERMINAL_CWD priority, FileNotFoundError regression, happy path unchanged, and unrelated OSError (NotADirectoryError) still propagating instead of being swallowed.