71252f0dcb
A root-launched CLI session can leak /root into the terminal cwd state a non-root gateway/cron process later resolves (#65583). os.path.isdir('/root') is True for a non-root user — stat only needs search permission on / — so _resolve_safe_cwd returned it and subprocess.Popen(cwd='/root') died with PermissionError: [Errno 13], failing EVERY cron job's terminal/file/search tool on every command until restart. _resolve_safe_cwd now requires X_OK (new _cwd_usable helper) and climbs to the nearest enterable ancestor, logging a WARNING that names the leak class when an existing-but-denied cwd is skipped. Missing-cwd recovery (#17558) behavior unchanged. E2E-verified: LocalEnvironment constructed with an unenterable cwd now runs commands from the fallback directory instead of raising.