Security & saved scrollback

Understand local permissions, updates, and what terminal output may reach disk.

Harness 2.0.13 min read
On this page

The terminal runs with your authority

Harness is deliberately not an App Sandbox application. A terminal and its child processes execute commands with your account’s permissions. Neither agent detection nor a notification constitutes an approval boundary for arbitrary commands.

Lua configuration is executable code. Agent hook installation changes the relevant tool’s configuration, with backups. Review unfamiliar scripts, hooks, and commands before running them.

Signed distribution and updates

The published Mac release is code-signed, uses hardened runtime, and is notarized. Automatic updates use Sparkle, an HTTPS appcast, and EdDSA-signed update artifacts. The app refreshes installed helper binaries from its signed bundle.

Signing verifies distribution integrity; it does not mean a command you choose to run is safe. Keep normal operating-system protections enabled.

The daemon’s access boundary

The local control socket is owner-only and incoming peers are checked against the daemon owner’s user ID. The Harness home directory is owner-only. Remote access forwards that control socket through your SSH connection.

This boundary protects against other local users; it is not isolation from a process already running as your user. Do not make the socket world-readable or expose it through an unauthenticated listener.

Know what is saved

Scrollback is raw terminal output. It can contain credentials, personal data, or other sensitive text printed by a program. Harness does not promise automatic redaction. Saved logs are owner-only, not a claim that all terminal history is encrypted.

persist-scrollback is on by default. Disable it globally or for one pane when output must not be stored as scrollback:

Disable disk scrollback for the calling pane
harness-cli set-option -p persist-scrollback off
Disable the global default
harness-cli set-option persist-scrollback off

An explicit pane override can take precedence over the global default. Check sensitive panes individually. The setting is supported at pane or global scope, not at tab, session, or workspace scope.

Set retention expectations

The default history-limit is 10,000 lines. A scrollback limit of 0 allows effectively unlimited history within the per-pane 512 MiB cap. That is a storage policy, not an assurance that no sensitive output will be retained.

Turning disk persistence back on records output from that point onward; output produced while it was off does not retroactively become saved history. Backups, copied files, or other external captures are outside this control.

Clipboard and paste protection

Clipboard reads via OSC 52 are disabled by default through allow-clipboard-read. Enabling them lets programs in a pane—including remote programs—request clipboard contents. Paste protection and bracketed-paste injection stripping reduce accidental execution risks, but do not replace reviewing what you paste.

Resize-aware replay and stored workspace data

New output records resize boundaries alongside the byte stream. The owner-only .scroll.sizes sidecar is tied to its log inode, rebased on compaction, and removed with the log on clear, persistence opt-out, or pane deletion. A replaced log does not inherit stale offsets.

Older logs and daemons without geometry retain the legacy replay fallback. Geometry from before this version cannot be reconstructed, and a crash can lose the last unflushed metadata.

2.0 uses Sparkle 2.9.6, including its upstream installer-path and delta-symlink fixes. Code signing, signed updates, daemon socket authentication, and scrollback opt-out remain separate security controls.

Source references Harness 2.0.1

Checked against the immutable shipping commit for Harness 2.0.1. For other versions, consult the installed CLI’s help and schemas.