mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-07 16:09:43 +02:00
docs(test): name the real reason the suite could reach ~/.codeman
#356 stopped a bare suite run from overwriting the production `remote-hosts.json` by pointing `CODEMAN_DATA_DIR` at a throwaway dir, and it gated every case-tree delete on the temp HOME. Both changes are right; the explanation written next to them is not. It says `os.homedir()` reads /etc/passwd rather than `$HOME` on Linux, which would mean the temp HOME in test/setup.ts never worked. It does: libuv checks the env var before the passwd entry (measured: `HOME=/tmp/x node -e 'console.log(os.homedir())'` prints /tmp/x), and CLAUDE.md's testing section relies on exactly that. What bypasses the temp HOME is `CODEMAN_DATA_DIR` itself. `getDataDir()` reads it as an absolute override before it looks at `homedir()`, so one inherited from the shell (a second instance, a beta run) sends the whole suite at the real data dir. That is the case setup.ts now closes, and #371 names the same variable from the other direction. The comments in setup.ts, the `safeRmHomeTree` helper, the voice-routes and case-clone tests now say that, and the containment gate is described as what it is: defense in depth. CLAUDE.md's testing paragraph gets the same note so the next reader does not chase a homedir() bug that does not exist. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qg6bcATm1pNNY4kQWGwzgu
This commit is contained in:
@@ -9,10 +9,10 @@
|
||||
* working tree in the case directory, that scaffolding does not overwrite the
|
||||
* repository's own files, and that a rejected URL never reaches git.
|
||||
*
|
||||
* `test/setup.ts` points HOME at a per-file temp dir, but CASES_DIR is
|
||||
* `join(homedir(), 'codeman-cases')` and `os.homedir()` ignores the HOME
|
||||
* override on some platforms/Node builds — so cleanup below goes through
|
||||
* `safeRmHomeTree`, which refuses to delete anything outside the temp HOME.
|
||||
* `test/setup.ts` points HOME at a per-file temp dir, so CASES_DIR
|
||||
* (`join(homedir(), 'codeman-cases')`) resolves inside the fixture; cleanup
|
||||
* below still goes through `safeRmHomeTree`, which refuses to delete anything
|
||||
* outside the temp HOME, so a wrong anchor can never reach the real tree.
|
||||
*
|
||||
* Port: N/A (app.inject).
|
||||
*/
|
||||
|
||||
@@ -25,9 +25,10 @@ import { registerVoiceRoutes, _resetVoiceStreamCountForTesting } from '../../src
|
||||
import { MAX_CONCURRENT_STREAMS } from '../../src/config/voice.js';
|
||||
|
||||
// SAFETY (2026-08-29): anchor on the REDIRECTED test HOME (process.env.HOME,
|
||||
// which test/setup.ts points at a throwaway dir) instead of os.homedir().
|
||||
// On some Linux builds os.homedir() reads /etc/passwd and would resolve to the
|
||||
// REAL home, clobbering the user's ~/.claude/.credentials.json.
|
||||
// which test/setup.ts points at a throwaway dir). `os.homedir()` follows it too,
|
||||
// but this file writes and deletes `~/.claude/.credentials.json`, the one file
|
||||
// where a wrong anchor would sign the developer out of their own CLI, so it
|
||||
// fails loudly if setup.ts did not run rather than trusting any fallback.
|
||||
function testHome(): string {
|
||||
if (!process.env.HOME) throw new Error('process.env.HOME unset — test/setup.ts must run first');
|
||||
return process.env.HOME;
|
||||
|
||||
Reference in New Issue
Block a user