mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-06 15:39:41 +02:00
docs(test): name the real reason the suite could reach ~/.codeman
#356 stopped a bare suite run from overwriting the production `remote-hosts.json` by pointing `CODEMAN_DATA_DIR` at a throwaway dir, and it gated every case-tree delete on the temp HOME. Both changes are right; the explanation written next to them is not. It says `os.homedir()` reads /etc/passwd rather than `$HOME` on Linux, which would mean the temp HOME in test/setup.ts never worked. It does: libuv checks the env var before the passwd entry (measured: `HOME=/tmp/x node -e 'console.log(os.homedir())'` prints /tmp/x), and CLAUDE.md's testing section relies on exactly that. What bypasses the temp HOME is `CODEMAN_DATA_DIR` itself. `getDataDir()` reads it as an absolute override before it looks at `homedir()`, so one inherited from the shell (a second instance, a beta run) sends the whole suite at the real data dir. That is the case setup.ts now closes, and #371 names the same variable from the other direction. The comments in setup.ts, the `safeRmHomeTree` helper, the voice-routes and case-clone tests now say that, and the containment gate is described as what it is: defense in depth. CLAUDE.md's testing paragraph gets the same note so the next reader does not chase a homedir() bug that does not exist. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Qg6bcATm1pNNY4kQWGwzgu
This commit is contained in:
+9
-8
@@ -34,14 +34,15 @@ process.env.HOME = testHome;
|
||||
process.env.USERPROFILE = testHome;
|
||||
process.env.VITEST = 'true';
|
||||
|
||||
// SAFETY: `getDataDir()` resolves via `homedir()` → `~/.codeman<INSTANCE_SUFFIX>`.
|
||||
// Overriding HOME above is NOT enough: on Linux `os.homedir()` reads /etc/passwd,
|
||||
// not $HOME, so without this a route test that writes `remote-hosts.json` (or
|
||||
// any state file) into `getDataDir()` silently clobbers the PRODUCTION
|
||||
// `~/.codeman` tree (found 2026-08-29: `session-routes-workspace-hooks.test.ts`
|
||||
// overwrote prod `remote-hosts.json` with an `h1/box/10.0.0.5` fixture during a
|
||||
// bare full-suite run, wiping every user-defined remote host and emptying the
|
||||
// launch case dropdown). Point every test at a throwaway data dir instead.
|
||||
// SAFETY: `getDataDir()` is `process.env.CODEMAN_DATA_DIR || join(homedir(), '.codeman<suffix>')`.
|
||||
// The temp HOME above already redirects the second half (`os.homedir()` follows
|
||||
// `$HOME`; libuv checks the env var before the passwd entry), but the first half
|
||||
// is an ABSOLUTE override: a `CODEMAN_DATA_DIR` inherited from the shell (a
|
||||
// second instance, a beta run) bypasses the temp HOME entirely, and a bare suite
|
||||
// run then reads and writes the REAL data dir (found 2026-08-29:
|
||||
// `session-routes-workspace-hooks.test.ts` overwrote the production
|
||||
// `remote-hosts.json` with an `h1/box/10.0.0.5` fixture, wiping every user-defined
|
||||
// remote host and emptying the launch case dropdown). Point it at a throwaway dir.
|
||||
process.env.CODEMAN_DATA_DIR = testDataDir;
|
||||
|
||||
delete process.env.CODEMAN_PASSWORD;
|
||||
|
||||
Reference in New Issue
Block a user