test(setup): one answer for CODEMAN_DATA_DIR, the strip from #371

#356 and #371 fixed the same leak two ways. #356 pointed CODEMAN_DATA_DIR at a
second throwaway directory and cleaned it up in afterAll and on exit; #371
deletes the variable along with CODEMAN_INSTANCE and CODEMAN_TMUX_SOCKET, so
`getDataDir()` falls back to `homedir()`, which the temp HOME already redirects.
Merged as they were, setup.ts set the variable and deleted it a few lines
later, and the second directory was created for nothing.

The strip wins: same protection, one tree to clean up, and the isolation test
#371 adds pins the list statically. The extra directory, its restore and its
two rmSync calls go, the vitest config `env` entries that set the same variable
go (they were documented as inert and would now be contradicted by the setup
file either way), the two test comments that described the old mechanism are
reworded, and CLAUDE.md's testing paragraph names the three stripped variables
and why CODEMAN_INSTANCE has to be stripped in the setup file rather than a hook.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Qg6bcATm1pNNY4kQWGwzgu
This commit is contained in:
Codeman maintainer
2026-09-04 14:20:11 +02:00
parent 65d19c725e
commit 72fd231d11
6 changed files with 15 additions and 40 deletions
+7 -19
View File
@@ -21,9 +21,7 @@ const originalHome = process.env.HOME;
const originalUserProfile = process.env.USERPROFILE;
const originalVitest = process.env.VITEST;
const originalPlaywrightBrowsersPath = process.env.PLAYWRIGHT_BROWSERS_PATH;
const originalCodemanDataDir = process.env.CODEMAN_DATA_DIR;
const testHome = mkdtempSync(join(tmpdir(), 'codeman-vitest-'));
const testDataDir = join(tmpdir(), `codeman-vitest-data-${process.pid}`);
if (originalPlaywrightBrowsersPath === undefined && originalHome) {
process.env.PLAYWRIGHT_BROWSERS_PATH =
@@ -37,17 +35,6 @@ process.env.HOME = testHome;
process.env.USERPROFILE = testHome;
process.env.VITEST = 'true';
// SAFETY: `getDataDir()` is `process.env.CODEMAN_DATA_DIR || join(homedir(), '.codeman<suffix>')`.
// The temp HOME above already redirects the second half (`os.homedir()` follows
// `$HOME`; libuv checks the env var before the passwd entry), but the first half
// is an ABSOLUTE override: a `CODEMAN_DATA_DIR` inherited from the shell (a
// second instance, a beta run) bypasses the temp HOME entirely, and a bare suite
// run then reads and writes the REAL data dir (found 2026-08-29:
// `session-routes-workspace-hooks.test.ts` overwrote the production
// `remote-hosts.json` with an `h1/box/10.0.0.5` fixture, wiping every user-defined
// remote host and emptying the launch case dropdown). Point it at a throwaway dir.
process.env.CODEMAN_DATA_DIR = testDataDir;
delete process.env.CODEMAN_PASSWORD;
delete process.env.CODEMAN_USERNAME;
// Gesture availability changes renderIndexHtml output (injects the
@@ -64,7 +51,13 @@ delete process.env.CODEMAN_GESTURE;
// `getDataDir()`, so it bypasses HOME entirely: a developer who exports it
// (or a shell left over from `codeman web -d`) has the suite reading and
// WRITING their real `state.json`, `users.json`, `intents.json` and
// `hook-secret` instead of a throwaway tree.
// `hook-secret` instead of a throwaway tree. Found live 2026-08-29 (#356):
// `session-routes-workspace-hooks.test.ts` overwrote a production
// `remote-hosts.json` with its `h1/box/10.0.0.5` fixture. `os.homedir()`
// itself DOES follow `$HOME`, so with this var gone `getDataDir()` lands
// under the temp HOME like everything else. (#356 first answered this by
// pointing the var at a second throwaway dir; deleting it is the same
// protection with one tree to clean up.)
// - CODEMAN_INSTANCE moves the data dir to `~/.codeman-<name>` and the socket to
// `codeman-<name>`. Inside the temp HOME that is not a data-loss risk, but it
// silently changes the paths tests assert on — and `scripts/run-beta.sh`
@@ -109,11 +102,7 @@ afterAll(async () => {
if (originalPlaywrightBrowsersPath === undefined) delete process.env.PLAYWRIGHT_BROWSERS_PATH;
else process.env.PLAYWRIGHT_BROWSERS_PATH = originalPlaywrightBrowsersPath;
if (originalCodemanDataDir === undefined) delete process.env.CODEMAN_DATA_DIR;
else process.env.CODEMAN_DATA_DIR = originalCodemanDataDir;
rmSync(testHome, { recursive: true, force: true });
rmSync(testDataDir, { recursive: true, force: true });
});
// afterAll never fires for a fully-skipped test file (no tests execute), which
@@ -121,5 +110,4 @@ afterAll(async () => {
// with force is a no-op when afterAll already removed it.
process.on('exit', () => {
rmSync(testHome, { recursive: true, force: true });
rmSync(testDataDir, { recursive: true, force: true });
});