mirror of https://github.com/garrytan/gstack.git
Merge 8489f33bd8 into 2be6c06ba8
This commit is contained in:
commit
8667e35165
|
|
@ -125,10 +125,21 @@ describe('hermetic wiring tripwire', () => {
|
||||||
expect(configDir.startsWith(runRoot + path.sep)).toBe(true);
|
expect(configDir.startsWith(runRoot + path.sep)).toBe(true);
|
||||||
expect(configDir.startsWith(operatorClaude)).toBe(false);
|
expect(configDir.startsWith(operatorClaude)).toBe(false);
|
||||||
const skillsDir = path.join(configDir, 'skills');
|
const skillsDir = path.join(configDir, 'skills');
|
||||||
|
const repoRootReal = fs.realpathSync(ROOT) + path.sep;
|
||||||
for (const entry of fs.readdirSync(skillsDir)) {
|
for (const entry of fs.readdirSync(skillsDir)) {
|
||||||
const target = fs.readlinkSync(path.join(skillsDir, entry, 'SKILL.md'));
|
const target = fs.readlinkSync(path.join(skillsDir, entry, 'SKILL.md'));
|
||||||
expect(target.startsWith(operatorClaude), `${entry}: symlink escapes to ${target}`).toBe(false);
|
const resolved = fs.realpathSync(target);
|
||||||
expect(fs.realpathSync(target).startsWith(fs.realpathSync(ROOT) + path.sep), `${entry}: symlink outside repo: ${target}`).toBe(true);
|
// Targets inside the live repo checkout are the blessed edge — exempt
|
||||||
|
// them BEFORE the operator-~/.claude ban. On the default global-git
|
||||||
|
// install the repo itself lives at ~/.claude/skills/gstack, so every
|
||||||
|
// CORRECT symlink carries the operatorClaude prefix and an unexempted
|
||||||
|
// ban can never pass (regression 2026-08-15: pristine v1.64.1.0 fails
|
||||||
|
// this test in any worktree under ~/.claude/skills/ and passes
|
||||||
|
// elsewhere — realpath both sides so a symlinked HOME can't dodge it).
|
||||||
|
if (!resolved.startsWith(repoRootReal)) {
|
||||||
|
expect(resolved.startsWith(operatorClaude), `${entry}: symlink escapes to ${target}`).toBe(false);
|
||||||
|
}
|
||||||
|
expect(resolved.startsWith(repoRootReal), `${entry}: symlink outside repo: ${target}`).toBe(true);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue