fix(#2665): scrub config-location env vars in TEST_ENV_BASE (#3134)

* fix(#2665): scrub config-location env vars in TEST_ENV_BASE

TEST_ENV_BASE scrubbed 14 session-identity vars but omitted CLAUDE_CONFIG_DIR,
GSD_RUNTIME, and CODEX_HOME. The config-home resolver (runtime-homes.cts)
consults these env vars BEFORE the HOME-derived fallback, so an ambient
value won unconditionally over a sandboxed HOME. npm test wrote fixtures
into the developer's live config directory when any of these were set.
One leaked fixture was a registered skill (gsd-dev-preferences/SKILL.md)
carrying behavioral directives that loaded into subsequent sessions.

All three config-location vars are now blanked in TEST_ENV_BASE. Per-site
overrides still win (env is spread last in the child-env merge).

* chore(#2665): backfill changeset PR number 3134

* ci: retry shard timeout flake (#2665)

* ci: retry shard-2 timeout flake (#2665)

---------

Co-authored-by: sim <sim@local>
This commit is contained in:
Tom Boucher
2026-08-06 20:50:21 -04:00
committed by GitHub
parent 94bf32a2bb
commit 0ccc18dd3c
2 changed files with 12 additions and 0 deletions

View File

@@ -0,0 +1,5 @@
---
type: Fixed
pr: 3134
---
**`npm test` no longer writes into the developer's live config directory** — `TEST_ENV_BASE` scrubbed 14 session-identity vars but omitted `CLAUDE_CONFIG_DIR`, `GSD_RUNTIME`, and `CODEX_HOME` (config-location vars that decide WHERE a child writes). The config-home resolver consults these before `HOME`, so an ambient value won unconditionally over a sandboxed `HOME`. All three are now blanked. (#2665)

View File

@@ -25,6 +25,13 @@ const TEST_ENV_BASE = {
ZELLIJ_SESSION_NAME: '',
TTY: '',
SSH_TTY: '',
// #2665: blank config-LOCATION vars so npm test never writes into the developer's
// live config directory. The resolver consults these before HOME, so an ambient
// value wins unconditionally over a sandboxed HOME. Per-site overrides still win
// because env is spread last in the child-env merge.
CLAUDE_CONFIG_DIR: '',
GSD_RUNTIME: '',
CODEX_HOME: '',
};
/**