diff --git a/.changeset/nimble-badgers-munch.md b/.changeset/nimble-badgers-munch.md new file mode 100644 index 000000000..b8c9ea11d --- /dev/null +++ b/.changeset/nimble-badgers-munch.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 3134 +--- +**`npm test` no longer writes into the developer's live config directory** — `TEST_ENV_BASE` scrubbed 14 session-identity vars but omitted `CLAUDE_CONFIG_DIR`, `GSD_RUNTIME`, and `CODEX_HOME` (config-location vars that decide WHERE a child writes). The config-home resolver consults these before `HOME`, so an ambient value won unconditionally over a sandboxed `HOME`. All three are now blanked. (#2665) diff --git a/tests/helpers.cjs b/tests/helpers.cjs index 9560b8f9c..56496b866 100644 --- a/tests/helpers.cjs +++ b/tests/helpers.cjs @@ -25,6 +25,13 @@ const TEST_ENV_BASE = { ZELLIJ_SESSION_NAME: '', TTY: '', SSH_TTY: '', + // #2665: blank config-LOCATION vars so npm test never writes into the developer's + // live config directory. The resolver consults these before HOME, so an ambient + // value wins unconditionally over a sandboxed HOME. Per-site overrides still win + // because env is spread last in the child-env merge. + CLAUDE_CONFIG_DIR: '', + GSD_RUNTIME: '', + CODEX_HOME: '', }; /**