From 0ccc18dd3c5b3c1099199c62a42f3abc930a899f Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Thu, 6 Aug 2026 20:50:21 -0400 Subject: [PATCH] fix(#2665): scrub config-location env vars in TEST_ENV_BASE (#3134) * fix(#2665): scrub config-location env vars in TEST_ENV_BASE TEST_ENV_BASE scrubbed 14 session-identity vars but omitted CLAUDE_CONFIG_DIR, GSD_RUNTIME, and CODEX_HOME. The config-home resolver (runtime-homes.cts) consults these env vars BEFORE the HOME-derived fallback, so an ambient value won unconditionally over a sandboxed HOME. npm test wrote fixtures into the developer's live config directory when any of these were set. One leaked fixture was a registered skill (gsd-dev-preferences/SKILL.md) carrying behavioral directives that loaded into subsequent sessions. All three config-location vars are now blanked in TEST_ENV_BASE. Per-site overrides still win (env is spread last in the child-env merge). * chore(#2665): backfill changeset PR number 3134 * ci: retry shard timeout flake (#2665) * ci: retry shard-2 timeout flake (#2665) --------- Co-authored-by: sim --- .changeset/nimble-badgers-munch.md | 5 +++++ tests/helpers.cjs | 7 +++++++ 2 files changed, 12 insertions(+) create mode 100644 .changeset/nimble-badgers-munch.md diff --git a/.changeset/nimble-badgers-munch.md b/.changeset/nimble-badgers-munch.md new file mode 100644 index 000000000..b8c9ea11d --- /dev/null +++ b/.changeset/nimble-badgers-munch.md @@ -0,0 +1,5 @@ +--- +type: Fixed +pr: 3134 +--- +**`npm test` no longer writes into the developer's live config directory** — `TEST_ENV_BASE` scrubbed 14 session-identity vars but omitted `CLAUDE_CONFIG_DIR`, `GSD_RUNTIME`, and `CODEX_HOME` (config-location vars that decide WHERE a child writes). The config-home resolver consults these before `HOME`, so an ambient value won unconditionally over a sandboxed `HOME`. All three are now blanked. (#2665) diff --git a/tests/helpers.cjs b/tests/helpers.cjs index 9560b8f9c..56496b866 100644 --- a/tests/helpers.cjs +++ b/tests/helpers.cjs @@ -25,6 +25,13 @@ const TEST_ENV_BASE = { ZELLIJ_SESSION_NAME: '', TTY: '', SSH_TTY: '', + // #2665: blank config-LOCATION vars so npm test never writes into the developer's + // live config directory. The resolver consults these before HOME, so an ambient + // value wins unconditionally over a sandboxed HOME. Per-site overrides still win + // because env is spread last in the child-env merge. + CLAUDE_CONFIG_DIR: '', + GSD_RUNTIME: '', + CODEX_HOME: '', }; /**