fix(3663): replace ../../.. fallback with descriptive error per CLAUDE.md

Both findInstallSourceRoot and findAgentsSourceRoot previously returned a
path.join(__dirname, '..', '..', '..', ...) fallback when the walk-up loop
found nothing. Replace with throw per CLAUDE.md "No Relative Path Traversal"
policy: ..  chains silently break on CWD changes; a throw with the failing
__dirname in the message is an unambiguous diagnostic.

The walk-up loop already uses path.dirname iteratively (no literal ..); only
the dead-end fallback used the banned pattern.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-05-17 00:42:19 -04:00
parent 8c16b1d338
commit 3711a4f04f

View File

@@ -66,7 +66,7 @@ function findInstallSourceRoot(overrideRoot) {
if (parent === dir) break;
dir = parent;
}
return path.join(__dirname, '..', '..', '..', 'commands', 'gsd');
throw new Error(`findInstallSourceRoot: could not locate commands/gsd from ${__dirname}`);
}
/**
@@ -85,7 +85,7 @@ function findAgentsSourceRoot(overrideRoot) {
if (parent === dir) break;
dir = parent;
}
return null;
throw new Error(`findAgentsSourceRoot: could not locate agents/ from ${__dirname}`);
}
// ---------------------------------------------------------------------------