From 3711a4f04fe4fd60934ec5f1474e820f1a20b05d Mon Sep 17 00:00:00 2001 From: Tom Boucher Date: Sun, 17 May 2026 00:42:19 -0400 Subject: [PATCH] fix(3663): replace ../../.. fallback with descriptive error per CLAUDE.md Both findInstallSourceRoot and findAgentsSourceRoot previously returned a path.join(__dirname, '..', '..', '..', ...) fallback when the walk-up loop found nothing. Replace with throw per CLAUDE.md "No Relative Path Traversal" policy: .. chains silently break on CWD changes; a throw with the failing __dirname in the message is an unambiguous diagnostic. The walk-up loop already uses path.dirname iteratively (no literal ..); only the dead-end fallback used the banned pattern. Co-Authored-By: Claude Sonnet 4.6 --- get-shit-done/bin/lib/runtime-artifact-layout.cjs | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/get-shit-done/bin/lib/runtime-artifact-layout.cjs b/get-shit-done/bin/lib/runtime-artifact-layout.cjs index 2aac59b93..ce62d827e 100644 --- a/get-shit-done/bin/lib/runtime-artifact-layout.cjs +++ b/get-shit-done/bin/lib/runtime-artifact-layout.cjs @@ -66,7 +66,7 @@ function findInstallSourceRoot(overrideRoot) { if (parent === dir) break; dir = parent; } - return path.join(__dirname, '..', '..', '..', 'commands', 'gsd'); + throw new Error(`findInstallSourceRoot: could not locate commands/gsd from ${__dirname}`); } /** @@ -85,7 +85,7 @@ function findAgentsSourceRoot(overrideRoot) { if (parent === dir) break; dir = parent; } - return null; + throw new Error(`findAgentsSourceRoot: could not locate agents/ from ${__dirname}`); } // ---------------------------------------------------------------------------