From 5863351281b1449c8190938592a73bd629af9c65 Mon Sep 17 00:00:00 2001 From: 0xdhx Date: Tue, 28 Jul 2026 06:05:42 -0500 Subject: [PATCH] test(#2665): separator-safe containment in the regression assertion startsWith(ambientConfigDir) also matches a sibling like /ambient-live-config-2, so it can report a leak that did not happen. Use path.relative and check for '..' or an absolute result, the repo's usual shape. The readdirSync assertion already carried the test, so this is cosmetic. Addresses review finding: Nit 9. --- tests/profile-output.test.cjs | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/tests/profile-output.test.cjs b/tests/profile-output.test.cjs index 849b804a3..62ad61681 100644 --- a/tests/profile-output.test.cjs +++ b/tests/profile-output.test.cjs @@ -223,8 +223,13 @@ describe('write-profile command', () => { [], 'a call site that sandboxes HOME must not write into an ambient CLAUDE_CONFIG_DIR' ); + // Containment via path.relative, not startsWith: startsWith(ambientConfigDir) + // also matches a SIBLING like `/ambient-live-config-2`, so it can report + // a false leak. A path is inside the dir iff the relative path neither escapes + // with '..' nor is absolute. + const rel = path.relative(ambientConfigDir, out.profile_path); assert.ok( - !out.profile_path.startsWith(ambientConfigDir), + rel.startsWith('..') || path.isAbsolute(rel), `profile must not resolve under the ambient config dir, got: ${out.profile_path}` ); });