docs(#3156): name the isolation this helper does NOT provide

Found by the pre-push adversarial review of this round, and worth recording in
the code rather than only in the PR thread.

installSpawnHome() creates one sandbox home per test-FILE process, not one per
spawn, so two installer spawns in the same file share .gsd state. The
containment claim is unaffected -- nothing reaches the developer's real home --
and it is strictly better than the status quo it replaces, which shared the real
home and every byte of its state. But "contained" and "isolated from each other"
are different properties, and only the first is claimed.
This commit is contained in:
0xdhx
2026-08-08 06:18:09 -05:00
parent 6ac4d2e6ab
commit f3ce2dbab5

View File

@@ -930,6 +930,14 @@ function clearSessionEnv() {
*
* The sandbox home is per-process and removed on exit, so a caller gets
* containment without having to own a lifecycle.
*
* SCOPE, stated because it is a real residual rather than an oversight: this is
* one home per test-FILE process, not one per spawn. Two installer spawns in the
* same file therefore share `.gsd` state, so a prior non-Claude install can be
* observed by a later spawn. That is strictly better than the status quo it
* replaces -- which shared the developer's REAL home, and all of its state --
* and it closes the leak this helper exists for; it does not claim isolation
* BETWEEN spawns. A test needing that passes its own { HOME, USERPROFILE }.
*/
let installSpawnHomeDir = null;
function installSpawnHome() {