From f3ce2dbab508a0daf92b12c968a22a7398f387d0 Mon Sep 17 00:00:00 2001 From: 0xdhx Date: Sat, 8 Aug 2026 06:18:09 -0500 Subject: [PATCH] docs(#3156): name the isolation this helper does NOT provide Found by the pre-push adversarial review of this round, and worth recording in the code rather than only in the PR thread. installSpawnHome() creates one sandbox home per test-FILE process, not one per spawn, so two installer spawns in the same file share .gsd state. The containment claim is unaffected -- nothing reaches the developer's real home -- and it is strictly better than the status quo it replaces, which shared the real home and every byte of its state. But "contained" and "isolated from each other" are different properties, and only the first is claimed. --- tests/helpers.cjs | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/tests/helpers.cjs b/tests/helpers.cjs index 7e224d74a..bcd850161 100644 --- a/tests/helpers.cjs +++ b/tests/helpers.cjs @@ -930,6 +930,14 @@ function clearSessionEnv() { * * The sandbox home is per-process and removed on exit, so a caller gets * containment without having to own a lifecycle. + * + * SCOPE, stated because it is a real residual rather than an oversight: this is + * one home per test-FILE process, not one per spawn. Two installer spawns in the + * same file therefore share `.gsd` state, so a prior non-Claude install can be + * observed by a later spawn. That is strictly better than the status quo it + * replaces -- which shared the developer's REAL home, and all of its state -- + * and it closes the leak this helper exists for; it does not claim isolation + * BETWEEN spawns. A test needing that passes its own { HOME, USERPROFILE }. */ let installSpawnHomeDir = null; function installSpawnHome() {