- warn (don't silently ignore) when --runtime is an unknown runtime that canonicalizeRuntimeName rejects; the warning surfaces via warnings[] so a typo like --runtime cluade or a runtime known to runtime-homes but not the alias manifest (e.g. grok) no longer silently resolves to the persisted runtime's config dir on this diagnostic command [M-1] - add end-to-end CLI test for loop render-hooks --runtime (the exact command the bug report calls out as silently no-op'ing) [L-2] - add closed-vocabulary rejection test: crafted --runtime values (../../etc/passwd, __proto__, --config-dir, garbage) are rejected, warn, and fall through to the persisted runtime — pins the security-load-bearing contract [NIT-01] - add boundary tests: --config-dir wins over --runtime (precedence); missing --runtime value errors with USAGE [N-1] Both orthogonal reviews returned APPROVE with no Critical/High findings. Security review confirmed --runtime cannot coerce getGlobalConfigDir into an arbitrary path (closed-vocabulary Map lookup + registry hash-key gate) and does not expand the trust surface beyond the existing operator-controlled --config-dir flag.
89 KiB
89 KiB