* fix(#131): pass explicit HOME and npm cache to before() npm invocations
npm reads $HOME/.npmrc (user config) and writes to $HOME/.npm (default
cache dir) unless overridden. On Docker hosts the running user's HOME
may be uninitialized, unwritable, or contain stale state from prior
runs — any of which causes `npm pack` / `npm install -g` in the
before() hook to fail with EACCES, cancelling all 6 subtests (A–F).
Fix: allocate a fresh mkdtemp dir once per test process in helpers.cjs
and inject it as HOME, npm_config_cache, and npm_config_userconfig for
every runNpm() call. A process.on('exit') handler removes the dir on
teardown. The caller-supplied env option (if any) is merged on top of
the isolated env so explicit overrides still win.
TDD: tests/bug-131-release-tarball-smoke-explicit-home.test.cjs
- Test 1: runNpm succeeds when process HOME is chmod-0500 (unwritable)
- Test 2: npm_config_cache resolves under tmpdir, not caller HOME
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(#131): extend HOME isolation to runSmoke spawnSync calls so A-F pass
Pass effectiveNpmEnv to the gsd-sdk --version and gsd-sdk query spawnSync
invocations inside runSmoke(), matching the isolation already applied to the
npm install step. Also add npmEnv: isolatedNpmEnv() to every runSmoke() call
in the install test so the full env isolation chain is in effect.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(#131): address CI feedback — prompt-injection comment, Windows USERPROFILE stub, macOS realpath
- Rephrase 'act as a poisoned HOME' comment to 'serve as a poisoned HOME'
to avoid triggering the prompt-injection scanner's act-as pattern
- Add paired process.env.USERPROFILE stub alongside process.env.HOME in
Test 1 inline script so Windows parity guard offender count stays at 8
- Fix macOS /var→/private/var symlink false-negative in Test 2 by resolving
the nearest existing ancestor with fs.realpathSync before the startsWith
comparison
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(#131): export isolatedNpmEnv from helpers.cjs (CI repro of missing symbol)
isolatedNpmEnv() was defined in tests/helpers.cjs but never committed —
the function body and the updated module.exports line were left as unstaged
local edits. CI checkouts saw the old module.exports (without isolatedNpmEnv),
causing TypeError: isolatedNpmEnv is not a function at the call site in
bug-131-release-tarball-smoke-explicit-home.test.cjs:178 and in
release-tarball-smoke.install.test.cjs wherever the function is destructured.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
* fix(#131): canonicalize macOS tmpdir in remaining startsWith assertions
Replace the ad-hoc try/catch realpathSync fallback chain in Test 2 and the
inline try/catch in Test 3 with a shared safeRealpath() helper that walks up
to the nearest existing ancestor before resolving, then reconstructs the
canonical path. This ensures /var→/private/var symlink expansion succeeds
even when the leaf (.npm cache dir) does not yet exist on macOS CI runners.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com>