tests: use private temp dir for route scanner probe to prevent symlink clobbering - #379
tests: use private temp dir for route scanner probe to prevent symlink clobbering#379luvs01 wants to merge 9 commits into
Conversation
release: promote dev into main for v2.32.1
# Conflicts: # package.json
[WRONG BRANCH] merge dev into main for the v2.33.0 release
Promotes the dev integration line onto main. The resulting tree is byte-identical to origin/dev, including package.json at 2.34.0. The package.json conflict is resolved to dev's side, NOT to main's stale 2.33.0. Earlier promotions (lidge-jun#2553, lidge-jun#2507) kept the target's version so the release bump would land on its own "release: vX.Y.Z" commit. That is no longer legal: this very delta adds tests/release-version-line.test.ts, which fails when the in-tree version sits behind the highest release tag. With v2.34.0-preview.20260827 now published, 2.33.0 orders behind it, so a promotion carrying the stale line turns CI red on every shard that runs the suite. The consequence for the release step is that scripts/release.ts skips the bump (release.ts:568, currentVersion === version), so v2.34.0 gets tagged on this merge commit rather than on a separate release commit. The workflow creates the tag itself after publishing and validates expected-sha against the checked-out commit, so the tag still names exactly the audited tree.
[WRONG BRANCH] promote dev onto main for v2.34.0
[WRONG BRANCH] promote dev onto main for v2.35.0
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
✅ Deterministic PR hygiene checks passed. |
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: ASSERTIVE Plan: Team Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
✅ READY
Hygiene✅ Deterministic PR hygiene checks passed. |
|
Closing this personal-fork review path because lidge-jun#3323 carries the same patch and additionally includes the reviewed cleanup fix. |
Motivation
.tmp-scanner-probe.ts) with a plainwriteFileSync, which can follow a pre-planted workspace symlink and truncate an attacker-chosen target; this change removes that attack surface.Description
mkdtempSync(join(tmpdir(), "ocx-route-scanner-")), write it withwriteFileSync, and remove the whole temp directory withrmSync(..., { recursive: true, force: true }), and add the requirednode:fs/node:osimports totests/management-route-registry.test.ts.Testing
bun test tests/management-route-registry.test.ts(passed),bun run typecheck(passed), andbun run privacy:scan(passed), and validated the scanner assertion still fails loud when appropriate; a fullbun run testrun was not relied on here because unrelated existing suite failures/timeouts were observed when run end-to-end.Codex Task