test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

test: anti-regression tests for tarball home directory mirroring - #2466

Closed
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression
Closed

test: anti-regression tests for tarball home directory mirroring#2466
AhmedTMM wants to merge 7 commits into
OpenRouterLabs:mainfrom
AhmedTMM:test/tarball-mirror-regression

Conversation

@AhmedTMM

Copy link
Copy Markdown
Collaborator

Summary

  • Adds the /root/$HOME/ mirroring step in agent-tarball.ts for non-root SSH users (GCP, AWS Lightsail)
  • Adds 4 anti-regression tests in a describe("non-root home directory mirroring") block:
    1. Mirrors dotfiles from /root/ to $HOME for non-root users
    2. Mirrors the .spawn-tarball marker file
    3. Returns true even when mirror step fails (non-fatal)
    4. Guards mirror behind non-root check (id -u)

Test plan

  • bunx @biomejs/biome check — 0 errors
  • bun test src/__tests__/agent-tarball.test.ts — 11 pass
  • bun test — 1501 pass, 0 fail

🤖 Generated with Claude Code

AhmedTMMand others added 2 commits March 10, 2026 15:54
Tarballs are built with absolute /root/ paths, but GCP and AWS Lightsail
SSH as a regular user whose $HOME is /home/<user>/. After extraction,
binaries like `claude` end up at /root/.claude/local/bin/ but the
launchCmd looks in $HOME/.claude/local/bin/ — causing "command not found".
Add a post-extraction step that copies /root/ dotfiles to $HOME/ when
the SSH user isn't root. This fixes `spawn claude gcp` failing with
exit code 127 after tarball install.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Adds 4 tests in a "non-root home directory mirroring" describe block to
prevent regression of the /root/ → $HOME/ copy step for non-root SSH
users (GCP, AWS Lightsail).
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 9a8b908

Summary

This PR adds anti-regression tests for tarball home directory mirroring functionality. The changes are test-only additions that verify the security-critical mirroring behavior added to prevent path injection issues.

Security Analysis

agent-tarball.ts (lines 116-135):

  • ✅ Non-root check properly uses id -u comparison (shell-safe)
  • ✅ Loop variable _d is locally scoped and not user-controlled
  • ✅ Source paths use double-quotes with proper escaping: "/root/$_d"
  • ✅ Destination paths use double-quotes: "$HOME/$_d"
  • ✅ Error suppression 2>/dev/null || true prevents failure propagation (non-fatal by design)
  • ✅ No command injection vectors (all paths are literal or shell-safe variables)
  • ✅ Hardcoded directory list (no user input): .claude, .local, .npm-global, .cargo, .opencode, .hermes, .bun

agent-tarball.test.ts (lines 172-224):

  • ✅ New test suite verifies the mirroring behavior
  • ✅ Tests check for proper non-root guard (id -u)
  • ✅ Tests verify hardcoded directory list
  • ✅ Tests verify non-fatal failure mode (line 205-213)
  • ✅ No security regressions introduced

Tests

  • bun test: ✅ PASS (11/11 tests)
  • biome lint: ✅ PASS (0 errors, 114 files)
  • bash -n: N/A (no shell script changes)
  • curl|bash: N/A (no shell script changes)
  • macOS compat: N/A (no shell script changes)

Findings

No security issues found. The code properly guards against:

  • Path traversal (hardcoded directory list)
  • Command injection (proper quoting, no user input)
  • Privilege escalation (non-root check before mirroring)

-- security/pr-reviewer

louisgvand others added 2 commits March 10, 2026 23:11
Files copied from /root/ retained root ownership, causing permission
errors when agents tried to write to their config dirs. Adds chown -R
after the cp -a step. Also adds a test to prevent regression.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
louisgv
louisgv previously approved these changes Mar 10, 2026
Comment threadpackages/cli/src/shared/agent-tarball.ts Outdated
…arball
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>

@louisgvlouisgv left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Security Review

Verdict: APPROVED
Commit: 4df5a7b

Summary

This PR adds anti-regression tests for tarball home directory mirroring and fixes ownership of mirrored files. The implementation properly addresses file ownership issues when tarballs are extracted as root but accessed by non-root users.

Security Findings

No security issues found.

The changes:

  • Add chown -R commands to fix ownership of mirrored dotfiles
  • Use safe command substitutions ($(id -u), $(id -g))
  • Properly guard operations with error suppression (2>/dev/null || true)
  • Execute only in non-root context (guarded by if [ "$(id -u)" != "0" ])
  • Use hardcoded directory list (no path traversal risk)

Tests

  • bun test: ✅ PASS (12 tests, 28 assertions)
  • Command injection: ✅ SAFE - Uses safe command substitutions
  • Path traversal: ✅ SAFE - Hardcoded directory list
  • Privilege escalation: ✅ SAFE - chown only works on user-owned files in non-root context
  • Error handling: ✅ SAFE - Non-fatal failures with proper guards

Code Quality

  • Follows project conventions (no try/catch, uses promise chaining)
  • Comprehensive test coverage for new functionality
  • Well-documented with inline comments

-- security/pr-reviewer

la14-1 pushed a commit that referenced this pull request Mar 11, 2026
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@la14-1

Copy link
Copy Markdown
Collaborator

Superseded by #2478 — same functionality (chown fix + tests) but uses the new asyncTryCatch Result helpers from #2477 instead of .then()/.catch() promise patterns.

@la14-1la14-1 closed this Mar 11, 2026
louisgv added a commit that referenced this pull request Mar 11, 2026
…2478)
Replace try/catch in agent-tarball.ts with asyncTryCatch Result helpers:
- Phase 3 (download/extract): asyncTryCatch → returns false on any failure
- Phase 4 (mirror): asyncTryCatch → non-fatal, logs warning on failure
Add chown ownership fix for non-root SSH users (GCP, AWS Lightsail):
files extracted as root need ownership corrected after mirroring.
Add 5 anti-regression tests for non-root home directory mirroring.
Supersedes #2466.
Co-authored-by: lab <6723574+louisgv@users.noreply.github.com>
Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@AhmedTMM
AhmedTMM deleted the test/tarball-mirror-regression branch April 7, 2026 00:42
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@AhmedTMM@la14-1@louisgv