Skip to content

Move the ephemeral-source guard to SkillInstaller, the seam all links share - #128

Merged
JPDuchesne merged 1 commit into
mainfrom
jpd/skill-installer-ephemeral-guard
Aug 19, 2026
Merged

Move the ephemeral-source guard to SkillInstaller, the seam all links share#128
JPDuchesne merged 1 commit into
mainfrom
jpd/skill-installer-ephemeral-guard

Conversation

@JPDuchesne

Copy link
Copy Markdown
Contributor

Summary

  • Live incident, caught today: the plans#40 integration ran dev from a temp clone (tmp-integration/dev inside the ai-flow build workspace), SHIPPED_SKILLS_DIR resolved relative to that running dev, and the machine-global ~/.cursor/skills/ai-flow and ~/.cursor/skills/capture-learning symlinks were re-pointed into the build workspace — dangling once it was purged. Exactly the class the org's harness-env-scrub invariant names: a machine-persistent artifact minted from a purgeable path.
  • The tmpdir guard from GemSkillLinker: links minted under a sandboxed session point into ephemeral sandbox cache paths #90 lived only in GemSkillLinker, one of the three link jobs. It now lives in SkillInstaller#install — the seam all three share (shipped skills, org knowledge links, gem skills) — refusing any source that resolves under the temp dir, with the same /var vs /private/var realpath containment.
  • GemSkillLinker drops its duplicated guard and threads its tmpdir override into the installer it builds. Its prune semantics are unchanged: an ephemeral resolution still counts its gem as present, so it never deletes a durable link.

Test plan

  • New installer tests (written first, watched fail): refuses an ephemeral source and warns; leaves an existing link alone rather than re-pointing it at purgeable state; containment sees through symlinked temp roots
  • Existing installer and learnings tests threaded through the same tmpdir-override convention the linker tests already use (their fixtures live under the real temp dir)
  • Full suite: 909 tests, 0 failures; rubocop and srb tc clean

Made with Cursor

… share
The tmpdir guard from dev#90 lived only in GemSkillLinker, so the other
two link jobs could still mint machine-persistent symlinks to purgeable
state — and today one did: a plans-repo integration ran dev from a temp
clone, SHIPPED_SKILLS_DIR resolved relative to that clone, and the
machine-global ai-flow and capture-learning links were re-pointed into
the build workspace, dangling once it was purged.
SkillInstaller#install now refuses sources that resolve under the temp
dir (both /var and /private/var spellings), protecting shipped skills,
org knowledge links, and gem skills at the one seam they share.
GemSkillLinker drops its duplicated guard and threads its tmpdir
override through; its prune semantics (an ephemeral resolution never
deletes a durable link) are unchanged.
Co-authored-by: Cursor <cursoragent@cursor.com>
@codecov

codecovBot commented Aug 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@JPDuchesne
JPDuchesne merged commit 916fe89 into mainAug 19, 2026
5 checks passed
@JPDuchesne
JPDuchesne deleted the jpd/skill-installer-ephemeral-guard branch August 19, 2026 20:20
JPDuchesne added a commit that referenced this pull request Aug 19, 2026
916fe89 Merge pull request #128 from d3mlabs/jpd/skill-installer-ephemeral-guard
b9ea143 Move the ephemeral-source guard to SkillInstaller, the seam all links share
36803f7 Merge pull request #127 from d3mlabs/jpd/capture-learning-root-cause-gate
d6e081e Name the wide-angle goal, not one command: an exact git-log depth invites checkbox compliance
f876dbe capture-learning: gate workaround learnings on root cause, add wide angle
7249198 Merge pull request #123 from d3mlabs/ai/119-pr-b-typed-child-process-failure-taxonom
e71063a Merge pull request #126 from d3mlabs/jpd/hermetic-scrub-guard
f911e38 Make the scrub-list guard hermetic: construct the bundler launch it measures
6c398b8 ai-flow /build: let's resolve conflicts
cb68d60 Merge pull request #122 from d3mlabs/ai/118-pr-d-split-commandexecutor-into-a-dispat
4477c6b Update the manifest-loader contract note for the eager toolchain pass
3ad03c3 Constructor-inject CommandRunner; two messages replace the wait flag
2ac941a Route help through the command path; group and eager-load usage
a78ba14 Add the help builtin
c7ae57a Add Category trait to the Command hierarchy
2e05625 ai-flow /build: let's fix the fake classes, put them within the test class
a29b5e6 Merge main: sealed-module Command hierarchy, super() convention, and bin/test.rb runner
5d9c57b Merge pull request #121 from d3mlabs/ai/117-pr-a-close-the-sealed-command-hierarchy
b8ed631 Call super() in every initializer that derives from the Command hierarchy
5bcc76f Rework the seal: Command becomes a sealed module, BuiltinCommand the abstract open-edge class
5c68c85 Merge pull request #120 from d3mlabs/ai/116-pr-c-bin-test-rb-tee-suite-output-to-a-s
c62efc8 ai-flow /build: PR B: Typed child-process failure taxonomy in CommandRunner (CommandFailedError / CommandKilledError / CommandSpawnError) mapped to exit codes in Runner#exit_for
f09f845 ai-flow /build: PR D: Split CommandExecutor into a dispatching composite with injectable BuiltinExecutor / ProjectExecutor / OverriddenExecutor strategies (exec_into vs run_waiting)
0775515 ai-flow /build: PR A: Close the sealed Command hierarchy honestly — BuiltinBody interface, final BuiltinCommand holding a body, delete the sorbet-runtime ivar pokes, un-private CommandRepository
5a5fb41 ai-flow /build: PR C: bin/test.rb — tee suite output to a stable log artifact and pass file args through to rake TEST
4c89408 Merge pull request #115 from d3mlabs/ai/37-layer-the-dev-runner-application-service
04d461c Add the simplecov-cobertura gem RBI
81677f6 Upload cobertura to codecov instead of SimpleCov JSON
0a741f0 Cover the default factories, image credential providers, and nocov the sealed absurd arm
fe7c94e ai-flow /build: Layer the dev Runner (application service + boundary coercion)
d782b1a Merge pull request #107 from d3mlabs/ai/101-dev-clone-host-global-builtin-cloning-vi
f305ac9 ai-flow /build: codecov coverage missing
fac96ee ai-flow /build: dev clone: host-global builtin cloning via gh auth to the canonical $DEV_CD_ROOT path
d16b757 Merge pull request #100 from d3mlabs/jpd/99-pin-homebrew-installer
2ad614e Pin the Homebrew installer to a commit SHA (dev#99)
53e3616 Merge pull request #90 from d3mlabs/ai/89-gemskilllinker-links-minted-under-a-sand
95ee372 Merge pull request #97 from d3mlabs/ai/learn-promote-rbenv-libruby-rpath-hijack
f7edc33 chore: nudge origin-firing after ai-flow#57 (removal diffs skip green)
646f189 Merge pull request #98 from d3mlabs/jpd/proposal-checks-edited
50e913a proposal-checks: re-verify on PR body edits (ai-flow#54)
59a3146 ai-flow /learn: drop rbenv-libruby-rpath-hijack (promoted to the org tier)
f119987 Merge pull request #96 from d3mlabs/jpd/ai-flow-knowledge-repo
b0e7131 ai-flow config: opt dev into org-tier learning promotion
d17b2ff Merge pull request #95 from d3mlabs/jpd/94-self-defending-entrypoint
29b2e16 Test readability: one aliased scrub list, one property per test
f7197ac Drift guard: the unset list must cover what the running bundler exports
049bbc8 Probe the shim scrub with a stub ruby instead of a full dev command run
88fa953 bin/dev: scrub foreign bundler activation before Ruby boots
9cf868a Merge pull request #92 from d3mlabs/ai/60-plan-pull-mangles-files-with-an-empty-fr
6783469 Merge pull request #93 from d3mlabs/ai/learn-issue-60
991d46d ai-flow /build: capture learnings from the build pass
fe64507 ai-flow /build: Plan pull mangles files with an empty frontmatter block above the real one (double frontmatter)
d8db57d ai-flow /build: GemSkillLinker: links minted under a sandboxed session point into ephemeral sandbox cache paths
b4526ea Merge pull request #88 from d3mlabs/jpd/ast-transform-3.1.1
de9beaf Bump ast_transform to 3.1.1 and drop the heredoc-emission workaround
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@JPDuchesne