Repository navigation
fix(init,remove): refuse to write or delete through a symlinked project directory (PHARN-02) - #196
Merged
Merged
Conversation
…ct directory (PHARN-02) `safeJoin` is lexical and `cpSync`/`rmSync` follow symlinked ancestors, so a project whose `.claude/commands` or `pharn/` is a symlink had `init` write the install OUTSIDE the project (overwriting external files without a prompt), and `pharn remove a11y` with `pharn -> ../shared` deleted `../shared/pharn-review/a11y`. - `installCapabilities` pre-flights every destination the install manifest says it writes (plus `.claude/settings.json`) with `findSymlinkComponent` and refuses the whole install, naming each symlinked component, before the first write — the posture `update` and `add` already had. - `remove` refuses (exit 1) when a target dir's path crosses a symlinked component, for the whole picker selection before its confirm. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…egExp CodeQL flagged the incomplete escaping in the per-link RegExp. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this changes
safeJoinonly checks the path as a string, andcpSync/rmSyncfollow symlinked parent directories. As a result, when a project directory was a symlink pointing outside the project,initandremoveacted outside it. Reproduced cases:.claude/commandssymlinked:initwrote 11pharn-*.mdfiles outside the project, with no prompt.pharn -> ../team-shared/pharn:initoverwrote an external file and created 421 files outside the project.pharn -> ../shared:pharn remove a11ydeleted../shared/pharn-review/a11y, including a user file inside it.The fix:
init: before the first write,installCapabilitieschecks every file path the install will write (the install manifest plus.claude/settings.json) withfindSymlinkComponent. If any path goes through a symlink, it refuses the whole install and names each symlinked directory.updateandaddalready behaved this way.remove: it exits 1 without deleting anything when a target directory's path goes through a symlink. In the picker, the whole selection is checked before the confirm prompt.features/is a symlink used to get every file exceptfeatures/README.md. Its install is now refused as a whole.CLAUDE.mdupdated.Built with
/pharn-dev-ship; stage artifacts are in.dev/features/dest-symlink-guard-init-remove/. Results:no-regressionsPASSType of change
feat— new stack option, wizard step, or command capabilityfix— bug fixdocs— docs-only changechore/refactor— tooling or internal restructure, no behavior changeArea(s) touched
lib/install-capabilities | commands/remove | docs (README.md, CLAUDE.md)
Checklist
.js-extension import convention.tests/*.test.ts. 15 of the new cases fail on the old source.src/lib/validate.ts.Quality gates
npm run checkpasses locally (format, lint, typecheck, 1292/1292 tests; non-root user, node 22).npm run buildsucceeds (left to CI).npm run test:coveragepasses (left to CI).Notes for the reviewer
The
/pharn-dev-reviewfindings below are advisory and not addressed here:features/behavior change described above;A symlink created between the check and the write (a TOCTOU race) is still not covered, the same gap
updatehas.🤖 Generated with Claude Code
https://claude.ai/code/session_01TvcuVhk8hTeDskp5pAJhnc
Generated by Claude Code