forked from bchanot/claude
job4: install guard fail-closed
install-plugins.sh: mktemp failure building CFG_SNAPSHOT now aborts the install loudly (err + exit 1) instead of warning and continuing UNGUARDED — a failed guard used to mean CLAUDE.md/.claude/settings.json/ settings.json could be silently rewritten by graphify's installer for the rest of that run. Closes §3.4. Added T5 to lib/tests/curated-config-guard.test.sh: extracts the WIDER header block (GUARDED_CONFIGS through the closing `fi` — the fail-closed logic lives in the top-level if/else, outside restore_curated_configs(), so it needs its own awk range) in a subshell with a stubbed `mktemp` forced to fail; asserts exit 1 and a loud "mktemp failed" message. +2 assertions (4→6). Verified: bash -n clean, shellcheck clean (both files), full `make test` exit 0.
This commit is contained in:
+4
-1
@@ -62,7 +62,10 @@ if [ -n "$CFG_SNAPSHOT" ]; then
|
||||
done
|
||||
trap restore_curated_configs EXIT
|
||||
else
|
||||
warn "Config guard disabled (mktemp failed) — CLAUDE.md/settings may drift"
|
||||
err "Config guard could not be created (mktemp failed) — refusing to run" \
|
||||
"unguarded: CLAUDE.md/.claude/settings.json/settings.json could be" \
|
||||
"silently rewritten by the installer. Fix mktemp/TMPDIR and retry."
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Read pinned version from plugins.lock.json
|
||||
|
||||
Reference in New Issue
Block a user