job4: install guard fail-closed

install-plugins.sh: mktemp failure building CFG_SNAPSHOT now aborts
the install loudly (err + exit 1) instead of warning and continuing
UNGUARDED — a failed guard used to mean CLAUDE.md/.claude/settings.json/
settings.json could be silently rewritten by graphify's installer for
the rest of that run. Closes §3.4.

Added T5 to lib/tests/curated-config-guard.test.sh: extracts the
WIDER header block (GUARDED_CONFIGS through the closing `fi` — the
fail-closed logic lives in the top-level if/else, outside
restore_curated_configs(), so it needs its own awk range) in a
subshell with a stubbed `mktemp` forced to fail; asserts exit 1 and a
loud "mktemp failed" message. +2 assertions (4→6).

Verified: bash -n clean, shellcheck clean (both files), full `make
test` exit 0.
This commit is contained in:
Bastien Chanot
2026-07-06 21:52:10 +02:00
parent f2948df639
commit 999c7c475e
2 changed files with 32 additions and 3 deletions
+4 -1
View File
@@ -62,7 +62,10 @@ if [ -n "$CFG_SNAPSHOT" ]; then
done
trap restore_curated_configs EXIT
else
warn "Config guard disabled (mktemp failed) — CLAUDE.md/settings may drift"
err "Config guard could not be created (mktemp failed) — refusing to run" \
"unguarded: CLAUDE.md/.claude/settings.json/settings.json could be" \
"silently rewritten by the installer. Fix mktemp/TMPDIR and retry."
exit 1
fi
# Read pinned version from plugins.lock.json