Repository navigation
fix(core): restrict Dev database data dir and state files to owner - #1775
Conversation
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019x6FTsyUiZqVBAitcJQQkW
🦋 Changeset detectedLatest commit: 60e0cca The changes in this PR will be included in the next version bump. This PR includes changesets to release 9 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Review of #1775 (fixes #1659: Dev database file permissions)The change does what the issue asks. The data dir is 0700, and the state and lock files are 0600. The changeset is present and is a Requested changes
Suggestions (non-blocking)
Generated by Claude Code |
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019x6FTsyUiZqVBAitcJQQkW
|
Addressed the review:
Generated by Claude Code |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 1cfda78251
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
|
|
||
| const modeOf = (file: string) => statSync(file).mode & 0o777 | ||
|
|
||
| test('a fresh data directory is 0700 and the state and lock files are 0600', async () => { |
There was a problem hiding this comment.
Give the database-start tests the boot timeout
On this Linux checkout, pnpm exec vitest run src/db/state-file.test.ts src/db/dev-database.test.ts makes both new asynchronous permission tests exceed Vitest's 5-second default timeout—the starts took approximately 7.7 and 6.0 seconds—while the existing boot tests use BOOT_TIMEOUT = 60_000. Because the tests at lines 94 and 106 await a full startDevDatabase without that timeout, the core suite fails on slower CI or development hosts; pass BOOT_TIMEOUT to both tests and make the constant available before this describe block.
Useful? React with 👍 / 👎.
There was a problem hiding this comment.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_019x6FTsyUiZqVBAitcJQQkW
Coverage Report for Core Package Coverage (./packages/core)
File Coverage
|
||||||||||||||||||||||||||||||||||||||||||||
Coverage Report for UI Package Coverage (./packages/ui)
File CoverageNo changed files found. |
Coverage Report for CLI Package Coverage (./packages/cli)
File CoverageNo changed files found. |
Coverage Report for Auth Package Coverage (./packages/auth)
File CoverageNo changed files found. |
Coverage Report for Storage Package Coverage (./packages/storage)
File CoverageNo changed files found. |
Coverage Report for RAG Package Coverage (./packages/rag)
File CoverageNo changed files found. |
Coverage Report for Storage S3 Package Coverage (./packages/storage-s3)
File CoverageNo changed files found. |
Coverage Report for Storage Vercel Package Coverage (./packages/storage-vercel)
File CoverageNo changed files found. |
Summary
0700and tightened on boot if it already exists; a chmod failure throws an error naming the path0600win32@opensaas/stack-corePassword enforcement is out of scope (#1758).
Test plan
pnpm lint, typecheck passCloses #1659
🤖 Generated with Claude Code
https://claude.ai/code/session_019x6FTsyUiZqVBAitcJQQkW
Generated by Claude Code