Skip to content

fix: default debug payload dir under os.TempDir (no cwd-relative writes) - #22

Open
ccf-lisa[bot] wants to merge 1 commit into
mainfrom
lisa/fix-debug-dir-tmp
Open

ccf-lisa[bot] wants to merge 1 commit into
mainfrom
lisa/fix-debug-dir-tmp

Conversation

@ccf-lisa

@ccf-lisa ccf-lisa Bot commented Oct 1, 2026

Copy link
Copy Markdown

Why

The CCF agent may run each plugin with its own per-plugin working directory, and the plugin contract is that plugins must not create files relative to their cwd. When debug payload dumping was enabled (debug_dump_payloads: true) without debug_payload_output_dir, this plugin defaulted to the relative debug-standardized-payloads directory, then MkdirAll'd it and wrote JSON files into it, so the files landed wherever the process happened to start.

What changed

  • Default dir: when dumping is enabled and no dir is configured, it now defaults to filepath.Join(os.TempDir(), "ccf-custodian-debug-payloads"). That path is absolute and honours $TMPDIR (otherwise /tmp). This follows the same pattern as the existing custodianCachePath().
  • Relative values still work: if an operator configures a relative debug_payload_output_dir, it is still used exactly as given, so existing configs don't break. Configure now logs a WARN saying the path resolves against the plugin process working directory.
  • Path is logged: the "Debug payload dumping enabled" log is raised from DEBUG to INFO and prints the resolved absolute path once, so operators can find the files.
  • README: the debug_payload_output_dir entry describes the new default and the relative-path behaviour.
  • cmd.Dir left unset on purpose: I did not set cmd.Dir for the spawned custodian process. Every path the plugin passes to it (-s output dir, --cache, policy.yaml) is already absolute. However, user policy content (for example value_from file references) may depend on relative paths resolving against the current cwd, so changing it would be a behaviour change outside this fix.

Tests

  • TestPluginConfigParse:
    • the default dir is absolute and equals os.TempDir()/ccf-custodian-debug-payloads (with TMPDIR overridden)
    • no dir is set when dumping is disabled
    • a relative dir is kept as configured
  • TestConfigureDebugPayloadOutputDir:
    • default: the dir is created under os.TempDir(), nothing is created in the cwd, no warning, and the resolved path is logged at INFO
    • explicit absolute: the dir is kept and created, with no warning
    • explicit relative: the dir is created under the cwd, a warning is logged, and the resolved absolute path is logged

go build ./... && go vet ./... && gofmt -l . && go test ./... all pass locally.

🤖 Generated with Claude Code

The CCF agent may run each plugin with its own working directory, so a
plugin must not create files relative to its cwd. When debug payload
dumping was enabled without debug_payload_output_dir, the plugin wrote
to the relative 'debug-standardized-payloads' directory.

Default to an absolute dir under os.TempDir instead. Relative values
configured by operators are still honoured but now log a warning, and
the resolved absolute path is logged once at INFO when dumping is on.
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: b1c4ffbd-c5af-4970-b9a6-ea8db465db03

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants