fix: default debug payload dir under os.TempDir (no cwd-relative writes) - #22
Open
ccf-lisa[bot] wants to merge 1 commit into
Open
ccf-lisa[bot] wants to merge 1 commit into
ccf-lisa[bot] wants to merge 1 commit into
Conversation
The CCF agent may run each plugin with its own working directory, so a plugin must not create files relative to its cwd. When debug payload dumping was enabled without debug_payload_output_dir, the plugin wrote to the relative 'debug-standardized-payloads' directory. Default to an absolute dir under os.TempDir instead. Relative values configured by operators are still honoured but now log a warning, and the resolved absolute path is logged once at INFO when dumping is on.
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Why
The CCF agent may run each plugin with its own per-plugin working directory, and the plugin contract is that plugins must not create files relative to their cwd. When debug payload dumping was enabled (
debug_dump_payloads: true) withoutdebug_payload_output_dir, this plugin defaulted to the relativedebug-standardized-payloadsdirectory, thenMkdirAll'd it and wrote JSON files into it, so the files landed wherever the process happened to start.What changed
filepath.Join(os.TempDir(), "ccf-custodian-debug-payloads"). That path is absolute and honours$TMPDIR(otherwise/tmp). This follows the same pattern as the existingcustodianCachePath().debug_payload_output_dir, it is still used exactly as given, so existing configs don't break.Configurenow logs aWARNsaying the path resolves against the plugin process working directory.debug_payload_output_direntry describes the new default and the relative-path behaviour.cmd.Dirleft unset on purpose: I did not setcmd.Dirfor the spawnedcustodianprocess. Every path the plugin passes to it (-soutput dir,--cache,policy.yaml) is already absolute. However, user policy content (for examplevalue_fromfile references) may depend on relative paths resolving against the current cwd, so changing it would be a behaviour change outside this fix.Tests
TestPluginConfigParse:os.TempDir()/ccf-custodian-debug-payloads(withTMPDIRoverridden)TestConfigureDebugPayloadOutputDir:os.TempDir(), nothing is created in the cwd, no warning, and the resolved path is logged at INFOgo build ./... && go vet ./... && gofmt -l . && go test ./...all pass locally.🤖 Generated with Claude Code