@@ -48,6 +48,22 @@ test("workspace-relative paths are unrestricted", () => {
4848 expect ( r . isRestricted ( "src/index.ts" , true ) ) . toBe ( false ) ;
4949} ) ;
5050
51+ test ( "an empty-string root does not turn containment into allow-all" , ( ) => {
52+ // Regression for CL-6700: root + sep === sep when root is "", which every
53+ // absolute path starts with. A sensitive absolute path resolved against
54+ // a provider that yields "" roots must still be denied.
55+ const r = createPathRestriction ( cwd , ( ) => [ "" ] , home ) ;
56+ expect ( r . isRestricted ( "/etc/passwd" , false ) ) . toBe ( true ) ;
57+ expect ( r . isRestricted ( "/etc/passwd" , true ) ) . toBe ( true ) ;
58+ } ) ;
59+
60+ test ( "a root of exactly \"/\" is not the same bug: it is not an allow-all prefix" , ( ) => {
61+ // Documents the non-bug: "/" + sep is "//", which "/etc/passwd" does not
62+ // start with, so an unrelated absolute path stays outside the workspace.
63+ const r = createPathRestriction ( cwd , ( ) => [ "/" ] , home ) ;
64+ expect ( r . isRestricted ( "/etc/passwd" , false ) ) . toBe ( true ) ;
65+ } ) ;
66+
5167test ( "a directory sharing a string prefix with the workspace root is still restricted" , async ( ) => {
5268 // "<cwd>baz" shares a string prefix with cwd but is a distinct sibling
5369 // directory outside the workspace — the boundary check must not leak into
0 commit comments