fix(scripts): re-inject .mcp.json as a pointer, not resolved content
reinject_mcp_servers copied .mcp.json's mcpServers into the compiled Copilot
manifest verbatim via jq. apm's own path does not: collect_mcp_servers runs
_sanitize_mcp_servers(), which drops env/headers/authorization and redacts
secret-shaped keys, because copying them into a committed manifest exfiltrates
them into the distributed artefact. The re-injection was the only route around
that sanitizer, and it wrote to a tracked, marketplace-distributed file.
Both host schemas document mcpServers as "string or object -- config path or
inline definitions", so the pointer form is valid and carries no resolved
content. It also preserves the ${VAR} indirection the sanitizer strips.
Also in this pass:
- mktemp+mv left the manifest at 0600 while --check compared content only, so
a real sync silently demoted a mode the gate could not see
- --check --all exited 0 when the marketplace yielded zero plugins, including
on unparseable JSON: the one gate whose work list comes from a generated file
could be silenced by regenerating its own input
- sync_dir took an unguarded $target_dir despite a comment claiming otherwise
- basename '.'/'..' escaped $SCRATCH_ROOT and made bundle selection arbitrary
- path_manifest compared only the exec bit, so check and sync disagreed
- sync-marketplace-mirror.sh fell back to pwd outside a worktree and reported
no drift on a tree it never identified
Mode comparison is deliberately files-only: directory modes come from umask on
one side and checkout on the other and git tracks neither, so comparing them
reports the runner's umask rather than a property of the mirror.
Tests: 44 -> 67 and 15 -> 19 assertions, each verified to fail under the
mutation it exists to catch.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
This commit is contained in:
@@ -255,6 +255,50 @@ else
|
||||
fail "an inherited GIT_DIR/GIT_WORK_TREE redirected the sync outside the fixture"
|
||||
fi
|
||||
|
||||
# --- 13. Outside any git worktree, REPO_ROOT cannot be guessed: hard error ---
|
||||
# `git rev-parse --show-toplevel 2>/dev/null || pwd` used to fall back to $PWD.
|
||||
# Both of this script's exit-0 paths are "the two files agree" or "neither file
|
||||
# exists", so a REPO_ROOT that is not this repo reports "no drift" over a tree it
|
||||
# never inspected — run --check from an empty non-worktree directory and that was
|
||||
# the literal outcome. Case 2 above (a real worktree with no source file) still
|
||||
# exits 0; the difference is whether the tree was identified at all.
|
||||
#
|
||||
# GIT_CEILING_DIRECTORIES rather than trusting `mktemp -d` to land outside a
|
||||
# worktree: TMPDIR may itself sit inside one (the same hazard make_fixture's
|
||||
# header documents), in which case rev-parse would succeed and this case would
|
||||
# quietly test nothing. The ceiling stops git's upward walk at the fixture's
|
||||
# parent, and the precondition below asserts it actually did.
|
||||
echo ""
|
||||
echo "--- outside a git worktree, --check errors instead of guessing \$PWD ---"
|
||||
NOREPO_PARENT="$(mktemp -d)"; track "$NOREPO_PARENT"
|
||||
NOREPO_PARENT="$(cd "$NOREPO_PARENT" && pwd -P)"
|
||||
NOREPO="$NOREPO_PARENT/not-a-worktree"
|
||||
mkdir -p "$NOREPO"
|
||||
if (cd "$NOREPO" && env -u GIT_DIR -u GIT_WORK_TREE GIT_CEILING_DIRECTORIES="$NOREPO_PARENT" \
|
||||
git rev-parse --show-toplevel > /dev/null 2>&1); then
|
||||
fail "precondition: git rev-parse still resolves a worktree under the ceiling — this case would test nothing"
|
||||
else
|
||||
for MODE in "--check" ""; do
|
||||
RC13=0
|
||||
OUT13="$( (cd "$NOREPO" && env -u GIT_DIR -u GIT_WORK_TREE \
|
||||
GIT_CEILING_DIRECTORIES="$NOREPO_PARENT" bash "$SCRIPT" ${MODE:+"$MODE"}) 2>&1 )" || RC13=$?
|
||||
case "$RC13:$OUT13" in
|
||||
0:*)
|
||||
fail "'${MODE:-real sync}' exited 0 outside a git worktree — it reported on a tree it never identified" ;;
|
||||
*"not inside a git worktree"*)
|
||||
pass "'${MODE:-real sync}' errors with a not-a-worktree message instead of falling back to \$PWD" ;;
|
||||
*)
|
||||
fail "'${MODE:-real sync}' failed for an unexpected reason (rc=$RC13): $OUT13" ;;
|
||||
esac
|
||||
done
|
||||
# And it must not have written anything into the directory it refused to trust.
|
||||
if [[ ! -e "$NOREPO/.github" ]]; then
|
||||
pass "nothing is written into the unidentified directory"
|
||||
else
|
||||
fail "the script created files under a directory it could not identify as the repo root"
|
||||
fi
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "Results: $PASS passed, $FAIL failed"
|
||||
[[ $FAIL -eq 0 ]]
|
||||
|
||||
Reference in New Issue
Block a user