From 210ead9246156a9b3b446329600bb692c1b9d298 Mon Sep 17 00:00:00 2001 From: huyplb Date: Sun, 27 Sep 2026 00:52:37 -0600 Subject: [PATCH 1/2] test: unit suite and security lint green on macOS again MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - vitest set FOXFLOW_FILES_DIR to realpathSync(tmpdir()). On macOS that is /private/var/folders/…, while the workflow suites build fixtures under tmpdir() = /var/folders/… (a symlink to it). The lexical half of the file-pipe containment check (c20efd3bb7) then refused every fixture: 41 tests in 10 files failed on every Mac. CI runs Linux, where /tmp is not a link, so it stayed green. The root is now tmpdir() as the suites spell it; the real-path half of the check resolves both sides itself, and the confinement tests (symlink escape, climbing out, prefix sibling) still pass. - Both ESLint configs ignore .claude/**. Agent worktrees are whole gitignored checkouts of the repo; the security gate linted them and failed on days-old copies of the code. Co-Authored-By: Claude Opus 5.5 --- eslint.config.js | 3 +++ eslint.security.config.js | 3 ++- vitest.config.ts | 11 ++++++++--- 3 files changed, 13 insertions(+), 4 deletions(-) diff --git a/eslint.config.js b/eslint.config.js index 6c0a1d42..19d94ae1 100644 --- a/eslint.config.js +++ b/eslint.config.js @@ -18,6 +18,9 @@ export default tseslint.config( '**/dist/**', '**/dist-bin/**', '**/node_modules/**', + // Agent worktrees are whole checkouts of this repo (gitignored). Linting + // them reports every finding twice, against code that may be days old. + '.claude/**', ], }, diff --git a/eslint.security.config.js b/eslint.security.config.js index 9018be92..12b431d1 100644 --- a/eslint.security.config.js +++ b/eslint.security.config.js @@ -40,7 +40,8 @@ export default tseslint.config( // does not run. Dead directives are the main config's job. { linterOptions: { reportUnusedDisableDirectives: 'off' } }, - { ignores: ['**/dist/**', '**/dist-bin/**', '**/node_modules/**'] }, + // `.claude/**`: agent worktrees are whole checkouts of this repo (gitignored). + { ignores: ['**/dist/**', '**/dist-bin/**', '**/node_modules/**', '.claude/**'] }, { files: ['**/*.ts', '**/*.tsx', '**/*.mts', '**/*.mjs'], diff --git a/vitest.config.ts b/vitest.config.ts index 19f18360..ccccc3d7 100644 --- a/vitest.config.ts +++ b/vitest.config.ts @@ -1,6 +1,5 @@ import { defaultExclude, defineConfig } from 'vitest/config'; import { fileURLToPath } from 'node:url'; -import { realpathSync } from 'node:fs'; import { tmpdir } from 'node:os'; const pkg = (p: string) => fileURLToPath(new URL(p, import.meta.url)); @@ -58,8 +57,14 @@ export default defineConfig({ // Workflow file pipes are confined to FOXFLOW_FILES_DIR. The suites // build their fixtures under the OS temp dir, so that is the root // here; the confinement itself is tested with its own roots. - // eslint-disable-next-line security/detect-non-literal-fs-filename -- the OS temp dir - env: { FOXFLOW_FILES_DIR: realpathSync(tmpdir()) }, + // + // `tmpdir()` as the suites spell it, not its real path. On macOS it + // is `/var/folders/…`, a symlink to `/private/var/folders/…`; with the + // resolved spelling as the root, every fixture path failed the + // lexical half of the containment check and 41 workflow tests failed + // on every Mac (CI runs Linux, where /tmp is not a link). The real-path + // half resolves both sides itself. + env: { FOXFLOW_FILES_DIR: tmpdir() }, testTimeout: 15_000, }, }, From 4a6ec00907b2b24cc92cc17ab77df409c1a491d6 Mon Sep 17 00:00:00 2001 From: huyplb Date: Sun, 27 Sep 2026 00:56:27 -0600 Subject: [PATCH 2/2] test(seed): make the advanced seed's portable type matrix lossless The gated CLI integration test (FOX_IT_DB=1) asserts that t_all_types is UNCHANGED from Postgres demo_c to MySQL demo_c. Since #290 the canonical type carries each engine's default fractional-seconds precision, so Postgres TIMESTAMP (6 digits) and MySQL DATETIME (0) are, correctly, a difference: migrating one onto the other truncates microseconds. The test has failed since then, unnoticed, because CI does not run it. The seed was what was wrong: a 'portable' matrix should be lossless. The MySQL and MariaDB c_ts columns are now DATETIME(6). Co-Authored-By: Claude Opus 5.5 --- scripts/seed/advanced/mariadb.sql | 4 ++-- scripts/seed/advanced/mysql.sql | 4 ++-- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/scripts/seed/advanced/mariadb.sql b/scripts/seed/advanced/mariadb.sql index ec5e3f10..7f644be3 100644 --- a/scripts/seed/advanced/mariadb.sql +++ b/scripts/seed/advanced/mariadb.sql @@ -66,7 +66,7 @@ CREATE TABLE t_all_types ( c_text TEXT, c_blob BLOB, c_date DATE, - c_ts DATETIME + c_ts DATETIME(6) ); -- [B4] Explicit column collation @@ -173,7 +173,7 @@ CREATE TABLE t_all_types ( c_varchar VARCHAR(200), c_text TEXT, c_date DATE, - c_ts DATETIME, + c_ts DATETIME(6), c_legacy VARCHAR(20) ); diff --git a/scripts/seed/advanced/mysql.sql b/scripts/seed/advanced/mysql.sql index 85694f57..1a3291e6 100644 --- a/scripts/seed/advanced/mysql.sql +++ b/scripts/seed/advanced/mysql.sql @@ -61,7 +61,7 @@ CREATE TABLE t_all_types ( c_text TEXT, c_blob BLOB, c_date DATE, - c_ts DATETIME + c_ts DATETIME(6) ); -- [B4] Explicit column collation (demo_d uses general_ci on name_ci) @@ -165,7 +165,7 @@ CREATE TABLE t_all_types ( c_varchar VARCHAR(200), c_text TEXT, c_date DATE, - c_ts DATETIME, + c_ts DATETIME(6), c_legacy VARCHAR(20) );