diff --git a/src/db/migrations/026_events_trace_id.sql b/src/db/migrations/026_events_trace_id.sql index 4b94af28f..2d6824d85 100644 --- a/src/db/migrations/026_events_trace_id.sql +++ b/src/db/migrations/026_events_trace_id.sql @@ -1,5 +1,5 @@ -- 026_events_trace_id.sql — Add trace_id and parent_event_id for distributed tracing (#859) ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS trace_id UUID; -ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS parent_event_id BIGINT REFERENCES genie_runtime_events(id); +ALTER TABLE genie_runtime_events ADD COLUMN IF NOT EXISTS parent_event_id BIGINT REFERENCES genie_runtime_events(id) ON DELETE SET NULL; CREATE INDEX IF NOT EXISTS idx_runtime_events_trace_id ON genie_runtime_events(trace_id) WHERE trace_id IS NOT NULL; diff --git a/src/term-commands/init.ts b/src/term-commands/init.ts index 2165b3f2e..60f728bb3 100644 --- a/src/term-commands/init.ts +++ b/src/term-commands/init.ts @@ -175,6 +175,12 @@ function resolveAgentsDir(wsRoot: string, dirOption?: string): string { /** genie init agent — scaffold agent directory */ async function initAgent(name: string, options: { dir?: string }): Promise { + // Guard against path traversal — name is CLI input and lands in join(baseDir, name) + if (!name || /[\/\\]/.test(name) || name === '.' || name === '..' || name.includes('..')) { + console.error('Error: Agent name must not contain path separators or traversal sequences.'); + process.exit(1); + } + const cwd = process.cwd(); const ws = findWorkspace(cwd); if (!ws) {