From 4288753fdd8fe4a3fc4e578e3af7784946f2bdfc Mon Sep 17 00:00:00 2001 From: Felipe Rosa Date: Wed, 22 Jul 2026 19:17:31 -0300 Subject: [PATCH] test(install): pin exit-2 fixture temp-parent mode to 0700 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit On umask-0002 hosts mkdirSync creates the harness TMPDIR parent group-writable (775), which install.sh's validate_private_temp_root correctly rejects — the suite then failed with exit 127 instead of exercising the exit-2 contract. Pin the fixture dir to 0700 so the test is umask-independent. Co-Authored-By: Claude Fable 5 --- tests/integration/install-exit2-propagation.test.ts | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/tests/integration/install-exit2-propagation.test.ts b/tests/integration/install-exit2-propagation.test.ts index 70fdd3a25..439004ca1 100644 --- a/tests/integration/install-exit2-propagation.test.ts +++ b/tests/integration/install-exit2-propagation.test.ts @@ -115,7 +115,9 @@ function runHarness(): { status: number | null; output: string } { describe('install.sh delivered-not-activated exit-2 propagation (executed)', () => { test('propagates exit 2 with the result trailer, no all-green footer, lock released, idempotent rerun', () => { - mkdirSync(join(work, 'tmp'), { recursive: true }); + // install.sh's validate_private_temp_root rejects a group-writable temp parent, + // so pin the mode instead of inheriting the host umask (0002 hosts create 775). + mkdirSync(join(work, 'tmp'), { recursive: true, mode: 0o700 }); const first = runHarness(); // Delivered-not-activated is exit 2, NOT the die-1 failure path. @@ -151,7 +153,9 @@ describe('install.sh delivered-not-activated exit-2 propagation (executed)', () ].join('\n'), { mode: 0o755 }, ); - mkdirSync(join(work, 'tmp'), { recursive: true }); + // install.sh's validate_private_temp_root rejects a group-writable temp parent, + // so pin the mode instead of inheriting the host umask (0002 hosts create 775). + mkdirSync(join(work, 'tmp'), { recursive: true, mode: 0o700 }); const result = runHarness(); expect(result.status).toBe(1); expect(result.output).toContain('installation remains incomplete and retryable');