Repository navigation
fix(update): normalize short Windows home paths for Scoop npm - #6494
Conversation
|
✅ Deterministic PR hygiene checks passed. |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe Scoop Node.js npm-invocation check now derives its persistent-bin path from the resolved ChangesScoop path validation
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to The Scoop npm lookup fix is ready to merge after normal checks; no actionable issue remains in the reviewed change. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change narrowly repairs Windows home-path alias handling while preserving executable containment, launch-directory exclusion, and rejection on resolution failure. No new caller, privilege path, or security bypass was identified. Runtime confirmation remains incomplete. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
Fix final Windows CI's Scoop npm lookup failure when USERPROFILE uses an 8.3 alias. The npm candidate and entry were physical paths, but the allowed persist-bin path retained the short home spelling and rejected the same directory.
Canonicalize only the configured home before appending the fixed Scoop persist path. Do not resolve the full persist path into an arbitrary redirected target; existing containment, cwd and fail-closed checks stay intact. This repairs Windows4 in final run37107354988; startup/Nous fixture findings are separate follow-ups.
Verification
Checklist
Maintainer integration
Owner lidge-jun elects integration into dev at
2b01f50f1f14ab06b87f8445122d38eca3b7fd8f. Exact-head pull_request CI 37109086281, attempt1, passed all requested jobs; independent security/native regression proof is recorded above. Final all-platform dispatch remains pending after the test-lifecycle follow-up. This is maintainer integration, not self-approval.