fix: fail closed when no safe export destination exists; polish salvage edges
- _profile_export_directory(): when the managed store, the home-sibling store, AND the temp dir all resolve inside Git checkouts, raise a clear ValueError instead of warning and proceeding — a stderr warning would not stop a scripted export from staging a secret-bearing archive in a source tree, which is the exact #92457 incident class. All three callers already surface ValueError cleanly (CLI/TUI print Error: + exit, API returns 400). - .dockerignore: drop the /default.tar.gz line made redundant by the global *.tar.gz pattern this PR adds. - hermes profile export -o help text: stop advertising the old <name>.tar.gz cwd default. - Tests: cwd-in-unrelated-checkout topology (the second production shape from the blocking review) and the fail-closed path. Mutation-checked: both fail on the pre-fix helper.
This commit is contained in:
@@ -111,6 +111,5 @@ plans/
|
||||
/log.txt
|
||||
/sqlite_leak_fix.png
|
||||
/*.png.bak
|
||||
/default.tar.gz
|
||||
*.tar.gz
|
||||
*.tgz
|
||||
|
||||
Reference in New Issue
Block a user