From a0daa319ca24357eec2c9ca527175b0213d31682 Mon Sep 17 00:00:00 2001 From: mptyl Date: Sat, 11 Jul 2026 21:26:47 +0200 Subject: [PATCH] fix(storage): contain logical corpus root --- harness/tests/test_portable_paths.py | 11 +++++++++++ harness/tht/paths.py | 2 +- 2 files changed, 12 insertions(+), 1 deletion(-) diff --git a/harness/tests/test_portable_paths.py b/harness/tests/test_portable_paths.py index 2f83fda3..2f60763c 100644 --- a/harness/tests/test_portable_paths.py +++ b/harness/tests/test_portable_paths.py @@ -79,6 +79,17 @@ def test_nested_root_symlink_escape_is_rejected(tmp_path): resolve_workspace_paths(cfg_path, cfg, tmp_path / "data") +def test_corpus_symlink_escape_is_rejected(tmp_path): + cfg_path = _write_config(tmp_path / "demo.yaml") + cfg = load_config(cfg_path) + workspace = tmp_path / "data/workspaces/demo" + workspace.mkdir(parents=True) + (workspace / "corpus").symlink_to(tmp_path / "private", target_is_directory=True) + + with pytest.raises(ConfigError, match="outside workspace root"): + resolve_workspace_paths(cfg_path, cfg, tmp_path / "data") + + def test_data_root_environment_activates_portable_paths(monkeypatch, tmp_path): cfg_path = _write_config(tmp_path / "demo.yaml") monkeypatch.setenv("THT_DATA_ROOT", str(tmp_path / "data")) diff --git a/harness/tht/paths.py b/harness/tht/paths.py index 51ea7b9d..d65249b4 100644 --- a/harness/tht/paths.py +++ b/harness/tht/paths.py @@ -50,5 +50,5 @@ def resolve_workspace_paths( sessions=_resolve_root(roots.sessions, workspace, "sessions"), artifacts=_resolve_root(roots.artifacts, workspace, "artifacts"), indexes=_resolve_root(roots.indexes, workspace, "indexes"), - corpus=(workspace / "corpus").resolve(), + corpus=_resolve_root(Path("corpus"), workspace, "corpus"), )