after moving all to cipher
This commit is contained in:
@@ -926,6 +926,33 @@ if (process.argv[1] && fileURLToPath(import.meta.url) === resolve(process.argv[1
|
||||
execSync(tarCmd, { stdio: 'pipe' });
|
||||
};
|
||||
|
||||
const taskDir = join('harbor-tasks', slug);
|
||||
|
||||
// tar records each file's mode as-is, and this container runs as root — so a
|
||||
// write-only file (Claude Code writes subagent session records --w-------) is
|
||||
// archived, not refused, and every later extraction of it is unreadable.
|
||||
// Normalize before packing; the catch below still repairs what only tar can see.
|
||||
try {
|
||||
const pre = normalizeTreePermissions(taskDir);
|
||||
if (didRepair(pre)) {
|
||||
log.info(
|
||||
{ ownerFixed: pre.ownerFixed.length, modeFixed: pre.modeFixed.length },
|
||||
'Normalized workspace permissions before packaging'
|
||||
);
|
||||
}
|
||||
if (pre.failures.length > 0) {
|
||||
log.warn(
|
||||
{ count: pre.failures.length, paths: pre.failures.slice(0, 5).map((f) => f.path) },
|
||||
`Could not normalize some paths. If the tarball has unreadable files, run:\n ${manualRepairHint(taskDir)}`
|
||||
);
|
||||
}
|
||||
} catch (repairErr) {
|
||||
log.warn(
|
||||
{ err: repairErr },
|
||||
`Permission normalization failed — packaging anyway. If the tarball has unreadable files, run:\n ${manualRepairHint(taskDir)}`
|
||||
);
|
||||
}
|
||||
|
||||
try {
|
||||
runTar();
|
||||
} catch (err) {
|
||||
@@ -952,7 +979,6 @@ if (process.argv[1] && fileURLToPath(import.meta.url) === resolve(process.argv[1
|
||||
}
|
||||
}
|
||||
|
||||
const taskDir = join('harbor-tasks', slug);
|
||||
// Guarded so a failed repair can't mask the real packaging error.
|
||||
let perms;
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user