INNER CODE UNIT · TypeScript

isSafeCachePath

ZaxbyHub/opencode-swarm · src/cli/index.ts:144

export function isSafeCachePath(p: string): boolean {
	const resolved = path.resolve(p);
	const home = path.resolve(os.homedir());
	// 1. Catastrophic-path floor.
	if (resolved === '/' || resolved === home || resolved.length <= home.length) {
		return false;
	}
	// 2. Require ≥ 4 path components below the filesystem root. This rejects
	// pathological XDG_CACHE_HOME='/' (3 components) while accepting any
	// legitimate cache layout including non-default XDG_CACHE_HOME=/var/cache
	// and tmpdir paths — cross-platform (drive letter excluded, see helper).
	if (segmentDepthBelowRoot(resolved) < 4) {
		return false;
	}
	// 3. Must end in a known cache leaf: the two static literals, or an
	// anchored version-pinned shape `opencode-swarm@<semver>` (issue #2236
	// RC3 — a version-pinned cache dir like `opencode-swarm@7.143.1` was
	// previously refused even if it had been discovered). `resolved` here is

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…