Repository navigation
fix(tunnel): keep tunnel captures out of git - #952
Open
tolgaergin wants to merge 4 commits into
Open
tolgaergin wants to merge 4 commits into
tolgaergin wants to merge 4 commits into
Conversation
Opening the capture database first adds `inspector.db*` to `.lpm/.gitignore`, so captures, which hold request headers and bodies, stay out of git wherever the project sits in a repository, without editing the project's own `.gitignore`. A linked `.lpm/.gitignore` is left alone. The capture warning names files git already tracks, which an ignore rule can't stop from being committed, and prints once: as a human warning, or on the log when that's hidden. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…bout captures The git call uses `-c core.fsmonitor=false -c safe.bareRepository=explicit`, so neither an archived project's fsmonitor nor a bare repository a cloned project carries can run code, and runs async with a 2 s timeout. The capture warning asks git which capture files it tracks or doesn't ignore, case-insensitively, says captures are kept out of git only when git ignores them all, and names tracked files quoted, with a `git rm --cached` command that works and the step to rotate what they held. `.lpm/.gitignore` lines are read as git reads them, a later negation needs the rule again, CRLF files keep their line endings, and a read-only file is left alone. A linked `.lpm` or capture file is refused, the database is created owner-only before SQLite opens it with no-follow, and existing capture files are made owner-only. Workflow tests check the warning appears once and names a tracked capture. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…irectly A linked sidecar now points at an existing outside file, so following it would change that file's mode or content. Leftover sidecars are made owner-only by the preparation step itself, before SQLite opens them. The corrupt-database workflow test matches the reworded advice. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
A repository tracking more capture files than the warning lists gets the capture pathspec in its `git rm --cached` command instead of every name. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Contributor
Author
Review round 1: ledgerTwo reviews of f2f0677 and lpm-dev/rust-client-docs#391 at a48dc35: correctness, and security. The security review found that the new git call could run code from a repository. Fixed in c650ea4 to 2edf4d1, and in lpm-dev/rust-client-docs#391 f4edbb6 to 616de8b. Security review
Correctness review
Verification
Round-2 reviews start now. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Keeps tunnel captures out of git automatically. Until now the CLI only told users to ignore them, and that advice is easy to miss.
.lpm/inspector.dbholds every captured request's and response's full headers and bodies, includingAuthorization,Cookieand*-Signatureheaders. The CLI warned users to add.lpm/inspector.db*to.gitignore. That warning had three gaps:--jsonandlpm dev --quiethid it;.lpm/inspector.db*rule in a repository's root.gitignoreis anchored to the root, so it misses a tunnel started in a subdirectory.One project committed its capture this way and kept it tracked for six months.
Changes
Capture files (
crates/lpm-inspect/src/db.rs)InspectorDb::openprepares the capture files before SQLite opens them:.lpmdirectory, or a linked or non-fileinspector.db,-wal,-shmor-journal, since a cloned repository could point them anywhere.SQLITE_OPEN_NOFOLLOW, on the directory's real path..lpm/.gitignorenext: it addsinspector.db*, which also covers the-wal,-shmand-journalfiles, unless git would already read the file as ignoring them./inspector.db*counts, and a later!rule for the database needs the rule added again..lpm/.gitignoreis left as it is and logged. The warning then says git doesn't ignore the captures..lpm/holds wherever the project sits in a repository, and leaves the project's own.gitignorealone.lpm tunnel,lpm dev --tunnel, andinspect,logandreplay.The capture warning (
crates/lpm-cli/src/commands/tunnel.rs)git ls-files -z -t --cached --others --exclude-standard -- ':(glob,icase).lpm/inspector.db*'..lpm/.gitignorekeeps the database out of git only when git ignores every capture file.git rm --cached -- '.lpm/inspector.db', and says to commit and to rotate any credentials they held.hardened_git_command(npmrc.rs) passes-c core.fsmonitor=false -c safe.bareRepository=explicit, and removesGIT_*variables. It's nowpub(crate), andlpm setup localgets the same flags.lpm=warnmatcheslpm_cli::tunnelby prefix, so the log copy printed alongside the human one.--json,--quiet).install/gitignore.rsnamed two helpers that no longer exist.--no-inspectstill saves captures. The docs say so ("disables the browser UI while capture continues"), andinspect/log/replayread them, so it's unchanged.Testing
lpm-inspect:.lpm/.gitignore, written once across reopens;.lpm/.gitignoreand its target are left alone;.lpmis refused;-walfile is refused, and its existing outside target keeps its mode and content;-wal,-shmand-journalfiles are made owner-only before SQLite opens them.lpm-cli, in fresh repositories:.lpm/added-sources.jsonisn't;core.fsmonitorprogram doesn't run;dev_tunnel):git rmcommand and no "kept out" claim;safe.bareRepository=explicit, whichls-filesrefuses in a bare repository anyway; the flag is defense in depth.The CI gate passes locally on 2edf4d1, with every workspace member rebuilt from this branch:
cargo clippy --workspace --all-targets --locked -- -D warnings,cargo fmt --checkandcargo build --workspace --locked;cargo test -p lpm-cli --bin lpm-rs -- --test-threads=1: 5,411 passed;runandcacheworkflow tests (172), and thedevanddev_tunnelworkflow tests (103), with the hermetic CLI.Docs: lpm-dev/rust-client-docs#391.
🤖 Generated with Claude Code