zara-coding: reject noncanonical repository/worktree evidence paths #185

Closed
opened 2026-09-08 02:03:10 +00:00 by nsaspy · 0 comments
Owner

Local #1 ownership/evidence slice. build_repository_evidence() currently requires absolute roots/worktree paths but accepts lexical ./.. components. That permits multiple symbolic identities for the same filesystem location and weakens exact repository/worktree ownership assertions. TDD: reject noncanonical absolute repository roots and worktree paths while preserving repository-relative changed-path rules. No cross-plugin composition or Core changes.

Local #1 ownership/evidence slice. `build_repository_evidence()` currently requires absolute roots/worktree paths but accepts lexical `.`/`..` components. That permits multiple symbolic identities for the same filesystem location and weakens exact repository/worktree ownership assertions. TDD: reject noncanonical absolute repository roots and worktree paths while preserving repository-relative changed-path rules. No cross-plugin composition or Core changes.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
nsaspy/zara-plugins#185
No description provided.