Repository navigation
Add NEXUS_CONFIG_DIR override, run security adversarial tests on Windows (#85, #83) - #87
Merged
AliRezaTaleghani merged 1 commit intoAug 27, 2026
Conversation
…n Windows Closes #85: nexus_core::Paths::resolve() now honors a NEXUS_CONFIG_DIR env override for config_dir, mirroring the existing NEXUS_CACHE_DIR override for data_dir. It's a plain env var read, not routed through the OS-specific directories crate, so it works identically on every platform - unlike the $HOME/$XDG_CONFIG_HOME redirection the adversarial security suite previously relied on, which directories' Windows backend (SHGetKnownFolderPath) ignores entirely. Closes #83 (the remaining part): crates/nexus-index/tests/path_security.rs now uses NEXUS_CONFIG_DIR directly in setup_fake_home/FakeHome instead of redirecting $HOME/$XDG_CONFIG_HOME, and the blanket #![cfg(unix)] gate at the top of the file is removed. Every non-symlink test now runs unconditionally, including on Windows; only the three symlink-creating tests keep an individual #[cfg(unix)]. Also updates docs/NexusContext-Wiki/Security-Model.md, ADR 0012, and docs/NexusContext-Wiki/Configuration.md to reflect the new override and the resolved Windows coverage gap. Claude-Session: https://claude.ai/code/session_01D6ND42psexN5cWTKewSpBG
AliRezaTaleghani
deleted the
config-dir-override-windows-security-tests
branch
August 27, 2026 15:26
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
NEXUS_CONFIG_DIRenv override tonexus_core::Paths::resolve(), mirroring the existingNEXUS_CACHE_DIRoverride fordata_dir. Plain env var read, nodirectories-crate/OS-API involvement, so it works identically cross-platform.crates/nexus-index/tests/path_security.rs'ssetup_fake_home/FakeHometo setNEXUS_CONFIG_DIRdirectly instead of redirecting$HOME/$XDG_CONFIG_HOME.#![cfg(unix)]gate at the top ofpath_security.rs. Only the three symlink-creating tests keep an individual#[cfg(unix)]:get_file_context_rejects_symlink_escaping_allowed_rootget_file_context_rejects_repo_path_itself_a_symlink_escaping_allowed_rootget_file_context_accepts_symlink_pointing_within_the_same_allowed_rootdocs/NexusContext-Wiki/Security-Model.md, ADR 0012, anddocs/NexusContext-Wiki/Configuration.md.Local verification
cargo build --workspace- cleancargo test --workspace- clean, includingpath_security.rs: 12 passed, 0 failed (Linux)cargo fmt --all -- --check- cleancargo clippy --workspace --all-targets -- -D warnings- cleanWindows CI verification (real job log, not a guess)
test-windowsjob (run 33087648098) actually ranpath_security.rsand passed all 9 non-symlink tests:9 = the file's 12 tests minus the 3
#[cfg(unix)]-gated symlink-creating tests, which correctly do not appear in the Windows binary at all (compiled out, not skipped) - matching the 12/12 passing locally on Linux. All 5 CI checks (clippy,fmt,test-linux,test-macos,test-windows) pass on this PR.Closes/Addresses
Closes #85andCloses #83: the harness exists, the rewire is done, and Windows CI evidence above genuinely confirms the non-symlink adversarial suite now runs and passes onwindows-latest. The three symlink-creating tests remain#[cfg(unix)]-only - that's the accepted, explicitly-documented remainder from #83's own success criteria ("if Windows symlink testing genuinely isn't feasible... document that explicitly as an accepted platform gap"), not an unresolved blocker: #83's own CI probe already confirmed Windows can create symlinks without elevation, so astd::os::windows::fs::symlink_file/symlink_dir-based Windows equivalent of those 3 tests is possible future work, just not implemented in this PR.Closes #85
Closes #83
https://claude.ai/code/session_01D6ND42psexN5cWTKewSpBG