diff --git a/package.json b/package.json index 3454330..987d67c 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "tallynote", - "version": "1.1.16", + "version": "1.1.17", "private": true, "type": "module", "packageManager": "pnpm@9.0.6", diff --git a/scripts/test-installer.sh b/scripts/test-installer.sh index c7a2246..bde7f5e 100755 --- a/scripts/test-installer.sh +++ b/scripts/test-installer.sh @@ -253,7 +253,11 @@ ln -s "$wrapper_prefix/releases/1.0.0" "$wrapper_prefix/current" printf '%s\n' '#!/usr/bin/env bash' 'pwd -P > "$TALLYNOTE_WRAPPER_LOG"' 'printf "%s\n" "$@" >> "$TALLYNOTE_WRAPPER_LOG"' > "$wrapper_prefix/releases/1.0.0/runtime/bin/node" chmod 755 "$wrapper_prefix/releases/1.0.0/runtime/bin/node" printf '%s\n' cli > "$wrapper_prefix/releases/1.0.0/dist/server/cli/admin-init.js" -TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \ +# This fixture verifies release-relative execution and argument forwarding. +# Force the wrapper's non-root branch so the root CI runner does not need a +# real `tallynote` service account or a privileged runuser hand-off; that +# privilege boundary is validated by the production checks themselves. +env EUID=1000 TALLYNOTE_INSTALL_PREFIX="$wrapper_prefix" TALLYNOTE_CONFIG_DIR="$tmp/no-config" TALLYNOTE_WRAPPER_LOG="$tmp/wrapper.log" \ bash "$root/bin/tallynote-admin-init" --generate wrapper_expected_root=$(cd "$wrapper_prefix/releases/1.0.0" && pwd -P) grep -Fxq "$wrapper_expected_root" "$tmp/wrapper.log"