Skip to content

fix(cloudrun): accept absolute targetPath outside MCP cwd - #1077

Merged
binggg merged 1 commit into
mainfrom
fix/cfdcf61a-cloudrun-absolute-path
Sep 28, 2026
Merged

binggg merged 1 commit into
mainfrom
fix/cfdcf61a-cloudrun-absolute-path

Conversation

@binggg

@binggg binggg commented Sep 23, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Absolute targetPath is accepted as-is; relative paths still cannot escape CWD via ../.
  • Root cause: the MCP process cwd is often an IDE home (~/.codex, ~/.workbuddy) while deploy/download targets the user project absolute path — a same-root prefix check incorrectly rejected valid deploys.
  • Adds cloudrun-path-validation.test.ts (4 cases) and richer pathOutsideCwd i18n guidance.

Test plan

  • vitest run src/tools/cloudrun-path-validation.test.ts — 4/4 pass
  • CI green on this PR

Made with Cursor

@binggg

binggg commented Sep 23, 2026

Copy link
Copy Markdown
Member Author

ATO cfdcf61a status

  • CI is green (build-and-publish + CodeQL + i18n + guards).
  • This PR re-lands the manageCloudRun absolute-targetPath false-reject fix (equivalent to 8bf9863d2).
  • Please merge when ready — ATO delivery gate requires human merge; agent will not self-merge.
  • Pending release version after merge: next bump from current mcp@2.34.6.
  • Lighthouse post-merge err_pct vs 2026-09-02 16.5% is blocked: tool_errors series gaps after 2026-09-03 (calls still present).

Absolute project paths were falsely rejected when the MCP process cwd
differed (e.g. ~/.codex vs the user project): a same-root prefix check
rejected valid deploys. Absolute paths now pass through; relative paths
still block ../ traversal.

Co-authored-by: Cursor <cursoragent@cursor.com>
@binggg
binggg force-pushed the fix/cfdcf61a-cloudrun-absolute-path branch from 7e026b6 to 764986a Compare September 23, 2026 07:41
@binggg
binggg merged commit b93027a into main Sep 28, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant