Skip to content

Installer must ignore agent UV/PIPX tool-path overrides and install to target user path #25

Description

@maxjustships

Bug

install.sh correctly sanitizes provider/config verification after #22, but still invokes uv tool install while inheriting agent process UV_TOOL_DIR / UV_TOOL_BIN_DIR (and potentially analogous pipx/XDG tool-location overrides).

Real dogfood during update:

  • Agent shell retained UV_TOOL_BIN_DIR=/tmp/.../home/.local/bin from an isolated test.
  • sh install.sh --json installed nomnom into that temporary bin, reported path repair, and the normal user shell had no nomnom command.
  • User installation was restored only by explicitly running uv with HOME=/home/max and a clean environment.

This violates #21's central contract: agent installation must create a user-level CLI in the target user's normal PATH, never in an agent/test/temporary tool bin.

Required fix

  1. Installer must not inherit tool-location overrides from the agent process:
    • UV_TOOL_DIR, UV_TOOL_BIN_DIR, PIPX_HOME, PIPX_BIN_DIR, XDG_BIN_HOME, and relevant XDG data/cache/state roots.
  2. Derive tool locations from the target user's clean login environment / HOME. Default safe paths are target-user XDG defaults (e.g. $HOME/.local/bin for executable), not agent env values.
  3. If supporting user custom tool locations, read them only from target user's sanitized login-shell configuration, never the outer agent env.
  4. Run uv tool install, uv tool dir --bin, pipx install, and post-install executable discovery under the same target-user sanitized environment.
  5. Add a regression test with poisoned outer env values pointing to temp paths. Assert:
    • installation command does not receive poisoned paths;
    • executable lands at target user's path;
    • normal user shell finds it;
    • user DB/cache remains untouched.
  6. Add a real temporary-home smoke with poisoned UV/PIPX/XDG outer env and validate output is a target-home executable.

Constraints

  • Preserve correct behavior for standard user installs and no-key/enhanced statuses.
  • No secrets/config leakage; no agent venv install.
  • No bundled food data.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions