Archived
Mutating each root-side control one at a time showed three that no test could see: a destination directory root does not own, a single user-owned asset inside an otherwise root-owned packaged directory, and an asset left group- or world-writable by its own mode. Deleting any of the three left the suite green, because the existing cases mark a whole tree untrusted and are caught by the directory check before the per-file one is reached. The harness already had the hook for the ownership pair: TEST_UNTRUSTED_SOURCE makes the stat shim report a chosen prefix as uid 1000, so those two only need it pointed at a destination directory and at a single file rather than at a whole tree. A mode has to be real, so that case stages a copy of the packaged tree the shim reports as root-owned and loosens one asset in it. The empty logo is refused by the destination size bound rather than the caller-side one, so that case pins the behaviour without isolating the check; the two bounds are exactly redundant. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_0115LngksSpXLD9NSXBEP3ki