fix: disable bunfig.toml and .env autoloading in compiled binary
Compiled Bun binaries unconditionally load bunfig.toml and .env from the current working directory at runtime, before any application code runs. Since omp is a coding agent that runs from arbitrary project directories, it picks up foreign project configs -- most critically preload directives that cause immediate crashes, but also a potential security issue since preloads execute arbitrary code. Add --no-compile-autoload-bunfig and --no-compile-autoload-dotenv to the bun build --compile invocations (available since Bun v1.3.3). Note: source installs via 'bun install -g' are still affected because 'bun run' has no equivalent flag. That remains an open issue.
This commit is contained in:
committed by
can1357
parent
d0c40b1d5d
commit
17df89086b
@@ -31,7 +31,7 @@
|
||||
"omp": "src/cli.ts"
|
||||
},
|
||||
"scripts": {
|
||||
"build": "bun --cwd=../stats scripts/generate-client-bundle.ts --generate && bun --cwd=../natives run embed:native && bun build --compile --define PI_COMPILED=true --external mupdf --root ../.. ./src/cli.ts --outfile dist/omp && bun --cwd=../natives run embed:native --reset && bun --cwd=../stats scripts/generate-client-bundle.ts --reset",
|
||||
"build": "bun --cwd=../stats scripts/generate-client-bundle.ts --generate && bun --cwd=../natives run embed:native && bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --external mupdf --root ../.. ./src/cli.ts --outfile dist/omp && bun --cwd=../natives run embed:native --reset && bun --cwd=../stats scripts/generate-client-bundle.ts --reset",
|
||||
"check": "biome check . && bun run check:types",
|
||||
"check:types": "tsgo -p tsconfig.json --noEmit",
|
||||
"lint": "biome lint .",
|
||||
|
||||
@@ -67,11 +67,11 @@ async function buildBinary(target: BinaryTarget): Promise<void> {
|
||||
console.log(`Building ${target.outfile}...`);
|
||||
await embedNative(target);
|
||||
if (isDryRun) {
|
||||
console.log(`DRY RUN bun build --compile --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`);
|
||||
console.log(`DRY RUN bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`);
|
||||
return;
|
||||
}
|
||||
|
||||
await $`bun build --compile --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`.cwd(
|
||||
await $`bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`.cwd(
|
||||
repoRoot,
|
||||
);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user