From 17df89086ba3e79a098994fb95031f8379957ea8 Mon Sep 17 00:00:00 2001 From: "fcremo (Filippo Cremonese)" Date: Tue, 21 Apr 2026 17:54:40 +0200 Subject: [PATCH] fix: disable bunfig.toml and .env autoloading in compiled binary Compiled Bun binaries unconditionally load bunfig.toml and .env from the current working directory at runtime, before any application code runs. Since omp is a coding agent that runs from arbitrary project directories, it picks up foreign project configs -- most critically preload directives that cause immediate crashes, but also a potential security issue since preloads execute arbitrary code. Add --no-compile-autoload-bunfig and --no-compile-autoload-dotenv to the bun build --compile invocations (available since Bun v1.3.3). Note: source installs via 'bun install -g' are still affected because 'bun run' has no equivalent flag. That remains an open issue. --- packages/coding-agent/package.json | 2 +- scripts/ci-release-build-binaries.ts | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/packages/coding-agent/package.json b/packages/coding-agent/package.json index bdb3eba05..fd53eedac 100644 --- a/packages/coding-agent/package.json +++ b/packages/coding-agent/package.json @@ -31,7 +31,7 @@ "omp": "src/cli.ts" }, "scripts": { - "build": "bun --cwd=../stats scripts/generate-client-bundle.ts --generate && bun --cwd=../natives run embed:native && bun build --compile --define PI_COMPILED=true --external mupdf --root ../.. ./src/cli.ts --outfile dist/omp && bun --cwd=../natives run embed:native --reset && bun --cwd=../stats scripts/generate-client-bundle.ts --reset", + "build": "bun --cwd=../stats scripts/generate-client-bundle.ts --generate && bun --cwd=../natives run embed:native && bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --external mupdf --root ../.. ./src/cli.ts --outfile dist/omp && bun --cwd=../natives run embed:native --reset && bun --cwd=../stats scripts/generate-client-bundle.ts --reset", "check": "biome check . && bun run check:types", "check:types": "tsgo -p tsconfig.json --noEmit", "lint": "biome lint .", diff --git a/scripts/ci-release-build-binaries.ts b/scripts/ci-release-build-binaries.ts index 8eb2d961b..0e9bd42b2 100644 --- a/scripts/ci-release-build-binaries.ts +++ b/scripts/ci-release-build-binaries.ts @@ -67,11 +67,11 @@ async function buildBinary(target: BinaryTarget): Promise { console.log(`Building ${target.outfile}...`); await embedNative(target); if (isDryRun) { - console.log(`DRY RUN bun build --compile --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`); + console.log(`DRY RUN bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`); return; } - await $`bun build --compile --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`.cwd( + await $`bun build --compile --no-compile-autoload-bunfig --no-compile-autoload-dotenv --define PI_COMPILED=true --root . --external mupdf --target=${target.target} ${entrypoint} --outfile ${target.outfile}`.cwd( repoRoot, ); }