fix: harden system-install review findings

Require root-owned, non-group/other-writable pmg for --system install;
allow remove without that validation. Doctor checks npm resolution for
PATH precedence, uses ImpliesInterception instead of message matching,
and documents version-manager shadowing. Pass profile bin dir from the
shim manager and note that system config ignores per-user files.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Sahilb315
2026-07-13 22:20:57 +05:30
co-authored by Cursor
parent 0d0399f665
commit 1c9b16f1fa
14 changed files with 277 additions and 57 deletions
+2 -2
View File
@@ -15,7 +15,7 @@ func TestErrIfSystemInstallAllowed(t *testing.T) {
t.Cleanup(func() { setupGeteuid = orig })
setupGeteuid = func() int { return 0 }
err := errIfSystemInstallAllowed()
err := requireSystemInstallSupported()
if runtime.GOOS == "linux" {
assert.NoError(t, err)
} else {
@@ -26,7 +26,7 @@ func TestErrIfSystemInstallAllowed(t *testing.T) {
}
setupGeteuid = func() int { return 1000 }
err = errIfSystemInstallAllowed()
err = requireSystemInstallSupported()
require.Error(t, err)
usefulErr, ok := usefulerror.AsUsefulError(err)
require.True(t, ok)