{"record":{"id":"bd8fabcb538e4f60","repo":"thedotmack/claude-mem","slug":"refusing-awareness-write-to-profile-md","errorCode":null,"errorMessage":"Refusing awareness write to profile.md","messagePattern":"Refusing awareness write to profile\\.md","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/services/integrations/GrokBotAwarenessPusher.ts","lineNumber":104,"sourceCode":"\nexport function awarenessLineBody(line: string): string {\n  const idx = line.indexOf(AWARENESS_TAG);\n  return idx >= 0 ? line.slice(idx).trim() : line.trim();\n}\n\nexport function grokBotAwarenessLogPath(agentDataRoot: string, agentId: string, now: Date = new Date()): string {\n  const yearMonth = now.toISOString().slice(0, 7);\n  return path.join(agentDataRoot, 'agents', agentId, 'memory', 'log', `${yearMonth}.md`);\n}\n\nfunction assertSafeAwarenessLogPath(agentDataRoot: string, agentId: string, logPath: string): void {\n  const expectedRoot = path.resolve(path.join(agentDataRoot, 'agents', agentId, 'memory', 'log'));\n  const resolved = path.resolve(logPath);\n  if (!resolved.startsWith(expectedRoot + path.sep) && resolved !== expectedRoot) {\n    throw new Error('Refusing awareness write outside agent memory/log');\n  }\n  if (path.basename(resolved) === 'profile.md') {\n    throw new Error('Refusing awareness write to profile.md');\n  }\n}\n\nexport function appendAwarenessLineAtomic(logPath: string, line: string): boolean {\n  const dir = path.dirname(logPath);\n  mkdirSync(dir, { recursive: true });\n\n  const existing = existsSync(logPath) ? readFileSync(logPath, 'utf8') : '';\n  const incomingBody = awarenessLineBody(line);\n  const alreadyPresent = existing\n    .split('\\n')\n    .some(existingLine => existingLine.trim() && awarenessLineBody(existingLine) === incomingBody);\n  if (alreadyPresent) {\n    return false;\n  }\n\n  const prefix = existing.length === 0 || existing.endsWith('\\n') ? existing : `${existing}\\n`;\n  const next = `${prefix}${line}\\n`;","sourceCodeStart":86,"sourceCodeEnd":122,"githubUrl":"https://github.com/thedotmack/claude-mem/blob/d8bc9755e74915e5c3b999181e10a67c889bce2a/src/services/integrations/GrokBotAwarenessPusher.ts#L86-L122","documentation":"Within assertSafeAwarenessLogPath(), any awareness write whose target basename is profile.md is rejected outright. profile.md is a protected agent artifact managed by a different subsystem; the awareness pusher (append-only log lines) must never overwrite it, so the guard throws unconditionally on that filename.","triggerScenarios":"notifyGrokBotAwareness() is given a logPath ending in profile.md — e.g. an awareness key mapped to 'profile', a shared filename constant reused across features, or a caller confusing the awareness log with the profile file.","commonSituations":"A routing map that sends both 'profile' and 'log' events through the awareness pusher; refactored constants where AWARENESS_LOG was accidentally set to profile.md; a caller intending to update the profile via the wrong API.","solutions":["Point the awareness write at the log file (e.g. awareness.md) instead of profile.md.","Use the dedicated profile-update API for profile content rather than the awareness pusher.","Add a caller-side guard: if (path.basename(logPath) === 'profile.md') skip or redirect the write."],"exampleFix":"// before\nconst logPath = path.join(agentDir, 'memory', 'log', 'profile.md');\n\n// after\nconst logPath = path.join(agentDir, 'memory', 'log', 'awareness.md');","handlingStrategy":"validation","validationCode":"import path from 'path';\nif (path.basename(logPath) === 'profile.md') {\n  throw new Error('profile.md is protected; use the profile API');\n}","typeGuard":null,"tryCatchPattern":"try {\n  notifyGrokBotAwareness(agentDataRoot, agentId, logPath, line);\n} catch (err) {\n  if (err instanceof Error && err.message.includes('profile.md')) {\n    // redirect to the profile-update flow instead of the awareness pusher\n  } else throw err;\n}","preventionTips":["Use a dedicated constant for the awareness log filename; never reuse the profile filename.","Centralize RESERVED_FILENAMES checks across all agent-writer helpers.","Send profile changes through the profile API, not append-style awareness writes."],"tags":["filesystem","protected-file","validation"],"backgroundTag":"path-traversal-blocked","analyzedSha":"d8bc9755e74915e5c3b999181e10a67c889bce2a","analyzedAt":"2026-09-17T16:40:26.182Z","contentChangedAt":"2026-09-17T16:40:26.182Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}