test(ipc): close the raw-bridge ratchet's cast-and-alias bypass

Arm 2 was anchored on `window`, so a cast between `window` and `.electron` plus an
aliased receiver hid a live raw-bridge call from both arms: with such a module in the
tree the ratchet passed 3/3. Dropping the anchor reddens arm 2 on that spelling and
leaves the clean tree green.

Typing the global does not close the door on its own -- `Window.electron` is already
declared in src/preload/api-types.ts and the cast spelling still compiles.
This commit is contained in:
Brennan Benson
2026-08-29 20:12:33 -07:00
committed by Merge Sim
parent dcb01cd1c9
commit 2e68ea8c62
@@ -29,7 +29,12 @@ const IGNORED_DIRECTORIES = new Set([
/** Whitespace and newlines are legal between the receiver and the call, and one call site used them. */
const RAW_INVOKE = /ipcRenderer\s*\.\s*invoke\s*\(/
const RAW_BRIDGE = /window\s*\.\s*electron\s*\.\s*ipcRenderer/
/** Not anchored on `window`: a cast (`(window as unknown as { electron: … }).electron.ipcRenderer`)
* sits between `window` and `.electron`, and aliasing the receiver hides the call from RAW_INVOKE
* as well — so a `window`-anchored arm 2 passed with a live raw-bridge escape in the tree. Typing
* the global does not close that door: `Window.electron` IS declared (`src/preload/api-types.ts`),
* and the cast spelling still compiles. The lookbehind keeps `electronFoo.ipcRenderer` out. */
const RAW_BRIDGE = /(?<!\w)electron\s*\.\s*ipcRenderer/
/**
* Comments name this shape on purpose — the modules that consume the envelope explain where it