From 2e68ea8c6227fe384cfa5d160d13ec6bd0bb4d30 Mon Sep 17 00:00:00 2001 From: Brennan Benson <79079362+brennanb2025@users.noreply.github.com> Date: Sat, 29 Aug 2026 12:41:40 -0700 Subject: [PATCH] test(ipc): close the raw-bridge ratchet's cast-and-alias bypass Arm 2 was anchored on `window`, so a cast between `window` and `.electron` plus an aliased receiver hid a live raw-bridge call from both arms: with such a module in the tree the ratchet passed 3/3. Dropping the anchor reddens arm 2 on that spelling and leaves the clean tree green. Typing the global does not close the door on its own -- `Window.electron` is already declared in src/preload/api-types.ts and the cast spelling still compiles. --- src/preload/ipc-invoke-boundary-ratchet.test.ts | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/src/preload/ipc-invoke-boundary-ratchet.test.ts b/src/preload/ipc-invoke-boundary-ratchet.test.ts index a27da0e74ae..bfe5d0fe38f 100644 --- a/src/preload/ipc-invoke-boundary-ratchet.test.ts +++ b/src/preload/ipc-invoke-boundary-ratchet.test.ts @@ -29,7 +29,12 @@ const IGNORED_DIRECTORIES = new Set([ /** Whitespace and newlines are legal between the receiver and the call, and one call site used them. */ const RAW_INVOKE = /ipcRenderer\s*\.\s*invoke\s*\(/ -const RAW_BRIDGE = /window\s*\.\s*electron\s*\.\s*ipcRenderer/ +/** Not anchored on `window`: a cast (`(window as unknown as { electron: … }).electron.ipcRenderer`) + * sits between `window` and `.electron`, and aliasing the receiver hides the call from RAW_INVOKE + * as well — so a `window`-anchored arm 2 passed with a live raw-bridge escape in the tree. Typing + * the global does not close that door: `Window.electron` IS declared (`src/preload/api-types.ts`), + * and the cast spelling still compiles. The lookbehind keeps `electronFoo.ipcRenderer` out. */ +const RAW_BRIDGE = /(?