From da33dda26af87838e889efa124d04dbedde4d988 Mon Sep 17 00:00:00 2001 From: Merge Sim Date: Sun, 6 Sep 2026 01:40:00 -0700 Subject: [PATCH] fix(packaging): verify every emitted main file for bare runtime imports The packaged-main verifier read two fixed entry files, but rolldown hoists modules shared by two entries into out/main/chunks. jsonc-parser is reached only from a chunk today, so nothing verified it, and the agent-hooks entry the list names contributes no coverage at all. An import that migrates into a chunk would silently stop being checked -- the same blindness that let the missing Claude agent SDK ship. Scan every out/main/**/*.js entry in the asar instead, keeping the two required-file assertions as a build-integrity check. Measured against the shipped 1.4.198 app: 93 entries in 72ms, reporting the absent SDK and nothing else. Also tighten the specifier match with a (? { } }) + it('verifies bare imports that rolldown hoisted into a shared main chunk', async () => { + const resourcesDir = await mkdtemp(join(tmpdir(), 'orca-runtime-chunk-imports-')) + try { + await writeFile(join(resourcesDir, 'app.asar'), '', 'utf8') + + // The entry points themselves carry no specifier; only the shared chunk does. + const sources = new Map([ + ['out/main/index.js', ''], + ['out/main/agent-hooks/managed-agent-hook-controls.js', ''], + ['out/main/chunks/managed-agent-hook-controls-CWf8D-KR.js', 'require(`jsonc-parser`)'] + ]) + const asar = { + listPackage: () => [...sources.keys()].map((entry) => `/${entry}`), + extractFile: (_asarPath, internalPath) => Buffer.from(sources.get(internalPath), 'utf8') + } + + expect(() => verifyPackagedMainRuntimeDeps(resourcesDir, asar)).toThrow(/jsonc-parser/) + + await mkdir(join(resourcesDir, 'node_modules', 'jsonc-parser'), { recursive: true }) + expect(() => verifyPackagedMainRuntimeDeps(resourcesDir, asar)).not.toThrow() + } finally { + await rm(resourcesDir, { recursive: true, force: true }) + } + }) + + it('ignores member calls onto Orca methods that are themselves named require', async () => { + const resourcesDir = await mkdtemp(join(tmpdir(), 'orca-runtime-member-require-')) + try { + await writeFile(join(resourcesDir, 'app.asar'), '', 'utf8') + + // electron-sidecar-tab-registry and browser-execution-host-grant-registry both + // expose require(key); a literal key must never read as a packaged specifier. + const sources = new Map([ + ['out/main/index.js', 'registry.require("public-a");grants.require(`host-key`)'], + ['out/main/agent-hooks/managed-agent-hook-controls.js', 'state.import("android-sdk")'] + ]) + const asar = { + listPackage: () => [...sources.keys()].map((entry) => `/${entry}`), + extractFile: (_asarPath, internalPath) => Buffer.from(sources.get(internalPath), 'utf8') + } + + expect(() => verifyPackagedMainRuntimeDeps(resourcesDir, asar)).not.toThrow() + } finally { + await rm(resourcesDir, { recursive: true, force: true }) + } + }) + it('normalizes host-specific asar entry separators', () => { expect(findAsarEntry(['\\out\\main\\index.js'], 'out/main/index.js')).toBe( '\\out\\main\\index.js'