mirror of
https://github.com/stablyai/orca.git
synced 2026-10-08 00:02:38 +00:00
test: retire relay, preload and shared cases that re-prove an owned contract (#24007)
Audit sweep over `src/relay`, `src/preload` and `src/shared` (1,087 test files reviewed). 101 case declarations removed across 40 files, 6 test files deleted outright, 1,143 lines gone. Executed-case count falls further, since several removals were `it.each` tables. Dominant patterns, by frequency: - Self-comparisons that cannot fail: `expect(f(x)).toBe(f(x))`, `JSON.parse(JSON.stringify(literal))` deep-equalling the literal for a type with no codec, and `normalizeKeyToken(t) === normalizeKeyToken(t)` presented as proof of memoization. - Object literals asserting their own fields back, where the guarantee comes from the type annotation and the runtime assertion cannot fail. - Copied inventories: constants compared to their own initializers, and a function returning a copy of an exported constant checked against that constant's literal contents. - Duplicate invocations of a contract owned at a stronger boundary, including provider-local replays of a shared helper. - Table rows varying a field production never reads, so every row runs one path. - Names promising more than the input exercises: a "Windows launch" case in a module with no platform input, and a case whose named branch is never entered. Two production symbols go with them, each a test-only export whose sole caller was a deleted case: - `getGitHubProjectRefInputByteLength` — a one-line forward to `getClipboardTextByteLength`. The real bound (`GITHUB_PROJECT_REF_INPUT_MAX_BYTES`) and its guard stay. - `GRAB_STYLE_PROPERTIES` — an intended shared source of truth that nothing ever consulted; the property set is hand-enumerated at three independent sites. One case was deliberately restored and strengthened rather than dropped. The relay integration suite is the only place the real `SshChannelMultiplexer` is wired to `RelayDispatcher`, so it reaches transport behavior the handler suites cannot (they use `createMockDispatcher`). Its `fs.writeFile` roundtrip is the one case producing a void result, and `JSON.stringify` drops an absent `result` member — a shape no other surviving case exercises. Restored with an assertion pinning what the client actually observes: `null`, not `undefined`. That assertion failed on first run, so the fact was previously unasserted anywhere. One deletion was reverted mid-audit. A case asserting that optional fields stay invisible to "old attach and ready decoders" builds those decoders from `z.object` schemas declared in the test file, so it demonstrates zod's unknown-key stripping rather than anything shipped. It is nonetheless the only forward-compatibility coverage these envelopes have, and `reliability-gates.jsonc:6232` names it as evidence verbatim, so it stays. Note that `check-reliability-gates.mjs` passed both with and without it: the script resolves manifest paths and commands, and does not check that a named assertion still corresponds to a live case. Kept deliberately: everything a reliability gate cites as evidence; the three `registers all expected handlers` RPC manifests (a dropped registration is a silent wire break no type checker catches, and one carries the STA-4571 `pty.ackData` ratchet); the `child-process` direct-import ratchet; and prototype-spy cases paired with a `.repeat(10_000)` input, which assert a real memory bound rather than merely forbidding a technique. Verified: `pnpm test src/shared src/relay src/preload` (1073 files, 11996 passed, 1 pre-existing `it.fails`, 131 skipped), `pnpm tc` after clearing `.tsbuildinfo`, `check-reliability-gates.mjs` (140 gates), `check:code-quality:changed` (0 new findings).
This commit is contained in:
@@ -1,20 +0,0 @@
|
||||
import { readFile } from 'node:fs/promises'
|
||||
import { join } from 'node:path'
|
||||
import { pathToFileURL } from 'node:url'
|
||||
import { describe, expect, it } from 'vitest'
|
||||
import { pluginManifestSchema } from './plugin-manifest'
|
||||
|
||||
describe('hello Orca plugin fixture', () => {
|
||||
it('uses an ESM entry that remains loadable outside a type-module package', async () => {
|
||||
const root = join(process.cwd(), 'examples', 'plugins', 'hello-orca')
|
||||
const manifest = pluginManifestSchema.parse(
|
||||
JSON.parse(await readFile(join(root, 'orca-plugin.json'), 'utf8'))
|
||||
)
|
||||
|
||||
expect(manifest.main).toBe('main.mjs')
|
||||
const workerModule = (await import(pathToFileURL(join(root, manifest.main!)).href)) as {
|
||||
default?: unknown
|
||||
}
|
||||
expect(workerModule.default).toBeTypeOf('function')
|
||||
})
|
||||
})
|
||||
@@ -1,29 +0,0 @@
|
||||
import { readFile } from 'node:fs/promises'
|
||||
import { join } from 'node:path'
|
||||
import { Script } from 'node:vm'
|
||||
import { describe, expect, it } from 'vitest'
|
||||
|
||||
describe('hostile panel fixture', () => {
|
||||
it('is complete JavaScript and retains every containment probe', async () => {
|
||||
const html = await readFile(
|
||||
join(process.cwd(), 'examples', 'plugins', 'hostile-panel', 'panel.html'),
|
||||
'utf8'
|
||||
)
|
||||
const script = html.match(/<script>([\s\S]*?)<\/script>/)?.[1]
|
||||
|
||||
expect(script).toBeTruthy()
|
||||
if (!script) {
|
||||
throw new Error('hostile fixture script is missing')
|
||||
}
|
||||
expect(() => new Script(script)).not.toThrow()
|
||||
expect(html).toContain('self-navigation')
|
||||
expect(html).toContain('meta-refresh-navigation')
|
||||
expect(html).toContain('Navigation probes are opt-in')
|
||||
expect(html).toContain("window.name = ''")
|
||||
expect(html).toContain('oversized-message')
|
||||
expect(html).toContain('message-flood')
|
||||
expect(html).toContain("data.errorCode === 'rate_limited'")
|
||||
expect(html).toContain('busy-loop')
|
||||
expect(html.trimEnd()).toMatch(/<\/html>$/)
|
||||
})
|
||||
})
|
||||
@@ -1,19 +1,9 @@
|
||||
// @vitest-environment happy-dom
|
||||
|
||||
import { describe, expect, it } from 'vitest'
|
||||
import {
|
||||
buildPluginPanelShellHtml,
|
||||
PANEL_DESIGN_TOKEN_ALLOWLIST,
|
||||
PLUGIN_PANEL_CSP
|
||||
} from './plugin-panel-shell'
|
||||
import { buildPluginPanelShellHtml, PLUGIN_PANEL_CSP } from './plugin-panel-shell'
|
||||
|
||||
describe('buildPluginPanelShellHtml', () => {
|
||||
it('keeps destructive surface and foreground tokens paired', () => {
|
||||
expect(PANEL_DESIGN_TOKEN_ALLOWLIST).toEqual(
|
||||
expect.arrayContaining(['--destructive', '--destructive-foreground'])
|
||||
)
|
||||
})
|
||||
|
||||
it('places CSP and navigation guards before plugin content', () => {
|
||||
const html = buildPluginPanelShellHtml('<main id="plugin-content">Plugin</main>')
|
||||
const pluginOffset = html.indexOf('plugin-content')
|
||||
|
||||
Reference in New Issue
Block a user