Files
orca/src/relay/agent-exec-handler-windows.test.ts
NeilandOrca 46646d7ff1 chore(lint): upgrade oxlint to 1.71 + enable 7 new rules (autofixed backlog) (#6841)
* chore(lint): upgrade oxlint to 1.71 and enable 7 new rules

Upgrade oxlint 1.67.0 -> 1.71.0 (1.72 was blocked by the repo's 3-day
minimum-release-age supply-chain guard; nothing here needs it). The
bump is a no-op on the existing config.

Enable 3 error rules (backlog autofixed to zero in this commit) and
4 warn rules (surface signal without gating CI):

error (autofixed, behavior-preserving):
- unicorn/prefer-node-protocol        (~1531 sites: bare builtin -> node:)
- typescript/no-import-type-side-effects (~36: all-inline-type -> import type)
- unicorn/no-array-reverse            (19: copy-then-reverse -> toReversed)

warn (real signal, current fires are test-only/correct):
- unicorn/no-array-fill-with-reference-type  (aliasing footgun guard)
- typescript/no-unsafe-function-type         (bans bare Function type)
- unicorn/prefer-array-flat-map              (map().flat() -> flatMap())
- unicorn/prefer-regexp-test                 (.match() in bool ctx -> .test())

mobile/.oxlintrc.json extends root, so it inherits all 7; the autofix
ran from root and covered mobile/ too.

Verification (all green): oxlint 0 errors (root+mobile+aux configs),
oxfmt clean, typecheck (node+cli+web), vitest 22795 passed / 0 failed,
builds (electron-vite + web + cli) succeed. node: rewrites confirmed to
skip embedded SSH/CLI string payloads (AST-only); all toReversed sites
verified to operate on fresh copies or write-once locals.

* chore(lint): bump mobile oxlint to 1.71 so inherited rules parse

mobile/ is a standalone pnpm project pinning its own oxlint@1.67, which
lacks unicorn/no-array-fill-with-reference-type (needs >=1.70). Since
mobile/.oxlintrc.json extends the root config, mobile CI's 'cd mobile &&
oxlint' failed to parse the new rule. Bump mobile to match root (1.71).

Verified in mobile/: oxlint 0 errors, oxfmt --check clean, tsc --noEmit
pass, vitest 978 passed / 0 failed.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-06-29 22:38:29 -07:00

109 lines
3.1 KiB
TypeScript

import { exec, spawn } from 'node:child_process'
import { mkdtempSync, rmSync, writeFileSync } from 'node:fs'
import { tmpdir } from 'node:os'
import { join } from 'node:path'
import { beforeEach, describe, expect, it, vi } from 'vitest'
import type * as ChildProcess from 'node:child_process'
import {
createFakeChild,
createHandlers,
requestContext,
withPlatform
} from './agent-exec-handler-test-harness'
vi.mock('child_process', async (importOriginal) => {
const actual = await importOriginal<typeof ChildProcess>()
return {
...actual,
exec: vi.fn(),
spawn: vi.fn()
}
})
const spawnMock = vi.mocked(spawn)
const execMock = vi.mocked(exec)
describe('AgentExecHandler Windows command spawning', () => {
beforeEach(() => {
spawnMock.mockReset()
execMock.mockReset()
})
it('resolves bare Windows agent commands to batch shims before spawning', async () => {
const tempDir = mkdtempSync(join(tmpdir(), 'orca-agent-exec-'))
const originalComSpec = process.env.ComSpec
process.env.ComSpec = 'C:\\Windows\\System32\\cmd.exe'
try {
await withPlatform('win32', async () => {
const codexShim = join(tempDir, 'codex.cmd')
writeFileSync(codexShim, '@echo off\r\n')
const child = createFakeChild()
spawnMock.mockReturnValue(child as never)
const handlers = createHandlers()
const pending = handlers.get('agent.execNonInteractive')!(
{
binary: 'codex',
args: ['exec', '-s', 'read-only'],
cwd: 'C:\\repo',
stdin: 'PROMPT',
timeoutMs: 5_000,
env: { PATH: tempDir }
},
requestContext()
)
child.emit('close', 0)
await expect(pending).resolves.toMatchObject({
exitCode: 0,
timedOut: false
})
expect(spawnMock).toHaveBeenCalledWith(
'C:\\Windows\\System32\\cmd.exe',
['/d', '/s', '/c', `"${codexShim}" "exec" "-s" "read-only"`],
{
cwd: 'C:\\repo',
env: expect.objectContaining({ PATH: tempDir }),
stdio: ['pipe', 'pipe', 'pipe'],
windowsHide: true
}
)
})
} finally {
rmSync(tempDir, { recursive: true, force: true })
if (originalComSpec === undefined) {
delete process.env.ComSpec
} else {
process.env.ComSpec = originalComSpec
}
}
})
it('rejects unsafe args when routing Windows batch shims through cmd.exe', async () => {
await withPlatform('win32', async () => {
const handlers = createHandlers()
const result = await handlers.get('agent.execNonInteractive')!(
{
binary: 'C:\\tools\\agent.cmd',
args: ['hello & goodbye'],
cwd: 'C:\\repo',
stdin: null,
timeoutMs: 5_000
},
requestContext()
)
expect(result).toEqual({
stdout: '',
stderr: '',
exitCode: null,
timedOut: false,
spawnError: 'UNSAFE_WINDOWS_BATCH_ARGUMENTS'
})
expect(spawnMock).not.toHaveBeenCalled()
})
})
})