mirror of
https://github.com/stablyai/orca.git
synced 2026-09-30 08:03:12 +00:00
* chore(lint): upgrade oxlint to 1.71 and enable 7 new rules Upgrade oxlint 1.67.0 -> 1.71.0 (1.72 was blocked by the repo's 3-day minimum-release-age supply-chain guard; nothing here needs it). The bump is a no-op on the existing config. Enable 3 error rules (backlog autofixed to zero in this commit) and 4 warn rules (surface signal without gating CI): error (autofixed, behavior-preserving): - unicorn/prefer-node-protocol (~1531 sites: bare builtin -> node:) - typescript/no-import-type-side-effects (~36: all-inline-type -> import type) - unicorn/no-array-reverse (19: copy-then-reverse -> toReversed) warn (real signal, current fires are test-only/correct): - unicorn/no-array-fill-with-reference-type (aliasing footgun guard) - typescript/no-unsafe-function-type (bans bare Function type) - unicorn/prefer-array-flat-map (map().flat() -> flatMap()) - unicorn/prefer-regexp-test (.match() in bool ctx -> .test()) mobile/.oxlintrc.json extends root, so it inherits all 7; the autofix ran from root and covered mobile/ too. Verification (all green): oxlint 0 errors (root+mobile+aux configs), oxfmt clean, typecheck (node+cli+web), vitest 22795 passed / 0 failed, builds (electron-vite + web + cli) succeed. node: rewrites confirmed to skip embedded SSH/CLI string payloads (AST-only); all toReversed sites verified to operate on fresh copies or write-once locals. * chore(lint): bump mobile oxlint to 1.71 so inherited rules parse mobile/ is a standalone pnpm project pinning its own oxlint@1.67, which lacks unicorn/no-array-fill-with-reference-type (needs >=1.70). Since mobile/.oxlintrc.json extends the root config, mobile CI's 'cd mobile && oxlint' failed to parse the new rule. Bump mobile to match root (1.71). Verified in mobile/: oxlint 0 errors, oxfmt --check clean, tsc --noEmit pass, vitest 978 passed / 0 failed. Co-authored-by: Orca <help@stably.ai> --------- Co-authored-by: Orca <help@stably.ai>
109 lines
3.1 KiB
TypeScript
109 lines
3.1 KiB
TypeScript
import { exec, spawn } from 'node:child_process'
|
|
import { mkdtempSync, rmSync, writeFileSync } from 'node:fs'
|
|
import { tmpdir } from 'node:os'
|
|
import { join } from 'node:path'
|
|
import { beforeEach, describe, expect, it, vi } from 'vitest'
|
|
import type * as ChildProcess from 'node:child_process'
|
|
import {
|
|
createFakeChild,
|
|
createHandlers,
|
|
requestContext,
|
|
withPlatform
|
|
} from './agent-exec-handler-test-harness'
|
|
|
|
vi.mock('child_process', async (importOriginal) => {
|
|
const actual = await importOriginal<typeof ChildProcess>()
|
|
return {
|
|
...actual,
|
|
exec: vi.fn(),
|
|
spawn: vi.fn()
|
|
}
|
|
})
|
|
|
|
const spawnMock = vi.mocked(spawn)
|
|
const execMock = vi.mocked(exec)
|
|
|
|
describe('AgentExecHandler Windows command spawning', () => {
|
|
beforeEach(() => {
|
|
spawnMock.mockReset()
|
|
execMock.mockReset()
|
|
})
|
|
|
|
it('resolves bare Windows agent commands to batch shims before spawning', async () => {
|
|
const tempDir = mkdtempSync(join(tmpdir(), 'orca-agent-exec-'))
|
|
const originalComSpec = process.env.ComSpec
|
|
process.env.ComSpec = 'C:\\Windows\\System32\\cmd.exe'
|
|
try {
|
|
await withPlatform('win32', async () => {
|
|
const codexShim = join(tempDir, 'codex.cmd')
|
|
writeFileSync(codexShim, '@echo off\r\n')
|
|
const child = createFakeChild()
|
|
spawnMock.mockReturnValue(child as never)
|
|
const handlers = createHandlers()
|
|
|
|
const pending = handlers.get('agent.execNonInteractive')!(
|
|
{
|
|
binary: 'codex',
|
|
args: ['exec', '-s', 'read-only'],
|
|
cwd: 'C:\\repo',
|
|
stdin: 'PROMPT',
|
|
timeoutMs: 5_000,
|
|
env: { PATH: tempDir }
|
|
},
|
|
requestContext()
|
|
)
|
|
|
|
child.emit('close', 0)
|
|
|
|
await expect(pending).resolves.toMatchObject({
|
|
exitCode: 0,
|
|
timedOut: false
|
|
})
|
|
expect(spawnMock).toHaveBeenCalledWith(
|
|
'C:\\Windows\\System32\\cmd.exe',
|
|
['/d', '/s', '/c', `"${codexShim}" "exec" "-s" "read-only"`],
|
|
{
|
|
cwd: 'C:\\repo',
|
|
env: expect.objectContaining({ PATH: tempDir }),
|
|
stdio: ['pipe', 'pipe', 'pipe'],
|
|
windowsHide: true
|
|
}
|
|
)
|
|
})
|
|
} finally {
|
|
rmSync(tempDir, { recursive: true, force: true })
|
|
if (originalComSpec === undefined) {
|
|
delete process.env.ComSpec
|
|
} else {
|
|
process.env.ComSpec = originalComSpec
|
|
}
|
|
}
|
|
})
|
|
|
|
it('rejects unsafe args when routing Windows batch shims through cmd.exe', async () => {
|
|
await withPlatform('win32', async () => {
|
|
const handlers = createHandlers()
|
|
|
|
const result = await handlers.get('agent.execNonInteractive')!(
|
|
{
|
|
binary: 'C:\\tools\\agent.cmd',
|
|
args: ['hello & goodbye'],
|
|
cwd: 'C:\\repo',
|
|
stdin: null,
|
|
timeoutMs: 5_000
|
|
},
|
|
requestContext()
|
|
)
|
|
|
|
expect(result).toEqual({
|
|
stdout: '',
|
|
stderr: '',
|
|
exitCode: null,
|
|
timedOut: false,
|
|
spawnError: 'UNSAFE_WINDOWS_BATCH_ARGUMENTS'
|
|
})
|
|
expect(spawnMock).not.toHaveBeenCalled()
|
|
})
|
|
})
|
|
})
|