mirror of
https://github.com/stablyai/orca.git
synced 2026-09-30 08:03:12 +00:00
* fix(codex): stop overwriting and deleting Codex files that were merely unreadable (STA-4737)
Three modules shared by the host and WSL Codex lanes decided a file was absent
from a read that had only failed, and then wrote over it or removed it.
- `codex-config-mirror`: `existsSync` on the RUNTIME config.toml returned false
for a locked file exactly as for an absent one, so the mirror took the
"seed a fresh runtime config" branch and replaced the user's config wholesale.
- `config-settings-promotion`: an unreadable ~/.codex/config.toml counted as
having no promoted settings, and the write path then rebuilt the user's
canonical Codex config from Orca's runtime copy.
- `codex-home-paths`: both delete branches in `linkSystemCodexResource` remove
Orca's mirrored copy because the system resource "is not there". `existsSync`
and `systemResourceIsRegularFile`'s `catch { return false }` both reported
that for a source nobody could read, so one denied read on ~/.codex/AGENTS.md
removed the managed copy on the next launch.
`src/shared/definitive-filesystem-absence.ts` now owns the one errno allowlist —
ENOENT and ENOTDIR, with every other code including unrecognised ones treated as
indeterminate — and `host-codex-managed-home-ownership.ts` drops its private
copy rather than letting the two drift. `codex-path-observation.ts` builds the
three-valued observation on top of it.
The resource sync's two `existsSync`/`statSync` probes collapse into one
resolved stat, which answers reachability and regular-file-ness together and
closes the window between them.
`config-settings-promotion.ts` crossed its max-lines budget, so the write-target
resolution moves to its own module rather than taking a lint exemption.
Deliberately not here: the hook-service trust writes that run after a refused
mirror, and the promotion write target's own classification, which is
unreachable because it always resolves to the same file the read above already
refused. Both are noted in comments rather than half-built.
* fix(codex): preserve resource copies on indeterminate reads
18 lines
835 B
TypeScript
18 lines
835 B
TypeScript
/**
|
|
* The single errno allowlist for "this path is definitively not there".
|
|
*
|
|
* `existsSync` returns `false` for `ENOENT` and for `EPERM`, `EACCES`, `EBUSY`,
|
|
* `EIO`, `UNKNOWN` and every unrecognised code alike, and a `catch` returning a
|
|
* default does the same. Callers that act on absence — deleting a mirror,
|
|
* overwriting a config, clearing a credential — must be able to tell the two
|
|
* apart, and they must all agree on where the line is, so this lives in one
|
|
* place rather than being re-derived per lane.
|
|
*
|
|
* An unknown code is never absence. Mapping the unknown to a verdict is the
|
|
* category error this predicate exists to prevent.
|
|
*/
|
|
export function isDefinitiveAbsence(error: unknown): boolean {
|
|
const code = (error as NodeJS.ErrnoException | null)?.code
|
|
return code === 'ENOENT' || code === 'ENOTDIR'
|
|
}
|