Files
orca/config/scripts/lint-react-doctor-changed.mjs
OrcaWinandOrca Worker 3ae51076b1 fix(tooling): run oxlint gates without a Windows .cmd shim (#17894)
* fix(tooling): run oxlint gates without a Windows .cmd shim

`check:code-quality:changed` spawned `pnpm.cmd` without a shell, which Node
refuses under the CVE-2024-27980 mitigation, so the gate died with EINVAL
before linting anything. Resolve oxlint's own Node bin and run it under this
process's node instead — no shim, no shell, no quoting question — and add a
ratchet so the idiom cannot spread back into config/scripts.

* fix(tooling): validate the react-doctor diff base and widen the shim ratchet

`base` reaches cmd.exe unquoted on the shell fallback, so reject anything
outside a git revision before spawning. The ratchet matched only a handful of
runner names, which let `vitest.cmd` through even though config/scripts already
spawns vitest, playwright and electron-builder; match any batch-shim literal
instead, walk subdirectories, and cover tests/tools.

* docs(tooling): state what the shim ratchet and diff-base check miss

Both comments read as complete accounts of their guard's coverage. The revision
class rejects reflog syntax like HEAD@{1}, deliberately, since braces have no
business in a cmd.exe-bound argument; the ratchet misses a drive-lettered
literal because a colon is not in its class. Say so beside the template-literal
ceiling already noted.

---------

Co-authored-by: Orca Worker <orca-worker@localhost>
2026-09-01 23:21:26 -07:00

46 lines
1.2 KiB
JavaScript

import { existsSync } from 'node:fs'
import { spawnSync } from 'node:child_process'
import { resolveOxlintInvocation } from './oxlint-cli-invocation.mjs'
const SOURCE_FILE_PATTERN = /\.(?:[cm]?[jt]sx?)$/
function run(command, args) {
const result = spawnSync(command, args, {
encoding: 'utf8',
stdio: ['ignore', 'pipe', 'inherit']
})
if (result.error) {
throw result.error
}
if (result.status !== 0) {
return []
}
return result.stdout.split(/\r?\n/).filter(Boolean)
}
const changedFiles = new Set([
...run('git', ['diff', '--name-only', '--diff-filter=ACMRTUB']),
...run('git', ['diff', '--cached', '--name-only', '--diff-filter=ACMRTUB']),
...run('git', ['ls-files', '--others', '--exclude-standard'])
])
const lintTargets = [...changedFiles].filter(
(file) => SOURCE_FILE_PATTERN.test(file) && existsSync(file)
)
if (lintTargets.length === 0) {
process.exit(0)
}
const { command, prefixArgs } = resolveOxlintInvocation()
const result = spawnSync(
command,
[...prefixArgs, '--config', 'config/oxlint-react-doctor.json', ...lintTargets],
{ stdio: 'inherit', windowsHide: true }
)
if (result.error) {
throw result.error
}
process.exit(result.status ?? 1)