mirror of
https://github.com/stablyai/orca.git
synced 2026-09-22 16:02:32 +00:00
* fix(codex): stop blocking the main thread on trust grants (#16441) Codex hook trust was granted by blocking the Electron main thread on `spawnSync` of a bundled ELECTRON_RUN_AS_NODE entry for the whole app-server deadline: 15s native, 35s WSL, ~45s on the real-home path (rebase inspect + repair + grant). Cold start and every Codex pane launch showed "Not Responding"; the reported event-loop gap was 15,049 ms. The subprocess only ever existed to donate an event loop to a deliberately blocked parent — `runCodexHookTrustGrantSession` was already the real async implementation. Make the callers async and the fork is unnecessary, so the bridge, the forked entry and its envelope are deleted along with their build/knip/tsconfig registrations. The CLI `agent hooks prepare-codex` handler is already async, so it awaits the in-process session and saves a process spawn per managed-home shell. `resolveCodexTrustGrantHost` is async too; the WSL identity probe moves from `execFileSync` to `runProcess`, dropping that file from the child-process import allowlist. Status reads keep a synchronous native-only stamp path. Two invariants that held only because the lane blocked: - Overlapping capability probes were impossible by construction. `GitCapabilityCache`'s dedupe engine is extracted to a shared `CapabilityProbeCache` and `CodexAppServerCapabilityCache` now inherits it, so concurrent launches against a cold host share one app-server session instead of one each. - Two grants on one `config.toml` could not interleave capture and restore. A reentrant per-file lane now serializes the whole install sequence (managed, WSL runtime, real-home ensure, legacy sweep) and the grant and rebase inside it. Cold-start work moves off the critical path: retained-home reconciliation (N sequential sessions) is fire-and-forget behind the daemon provider, and the startup real-home ensure chains into managed hook reconciliation instead of blocking app init. Every preserved semantic is unchanged: never throws, the ORCA_DISABLE_CODEX_TRUST_RPC kill switch, ledger hits, backfill-pending and cooldown fallbacks, config rollback on every failure path, pre-grant self-computed trust removal, the verify-failure taxonomy, diagnostics and telemetry. * fix(codex): widen the trust-config lane to every config.toml writer Review follow-ups on #16441's async trust grant: - `markCodexProjectTrusted` now runs inside the runtime+system config.toml lanes, so a project-trust write can no longer land inside a hook grant's capture->restore window and be silently reverted. Its callers await it. - `install`/`refreshRuntimeUserHooks`/`remove` hold the system config.toml lane as well as the runtime one — they promote approvals into ~/.codex/config.toml and mirror it back. Lock order is runtime-before-system everywhere. - The real-home ensure chain resumes after a rejection instead of returning the same rejected promise to every later pane launch, and resolving the real home is now inside the module's never-throws boundary. - `buildSpawnEnv` awaits inside a cancelable pending-spawn registration, so shutdown during the (now long) env build stops the PTY from launching. `prepareLocalPtySpawn` generalizes into `awaitCancelableLocalPtySpawn`. - CapabilityProbeCache drops the test-only `nowMs` passthrough; its probe backstop comment now describes what it actually guards. - Preflight is a plain async function; the trust dispatch in orca-runtime collapses into one `markWorkspaceTrustedForAgent`. * test(codex): exercise the trust-config lane under real concurrency The async grant makes two pane launches overlap for the first time. These drive the real modules end to end on real files: a rollback swallowing a sibling's grant, a markCodexProjectTrusted write landing inside a capture -> restore window, shared capability-probe dedupe on a cold host, the host-scoped transient cooldown, and reentrancy from inside an installer. Each was verified to fail against a deliberately broken implementation (lane removed, dedupe disabled, cooldown made global, reentrancy pass- through disabled). * test(codex): stop hook-service suites spawning the developer's real codex The forked grant bundle never existed under vitest, so the RPC lane was unreachable in tests on main. Running it in-process makes these suites spawn a real `codex app-server` when one is installed: 38 spawns and two failures in hook-service-runtime-trust-repair on a machine with codex, green in CI where there is none. Stand in for the missing binary so both environments exercise the same fallback lane. * docs(codex): scope the trust-RPC kill switch comment to what it actually gates The comment read as though the flag forces the fallback lane everywhere. It gates the managed grant only: the real-home rebase still runs its own inspect/repair app-server sessions when Orca's insertion shifts a user's hook positions, and never reads the flag. Verified by exercise, not by reading — with the flag set, both inspect-user-hook-trust and repair-user-hook-trust still ran. Pre-existing: main has no check there either, it just blocked the main thread while doing it. Widening the flag to cover the rebase is a follow-up; this only stops the comment promising something the constant does not do.
47 lines
1.7 KiB
JSON
47 lines
1.7 KiB
JSON
{
|
|
"$schema": "https://unpkg.com/knip@5/schema.json",
|
|
"entry": [
|
|
"src/main/index.ts",
|
|
"src/preload/index.ts",
|
|
"src/preload/browser-window-close.ts",
|
|
"src/main/daemon/daemon-entry.ts",
|
|
"src/main/plugins/plugin-host-entry.ts",
|
|
"src/main/computer/sidecar-entry.ts",
|
|
"src/main/speech/stt-worker.ts",
|
|
"src/main/warp-themes/warp-theme-parser-worker.ts",
|
|
"src/main/ai-vault/session-scanner-opencode-sqlite-worker-entry.ts",
|
|
"src/main/ai-vault/session-scanner-worker-entry.ts",
|
|
"src/main/ports/port-scan-command-worker-entry.ts",
|
|
"src/main/ipc/parcel-watcher-process-entry.ts",
|
|
"src/main/hang-watchdog/main-thread-hang-watchdog-entry.ts",
|
|
"src/main/agent-hooks/managed-agent-hook-controls.ts",
|
|
"src/main/claude-accounts/keychain.ts",
|
|
"src/renderer/src/main.tsx",
|
|
"src/renderer/src/popout.tsx",
|
|
"src/renderer/src/web/main.tsx",
|
|
"src/renderer/src/**/*.worker.ts",
|
|
"src/cli/index.ts",
|
|
"src/relay/relay.ts",
|
|
"src/relay/wsl-agent-hook-relay.ts",
|
|
"config/scripts/**/*.{mjs,cjs,js,ts}",
|
|
"config/build-plugins/**/*.ts",
|
|
"electron.vite.config.ts",
|
|
"vite.web.config.ts",
|
|
"config/vitest.config.ts",
|
|
"config/i18next.config.ts",
|
|
"config/electron-builder.config.cjs",
|
|
"config/oxlint-plugins/**/*.{js,mjs,ts}",
|
|
"tests/**/*.{ts,tsx,mjs}",
|
|
"**/*.test.{ts,tsx}"
|
|
],
|
|
"project": [
|
|
"src/**/*.{ts,tsx}",
|
|
"config/scripts/**/*.{mjs,cjs,js,ts}",
|
|
"config/build-plugins/**/*.ts"
|
|
],
|
|
"ignore": ["mobile/**", "out/**", "dist/**", "node_modules/**", "resources/**"],
|
|
"ignoreDependencies": ["electron", "@types/*"],
|
|
"ignoreExportsUsedInFile": true,
|
|
"includeEntryExports": false
|
|
}
|