mirror of
https://github.com/stablyai/orca.git
synced 2026-09-28 16:02:45 +00:00
* chore(lint): upgrade oxlint to 1.71 and enable 7 new rules Upgrade oxlint 1.67.0 -> 1.71.0 (1.72 was blocked by the repo's 3-day minimum-release-age supply-chain guard; nothing here needs it). The bump is a no-op on the existing config. Enable 3 error rules (backlog autofixed to zero in this commit) and 4 warn rules (surface signal without gating CI): error (autofixed, behavior-preserving): - unicorn/prefer-node-protocol (~1531 sites: bare builtin -> node:) - typescript/no-import-type-side-effects (~36: all-inline-type -> import type) - unicorn/no-array-reverse (19: copy-then-reverse -> toReversed) warn (real signal, current fires are test-only/correct): - unicorn/no-array-fill-with-reference-type (aliasing footgun guard) - typescript/no-unsafe-function-type (bans bare Function type) - unicorn/prefer-array-flat-map (map().flat() -> flatMap()) - unicorn/prefer-regexp-test (.match() in bool ctx -> .test()) mobile/.oxlintrc.json extends root, so it inherits all 7; the autofix ran from root and covered mobile/ too. Verification (all green): oxlint 0 errors (root+mobile+aux configs), oxfmt clean, typecheck (node+cli+web), vitest 22795 passed / 0 failed, builds (electron-vite + web + cli) succeed. node: rewrites confirmed to skip embedded SSH/CLI string payloads (AST-only); all toReversed sites verified to operate on fresh copies or write-once locals. * chore(lint): bump mobile oxlint to 1.71 so inherited rules parse mobile/ is a standalone pnpm project pinning its own oxlint@1.67, which lacks unicorn/no-array-fill-with-reference-type (needs >=1.70). Since mobile/.oxlintrc.json extends the root config, mobile CI's 'cd mobile && oxlint' failed to parse the new rule. Bump mobile to match root (1.71). Verified in mobile/: oxlint 0 errors, oxfmt --check clean, tsc --noEmit pass, vitest 978 passed / 0 failed. Co-authored-by: Orca <help@stably.ai> --------- Co-authored-by: Orca <help@stably.ai>
35 lines
1.3 KiB
TypeScript
35 lines
1.3 KiB
TypeScript
import { resolve } from 'node:path'
|
|
import { homedir } from 'node:os'
|
|
|
|
// Why: Node's fs APIs don't understand shell tilde expansion. Old repos may
|
|
// have been stored with `~` or `~/…` paths before the client-side fix, so the
|
|
// relay must expand them to absolute paths as a safety net.
|
|
export function expandTilde(p: string): string {
|
|
if (p === '~' || p === '~/' || p === '~\\') {
|
|
return homedir()
|
|
}
|
|
if (p.startsWith('~/')) {
|
|
return resolve(homedir(), p.slice(2))
|
|
}
|
|
if (p.startsWith('~\\')) {
|
|
return `${homedir()}\\${p.slice(2)}`
|
|
}
|
|
return p
|
|
}
|
|
|
|
// Why: the relay runs as the SSH user and trusts the renderer process. A
|
|
// compromised renderer can already weaponize pty.spawn and git.exec to reach
|
|
// any path the SSH user can reach, so the FS-side allowlist provided friction
|
|
// without meaningfully narrowing the blast radius. See
|
|
// docs/relay-fs-allowlist-removal.md.
|
|
//
|
|
// registerRoot is retained as a no-op so existing session.registerRoot RPC
|
|
// calls (notification + request) remain valid during the relay-deploy upgrade
|
|
// window where an old main may still call into a new relay (and vice versa).
|
|
// Tracked for deletion once the relay-version floor moves past the cutover.
|
|
export class RelayContext {
|
|
registerRoot(_rootPath: string): void {
|
|
// intentionally empty
|
|
}
|
|
}
|