Files
orca/config/tsconfig.cli.json
T
Brennan Benson a84bd1c4fd fix(claude): write only the hook events and statusLine the user's Claude accepts (#23614)
* refactor(claude): name the Claude version module after the hook events it gates

Pure move of claude-session-end-hook-capability.ts and its tests; the next
commit turns its one-event SessionEnd floor into a per-event version table.

* fix(claude): write only the hook events the resolved Claude knows

Claude 1.0.81 through 2.1.100 validate settings.json `hooks` against a
closed event enum and discard the whole file on one unknown name, so
Orca's install made Claude <= 2.1.77 silently ignore the user's env,
permissions and hooks. Each managed event now carries the first Claude
release that knows it (pinned to per-release enums read from the npm
packages), and install, status and the SSH/WSL relay installer write
only the events the resolved Claude accepts. An unresolved version gets
the set every tabled Claude knows; a downgrade removes only Orca's own
entry for an event the older Claude would reject.

* refactor(claude): move the managed Claude hook events into their own module

hook-settings.ts is at its line limit; the event list and its version gate
move out whole so the next change has room.

* fix(claude): an unresolved Claude version never removes Orca's hook entries

A failed or timed-out version probe is no evidence of an old Claude, so it
must not strip StopFailure, PermissionRequest and the other newer events a
version-aware install wrote. With the version unknown, install adds only
the set every tabled Claude knows and leaves every other entry exactly as
it is; only a known version that lacks an event retires Orca's entry.

* fix(claude): gate the core hook events on the Claude release that added them

Claude validates hooks against a closed event list from 1.0.23, not 1.0.81.
The table treated SessionStart, UserPromptSubmit, Stop, SubagentStop,
PreToolUse and PostToolUse as known by every resolved version, so a Claude
from 1.0.23 to 1.0.61 was still sent names it rejects, and it dropped the
whole settings file. Pin each to its first release from the packed enums and
keep the unresolved-version set as its own policy.

* fix(claude): write Orca's statusLine only for a Claude that knows it

Claude 1.0.49 through 1.0.66 also reject any unknown top-level settings
key, and statusLine joined that schema only in 1.0.64. Orca wrote its
statusLine for every Claude, so 1.0.49 to 1.0.63 still dropped the whole
settings file even with the event gate. Gate statusLine on 1.0.64, pinned
by the packed schemas; a known older Claude has Orca's own statusLine
removed along with the opt-out marker, so an upgrade re-adds it. An
unresolved version is now assumed to be 1.0.64, which knows the same core
events and keeps the statusLine install it had before.

* test(claude): a user statusLine opt-out survives a downgrade and upgrade

Retiring Orca's statusLine for a Claude older than 1.0.64 forgets the
install marker only when Orca's own statusLine was removed. Pin that, so
a user who deleted Orca's statusLine is not opted back in by an upgrade.

* test(claude): check the whole written settings file against each strict schema

Claude 1.0.49 through 1.0.66 discard the whole settings file over any
top-level key their schema lacks. The fixture recorded only whether each
release knew statusLine, so a new top-level key Orca wrote would pass every
test. Record each release's top-level keys instead (statusLine is derived
from them), add the hook enums for every packed release in that window,
and check that a real install and a downgrade write only keys and events
each strict release accepts.
2026-09-28 12:04:59 -07:00

250 lines
14 KiB
JSON

{
"extends": "@electron-toolkit/tsconfig/tsconfig.node.json",
"include": [
"../src/cli/**/*",
"../src/shared/**/*",
"../src/main/agent-state-file-reader.ts",
"../src/main/agent-hooks/grok-replay-guard.ts",
"../src/main/claude/hook-script.ts",
"../src/main/claude/claude-hook-event-versions.ts",
"../src/main/claude/claude-managed-hook-events.ts",
"../src/main/qoder/hook-service.ts",
"../src/main/agent-hooks/hook-stdin-contract.ts",
"../src/main/agent-hooks/hook-post-command.ts",
"../src/main/agent-hooks/hook-config-write-path.ts",
"../src/main/agent-hooks/hooks-json-read.ts",
"../src/main/agent-hooks/installer-utils.ts",
"../src/main/agent-hooks/installer-utils-remote.ts",
"../src/main/agent-hooks/local-agent-cli-presence.ts",
"../src/main/agent-hooks/managed-toml-ownership.ts",
"../src/main/agent-hooks/managed-agent-hook-controls.ts",
"../src/main/agent-hooks/managed-agent-hook-registry.ts",
"../src/main/agent-hooks/managed-hook-script-refresh.ts",
"../src/main/agent-hooks/managed-hooks-json-events.ts",
"../src/main/agent-hooks/posix-hook-command.ts",
"../src/main/agent-hooks/runtime-home-hook-command.ts",
"../src/main/orca-profiles/profile-storage-paths.ts",
"../src/main/orca-profiles/profile-index-store.ts",
"../src/main/orca-profiles/profile-telemetry-consent-seed.ts",
"../src/main/orca-profiles/profile-legacy-state-import.ts",
"../src/main/persistence/profile-state/profile-state-migration.ts",
"../src/main/persistence/profile-state/profile-state-database-publication.ts",
"../src/main/persistence/profile-state/profile-state-database.ts",
"../src/main/persistence/profile-state/profile-state-database-errors.ts",
"../src/main/persistence/profile-state/profile-state-database-validation.ts",
"../src/main/persistence/profile-state/profile-state-database-schema.ts",
"../src/main/persistence/profile-state/profile-state-documents.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-json-acceptance.ts",
"../src/main/persistence/profile-state/profile-state-revision.ts",
"../src/main/persistence/profile-state/profile-state-read-snapshot.ts",
"../src/main/persistence/profile-state/profile-state-sqlite-authority.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-authority-exports.ts",
"../src/main/persistence/profile-state/profile-state-complete-replacements.ts",
"../src/main/persistence/profile-state/profile-state-revision-readmission.ts",
"../src/main/persistence/profile-state/profile-state-writer-protocol.ts",
"../src/main/persistence/loading-store/profile-state-authority.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-migration.ts",
"../src/main/persistence/profile-state/profile-state-document-reader.ts",
"../src/main/persistence/profile-state/profile-state-document-validation.ts",
"../src/main/persistence/profile-state/profile-state-domain-writes.ts",
"../src/main/persistence/profile-state/profile-state-write-transaction.ts",
"../src/main/persistence/profile-state/profile-state-domain-write-validation.ts",
"../src/main/persistence/profile-state/profile-state-domain-reader.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-model.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-payload.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-reader.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-storage.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-validation.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-writer.ts",
"../src/main/persistence/profile-state/profile-state-offline-settings.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-export-path.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-legacy-backup-path.ts",
"../src/main/persistence/profile-state/profile-state-backup-path.ts",
"../src/main/persistence/profile-state/profile-state-backup-rotation.ts",
"../src/main/persistence/profile-state/profile-state-backup-job.ts",
"../src/main/persistence/profile-state/profile-state-backup-worker.ts",
"../src/main/persistence/profile-state/profile-state-backup-worker-entry.ts",
"../src/main/worker-thread-entry-path.ts",
"../src/main/persistence/profile-state/profile-state-database-snapshot.ts",
"../src/main/persistence/profile-state/profile-state-database-recovery.ts",
"../src/main/persistence/profile-state/profile-state-recovery-required.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-recovery.ts",
"../src/main/persistence/profile-state/profile-state-recovery-copy.ts",
"../src/main/persistence/profile-state/profile-state-recovery-command.ts",
"../src/main/orca-profiles/profile-project-move-record.ts",
"../src/main/orca-profiles/profile-project-domain-changes.ts",
"../src/main/persistence/profile-state/profile-state-active-location.ts",
"../src/main/persistence/profile-state/profile-state-access.ts",
"../src/main/persistence/profile-state/profile-state-access-owner.ts",
"../src/main/persistence/profile-state/profile-state-access-identity.ts",
"../src/main/windows-native-registry.ts",
"../src/main/windows/windows-command-line-recovery-health.ts",
"../src/main/windows/windows-process-table.ts",
"../src/main/windows/windows-process-table-cim-scan.ts",
"../src/main/daemon/daemon-process-start-time.ts",
"../src/main/daemon/daemon-process-identity-query.ts",
"../src/main/startup/startup-diagnostics.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-versioned-export.ts",
"../src/main/persistence/profile-state/profile-state-backup-temporary-files.ts",
"../src/main/persistence/profile-state/profile-state-database-quarantine.ts",
"../src/main/persistence/profile-state/profile-state-storage-classification.ts",
"../src/main/durable-file-write.ts",
"../src/shared/secure-file.ts",
"../src/main/sqlite/harden-database-files.ts",
"../src/main/startup/http1-compatibility-marker.ts",
"../src/main/startup/http1-compatibility-profile-state.ts",
"../src/main/agent-hooks/windows-direct-cmd-hook-command.ts",
"../src/main/agent-hooks/windows-powershell-hook-launcher.ts",
"../src/main/amp/agent-status-plugin-source.ts",
"../src/main/amp/hook-service.ts",
"../src/main/amp/managed-plugin-install-status.ts",
"../src/main/antigravity/hook-events.ts",
"../src/main/antigravity/hook-script.ts",
"../src/main/antigravity/hook-service.ts",
"../src/main/antigravity/hooks-json-bundle.ts",
"../src/main/claude/hook-settings.ts",
"../src/main/claude/hook-service.ts",
"../src/main/claude/statusline-script.ts",
"../src/main/claude-accounts/keychain.ts",
"../src/main/macos-keychain/generic-password.ts",
"../src/main/codex/codex-app-server-capability-cache.ts",
"../src/main/codex/codex-app-server-capability-signal.ts",
"../src/main/codex/codex-app-server-client.ts",
"../src/main/codex/codex-app-server-process-tree-kill.ts",
"../src/main/codex/codex-app-server-record-reader.ts",
"../src/main/codex/codex-app-server-session.ts",
"../src/main/codex/codex-config-mirror.ts",
"../src/main/codex/codex-config-path-reference-rewrite.ts",
"../src/main/codex/codex-config-settings-preservation.ts",
"../src/main/codex/codex-config-settings-removal.ts",
"../src/main/codex/codex-config-settings-upsert.ts",
"../src/main/codex/codex-daemon-socket-path-guard.ts",
"../src/main/codex/codex-home-paths.ts",
"../src/main/codex/codex-hook-definition.ts",
"../src/main/codex/codex-managed-home-resource-copy-marker.ts",
"../src/main/codex/codex-managed-trust-grant-plan.ts",
"../src/main/codex/codex-path-observation.ts",
"../src/main/codex/codex-hook-identity.ts",
"../src/main/codex/codex-hook-legacy-cleanup.ts",
"../src/main/codex/codex-hook-local-install.ts",
"../src/main/codex/codex-hook-local-maintenance.ts",
"../src/main/codex/codex-hook-remote-install.ts",
"../src/main/codex/codex-hook-script.ts",
"../src/main/codex/codex-hook-service-implementation.ts",
"../src/main/codex/codex-hook-status.ts",
"../src/main/codex/codex-hook-system-trust.ts",
"../src/main/codex/codex-hook-trust-cleanup.ts",
"../src/main/codex/codex-hook-trust-grant.ts",
"../src/main/codex/codex-hook-trust-queue.ts",
"../src/main/codex/codex-hook-user-mirroring.ts",
"../src/main/codex/codex-hook-wsl-runtime.ts",
"../src/main/codex/codex-managed-trust-reconciliation.ts",
"../src/main/codex/codex-process-exit-deadline.ts",
"../src/main/codex/codex-state-db.ts",
"../src/main/codex/codex-trust-identity.ts",
"../src/main/codex/codex-trust-config-rollback.ts",
"../src/main/codex/codex-trust-config-mutation-queue.ts",
"../src/main/codex/codex-trust-grant-telemetry.ts",
"../src/main/codex/codex-trust-grant-host.ts",
"../src/main/codex/codex-trust-grant-ledger.ts",
"../src/main/codex/codex-user-hook-trust-rebase-client.ts",
"../src/main/codex/codex-user-hook-trust-rebase.ts",
"../src/main/codex/codex-wsl-hook-install-plan.ts",
"../src/main/codex/config-settings-baseline.ts",
"../src/main/codex/config-settings-conflict-resolution.ts",
"../src/main/codex/config-plugin-registration-promotion.ts",
"../src/main/codex/config-toml-plugin-registration-tables.ts",
"../src/main/codex/config-toml-promoted-setting-values.ts",
"../src/main/codex/config-settings-promotion.ts",
"../src/main/codex/config-settings-promotion-write-target.ts",
"../src/main/codex/config-sync-stall.ts",
"../src/main/codex/config-toml-atomic-write.ts",
"../src/main/codex/config-toml-deprecated-hook-flag.ts",
"../src/main/codex/config-toml-hook-trust-blocks.ts",
"../src/main/codex/config-toml-hook-trust-edit.ts",
"../src/main/codex/config-toml-hook-trust-read.ts",
"../src/main/codex/config-toml-key-path.ts",
"../src/main/codex/config-toml-line-scan.ts",
"../src/main/codex/config-toml-mcp-servers.ts",
"../src/main/codex/config-toml-project-trust.ts",
"../src/main/codex/config-toml-runtime-owned-sections.ts",
"../src/main/codex/config-toml-syntax.ts",
"../src/main/codex/config-toml-trust.ts",
"../src/main/codex/hook-service.ts",
"../src/main/codex/hook-trust-promotion.ts",
"../src/main/codex/managed-home-shell-preflight.ts",
"../src/main/codex-accounts/fs-utils.ts",
"../src/main/codex-accounts/wsl-codex-command.ts",
"../src/main/codex-cli/command.ts",
"../src/main/command-code/command-code-managed-script.ts",
"../src/main/command-code/hook-service.ts",
"../src/main/copilot/copilot-managed-hook-definitions.ts",
"../src/main/copilot/copilot-managed-script.ts",
"../src/main/copilot/copilot-remote-hook-install.ts",
"../src/main/copilot/hook-service.ts",
"../src/main/cursor/hook-events.ts",
"../src/main/cursor/hook-script.ts",
"../src/main/cursor/hook-service.ts",
"../src/main/droid/hook-service.ts",
"../src/main/gemini/hook-service.ts",
"../src/main/grok/grok-hook-config.ts",
"../src/main/grok/grok-hook-config-cleanup.ts",
"../src/main/grok/grok-hook-config-file.ts",
"../src/main/grok/grok-hook-owners.ts",
"../src/main/grok/grok-hook-remote-install.ts",
"../src/main/grok/grok-hook-script.ts",
"../src/main/grok/grok-hook-symlink-cleanup-marker.ts",
"../src/main/grok/hook-service.ts",
"../src/main/grok/windows-grok-hook-script.ts",
"../src/main/devin/hook-settings.ts",
"../src/main/devin/hook-service.ts",
"../src/main/devin/hook-config-json.ts",
"../src/main/hermes/hermes-config-document.ts",
"../src/main/hermes/hermes-config-source-edits.ts",
"../src/main/hermes/hermes-config-yaml.ts",
"../src/main/hermes/hermes-home-filesystem.ts",
"../src/main/hermes/hermes-managed-plugin-source.ts",
"../src/main/hermes/hook-service.ts",
"../src/main/git-bash.ts",
"../src/main/in-flight-run-dedupe.ts",
"../src/main/kimi/hook-service.ts",
"../src/main/kimi/kimi-hook-config-toml.ts",
"../src/main/dsh/dsh-home-patch.ts",
"../src/main/dsh/hook-service.ts",
"../src/main/dsh/hook-settings.ts",
"../src/main/muse/hook-config-json.ts",
"../src/main/muse/hook-service.ts",
"../src/main/muse/hook-settings.ts",
"../src/main/zcode/hook-config-json.ts",
"../src/main/zcode/hook-service.ts",
"../src/main/zcode/hook-settings.ts",
"../src/main/openclaude/hook-service.ts",
"../src/main/rolling-file-backup.ts",
"../src/main/startup/hydrate-shell-path.ts",
"../src/main/startup/windows-shell-path-ownership.ts",
// Why: serve-electron-flag-parity.test.ts checks the Electron-side serve argv rewrite against this
// project's serve spec; the module has no imports, so listing it pulls in nothing else.
"../src/main/startup/serve-mode-argv.ts",
// The parity test keeps this import-free list aligned with COMMAND_SPECS.
"../src/main/startup/cli-command-names.ts",
"../src/main/runtime/runtime-metadata.ts",
"../src/main/sqlite/sync-database.ts",
"../src/main/sqlite/bun-readonly-wal.ts",
"../src/main/sqlite/sqlite-statement.ts",
"../src/main/sqlite/sqlite-integer-reader.ts",
"../src/main/sqlite/node-sqlite-statement.ts",
"../src/main/sqlite/bun-sqlite-statement.ts",
"../src/main/sqlite/bun-sqlite-database.ts",
"../src/main/win32-utils.ts"
],
"compilerOptions": {
"composite": true,
// TypeScript 7 removed node10 resolution; Node16 preserves CommonJS emit for this package.
"module": "Node16",
"moduleResolution": "Node16",
"rootDir": "../src",
"outDir": "../out"
}
}