mirror of
https://github.com/stablyai/orca.git
synced 2026-09-22 16:02:32 +00:00
* fix(tooling): run oxlint gates without a Windows .cmd shim
`check:code-quality:changed` spawned `pnpm.cmd` without a shell, which Node
refuses under the CVE-2024-27980 mitigation, so the gate died with EINVAL
before linting anything. Resolve oxlint's own Node bin and run it under this
process's node instead — no shim, no shell, no quoting question — and add a
ratchet so the idiom cannot spread back into config/scripts.
* fix(tooling): validate the react-doctor diff base and widen the shim ratchet
`base` reaches cmd.exe unquoted on the shell fallback, so reject anything
outside a git revision before spawning. The ratchet matched only a handful of
runner names, which let `vitest.cmd` through even though config/scripts already
spawns vitest, playwright and electron-builder; match any batch-shim literal
instead, walk subdirectories, and cover tests/tools.
* docs(tooling): state what the shim ratchet and diff-base check miss
Both comments read as complete accounts of their guard's coverage. The revision
class rejects reflog syntax like HEAD@{1}, deliberately, since braces have no
business in a cmd.exe-bound argument; the ratchet misses a drive-lettered
literal because a colon is not in its class. Say so beside the template-literal
ceiling already noted.
---------
Co-authored-by: Orca Worker <orca-worker@localhost>
30 lines
965 B
JavaScript
30 lines
965 B
JavaScript
import { spawnSync } from 'node:child_process'
|
|
import path from 'node:path'
|
|
import process from 'node:process'
|
|
import { describe, expect, it } from 'vitest'
|
|
|
|
const repoRoot = path.resolve(import.meta.dirname, '..', '..')
|
|
const script = path.join(repoRoot, 'config', 'scripts', 'check-react-doctor-changed.mjs')
|
|
|
|
function runWithBase(base) {
|
|
return spawnSync(process.execPath, [script, base], {
|
|
cwd: repoRoot,
|
|
encoding: 'utf8',
|
|
windowsHide: true
|
|
})
|
|
}
|
|
|
|
describe('check-react-doctor-changed diff base', () => {
|
|
// The pnpm invocation can still fall back to a shell, so an unvalidated base
|
|
// would reach cmd.exe unquoted. Rejection has to happen before the spawn.
|
|
it.each(['main & calc', 'main | whoami', 'main"x', '%PATH%', 'main $(id)'])(
|
|
'refuses %j',
|
|
(base) => {
|
|
const result = runWithBase(base)
|
|
|
|
expect(result.status).not.toBe(0)
|
|
expect(result.stderr).toContain('Refusing to pass an unsafe diff base')
|
|
}
|
|
)
|
|
})
|