Files
orca/config/tsconfig.cli.json
T
Brennan Benson 444e0b1cf9 fix(codex): recognise Codex's quoted spellings in config.toml, and repair Orca's duplicates (#22592) (#23958)
* fix(codex): recognise Codex's quoted project-trust spellings in config.toml (#22592)

Codex's settings screen writes project trust as ["projects"."/p"] and
"trust_level" = "trusted". Orca's matchers only knew the bare spelling, so a
trust write appended a second [projects."/p"] table (or a second trust_level
line) and every codex command then failed with "duplicate key". The config
mirror kept both spellings in Orca-managed homes for the same reason.

- Project table headers are now read through the existing TOML key-path
  parser, so bare, quoted, literal-quoted, mixed and spaced spellings are the
  same table for trust writes and the managed-home mirror/dedupe.
- trust_level is found by decoded key, in both the trust writer and the
  mirror's trust reader, and an existing key is rewritten, never duplicated.
- On the next trust write, a table older Orca appended (exactly
  [projects."<p>"] holding only trust_level = "trusted") that duplicates the
  user's table, or the bare line it inserted under a quoted "trust_level", is
  removed; the user's table wins and the atomic writer keeps config.toml.bak.
  Any other duplicate, or a repair that would still leave one, leaves the file
  untouched and logs once.

* build(cli): list the new Codex trust modules in the CLI project

* fix(codex): recognise Codex's quoted hooks.state spellings and repair Orca's copies (#22592)

Codex writes hook trust as ["hooks"."state"."<key>"] (and the parent as
["hooks"."state"]). Orca's hook-trust writer, parent-table check and mirror
only knew the bare spelling, so a hook-trust write appended a bare copy and
the file failed to parse with "Cannot declare ... twice".

- The hooks.state header, parent-table and mirror checks now use the TOML
  key-path parser, like project tables.
- The duplicate repair now also removes Orca's own hooks.state tables (an
  exact [hooks.state."<k>"] with only enabled + trusted_hash, or an empty
  [hooks.state]) that repeat a table in another spelling, and runs on hook
  trust writes too, so a file with both project and hook duplicates is fully
  repaired. The Orca-shaped copy is removed whichever order the two tables are
  in, only when exactly one other table (the user's) remains; anything else is
  left untouched and logged once.

* fix(codex): carry plain-Codex plugin and project hook trust into Orca's Codex homes (#22592)

Codex keeps hook trust in $CODEX_HOME/config.toml under hooks.state, keyed
by the hook's source. Plugin keys (`id@mkt:path`) and project keys
(`<repo>/.codex/...`) are the same in every home, but the mirror dropped
every hooks.state table from ~/.codex, so Codex inside Orca asked users to
re-trust plugin and project hooks they had already trusted in plain Codex.

- classifyHookTrustKey splits keys into home-scoped (the home's own
  hooks.json/config.toml, re-keyed by install as before) and shared.
- The mirror now carries shared hook trust from ~/.codex in every spelling.
  A key the managed home already holds keeps the managed copy, a key
  repeated in ~/.codex is carried once, and the parent [hooks.state] table
  is never copied, so the result never declares a table twice.
- mergeSystemCodexConfigIntoRuntime moves to codex-config-mirror-merge.ts
  to keep codex-config-mirror.ts under the line limit.
- Tests cover plugin/project carry in each spelling, user-hook keys staying
  out, repeated launches, managed-copy precedence, Windows key spellings,
  parent tables, and user-hook trust re-keying (trusted_hash and enabled)
  from every ~/.codex spelling.

* fix(codex): carry session_end and interrupt hook trust into Orca's Codex homes (#22592)

The shared-trust classifier parsed hook keys with Orca's own trust-key
parser, which only knows the ten events Orca installs hooks for. Keys for
Codex's session_end and interrupt events did not parse, so their plugin and
project trust was treated as home-scoped and left out of the managed home.

The classifier now reads the source path from Codex's key shape
`{source}:{event}:{group}:{handler}` for any event label. A key without
that shape is still never carried. Tests cover both events for plugin and
project keys in both spellings, user-layer keys for both events, and five
unattributable key shapes.
2026-09-30 00:09:26 -07:00

254 lines
14 KiB
JSON

{
"extends": "@electron-toolkit/tsconfig/tsconfig.node.json",
"include": [
"../src/cli/**/*",
"../src/shared/**/*",
"../src/main/agent-state-file-reader.ts",
"../src/main/agent-hooks/grok-replay-guard.ts",
"../src/main/claude/hook-script.ts",
"../src/main/claude/claude-hook-event-versions.ts",
"../src/main/claude/claude-managed-hook-events.ts",
"../src/main/qoder/hook-service.ts",
"../src/main/codebuddy/hook-service.ts",
"../src/main/agent-hooks/hook-stdin-contract.ts",
"../src/main/agent-hooks/hook-post-command.ts",
"../src/main/agent-hooks/hook-config-write-path.ts",
"../src/main/agent-hooks/hooks-json-read.ts",
"../src/main/agent-hooks/installer-utils.ts",
"../src/main/agent-hooks/installer-utils-remote.ts",
"../src/main/agent-hooks/local-agent-cli-presence.ts",
"../src/main/agent-hooks/managed-toml-ownership.ts",
"../src/main/agent-hooks/managed-agent-hook-controls.ts",
"../src/main/agent-hooks/managed-agent-hook-registry.ts",
"../src/main/agent-hooks/managed-hook-script-refresh.ts",
"../src/main/agent-hooks/managed-hooks-json-events.ts",
"../src/main/agent-hooks/posix-hook-command.ts",
"../src/main/agent-hooks/runtime-home-hook-command.ts",
"../src/main/orca-profiles/profile-storage-paths.ts",
"../src/main/orca-profiles/profile-index-store.ts",
"../src/main/orca-profiles/profile-telemetry-consent-seed.ts",
"../src/main/orca-profiles/profile-legacy-state-import.ts",
"../src/main/persistence/profile-state/profile-state-migration.ts",
"../src/main/persistence/profile-state/profile-state-database-publication.ts",
"../src/main/persistence/profile-state/profile-state-database.ts",
"../src/main/persistence/profile-state/profile-state-database-errors.ts",
"../src/main/persistence/profile-state/profile-state-database-validation.ts",
"../src/main/persistence/profile-state/profile-state-database-schema.ts",
"../src/main/persistence/profile-state/profile-state-documents.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-json-acceptance.ts",
"../src/main/persistence/profile-state/profile-state-revision.ts",
"../src/main/persistence/profile-state/profile-state-read-snapshot.ts",
"../src/main/persistence/profile-state/profile-state-sqlite-authority.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-authority-exports.ts",
"../src/main/persistence/profile-state/profile-state-complete-replacements.ts",
"../src/main/persistence/profile-state/profile-state-revision-readmission.ts",
"../src/main/persistence/profile-state/profile-state-writer-protocol.ts",
"../src/main/persistence/loading-store/profile-state-authority.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-migration.ts",
"../src/main/persistence/profile-state/profile-state-document-reader.ts",
"../src/main/persistence/profile-state/profile-state-document-validation.ts",
"../src/main/persistence/profile-state/profile-state-domain-writes.ts",
"../src/main/persistence/profile-state/profile-state-write-transaction.ts",
"../src/main/persistence/profile-state/profile-state-domain-write-validation.ts",
"../src/main/persistence/profile-state/profile-state-domain-reader.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-model.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-payload.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-reader.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-storage.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-validation.ts",
"../src/main/persistence/profile-state/profile-state-automation-runs-writer.ts",
"../src/main/persistence/profile-state/profile-state-offline-settings.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-export-path.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-legacy-backup-path.ts",
"../src/main/persistence/profile-state/profile-state-backup-path.ts",
"../src/main/persistence/profile-state/profile-state-backup-rotation.ts",
"../src/main/persistence/profile-state/profile-state-backup-job.ts",
"../src/main/persistence/profile-state/profile-state-backup-worker.ts",
"../src/main/persistence/profile-state/profile-state-backup-worker-entry.ts",
"../src/main/worker-thread-entry-path.ts",
"../src/main/persistence/profile-state/profile-state-database-snapshot.ts",
"../src/main/persistence/profile-state/profile-state-database-recovery.ts",
"../src/main/persistence/profile-state/profile-state-recovery-required.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-recovery.ts",
"../src/main/persistence/profile-state/profile-state-recovery-copy.ts",
"../src/main/persistence/profile-state/profile-state-recovery-command.ts",
"../src/main/orca-profiles/profile-project-move-record.ts",
"../src/main/orca-profiles/profile-project-domain-changes.ts",
"../src/main/persistence/profile-state/profile-state-active-location.ts",
"../src/main/persistence/profile-state/profile-state-access.ts",
"../src/main/persistence/profile-state/profile-state-access-owner.ts",
"../src/main/persistence/profile-state/profile-state-access-identity.ts",
"../src/main/windows-native-registry.ts",
"../src/main/windows/windows-command-line-recovery-health.ts",
"../src/main/windows/windows-process-table.ts",
"../src/main/windows/windows-process-table-cim-scan.ts",
"../src/main/daemon/daemon-process-start-time.ts",
"../src/main/daemon/daemon-process-identity-query.ts",
"../src/main/startup/startup-diagnostics.ts",
"../src/main/persistence/profile-state/legacy-json/profile-state-versioned-export.ts",
"../src/main/persistence/profile-state/profile-state-backup-temporary-files.ts",
"../src/main/persistence/profile-state/profile-state-database-quarantine.ts",
"../src/main/persistence/profile-state/profile-state-storage-classification.ts",
"../src/main/durable-file-write.ts",
"../src/shared/secure-file.ts",
"../src/main/sqlite/harden-database-files.ts",
"../src/main/startup/http1-compatibility-marker.ts",
"../src/main/startup/http1-compatibility-profile-state.ts",
"../src/main/agent-hooks/windows-direct-cmd-hook-command.ts",
"../src/main/agent-hooks/windows-powershell-hook-launcher.ts",
"../src/main/amp/agent-status-plugin-source.ts",
"../src/main/amp/hook-service.ts",
"../src/main/amp/managed-plugin-install-status.ts",
"../src/main/antigravity/hook-events.ts",
"../src/main/antigravity/hook-script.ts",
"../src/main/antigravity/hook-service.ts",
"../src/main/antigravity/hooks-json-bundle.ts",
"../src/main/claude/hook-settings.ts",
"../src/main/claude/hook-service.ts",
"../src/main/claude/statusline-script.ts",
"../src/main/claude-accounts/keychain.ts",
"../src/main/macos-keychain/generic-password.ts",
"../src/main/codex/codex-app-server-capability-cache.ts",
"../src/main/codex/codex-app-server-capability-signal.ts",
"../src/main/codex/codex-app-server-client.ts",
"../src/main/codex/codex-app-server-process-tree-kill.ts",
"../src/main/codex/codex-app-server-record-reader.ts",
"../src/main/codex/codex-app-server-session.ts",
"../src/main/codex/codex-config-mirror.ts",
"../src/main/codex/codex-config-mirror-merge.ts",
"../src/main/codex/codex-config-path-reference-rewrite.ts",
"../src/main/codex/codex-config-settings-preservation.ts",
"../src/main/codex/codex-config-settings-removal.ts",
"../src/main/codex/codex-config-settings-upsert.ts",
"../src/main/codex/codex-daemon-socket-path-guard.ts",
"../src/main/codex/codex-home-paths.ts",
"../src/main/codex/codex-hook-definition.ts",
"../src/main/codex/codex-managed-home-resource-copy-marker.ts",
"../src/main/codex/codex-managed-trust-grant-plan.ts",
"../src/main/codex/codex-path-observation.ts",
"../src/main/codex/codex-hook-identity.ts",
"../src/main/codex/codex-hook-legacy-cleanup.ts",
"../src/main/codex/codex-hook-local-install.ts",
"../src/main/codex/codex-hook-local-maintenance.ts",
"../src/main/codex/codex-hook-remote-install.ts",
"../src/main/codex/codex-hook-script.ts",
"../src/main/codex/codex-hook-service-implementation.ts",
"../src/main/codex/codex-hook-status.ts",
"../src/main/codex/codex-hook-system-trust.ts",
"../src/main/codex/codex-hook-trust-cleanup.ts",
"../src/main/codex/codex-hook-trust-grant.ts",
"../src/main/codex/codex-hook-trust-queue.ts",
"../src/main/codex/codex-hook-user-mirroring.ts",
"../src/main/codex/codex-hook-wsl-runtime.ts",
"../src/main/codex/codex-managed-trust-reconciliation.ts",
"../src/main/codex/codex-process-exit-deadline.ts",
"../src/main/codex/codex-state-db.ts",
"../src/main/codex/codex-trust-identity.ts",
"../src/main/codex/codex-trust-config-rollback.ts",
"../src/main/codex/codex-trust-config-mutation-queue.ts",
"../src/main/codex/codex-trust-grant-telemetry.ts",
"../src/main/codex/codex-trust-grant-host.ts",
"../src/main/codex/codex-trust-grant-ledger.ts",
"../src/main/codex/codex-user-hook-trust-rebase-client.ts",
"../src/main/codex/codex-user-hook-trust-rebase.ts",
"../src/main/codex/codex-wsl-hook-install-plan.ts",
"../src/main/codex/config-settings-baseline.ts",
"../src/main/codex/config-settings-conflict-resolution.ts",
"../src/main/codex/config-plugin-registration-promotion.ts",
"../src/main/codex/config-toml-plugin-registration-tables.ts",
"../src/main/codex/config-toml-promoted-setting-values.ts",
"../src/main/codex/config-settings-promotion.ts",
"../src/main/codex/config-settings-promotion-write-target.ts",
"../src/main/codex/config-sync-stall.ts",
"../src/main/codex/config-toml-atomic-write.ts",
"../src/main/codex/config-toml-deprecated-hook-flag.ts",
"../src/main/codex/config-toml-hook-trust-blocks.ts",
"../src/main/codex/config-toml-hook-trust-edit.ts",
"../src/main/codex/config-toml-hook-trust-read.ts",
"../src/main/codex/config-toml-key-path.ts",
"../src/main/codex/config-toml-line-scan.ts",
"../src/main/codex/config-toml-mcp-servers.ts",
"../src/main/codex/config-toml-project-trust.ts",
"../src/main/codex/config-toml-project-trust-level.ts",
"../src/main/codex/config-toml-project-duplicate-repair.ts",
"../src/main/codex/config-toml-runtime-owned-sections.ts",
"../src/main/codex/config-toml-syntax.ts",
"../src/main/codex/config-toml-trust.ts",
"../src/main/codex/hook-service.ts",
"../src/main/codex/hook-trust-promotion.ts",
"../src/main/codex/managed-home-shell-preflight.ts",
"../src/main/codex-accounts/fs-utils.ts",
"../src/main/codex-accounts/wsl-codex-command.ts",
"../src/main/codex-cli/command.ts",
"../src/main/command-code/command-code-managed-script.ts",
"../src/main/command-code/hook-service.ts",
"../src/main/copilot/copilot-managed-hook-definitions.ts",
"../src/main/copilot/copilot-managed-script.ts",
"../src/main/copilot/copilot-remote-hook-install.ts",
"../src/main/copilot/hook-service.ts",
"../src/main/cursor/hook-events.ts",
"../src/main/cursor/hook-script.ts",
"../src/main/cursor/hook-service.ts",
"../src/main/droid/hook-service.ts",
"../src/main/gemini/hook-service.ts",
"../src/main/grok/grok-hook-config.ts",
"../src/main/grok/grok-hook-config-cleanup.ts",
"../src/main/grok/grok-hook-config-file.ts",
"../src/main/grok/grok-hook-owners.ts",
"../src/main/grok/grok-hook-remote-install.ts",
"../src/main/grok/grok-hook-script.ts",
"../src/main/grok/grok-hook-symlink-cleanup-marker.ts",
"../src/main/grok/hook-service.ts",
"../src/main/grok/windows-grok-hook-script.ts",
"../src/main/devin/hook-settings.ts",
"../src/main/devin/hook-service.ts",
"../src/main/devin/hook-config-json.ts",
"../src/main/hermes/hermes-config-document.ts",
"../src/main/hermes/hermes-config-source-edits.ts",
"../src/main/hermes/hermes-config-yaml.ts",
"../src/main/hermes/hermes-home-filesystem.ts",
"../src/main/hermes/hermes-managed-plugin-source.ts",
"../src/main/hermes/hook-service.ts",
"../src/main/git-bash.ts",
"../src/main/in-flight-run-dedupe.ts",
"../src/main/kimi/hook-service.ts",
"../src/main/kimi/kimi-hook-config-toml.ts",
"../src/main/dsh/dsh-home-patch.ts",
"../src/main/dsh/hook-service.ts",
"../src/main/dsh/hook-settings.ts",
"../src/main/muse/hook-config-json.ts",
"../src/main/muse/hook-service.ts",
"../src/main/muse/hook-settings.ts",
"../src/main/zcode/hook-config-json.ts",
"../src/main/zcode/hook-service.ts",
"../src/main/zcode/hook-settings.ts",
"../src/main/openclaude/hook-service.ts",
"../src/main/rolling-file-backup.ts",
"../src/main/startup/hydrate-shell-path.ts",
"../src/main/startup/windows-shell-path-ownership.ts",
// Why: serve-electron-flag-parity.test.ts checks the Electron-side serve argv rewrite against this
// project's serve spec; the module has no imports, so listing it pulls in nothing else.
"../src/main/startup/serve-mode-argv.ts",
// The parity test keeps this import-free list aligned with COMMAND_SPECS.
"../src/main/startup/cli-command-names.ts",
"../src/main/runtime/runtime-metadata.ts",
"../src/main/sqlite/sync-database.ts",
"../src/main/sqlite/bun-readonly-wal.ts",
"../src/main/sqlite/sqlite-statement.ts",
"../src/main/sqlite/sqlite-integer-reader.ts",
"../src/main/sqlite/node-sqlite-statement.ts",
"../src/main/sqlite/bun-sqlite-statement.ts",
"../src/main/sqlite/bun-sqlite-database.ts",
"../src/main/win32-utils.ts"
],
"compilerOptions": {
"composite": true,
// TypeScript 7 removed node10 resolution; Node16 preserves CommonJS emit for this package.
"module": "Node16",
"moduleResolution": "Node16",
"rootDir": "../src",
"outDir": "../out"
}
}