Files
orca/src/shared/plugins/plugin-kill-list.ts
T
Neil bb667a33bd test: retire the last private-predicate duplicates in the leaked-internals sweep (#23949)
Sixth and final wave over the modules that export symbols only tests import.
Deletes private-predicate cases whose behavior is already asserted through the
module's real entry point, then makes the symbol private again.

Also removes three distinct junk shapes the earlier detectors missed:
- a self-comparison whose expected empty row was produced by the helper under
  test (`worktree-palette-search`), now a literal;
- expected values computed by a sibling helper rather than asserted
  (`terminal-theme`), now read through the production `getBuiltinTheme`;
- a negative control that cannot fail — `expect('json' in jsonlMonarchLanguage)
  .toBe(false)`, where `IMonarchLanguage` has no such key, so it guarded nothing
  while appearing to guard "does not attach the JSON language service".

Dead production code removed where tests were its only callers:
`refreshWindowsTerminalCapabilities` (a one-line alias for
`loadWindowsTerminalCapabilities({force: true})`), `readSpoolRecords`,
`buildAgentPromptSubmitBytes`, and `getCommitMessageModelCapability`.

About 70% of everything this detector flagged across the whole vein was a false
positive, so most modules were left untouched. Bounds consumed as test input,
`*ForTests` seams, non-hook cores of `useSyncExternalStore` hooks, and
value-position registrations all look identical to a leaked internal from the
outside and are not.
2026-09-29 17:04:42 -07:00

60 lines
2.1 KiB
TypeScript

import { z } from 'zod'
import { isQualifiedPluginKey } from './plugin-manifest'
export const PLUGIN_KILL_LIST_ENTRY_LIMIT = 4_096
/** Publisher clocks and client clocks disagree by minutes, never by days. */
export const PLUGIN_KILL_LIST_FUTURE_SKEW_MS = 24 * 60 * 60 * 1000
const advisoryUrlSchema = z
.string()
.url()
.max(2_048)
.refine((value) => new URL(value).protocol === 'https:', 'advisory URL must use HTTPS')
export const pluginKillListEntrySchema = z.strictObject({
pluginKey: z.string().refine(isQualifiedPluginKey, 'invalid qualified plugin key'),
reason: z.string().min(1).max(1_024),
advisoryUrl: advisoryUrlSchema.optional()
})
export const pluginKillListSchema = z
.strictObject({
version: z.literal(1),
generatedAt: z.string().datetime({ offset: true }),
plugins: z.array(pluginKillListEntrySchema).max(PLUGIN_KILL_LIST_ENTRY_LIMIT)
})
.superRefine((killList, context) => {
const seen = new Set<string>()
for (const [index, plugin] of killList.plugins.entries()) {
if (seen.has(plugin.pluginKey)) {
context.addIssue({
code: z.ZodIssueCode.custom,
path: ['plugins', index, 'pluginKey'],
message: `duplicate killed plugin: ${plugin.pluginKey}`
})
}
seen.add(plugin.pluginKey)
}
})
export type PluginKillList = z.infer<typeof pluginKillListSchema>
export type PluginKillListEntry = z.infer<typeof pluginKillListEntrySchema>
/** A far-future generatedAt makes every genuine later list look "older" and
* disables revocation permanently. Checked only on freshly fetched snapshots:
* a cached list was already accepted once, and re-judging it against the
* device clock would drop live revocations whenever that clock runs slow. */
export function isPluginKillListTooFarInFuture(
killList: PluginKillList,
now = Date.now()
): boolean {
return Date.parse(killList.generatedAt) > now + PLUGIN_KILL_LIST_FUTURE_SKEW_MS
}
export function findKilledPlugin(
killList: PluginKillList,
pluginKey: string
): PluginKillListEntry | null {
return killList.plugins.find((plugin) => plugin.pluginKey === pluginKey) ?? null
}