mirror of
https://github.com/stablyai/orca.git
synced 2026-10-07 08:02:21 +00:00
Sixth and final wave over the modules that export symbols only tests import.
Deletes private-predicate cases whose behavior is already asserted through the
module's real entry point, then makes the symbol private again.
Also removes three distinct junk shapes the earlier detectors missed:
- a self-comparison whose expected empty row was produced by the helper under
test (`worktree-palette-search`), now a literal;
- expected values computed by a sibling helper rather than asserted
(`terminal-theme`), now read through the production `getBuiltinTheme`;
- a negative control that cannot fail — `expect('json' in jsonlMonarchLanguage)
.toBe(false)`, where `IMonarchLanguage` has no such key, so it guarded nothing
while appearing to guard "does not attach the JSON language service".
Dead production code removed where tests were its only callers:
`refreshWindowsTerminalCapabilities` (a one-line alias for
`loadWindowsTerminalCapabilities({force: true})`), `readSpoolRecords`,
`buildAgentPromptSubmitBytes`, and `getCommitMessageModelCapability`.
About 70% of everything this detector flagged across the whole vein was a false
positive, so most modules were left untouched. Bounds consumed as test input,
`*ForTests` seams, non-hook cores of `useSyncExternalStore` hooks, and
value-position registrations all look identical to a leaked internal from the
outside and are not.
60 lines
2.1 KiB
TypeScript
60 lines
2.1 KiB
TypeScript
import { z } from 'zod'
|
|
import { isQualifiedPluginKey } from './plugin-manifest'
|
|
|
|
export const PLUGIN_KILL_LIST_ENTRY_LIMIT = 4_096
|
|
/** Publisher clocks and client clocks disagree by minutes, never by days. */
|
|
export const PLUGIN_KILL_LIST_FUTURE_SKEW_MS = 24 * 60 * 60 * 1000
|
|
|
|
const advisoryUrlSchema = z
|
|
.string()
|
|
.url()
|
|
.max(2_048)
|
|
.refine((value) => new URL(value).protocol === 'https:', 'advisory URL must use HTTPS')
|
|
|
|
export const pluginKillListEntrySchema = z.strictObject({
|
|
pluginKey: z.string().refine(isQualifiedPluginKey, 'invalid qualified plugin key'),
|
|
reason: z.string().min(1).max(1_024),
|
|
advisoryUrl: advisoryUrlSchema.optional()
|
|
})
|
|
|
|
export const pluginKillListSchema = z
|
|
.strictObject({
|
|
version: z.literal(1),
|
|
generatedAt: z.string().datetime({ offset: true }),
|
|
plugins: z.array(pluginKillListEntrySchema).max(PLUGIN_KILL_LIST_ENTRY_LIMIT)
|
|
})
|
|
.superRefine((killList, context) => {
|
|
const seen = new Set<string>()
|
|
for (const [index, plugin] of killList.plugins.entries()) {
|
|
if (seen.has(plugin.pluginKey)) {
|
|
context.addIssue({
|
|
code: z.ZodIssueCode.custom,
|
|
path: ['plugins', index, 'pluginKey'],
|
|
message: `duplicate killed plugin: ${plugin.pluginKey}`
|
|
})
|
|
}
|
|
seen.add(plugin.pluginKey)
|
|
}
|
|
})
|
|
|
|
export type PluginKillList = z.infer<typeof pluginKillListSchema>
|
|
export type PluginKillListEntry = z.infer<typeof pluginKillListEntrySchema>
|
|
|
|
/** A far-future generatedAt makes every genuine later list look "older" and
|
|
* disables revocation permanently. Checked only on freshly fetched snapshots:
|
|
* a cached list was already accepted once, and re-judging it against the
|
|
* device clock would drop live revocations whenever that clock runs slow. */
|
|
export function isPluginKillListTooFarInFuture(
|
|
killList: PluginKillList,
|
|
now = Date.now()
|
|
): boolean {
|
|
return Date.parse(killList.generatedAt) > now + PLUGIN_KILL_LIST_FUTURE_SKEW_MS
|
|
}
|
|
|
|
export function findKilledPlugin(
|
|
killList: PluginKillList,
|
|
pluginKey: string
|
|
): PluginKillListEntry | null {
|
|
return killList.plugins.find((plugin) => plugin.pluginKey === pluginKey) ?? null
|
|
}
|