Files
orca/src/preload/window-close-request-subscription.ts
T
Brennan Benson 84bbf3b540 test(preload): pin the one hop that keeps a malformed survival answer from skipping the quit warning
The rule that only an explicit yes is a yes had two expressions. The one in
resolveLocalPtysSurviveQuit answers a typed in-process getter with a single
production call site whose every path returns a boolean literal: instrumented
across 35,022 tests it was evaluated 6 times, saw 'boolean' 6 times, and
discriminated 0 times, and both deleting the check and swapping it for Boolean()
reddened 0 of 115 while inverting it reddened 5. Deleted, since even a type
violation there is caught downstream.

The expression that survives is readWindowCloseRequestPayload, on the IPC hop
where the answer really is unknown. Its own tests were green, but its only
production call site was inline in the api object and no test in the tree
imported it — forwarding the raw payload instead reddened 0 of 11,136. Extracted
so the hop is reachable, and pinned: bypassing the reader now reddens 7,
weakening it to Boolean() 5, acking after the callback 1, echoing a raw
requestId 1, and dropping the unsubscribe 1.
2026-08-29 01:33:31 -07:00

37 lines
1.7 KiB
TypeScript

import type { IpcRenderer } from 'electron'
import {
readWindowCloseRequestPayload,
type WindowCloseRequestPayload
} from '../shared/window-close-request'
const CLOSE_REQUESTED_CHANNEL = 'window:close-requested'
const CLOSE_REQUEST_RECEIVED_CHANNEL = 'window:close-request-received'
/**
* Subscribes the renderer to main's `window:close-requested`.
*
* Why the payload is read here and not forwarded: this is the only boundary the
* survival answer crosses untyped, and the renderer spends
* `localPtysSurviveQuit: true` as permission to close over running work with no
* warning. So the rule that only an explicit yes is a yes lives once, in
* `readWindowCloseRequestPayload`, and this is its single call site — forwarding
* the raw payload would restore the unconditional quit bypass for anything that
* is not a clean boolean (docs/reference/ssh-execution-boundary.md).
*
* Extracted from the api object so that hop is reachable by a test at all; while
* it was inline in index.ts nothing in the tree could observe it.
*/
export function subscribeToWindowCloseRequest(
ipcRenderer: Pick<IpcRenderer, 'on' | 'removeListener' | 'send'>,
callback: (data: WindowCloseRequestPayload) => void
): () => void {
const listener = (_event: Electron.IpcRendererEvent, data: unknown): void => {
const payload = readWindowCloseRequestPayload(data)
// Why: main cannot reach will-quit while a frozen renderer owns the window close handshake.
ipcRenderer.send(CLOSE_REQUEST_RECEIVED_CHANNEL, payload.requestId)
callback(payload)
}
ipcRenderer.on(CLOSE_REQUESTED_CHANNEL, listener)
return () => ipcRenderer.removeListener(CLOSE_REQUESTED_CHANNEL, listener)
}