Files
orca/src/shared/remote-runtime-request-connection.test.ts
T
NeilandOrca 46646d7ff1 chore(lint): upgrade oxlint to 1.71 + enable 7 new rules (autofixed backlog) (#6841)
* chore(lint): upgrade oxlint to 1.71 and enable 7 new rules

Upgrade oxlint 1.67.0 -> 1.71.0 (1.72 was blocked by the repo's 3-day
minimum-release-age supply-chain guard; nothing here needs it). The
bump is a no-op on the existing config.

Enable 3 error rules (backlog autofixed to zero in this commit) and
4 warn rules (surface signal without gating CI):

error (autofixed, behavior-preserving):
- unicorn/prefer-node-protocol        (~1531 sites: bare builtin -> node:)
- typescript/no-import-type-side-effects (~36: all-inline-type -> import type)
- unicorn/no-array-reverse            (19: copy-then-reverse -> toReversed)

warn (real signal, current fires are test-only/correct):
- unicorn/no-array-fill-with-reference-type  (aliasing footgun guard)
- typescript/no-unsafe-function-type         (bans bare Function type)
- unicorn/prefer-array-flat-map              (map().flat() -> flatMap())
- unicorn/prefer-regexp-test                 (.match() in bool ctx -> .test())

mobile/.oxlintrc.json extends root, so it inherits all 7; the autofix
ran from root and covered mobile/ too.

Verification (all green): oxlint 0 errors (root+mobile+aux configs),
oxfmt clean, typecheck (node+cli+web), vitest 22795 passed / 0 failed,
builds (electron-vite + web + cli) succeed. node: rewrites confirmed to
skip embedded SSH/CLI string payloads (AST-only); all toReversed sites
verified to operate on fresh copies or write-once locals.

* chore(lint): bump mobile oxlint to 1.71 so inherited rules parse

mobile/ is a standalone pnpm project pinning its own oxlint@1.67, which
lacks unicorn/no-array-fill-with-reference-type (needs >=1.70). Since
mobile/.oxlintrc.json extends the root config, mobile CI's 'cd mobile &&
oxlint' failed to parse the new rule. Bump mobile to match root (1.71).

Verified in mobile/: oxlint 0 errors, oxfmt --check clean, tsc --noEmit
pass, vitest 978 passed / 0 failed.

Co-authored-by: Orca <help@stably.ai>

---------

Co-authored-by: Orca <help@stably.ai>
2026-06-29 22:38:29 -07:00

143 lines
4.0 KiB
TypeScript

import type { AddressInfo } from 'node:net'
import { afterEach, describe, expect, it } from 'vitest'
import { WebSocketServer, type WebSocket } from 'ws'
import { encodePairingOffer, parsePairingCode, type PairingOffer } from './pairing'
import {
decrypt,
deriveSharedKey,
encrypt,
generateKeyPair,
publicKeyFromBase64,
publicKeyToBase64
} from './e2ee-crypto'
import { RemoteRuntimeRequestConnection } from './remote-runtime-request-connection'
type TestServer = {
wss: WebSocketServer
pairing: PairingOffer
requests: unknown[]
connectionCount: () => number
}
const servers: WebSocketServer[] = []
afterEach(async () => {
await Promise.all(
servers.splice(0).map(
(server) =>
new Promise<void>((resolve) => {
for (const client of server.clients) {
client.close()
}
server.close(() => resolve())
})
)
)
})
describe('RemoteRuntimeRequestConnection', () => {
it('reuses one encrypted WebSocket for multiple one-shot RPCs', async () => {
const server = await createServer()
const connection = new RemoteRuntimeRequestConnection(server.pairing)
const first = await connection.request('status.get', undefined, 1000)
const second = await connection.request('terminal.send', { terminal: 't1', text: 'ab' }, 1000)
expect(first).toMatchObject({
ok: true,
result: { method: 'status.get' },
_meta: { runtimeId: 'runtime-test' }
})
expect(second).toMatchObject({
ok: true,
result: { method: 'terminal.send' },
_meta: { runtimeId: 'runtime-test' }
})
expect(server.connectionCount()).toBe(1)
expect(server.requests).toMatchObject([
{ method: 'status.get' },
{ method: 'terminal.send', params: { terminal: 't1', text: 'ab' } }
])
connection.close()
})
})
async function createServer(): Promise<TestServer> {
const serverKeyPair = generateKeyPair()
const requests: unknown[] = []
let connectionCount = 0
const wss = new WebSocketServer({ port: 0 })
servers.push(wss)
wss.on('connection', (ws) => {
connectionCount += 1
let sharedKey: Uint8Array | null = null
let authenticated = false
ws.on('message', (data, isBinary) => {
if (isBinary) {
return
}
const frame = data.toString()
if (!sharedKey) {
const hello = JSON.parse(frame) as { type: string; publicKeyB64: string }
const clientPublicKey = publicKeyFromBase64(hello.publicKeyB64)
sharedKey = deriveSharedKey(serverKeyPair.secretKey, clientPublicKey)
ws.send(JSON.stringify({ type: 'e2ee_ready' }))
return
}
const plaintext = decrypt(frame, sharedKey)
if (plaintext === null) {
return
}
if (!authenticated) {
const auth = JSON.parse(plaintext) as { type: string; deviceToken: string }
expect(auth).toEqual({ type: 'e2ee_auth', deviceToken: 'device-token' })
authenticated = true
sendEncrypted(ws, sharedKey, { type: 'e2ee_authenticated' })
return
}
const request = JSON.parse(plaintext) as {
id: string
method: string
params?: unknown
}
requests.push(request)
sendEncrypted(ws, sharedKey, {
id: request.id,
ok: true,
result: { method: request.method },
_meta: { runtimeId: 'runtime-test' }
})
})
})
await new Promise<void>((resolve) => wss.once('listening', resolve))
const address = wss.address() as AddressInfo
const pairing = parsePairingCode(
encodePairingOffer({
v: 2,
endpoint: `ws://127.0.0.1:${address.port}`,
deviceToken: 'device-token',
publicKeyB64: publicKeyToBase64(serverKeyPair.publicKey)
})
)
if (!pairing) {
throw new Error('Failed to create test pairing')
}
return {
wss,
pairing,
requests,
connectionCount: () => connectionCount
}
}
function sendEncrypted(ws: WebSocket, sharedKey: Uint8Array, message: unknown): void {
ws.send(encrypt(JSON.stringify(message), sharedKey))
}