Files
orca/src/main/linux-package-install-command.ts
T
Neil 77f23b013f refactor(shared): drop the shared/types barrel and import from the real modules (#14447)
#14397 split `shared/types.ts` into 46 per-domain modules but kept the path as
a re-export barrel so the import sites did not have to change. This removes
the barrel: every consumer now imports from the module that actually declares
the type, and `src/shared/types.ts` is deleted.

Barrels hide where a type lives, make every consumer look like it depends on
the whole domain, and let an unrelated edit invalidate a module that ~2,000
files transitively import.

2,323 import declarations across 2,321 files. Rewritten mechanically: each
specifier was resolved to an absolute path via the TypeScript AST and
recomputed, rather than string-substituted, so alias forms (`@/../../shared/
types`) and per-specifier `type` modifiers survive.

Four cases the mechanical pass had to handle, each found by a gate rather than
by reading the diff:

- Modules inside `src/shared` import the barrel as `./types`, not
  `shared/types`. A pre-filter on the latter string skipped 176 of them and
  left imports dangling at a deleted file, which surfaced as confusing
  `Property 'x' is optional in type 'Repo' but required in Pick<Repo, ...>`
  errors rather than "module not found".
- The barrel RENAMED one type on the way through
  (`WorkspaceSource as WorkspaceCreateTelemetrySource`), so the original name
  in the owning module has to be re-aliased at each consumer.
- Three test files put `;(globalThis as ...)` on the line after the import.
  TypeScript parses that `;` as the import statement's terminator, so
  replacing through `statement.getEnd()` deletes it and breaks ASI. The
  rewrite now stops at the module specifier.
- A file that already imported directly from a module got a SECOND import
  from it, because the barrel re-exported those same names — which trips
  `import/no-duplicates` under `--deny-warnings`. A post-pass merges
  declarations sharing a specifier and type-only-ness; the `import type` plus
  `import` pair from one module is left alone, since that form is allowed.

Splitting one barrel import into several genuinely adds lines, which pushed
`terminal-layout-pty-ownership.ts` to 301 counted lines: its 107-character
import must wrap, and neither local type collapses onto one line (101 and 116
characters). Rather than contort a type declaration to fit a line budget,
`collectLeafIds` and `pruneLeaves` move to `terminal-pane-layout-tree.ts` —
they are pure structural operations on the layout tree and independent of PTY
ownership. `visible-worktrees.ts` similarly loses its own mini-barrel
re-export of `isDefaultBranchWorkspace`, with the four real consumers
repointed at the declaring module. No `max-lines` bypass added.

Verified: cold `tsc --noEmit` green on node, cli, and web (buildinfo deleted
first — these projects are `composite: true` and reuse stale caches); the full
`pnpm lint` green, not just bare oxlint — the narrower local check is what let
the duplicate imports reach CI; max-lines ratchet OK at 344.
2026-08-13 22:48:24 -07:00

84 lines
3.3 KiB
TypeScript

import { statSync } from 'node:fs'
import path from 'node:path'
import type { LinuxRootPackageType } from '../shared/update-status-types'
// Why: an absolute but user-writable PATH entry must never be treated as a trusted package manager.
const TRUSTED_EXECUTABLE_DIRECTORIES = ['/usr/bin', '/bin', '/usr/sbin', '/sbin']
const DEB_PACKAGE_MANAGERS: { name: string; args: string[] }[] = [
{ name: 'apt', args: ['install', '--'] },
{ name: 'dpkg', args: ['-i', '--'] }
]
// No `--` terminator: these tools do not accept one. Safe because capture requires an absolute path,
// so the argument can never be read as an option.
const RPM_PACKAGE_MANAGERS: { name: string; args: string[] }[] = [
{
name: 'zypper',
args: ['--no-refresh', 'install', '--allow-unsigned-rpm', '-f']
},
{ name: 'dnf', args: ['install', '--nogpgcheck'] },
{ name: 'yum', args: ['install', '--nogpgcheck'] },
{ name: 'rpm', args: ['-Uvh'] }
]
export type LinuxPackageInstallCommandResult =
| { ok: true; command: string }
| { ok: false; reason: 'no-sudo' | 'no-package-manager' | 'invalid-package-path' }
/** POSIX single-quoting: the only metacharacter left is `'`, closed and re-opened around a literal. */
export function quoteForPosixShell(value: string): string {
return `'${value.split("'").join(`'"'"'`)}'`
}
/**
* Resolves an executable strictly from the trusted system directories. A symlink inside those
* directories is fine — its target is what `statSync` checks — but nothing outside them is consulted
* and no shell is ever invoked for discovery.
*/
export function resolveTrustedExecutable(name: string): string | null {
for (const directory of TRUSTED_EXECUTABLE_DIRECTORIES) {
// posix.join: these are POSIX paths, and this module only ever runs on Linux.
const candidate = path.posix.join(directory, name)
try {
const stats = statSync(candidate)
if (stats.isFile() && (stats.mode & 0o111) !== 0) {
return candidate
}
} catch {
// Absent here; keep looking in the remaining trusted directories.
}
}
return null
}
/**
* Builds the interactive command the user pastes into their own terminal. Every token except the
* package path is a fixed literal, and the path is POSIX-single-quoted — Orca never runs this.
*/
export function buildLinuxPackageInstallCommand(
packageType: LinuxRootPackageType,
packagePath: string
): LinuxPackageInstallCommandResult {
// Why: several package managers accept no `--` terminator, so a relative or dash-leading path would
// be read as an option. Hold that property here rather than relying on a caller two modules away.
if (!path.isAbsolute(packagePath)) {
return { ok: false, reason: 'invalid-package-path' }
}
const sudoPath = resolveTrustedExecutable('sudo')
if (!sudoPath) {
return { ok: false, reason: 'no-sudo' }
}
const candidates = packageType === 'deb' ? DEB_PACKAGE_MANAGERS : RPM_PACKAGE_MANAGERS
for (const candidate of candidates) {
const managerPath = resolveTrustedExecutable(candidate.name)
if (!managerPath) {
continue
}
// No -y/--noconfirm: the user must see and confirm the privileged transaction.
const tokens = [sudoPath, managerPath, ...candidate.args, quoteForPosixShell(packagePath)]
return { ok: true, command: tokens.join(' ') }
}
return { ok: false, reason: 'no-package-manager' }
}