Files
orca/tests/e2e/helpers/electron-home-isolation.unit.test.ts
T
Brennan Benson 4c49989c2e refactor(codex): delete the unreachable managed shared-mirror lane (#12614)
PR 9501 shipped real-home routing for the host system default, and the
env override that could turn it back off was never a shipped control. The
managed-account half of the shared runtime mirror has been unreachable
since: every host account routes to its own self-contained CODEX_HOME
before that code runs.

Delete the flag module and its env plumbing plus the managed branch of
syncForCurrentSelection and the six helpers only it called. The three
lanes that still use the shared mirror -- Windows, a custom CODEX_HOME,
and a hook-lane gate that reports unusable -- are untouched, as are every
legacy migration and the WSL read-back helpers.
2026-08-05 12:57:02 -07:00

91 lines
2.9 KiB
TypeScript

import { mkdtempSync, realpathSync, rmSync } from 'node:fs'
import os from 'node:os'
import path from 'node:path'
import { afterEach, describe, expect, it } from 'vitest'
import {
areSameHomePath,
assertElectronResolvedIsolatedHome,
createElectronHomeIsolation
} from './electron-home-isolation'
const tempDirs: string[] = []
afterEach(() => {
for (const tempDir of tempDirs.splice(0)) {
rmSync(tempDir, { recursive: true, force: true })
}
})
function createUserDataDir(): string {
const tempDir = mkdtempSync(path.join(os.tmpdir(), 'orca-home-isolation-test-'))
tempDirs.push(tempDir)
return tempDir
}
describe('createElectronHomeIsolation', () => {
it('strips ambient home and Codex state before forcing a disposable home', () => {
const userDataDir = createUserDataDir()
const isolation = createElectronHomeIsolation({
inheritedEnv: {
HOME: '/real/home',
USERPROFILE: '/real/home',
CODEX_HOME: '/real/codex',
ORCA_CODEX_HOME: '/real/orca-codex',
ZDOTDIR: '/real/zdotdir',
PATH: '/bin'
},
launchEnv: { TEST_TOKEN: 'safe' },
extraEnv: { EXTRA_TEST_FLAG: '1' },
userDataDir,
realHome: '/real/home'
})
// Why: the disposable home must be the canonical spelling (no tmpdir
// symlink/8.3 alias) or git-canonicalized worktree paths stop matching.
const canonicalHome = realpathSync.native(path.join(userDataDir, 'home'))
expect(isolation.isolatedHome).toBe(canonicalHome)
expect(isolation.env).toMatchObject({
PATH: '/bin',
TEST_TOKEN: 'safe',
EXTRA_TEST_FLAG: '1',
HOME: canonicalHome,
USERPROFILE: canonicalHome,
ORCA_E2E_USER_DATA_DIR: userDataDir
})
expect(isolation.env.CODEX_HOME).toBeUndefined()
expect(isolation.env.ORCA_CODEX_HOME).toBeUndefined()
expect(isolation.env.ZDOTDIR).toBeUndefined()
// Codex always routes to the resolved home, so the post-launch guard must
// accept the boundary this env produces.
expect(() =>
assertElectronResolvedIsolatedHome(isolation.isolatedHome, isolation)
).not.toThrow()
})
it('rejects generic fixture overlays that could escape the boundary', () => {
expect(() =>
createElectronHomeIsolation({
inheritedEnv: {},
launchEnv: { CODEX_HOME: '/unsafe' },
extraEnv: {},
userDataDir: createUserDataDir(),
realHome: '/real/home'
})
).toThrow(/launchEnv\.CODEX_HOME/)
expect(() =>
createElectronHomeIsolation({
inheritedEnv: {},
launchEnv: {},
extraEnv: { ORCA_E2E_USER_DATA_DIR: '/unsafe' },
userDataDir: createUserDataDir(),
realHome: '/real/home'
})
).toThrow(/orcaAppExtraEnv\.ORCA_E2E_USER_DATA_DIR/)
})
it('compares Windows home paths case-insensitively', () => {
expect(areSameHomePath('C:\\Users\\Alice', 'c:\\users\\alice', 'win32')).toBe(true)
})
})