Files
orca/src/main/appimage-runtime-identity.test.ts
T
Neil c7218f20dc test: retire src/main/runtime cases that re-prove an owned contract (#24043)
Completes the `src/main` audit. Sweep over `src/main/runtime` (flat, rpc,
orchestration, relay, push) and flat `src/main`. 42 case declarations removed
across 24 files, 783 lines gone. No file deleted whole, no production code touched.

Highest-yield area by far was `runtime/orchestration` (21 cases from 151 files);
the rest of runtime measured under 1%.

What went, by pattern:

- Tests whose subject is the test itself: a source-scanning boundary test with no
  production import at all, three of whose cases checked its own regex against
  strings it declares; and a benchmark whose own simulation contains the
  short-circuit it asserts, with `expect(wouldHaveBeen).toBe(60000)` comparing the
  test's own arithmetic.
- Identity copiers: seven db cases where every asserted value is the literal input
  (`type: 'question'` in, `type === 'question'` out).
- Permanently skipped tests for behavior that does not exist — two cases carrying
  `// TODO: inline restore on re-subscribe not yet implemented`. A skipped test for
  an unimplemented feature can never fail; it is a note in test syntax.
- Duplicate invocations of a contract owned at a stronger boundary, including three
  reset scopes and two dependency-promotion cases owned by dedicated suites.
- Registration manifests whose every entry is referenced by other tests.
- Table rows and cases varying a field production never reads: a mobile tab-restore
  case varying `clientCapabilities`, which the mobile branch does not consult, and
  a Windows worker case in a module with no platform input at all.
- Names promising more than the input exercises: a case titled for forged AppImage
  variables whose body only removes `AppRun`, byte-identical to a row of the
  `it.each` table twenty lines above.
- Negative controls passing for an unrelated reason: a foreign-pane rejection whose
  fixture also differs in sender handle, so the handle guard can reject it.
- Self-comparisons, including `format(m, { authority: 'current' }) === format(m)`.

Two deletions were justified by the wrong argument and kept only after checking a
better one. "A generated-catalog check gates registration" is false: that script
prevents the catalog and dispatcher from drifting apart, so a developer who removes
a method regenerates the catalog and the check passes. Like a type annotation over
an interface and its implementing class, it verifies internal consistency and
cannot see a declaration and its use removed together. Both inventories go on
per-entry evidence instead — every name is referenced by other tests.

The same rule kept a 37-entry terminal-method inventory in the same wave, because
some of its entries are pinned solely by it. An inventory is a ratchet if and only
if at least one entry is pinned solely by it; that is evidence per entry, not a
verdict by shape.

Kept deliberately: everything a gate cites, checked by case title and not only by
file path; source-scanning ratchets that pair their negative assertion with a
positive one against real source (the surviving boundary case asserts the pattern
still matches the writer module, so a silently-broken regex goes red); a
destructive-delete PTY waiver guard; `it.fails` markers, which go red if the bug is
fixed; and `it.skipIf(platform)` cases, which do run on other hosts.

Coverage is partial and stated as such: 1,195 files in scope, roughly 660 read
case-by-case, the remainder title-scanned and mechanically triaged. Unread paths are
recorded for a later sweep rather than assumed clean.

Verified: `check-reliability-gates.mjs` (140 gates), `check:code-quality:changed`
(0 new findings). No `pnpm tc` needed since no production file changed. A local run
of `src/main` surfaced 42 failures in three files this change does not touch
(`browser-manager-tab-identity`, `browser-manager-viewport-ownership`,
`session-scanner-codex-workers`); all 42 reproduce on a pristine `origin/main`
worktree, so they predate this wave and are environment-dependent locally — CI was
green on main at `2d85fdc753e2`.
2026-09-30 00:05:55 -07:00

235 lines
7.8 KiB
TypeScript

import {
chmodSync,
mkdirSync,
mkdtempSync,
renameSync,
rmSync,
symlinkSync,
writeFileSync
} from 'node:fs'
import { tmpdir } from 'node:os'
import { dirname, join } from 'node:path'
import { afterEach, describe, expect, it } from 'vitest'
import {
hasAppImagePathEnvironment,
resolveAppImageRuntimeIdentity
} from './appimage-runtime-identity'
const fixtureRoots: string[] = []
function appImageHeader(machine: number): Buffer {
const header = Buffer.alloc(64)
header.set([0x7f, 0x45, 0x4c, 0x46, 0x02, 0x01, 0x01])
header.set([0x41, 0x49, 0x02], 8)
header.writeUInt16LE(machine, 18)
return header
}
function createFixture(appDirName = '.mount_Orca123', machine = 0x3e) {
const root = mkdtempSync(join(tmpdir(), 'orca-appimage-identity-'))
const appImagePath = join(root, 'Applications', 'Orca.AppImage')
const appDirPath = join(root, appDirName)
const execPath = join(appDirPath, 'orca-ide')
const resourcesPath = join(appDirPath, 'resources')
const packageTypePath = join(resourcesPath, 'package-type')
const packageMarkerPath = join(resourcesPath, 'app.asar.unpacked', 'out', 'package.json')
fixtureRoots.push(root)
mkdirSync(dirname(appImagePath), { recursive: true })
mkdirSync(dirname(packageMarkerPath), { recursive: true })
writeFileSync(appImagePath, appImageHeader(machine), { mode: 0o755 })
writeFileSync(join(appDirPath, 'AppRun'), '#!/bin/sh\n', { mode: 0o755 })
writeFileSync(execPath, appImageHeader(machine), { mode: 0o755 })
writeFileSync(
packageMarkerPath,
JSON.stringify({ name: 'orca-compiled-output', type: 'commonjs', private: true })
)
return {
root,
appImagePath,
appDirPath,
execPath,
resourcesPath,
packageTypePath,
packageMarkerPath,
identity: {
platform: 'linux' as const,
environment: { APPIMAGE: appImagePath, APPDIR: appDirPath },
execPath,
resourcesPath
}
}
}
afterEach(() => {
for (const root of fixtureRoots.splice(0)) {
rmSync(root, { recursive: true, force: true })
}
})
describe.skipIf(process.platform === 'win32')('resolveAppImageRuntimeIdentity', () => {
it.each([
['x64', 0x3e, '.mount_Orca123'],
['ARM64 extract-and-run', 0xb7, 'appimage_extracted_123']
])('accepts a complete %s AppImage runtime', (_architecture, machine, appDirName) => {
const fixture = createFixture(appDirName, machine)
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toEqual({
appImagePath: fixture.appImagePath
})
})
it('accepts an AppImage moved independently of its runtime directory', () => {
const fixture = createFixture()
const movedPath = join(fixture.root, 'Moved Apps', 'Orca current.AppImage')
mkdirSync(dirname(movedPath), { recursive: true })
renameSync(fixture.appImagePath, movedPath)
fixture.identity.environment.APPIMAGE = movedPath
expect(resolveAppImageRuntimeIdentity(fixture.identity)?.appImagePath).toBe(movedPath)
})
it('accepts the exact AppImage package-type marker', () => {
const fixture = createFixture()
rmSync(fixture.packageMarkerPath)
writeFileSync(fixture.packageTypePath, 'AppImage')
expect(resolveAppImageRuntimeIdentity(fixture.identity)).not.toBeNull()
})
it.each([
['APPIMAGE', undefined],
['APPIMAGE', 'relative/Orca.AppImage'],
['APPDIR', undefined],
['APPDIR', 'relative/mount'],
['APPIMAGE', '/tmp/Orca\0.AppImage']
] as const)('rejects an unusable %s value', (key, value) => {
const fixture = createFixture()
expect(
resolveAppImageRuntimeIdentity({
...fixture.identity,
environment: { ...fixture.identity.environment, [key]: value }
})
).toBeNull()
})
it.each([
['an ordinary executable', (path: string) => writeFileSync(path, '#!/bin/sh\n')],
[
'bad ELF magic',
(path: string) => {
const header = appImageHeader(0x3e)
header[0] = 0
writeFileSync(path, header)
}
],
[
'bad AppImage type magic',
(path: string) => {
const header = appImageHeader(0x3e)
header[10] = 1
writeFileSync(path, header)
}
],
['a non-executable file', (path: string) => chmodSync(path, 0o644)],
[
'a directory',
(path: string) => {
rmSync(path)
mkdirSync(path)
}
]
])('rejects APPIMAGE pointing to %s', (_case, mutate) => {
const fixture = createFixture()
mutate(fixture.appImagePath)
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toBeNull()
})
it.each([
[
'AppRun',
(fixture: ReturnType<typeof createFixture>) => rmSync(join(fixture.appDirPath, 'AppRun'))
],
[
'an executable AppRun',
(fixture: ReturnType<typeof createFixture>) =>
chmodSync(join(fixture.appDirPath, 'AppRun'), 0o644)
],
[
'the Orca package marker',
(fixture: ReturnType<typeof createFixture>) => rmSync(fixture.packageMarkerPath)
]
])('rejects a runtime missing %s', (_case, mutate) => {
const fixture = createFixture()
mutate(fixture)
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toBeNull()
})
it('rejects a package marker for a different application', () => {
const fixture = createFixture()
writeFileSync(
fixture.packageMarkerPath,
JSON.stringify({ name: 'foreign-compiled-output', type: 'commonjs' })
)
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toBeNull()
})
it('rejects an inexact package-type marker without the Orca fallback', () => {
const fixture = createFixture()
rmSync(fixture.packageMarkerPath)
writeFileSync(fixture.packageTypePath, 'appimage')
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toBeNull()
})
it('rejects payload evidence that resolves outside APPDIR', () => {
const fixture = createFixture()
const externalAppRun = join(fixture.root, 'foreign-AppRun')
writeFileSync(externalAppRun, '#!/bin/sh\n', { mode: 0o755 })
rmSync(join(fixture.appDirPath, 'AppRun'))
symlinkSync(externalAppRun, join(fixture.appDirPath, 'AppRun'))
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toBeNull()
})
it('rejects a package marker that resolves outside APPDIR', () => {
const fixture = createFixture()
const externalMarker = join(fixture.root, 'foreign-package.json')
writeFileSync(
externalMarker,
JSON.stringify({ name: 'orca-compiled-output', type: 'commonjs' })
)
rmSync(fixture.packageMarkerPath)
symlinkSync(externalMarker, fixture.packageMarkerPath)
expect(resolveAppImageRuntimeIdentity(fixture.identity)).toBeNull()
})
it('rejects inherited AppImage variables around a non-AppImage executable', () => {
const fixture = createFixture()
expect(
resolveAppImageRuntimeIdentity({
...fixture.identity,
execPath: join(fixture.root, 'opt', 'Orca', 'orca-ide'),
resourcesPath: join(fixture.root, 'opt', 'Orca', 'resources')
})
).toBeNull()
})
it('rejects a resources path outside the runtime root', () => {
const fixture = createFixture()
expect(
resolveAppImageRuntimeIdentity({
...fixture.identity,
resourcesPath: `${fixture.appDirPath}-other/resources`
})
).toBeNull()
})
it('rejects the identity off Linux', () => {
const fixture = createFixture()
expect(resolveAppImageRuntimeIdentity({ ...fixture.identity, platform: 'darwin' })).toBeNull()
})
})
describe('hasAppImagePathEnvironment', () => {
it('requires the AppImage file path before treating the runtime as verifiable', () => {
expect(hasAppImagePathEnvironment({ APPIMAGE: '/tmp/Orca.AppImage' })).toBe(true)
expect(hasAppImagePathEnvironment({ APPDIR: '/tmp/.mount_Orca123' })).toBe(false)
expect(hasAppImagePathEnvironment({ APPIMAGE: '', APPDIR: '/tmp/.mount_Orca123' })).toBe(false)
})
})