mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 00:02:10 +00:00
* docs(security): add the antivirus clearance path for future releases Every AV false positive here has been handled one vendor and one shipped version at a time. Document the programs that clear future releases instead -- signer and product enrollment rather than per-build sample submission -- and add a script that reports an RC's current detection state by hash, so a verdict is found before users meet it in an issue report. Hash lookup only by default; --upload transmits the artifact and stays manual. * fix(windows): replace the managed CLI launcher with a native one resources\bin\orca.exe was a csc-compiled MSIL assembly: a small, freshly compiled .NET image in a user-writable directory that mutates environment variables and proxies a child process. That is the shape .NET dropper heuristics are trained on, and every verdict against it named the family -- MSILHeracles from two vendors, Wacatac!ml from a third. Signing the file does not change its shape, so signing never cleared it. Rebuild it in Rust. Same resolution, same environment contract, same argv passthrough that keeps newline-bearing orchestration bodies intact (#8374), and the child still inherits our environment block rather than an explicit map, so a block carrying both PATH and Path survives (#12046). The PE now carries publisher, version, icon and an asInvoker manifest from build.rs. Refs #23383 * ci(windows): install the Rust toolchain before building the CLI launcher The hosted runners happen to ship cargo, but a real Windows dev box does not -- verified on our own Windows QA host, where cargo and rustc were both absent. Relying on the image means a future image change fails deep inside electron-builder's native hook instead of at an obvious step.
310 lines
12 KiB
JavaScript
310 lines
12 KiB
JavaScript
import {
|
|
copyFileSync,
|
|
existsSync,
|
|
mkdirSync,
|
|
mkdtempSync,
|
|
readFileSync,
|
|
rmSync,
|
|
utimesSync,
|
|
writeFileSync
|
|
} from 'node:fs'
|
|
import { tmpdir } from 'node:os'
|
|
import { dirname, join, resolve } from 'node:path'
|
|
import { spawnSync } from 'node:child_process'
|
|
import { describe, expect, it } from 'vitest'
|
|
import {
|
|
shouldReuseCompiledWindowsCliLauncher,
|
|
windowsCliLauncherFileVersion,
|
|
windowsCliLauncherFingerprint
|
|
} from './build-windows-cli-launcher.mjs'
|
|
|
|
const itCrossHost = process.platform === 'win32' ? it.skip : it
|
|
const projectRoot = resolve(import.meta.dirname, '../..')
|
|
const WINDOWS_LOCK_CODES = ['EBUSY', 'ENOTEMPTY', 'EPERM']
|
|
|
|
// Why: Windows releases the image handle on a just-executed exe (and finishes the
|
|
// AV scan of the freshly compiled one) after the process exits, so tearing down the
|
|
// fixture races those locks. Retry, then leave the temp tree rather than reporting a
|
|
// teardown lock as a launcher failure.
|
|
function removeFixtureTree(path) {
|
|
try {
|
|
rmSync(path, { recursive: true, force: true, maxRetries: 10, retryDelay: 100 })
|
|
} catch (error) {
|
|
if (process.platform !== 'win32' || !WINDOWS_LOCK_CODES.includes(error?.code)) {
|
|
throw error
|
|
}
|
|
}
|
|
}
|
|
// Why: a cold cargo build compiles the resource crate and links from scratch,
|
|
// which far exceeds Vitest's 5s unit budget on a hosted Windows runner. Later
|
|
// cases reuse the shared target directory, so only the first pays it.
|
|
function itWindows(name, test) {
|
|
const runner = process.platform === 'win32' ? it : it.skip
|
|
runner(name, { timeout: 300_000 }, test)
|
|
}
|
|
|
|
describe('Windows CLI launcher', () => {
|
|
it('reuses restored builds only while all embedded inputs and the release version match', () => {
|
|
const root = mkdtempSync(join(tmpdir(), 'orca-cli-launcher-reuse-'))
|
|
try {
|
|
const inputs = ['main.rs', 'build.rs', 'Cargo.toml', 'app.manifest', 'icon.ico'].map(
|
|
(name) => {
|
|
const path = join(root, name)
|
|
writeFileSync(path, name)
|
|
return path
|
|
}
|
|
)
|
|
const outputPath = join(root, 'orca.exe')
|
|
const fingerprint = windowsCliLauncherFingerprint(inputs, '1.4.214')
|
|
expect(shouldReuseCompiledWindowsCliLauncher(outputPath, fingerprint)).toBe(false)
|
|
writeFileSync(outputPath, 'binary')
|
|
expect(shouldReuseCompiledWindowsCliLauncher(outputPath, fingerprint)).toBe(false)
|
|
writeFileSync(`${outputPath}.sha256`, fingerprint)
|
|
for (const input of inputs) {
|
|
utimesSync(input, new Date(), new Date())
|
|
}
|
|
expect(
|
|
shouldReuseCompiledWindowsCliLauncher(
|
|
outputPath,
|
|
windowsCliLauncherFingerprint(inputs, '1.4.214')
|
|
)
|
|
).toBe(true)
|
|
expect(
|
|
shouldReuseCompiledWindowsCliLauncher(
|
|
outputPath,
|
|
windowsCliLauncherFingerprint(inputs, '1.4.215')
|
|
)
|
|
).toBe(false)
|
|
for (const input of inputs) {
|
|
const original = readFileSync(input)
|
|
writeFileSync(input, 'changed')
|
|
expect(
|
|
shouldReuseCompiledWindowsCliLauncher(
|
|
outputPath,
|
|
windowsCliLauncherFingerprint(inputs, '1.4.214')
|
|
)
|
|
).toBe(false)
|
|
writeFileSync(input, original)
|
|
}
|
|
} finally {
|
|
removeFixtureTree(root)
|
|
}
|
|
})
|
|
|
|
it('reduces a prerelease to the numeric version Windows can record', () => {
|
|
expect(windowsCliLauncherFileVersion('1.4.214-daily.202609281300')).toBe('1.4.214.0')
|
|
expect(windowsCliLauncherFileVersion('1.4.214')).toBe('1.4.214.0')
|
|
for (const version of ['1.4.65535', '1.4', '1.4.214"', undefined]) {
|
|
expect(() => windowsCliLauncherFileVersion(version)).toThrow('Invalid Windows')
|
|
}
|
|
})
|
|
|
|
itWindows(
|
|
'embeds publisher, release version, icon and an unelevated application manifest',
|
|
() => {
|
|
const root = mkdtempSync(join(tmpdir(), 'orca launcher metadata '))
|
|
try {
|
|
const launcherPath = join(root, 'orca.exe')
|
|
const build = spawnSync(
|
|
process.execPath,
|
|
['config/scripts/build-windows-cli-launcher.mjs', '--output', launcherPath],
|
|
{ cwd: projectRoot, encoding: 'utf8' }
|
|
)
|
|
expect(build.status, `${build.stdout}\n${build.stderr}`).toBe(0)
|
|
const inspect = spawnSync(
|
|
'powershell.exe',
|
|
[
|
|
'-NoProfile',
|
|
'-NonInteractive',
|
|
'-Command',
|
|
'[Diagnostics.FileVersionInfo]::GetVersionInfo($env:ORCA_TEST_LAUNCHER) | ConvertTo-Json -Compress'
|
|
],
|
|
{ encoding: 'utf8', env: { ...process.env, ORCA_TEST_LAUNCHER: launcherPath } }
|
|
)
|
|
expect(inspect.status, inspect.stderr).toBe(0)
|
|
const info = JSON.parse(inspect.stdout)
|
|
const { version } = JSON.parse(readFileSync(join(projectRoot, 'package.json'), 'utf8'))
|
|
expect(info.CompanyName).toBe('Stably AI')
|
|
expect(info.ProductName).toBe('Orca')
|
|
expect(info.FileDescription).toBe('Orca CLI Launcher')
|
|
expect(info.FileVersion).toBe(`${version.split(/[+-]/)[0]}.0`)
|
|
expect(info.ProductVersion).toBe(version)
|
|
const binary = readFileSync(launcherPath)
|
|
expect(binary.includes(Buffer.from('requestedExecutionLevel level="asInvoker"'))).toBe(true)
|
|
const icon = readFileSync(join(projectRoot, 'resources', 'build', 'icon.ico'))
|
|
const imageSize = icon.readUInt32LE(14)
|
|
const imageOffset = icon.readUInt32LE(18)
|
|
expect(binary.includes(icon.subarray(imageOffset, imageOffset + imageSize))).toBe(true)
|
|
} finally {
|
|
removeFixtureTree(root)
|
|
}
|
|
}
|
|
)
|
|
|
|
itCrossHost('fails closed when the Windows launcher cannot be compiled on this host', () => {
|
|
const outputRoot = mkdtempSync(join(tmpdir(), 'orca cross-host launcher '))
|
|
try {
|
|
const result = spawnSync(
|
|
process.execPath,
|
|
['config/scripts/build-windows-cli-launcher.mjs', '--output', join(outputRoot, 'orca.exe')],
|
|
{ cwd: projectRoot, encoding: 'utf8' }
|
|
)
|
|
|
|
expect(result.status).not.toBe(0)
|
|
expect(result.stderr).toContain('Windows CLI launcher')
|
|
expect(result.stderr).toContain('Windows host')
|
|
} finally {
|
|
removeFixtureTree(outputRoot)
|
|
}
|
|
})
|
|
|
|
itCrossHost('never hands the child an explicit environment map', () => {
|
|
// Why: setting any entry on the child's environment makes the spawn build its own
|
|
// block from a case-insensitive map, which collapses an inherited PATH and Path
|
|
// into one entry and killed the CLI (stablyai/orca#12046). Mutating this process
|
|
// and leaving the map untouched passes the block through verbatim.
|
|
const source = readFileSync(
|
|
join(projectRoot, 'native', 'windows-cli-launcher', 'src', 'main.rs'),
|
|
'utf8'
|
|
)
|
|
const code = source.replace(/^\s*\/\/.*$/gm, '')
|
|
|
|
expect(code).not.toMatch(/\.envs?\(/u)
|
|
expect(code).not.toContain('env_clear')
|
|
expect(code).toContain('env::set_var')
|
|
})
|
|
|
|
itCrossHost('never reintroduces a managed launcher alongside the native one', () => {
|
|
// Why: the MSIL image is what vendors flagged (stablyai/orca#23383). A stray .cs
|
|
// left in the crate would compile back into the shape the rewrite removed.
|
|
expect(
|
|
existsSync(join(projectRoot, 'native', 'windows-cli-launcher', 'OrcaCliLauncher.cs'))
|
|
).toBe(false)
|
|
})
|
|
|
|
itWindows('preserves a multiline argument from PowerShell through the native launcher', () => {
|
|
const appRoot = mkdtempSync(join(tmpdir(), 'orca cli launcher '))
|
|
try {
|
|
const resourcesPath = join(appRoot, 'resources')
|
|
const launcherPath = join(resourcesPath, 'bin', 'orca.exe')
|
|
const cliPath = join(resourcesPath, 'app.asar.unpacked', 'out', 'cli', 'index.js')
|
|
mkdirSync(join(resourcesPath, 'bin'), { recursive: true })
|
|
mkdirSync(dirname(cliPath), { recursive: true })
|
|
copyFileSync(process.execPath, join(appRoot, 'Orca.exe'))
|
|
writeFileSync(
|
|
cliPath,
|
|
`process.stdout.write(JSON.stringify({
|
|
argv: process.argv.slice(2),
|
|
electronRunAsNode: process.env.ELECTRON_RUN_AS_NODE,
|
|
nodeOptions: process.env.NODE_OPTIONS ?? null,
|
|
orcaNodeOptions: process.env.ORCA_NODE_OPTIONS ?? null
|
|
}))\n`,
|
|
'utf8'
|
|
)
|
|
|
|
const build = spawnSync(
|
|
process.execPath,
|
|
['config/scripts/build-windows-cli-launcher.mjs', '--output', launcherPath],
|
|
{ cwd: projectRoot, encoding: 'utf8' }
|
|
)
|
|
expect(build.status, `${build.stdout}\n${build.stderr}`).toBe(0)
|
|
|
|
const body = 'paragraph one line one\nparagraph one line two\n\nparagraph two'
|
|
const powershell = spawnSync(
|
|
'powershell.exe',
|
|
[
|
|
'-NoProfile',
|
|
'-NonInteractive',
|
|
'-Command',
|
|
'& $env:ORCA_TEST_LAUNCHER orchestration send --body $env:ORCA_TEST_BODY --json'
|
|
],
|
|
{
|
|
encoding: 'utf8',
|
|
env: {
|
|
...process.env,
|
|
NODE_OPTIONS: '--no-warnings',
|
|
ORCA_TEST_BODY: body,
|
|
ORCA_TEST_LAUNCHER: launcherPath
|
|
}
|
|
}
|
|
)
|
|
|
|
expect(powershell.status, powershell.stderr).toBe(0)
|
|
expect(JSON.parse(powershell.stdout)).toEqual({
|
|
argv: ['orchestration', 'send', '--body', body, '--json'],
|
|
electronRunAsNode: '1',
|
|
nodeOptions: null,
|
|
orcaNodeOptions: '--no-warnings'
|
|
})
|
|
} finally {
|
|
removeFixtureTree(appRoot)
|
|
}
|
|
})
|
|
|
|
itWindows('survives an inherited environment block containing PATH and Path', () => {
|
|
const appRoot = mkdtempSync(join(tmpdir(), 'orca duplicate path launcher '))
|
|
try {
|
|
const resourcesPath = join(appRoot, 'resources')
|
|
const launcherPath = join(resourcesPath, 'bin', 'orca.exe')
|
|
const cliPath = join(resourcesPath, 'app.asar.unpacked', 'out', 'cli', 'index.js')
|
|
const outputPath = join(appRoot, 'child-result.json')
|
|
const harnessSourcePath = join(
|
|
projectRoot,
|
|
'config',
|
|
'scripts',
|
|
'fixtures',
|
|
'DuplicatePathProcessLauncher.cs'
|
|
)
|
|
const harnessPath = join(appRoot, 'DuplicatePathLauncher.exe')
|
|
mkdirSync(dirname(launcherPath), { recursive: true })
|
|
mkdirSync(dirname(cliPath), { recursive: true })
|
|
copyFileSync(process.execPath, join(appRoot, 'Orca.exe'))
|
|
writeFileSync(
|
|
cliPath,
|
|
`require('node:fs').writeFileSync(process.env.ORCA_TEST_OUTPUT, JSON.stringify({
|
|
electronRunAsNode: process.env.ELECTRON_RUN_AS_NODE,
|
|
pathKeys: Object.keys(process.env).filter((key) => key.toLowerCase() === 'path')
|
|
}))\n`,
|
|
'utf8'
|
|
)
|
|
const build = spawnSync(
|
|
process.execPath,
|
|
['config/scripts/build-windows-cli-launcher.mjs', '--output', launcherPath],
|
|
{ cwd: projectRoot, encoding: 'utf8' }
|
|
)
|
|
expect(build.status, `${build.stdout}\n${build.stderr}`).toBe(0)
|
|
|
|
const compiler = findFrameworkCompiler()
|
|
expect(compiler).not.toBeNull()
|
|
const compileHarness = spawnSync(
|
|
compiler,
|
|
['/nologo', '/target:exe', `/out:${harnessPath}`, harnessSourcePath],
|
|
{ encoding: 'utf8' }
|
|
)
|
|
expect(compileHarness.status, `${compileHarness.stdout}\n${compileHarness.stderr}`).toBe(0)
|
|
|
|
const launch = spawnSync(harnessPath, [launcherPath, outputPath], { encoding: 'utf8' })
|
|
expect(launch.status, `${launch.stdout}\n${launch.stderr}`).toBe(0)
|
|
expect(JSON.parse(readFileSync(outputPath, 'utf8'))).toEqual({
|
|
electronRunAsNode: '1',
|
|
pathKeys: ['PATH', 'Path']
|
|
})
|
|
} finally {
|
|
removeFixtureTree(appRoot)
|
|
}
|
|
})
|
|
})
|
|
|
|
function findFrameworkCompiler() {
|
|
const windowsDirectory = process.env.WINDIR ?? process.env.SystemRoot
|
|
if (!windowsDirectory) {
|
|
return null
|
|
}
|
|
return (
|
|
[
|
|
join(windowsDirectory, 'Microsoft.NET', 'Framework64', 'v4.0.30319', 'csc.exe'),
|
|
join(windowsDirectory, 'Microsoft.NET', 'Framework', 'v4.0.30319', 'csc.exe')
|
|
].find((candidate) => existsSync(candidate)) ?? null
|
|
)
|
|
}
|