mirror of
https://github.com/stablyai/orca.git
synced 2026-10-07 08:02:21 +00:00
Three fixes, all on paths this PR could not exercise locally. The managed hook command was stored as a bare path. jcode tokenizes that string shell-style before exec'ing it directly (parse_hook_command, crates/jcode-terminal-launch/src/lib.rs): unquoted whitespace splits, and every unquoted backslash is consumed as an escape. So on Windows `C:\Users\me\.orca\agent-hooks\jcode-hook.cmd` reached exec as `C:Usersme.orcaagent-hooksjcode-hook.cmd` and no hook fired at all, and a POSIX home with a space split into two arguments. Store the path single-quoted (verbatim, backslashes included), falling back to double quotes for a path containing a single quote. Existing bare entries are already repointed by the stale-key path, and getStatus accepts both forms so the repair is not reported as a user-owned hook. The quoting helper was previously dead code that only tests called; the three production sites now use it. isJcodeManagedCommand also normalizes separators, since a `/`-only needle never matched a Windows entry. Commit-message generation feeds a staged patch to `jcode run` as the prompt — attacker-influenced text — while jcode's default profile exposes shell, read, write, and MCP. Pass `--tool-profile none`, which resolves to an empty allowed-tool set in jcode's config (base_allowed_tools), matching the read-only posture claude (plan) and codex (read-only) already take. docs/reference/jcode-hook-events.md was never actually in this PR: the repo ignores docs/** and tracks reference docs by allow-list only, so the captured-payload evidence four source comments point at was silently dropped. Allow-list it. Co-authored-by: czzczz <chanzrz_zbf@foxmail.com>
207 lines
5.7 KiB
Plaintext
207 lines
5.7 KiB
Plaintext
# Build artifacts
|
|
tsconfig.*.tsbuildinfo
|
|
|
|
# TypeScript emit artifacts next to sources (tsc produced these accidentally;
|
|
# real source lives in .ts/.tsx). Hand-authored declaration files are
|
|
# re-included below.
|
|
src/**/*.js
|
|
src/**/*.d.ts
|
|
/electron.vite.config.js
|
|
/electron.vite.config.d.ts
|
|
!src/main/types/hosted-git-info.d.ts
|
|
!src/preload/api-types.d.ts
|
|
!src/preload/index.d.ts
|
|
!src/renderer/src/env.d.ts
|
|
!src/renderer/src/mermaid.d.ts
|
|
!src/types/build-constants.d.ts
|
|
|
|
# Dependencies
|
|
node_modules/
|
|
# Why: the trailing-slash form matches directories only, so a node_modules SYMLINK (how agent
|
|
# worktrees share an install) slipped past a bulk `git add` and got committed — twice.
|
|
node_modules
|
|
|
|
# Build output
|
|
dist/
|
|
dist-electron/
|
|
out/
|
|
/build/
|
|
release/
|
|
native/**/.build/
|
|
native/windows-cli-launcher/target/
|
|
# node-gyp output for the vendored Windows registry addon; generated per host and ABI.
|
|
native/windows-registry/build/
|
|
native/windows-registry/bin/
|
|
|
|
# pnpm
|
|
.pnpm-store/
|
|
package-lock.json
|
|
|
|
# Environment
|
|
.env
|
|
.env.local
|
|
.env.*.local
|
|
|
|
# IDE
|
|
.vscode/
|
|
.idea/
|
|
.serena/
|
|
*.swp
|
|
*.swo
|
|
*~
|
|
|
|
# OS
|
|
# Keep these in step with isOsMetadataSkillEntryName (skill-package-identity.ts): both disk
|
|
# walkers skip a plain file with one of these names, the git-tree producer does not, and
|
|
# ignoring them here is what keeps `git add -A` from committing a stray one.
|
|
*.stackdump
|
|
.DS_Store
|
|
._*
|
|
Thumbs.db
|
|
ehthumbs.db
|
|
desktop.ini
|
|
|
|
# Lint/cache
|
|
.oxlintcache
|
|
|
|
# Logs
|
|
*.log
|
|
*.log.*
|
|
npm-debug.log*
|
|
pnpm-debug.log*
|
|
|
|
# Coverage
|
|
coverage/
|
|
|
|
# Prod release scan output (accidental adds)
|
|
prod-release-scan-*.md
|
|
|
|
# Benchmark run output
|
|
/tests/tools/benchmarks/results/*.json
|
|
/.bench-fixtures/
|
|
|
|
# Temp
|
|
tmp/
|
|
.tmp/
|
|
design-docs/
|
|
.context/
|
|
.atl/
|
|
|
|
# Machine-local agent hook endpoint files may contain auth tokens.
|
|
/agent-hooks/
|
|
|
|
# Local-only design/planning docs (not checked in), including most of docs/reference/.
|
|
# Durable docs that should be tracked must live in one of the allow-listed
|
|
# locations below (assets, readme, STYLEGUIDE, mobile terminal shortcut bar,
|
|
# and the tracked reference docs linked from AGENTS.md / README.md).
|
|
docs/**
|
|
!docs/
|
|
# The deployable docs app is source, not local engineering notes.
|
|
!docs/site/
|
|
!docs/site/**
|
|
!docs/audits/
|
|
!docs/audits/closed-editor-model-lifetime/
|
|
!docs/audits/closed-editor-model-lifetime/**
|
|
!docs/assets/
|
|
!docs/assets/**
|
|
!docs/audits/
|
|
!docs/audits/plugin-uninstall-log-retirement/
|
|
!docs/audits/plugin-uninstall-log-retirement/**
|
|
!docs/readme/
|
|
!docs/readme/**
|
|
!docs/bug-reproductions/
|
|
!docs/bug-reproductions/**
|
|
!docs/STYLEGUIDE.md
|
|
!docs/audits/
|
|
!docs/audits/crashpad-read-limit/
|
|
!docs/audits/crashpad-read-limit/source-hashes.json
|
|
!docs/agent-skill-sharing-implementation-checklist.md
|
|
!docs/mobile-terminal-shortcut-bar.md
|
|
!docs/reference/
|
|
!docs/reference/agent-pty-transcript-capture.md
|
|
!docs/reference/agent-session-search-query-tuning.md
|
|
!docs/reference/agent-session-search-contract.md
|
|
!docs/reference/agent-status-store.md
|
|
!docs/reference/antigravity-readiness-evidence.md
|
|
!docs/reference/antivirus-prerelease-clearance.md
|
|
!docs/reference/cline-and-prime-agent-readiness-evidence.md
|
|
!docs/reference/git-compatibility.md
|
|
!docs/reference/headless-linux-server.md
|
|
!docs/reference/ime-regression-checklist.md
|
|
!docs/reference/jcode-hook-events.md
|
|
!docs/reference/linux-glibc-compatibility.md
|
|
!docs/reference/macos-press-and-hold.md
|
|
!docs/reference/orcad-operations.md
|
|
!docs/reference/pnpm-install-policy.md
|
|
!docs/reference/relay-grace-time-reconfiguration.md
|
|
!docs/reference/windows-cmd-shim-resolution.md
|
|
!docs/reference/windows-daemon-host-relocation.md
|
|
!docs/reference/windows-edr-posture.md
|
|
!docs/reference/windows-msys-job-breakaway.md
|
|
!docs/reference/windows-process-enumeration.md
|
|
!docs/reference/wsl-runner-verification.md
|
|
!docs/reference/remote-wire-compatibility.md
|
|
!docs/reference/renderer-agent-status-performance.md
|
|
!docs/reference/ssh-execution-boundary.md
|
|
!docs/reference/ssh-host-key-verification.md
|
|
!docs/reference/ssh-reconnect-source-recovery.md
|
|
!docs/reference/windows-setup-shell.md
|
|
!docs/reference/windows-terminal-shell-selection.md
|
|
!docs/reference/worktree-scan-fingerprint.md
|
|
!docs/reference/wsl-command-execution.md
|
|
!docs/reference/wsl-probe-failure-semantics.md
|
|
!docs/reference/xterm-patch-regeneration.md
|
|
|
|
# Stably CLI (only docs/ are tracked)
|
|
.stably/*
|
|
!.stably/docs/
|
|
.playwright-cli
|
|
.validate-ui-screenshots/
|
|
validation-screenshots/
|
|
.stably-browser
|
|
|
|
# Local scratch notes and PR evidence screenshots (not part of the product).
|
|
/notes/
|
|
/pr-evidence/
|
|
|
|
# Playwright
|
|
test-results/
|
|
playwright-report/
|
|
|
|
# Agent skill installations (machine-local, populated by agent tooling)
|
|
/.claude/skills/
|
|
/.agents/skills/
|
|
/skills-lock.json
|
|
|
|
# Generated Clawpatch state includes machine-local paths and review records.
|
|
/.clawpatch/
|
|
/mobile/.clawpatch/
|
|
|
|
# Agent hook runtime endpoints (machine-local secrets)
|
|
/agent-hooks/
|
|
validation-screenshots/
|
|
|
|
# Localization bootstrap cache (regenerated by bootstrap:*-catalog)
|
|
src/renderer/src/i18n/locales/.zh-catalog-cache.json
|
|
src/renderer/src/i18n/locales/.ko-catalog-cache.json
|
|
src/renderer/src/i18n/locales/.ja-catalog-cache.json
|
|
src/renderer/src/i18n/locales/.es-catalog-cache.json
|
|
src/renderer/src/i18n/locales/.fr-catalog-cache.json
|
|
|
|
# Bench result JSONs are working artifacts
|
|
tests/tools/benchmarks/results/terminal-pipeline-*.json
|
|
|
|
# Old release trees the cross-version wire harness extracts on demand
|
|
tests/e2e/.cross-version-checkouts/
|
|
|
|
# Bundler's install path for the mobile release toolchain (mobile/Gemfile.lock
|
|
# IS committed). Also keeps oxfmt/oxlint, which honor this file, from walking
|
|
# vendored gems.
|
|
/mobile/vendor/
|
|
|
|
# Generated by config/scripts/sync-anti-slop-plugin.mjs from the pinned oxlint-plugin-anti-slop
|
|
.anti-slop-plugin/
|
|
|
|
# Generated by the CI unit-test sequencer (and by reproducing a shard locally).
|
|
ci-shards/
|