mirror of
https://github.com/stablyai/orca.git
synced 2026-10-01 00:02:10 +00:00
Audit sweep over `src/relay`, `src/preload` and `src/shared` (1,087 test files reviewed). 101 case declarations removed across 40 files, 6 test files deleted outright, 1,143 lines gone. Executed-case count falls further, since several removals were `it.each` tables. Dominant patterns, by frequency: - Self-comparisons that cannot fail: `expect(f(x)).toBe(f(x))`, `JSON.parse(JSON.stringify(literal))` deep-equalling the literal for a type with no codec, and `normalizeKeyToken(t) === normalizeKeyToken(t)` presented as proof of memoization. - Object literals asserting their own fields back, where the guarantee comes from the type annotation and the runtime assertion cannot fail. - Copied inventories: constants compared to their own initializers, and a function returning a copy of an exported constant checked against that constant's literal contents. - Duplicate invocations of a contract owned at a stronger boundary, including provider-local replays of a shared helper. - Table rows varying a field production never reads, so every row runs one path. - Names promising more than the input exercises: a "Windows launch" case in a module with no platform input, and a case whose named branch is never entered. Two production symbols go with them, each a test-only export whose sole caller was a deleted case: - `getGitHubProjectRefInputByteLength` — a one-line forward to `getClipboardTextByteLength`. The real bound (`GITHUB_PROJECT_REF_INPUT_MAX_BYTES`) and its guard stay. - `GRAB_STYLE_PROPERTIES` — an intended shared source of truth that nothing ever consulted; the property set is hand-enumerated at three independent sites. One case was deliberately restored and strengthened rather than dropped. The relay integration suite is the only place the real `SshChannelMultiplexer` is wired to `RelayDispatcher`, so it reaches transport behavior the handler suites cannot (they use `createMockDispatcher`). Its `fs.writeFile` roundtrip is the one case producing a void result, and `JSON.stringify` drops an absent `result` member — a shape no other surviving case exercises. Restored with an assertion pinning what the client actually observes: `null`, not `undefined`. That assertion failed on first run, so the fact was previously unasserted anywhere. One deletion was reverted mid-audit. A case asserting that optional fields stay invisible to "old attach and ready decoders" builds those decoders from `z.object` schemas declared in the test file, so it demonstrates zod's unknown-key stripping rather than anything shipped. It is nonetheless the only forward-compatibility coverage these envelopes have, and `reliability-gates.jsonc:6232` names it as evidence verbatim, so it stays. Note that `check-reliability-gates.mjs` passed both with and without it: the script resolves manifest paths and commands, and does not check that a named assertion still corresponds to a live case. Kept deliberately: everything a reliability gate cites as evidence; the three `registers all expected handlers` RPC manifests (a dropped registration is a silent wire break no type checker catches, and one carries the STA-4571 `pty.ackData` ratchet); the `child-process` direct-import ratchet; and prototype-spy cases paired with a `.repeat(10_000)` input, which assert a real memory bound rather than merely forbidding a technique. Verified: `pnpm test src/shared src/relay src/preload` (1073 files, 11996 passed, 1 pre-existing `it.fails`, 131 skipped), `pnpm tc` after clearing `.tsbuildinfo`, `check-reliability-gates.mjs` (140 gates), `check:code-quality:changed` (0 new findings).
38 lines
1.6 KiB
TypeScript
38 lines
1.6 KiB
TypeScript
import { describe, expect, it } from 'vitest'
|
|
import { normalizeKeyToken, parseKeybinding } from './keybindings/parser'
|
|
|
|
describe('parseKeybinding memoization', () => {
|
|
it('reuses the parsed result for a repeated binding string', () => {
|
|
const first = parseKeybinding('Mod+Shift+K')
|
|
const second = parseKeybinding('Mod+Shift+K')
|
|
expect(first).not.toBeNull()
|
|
expect(second).toBe(first)
|
|
})
|
|
|
|
it('never hands out an entry a caller can corrupt', () => {
|
|
const parsed = parseKeybinding('Mod+P')
|
|
expect(Object.isFrozen(parsed)).toBe(true)
|
|
expect(parseKeybinding('Mod+P')?.key).toBe('P')
|
|
})
|
|
|
|
it('stays bounded and correct when fed far more strings than the cache holds', () => {
|
|
for (let index = 0; index < 2000; index++) {
|
|
expect(parseKeybinding(`Mod+Alt+F${(index % 24) + 1}`)?.key).toBe(`F${(index % 24) + 1}`)
|
|
}
|
|
// A cleared cache must still return the right answer, not a stale neighbour.
|
|
expect(parseKeybinding('Mod+Shift+K')?.key).toBe('K')
|
|
expect(parseKeybinding('DoubleTap+Shift')?.doubleTapModifier).toBe('Shift')
|
|
})
|
|
|
|
it('maps token spellings through the table and blocks prototype keys', () => {
|
|
expect(normalizeKeyToken(' ')).toBe('Space')
|
|
expect(normalizeKeyToken('pgdn')).toBe('PageDown')
|
|
expect(normalizeKeyToken('subtract')).toBe('NumpadSubtract')
|
|
expect(normalizeKeyToken('nonsense')).toBe(null)
|
|
expect(normalizeKeyToken('')).toBe(null)
|
|
// Object.prototype keys must not leak through the token table.
|
|
expect(normalizeKeyToken('constructor')).toBe(null)
|
|
expect(normalizeKeyToken('__proto__')).toBe(null)
|
|
})
|
|
})
|