mirror of
https://github.com/stablyai/orca.git
synced 2026-10-07 08:02:21 +00:00
Flip `anti-slop/no-shape-in-symbol-names` from "off" to "error" and clear
every violation under src, config, tests and mobile.
What the rule bans
------------------
The case-insensitive substring "shape" in any JS/TS identifier: variables,
functions, parameters, types, type parameters, class members, private names,
object-literal keys and JSX identifiers. The one exemption is a statically
accessed member read owned by another value (`zodObject.shape` is fine), so
third-party APIs stay readable without a suppression.
"Shape" names a value's structure rather than its domain role. `UserShape`,
`validateArgShape` and `errorShape` all tell you the symbol is "an object
with some fields" -- which is already what a type says -- while saying
nothing about what the value is for or who owns it. The rule forces the
name to carry the domain instead.
Violations fixed
----------------
689 violations across 109 files at baseline (verified by re-running the
audit against the pre-change tree with the rule set to "error").
Fix pattern
-----------
Rename for the domain role, not the structure:
-type FieldShape = 'list' | 'map' | 'whole'
-const FIELD_SHAPES = { ... } satisfies Record<keyof Observation, FieldShape>
+type FieldEncoding = 'list' | 'map' | 'whole'
+const FIELD_ENCODINGS = { ... } satisfies Record<keyof Observation, FieldEncoding>
-function assertGitPushTargetShape(target: unknown): void
+function assertValidGitPushTarget(target: unknown): void
-function describeReadDirPathShape(p: string): ReadDirPathKind
+function classifyReadDirPath(p: string): ReadDirPathKind
Predicates became statements about the value (`isDeltaShapedProviderFrameKind`
-> `isDeltaProviderFrameKind`, `isDeleteShapedDiscardEntry` ->
`discardDeletesEntryFile`, `isSkillsCliAgentKeyShaped` ->
`isUsableSkillsCliAgentKey`). Type aliases dropped the suffix where the
remaining name was already unambiguous (`GhGraphqlErrorShape` ->
`GhGraphqlError`).
No wire-visible name was renamed: no IPC or RPC channel, stream opcode,
request/response param, persisted field, or i18n key. The `--shape=symlink|copy`
CLI flag read by .github/workflows/skill-update-roundtrip.yml is unchanged --
only the local variable holding it was renamed.
Exemptions
----------
They are file-scoped entries in config/oxlint-anti-slop.json, not inline
`oxlint-disable` comments. An inline directive naming an anti-slop rule reads
back as an UNUSED directive under the root lint scan, which does not load this
plugin -- the changed-code quality gate counts that warning, so the comment form
cannot be used for a rule that lives only in this config.
* src/renderer/src/components/browser-pane/annotate/**:
in the screenshot annotator a "shape" is the drawn geometry -- pen, arrow,
rect, ellipse, highlight. That is a genuine domain noun, and it pervades
every symbol in the module.
* repo-icon.tsx, repo-header-project-actions.tsx, mobile MobileRepoIcon.tsx:
lucide exports the icon component as `Shapes`. The name is theirs, and the
matching REPO_LUCIDE_ICONS key is the persisted icon name shared with the
desktop picker -- renaming it would orphan saved repo icons.
* src/shared/onboarding-state-types.ts, src/shared/constants.ts:
`shapedSidebar` is a persisted onboarding-checklist field and a telemetry
enum member; renaming it would orphan saved state.
* src/shared/rpc-contract/rpc-send-params.ts: matching zod's own literal `shape`
property is what selects the ZodObject branch of the conditional type.
No exemption was added merely to avoid a rename. Eight symbols initially
suppressed as "a cross-module refactor outside this change" were proven to have
zero non-TypeScript references repo-wide and renamed instead.
Zod's `ZodRawShape` needed no exemption at all: `Readonly<Record<string,
z.ZodType>>` is its definition, so repo-update-params.ts and
ui-update-value-tolerance-params.ts spell it out instead. Likewise
telemetry-event-classification.ts now reads `.shape` through an `in` narrowing,
which also retires two pre-existing type assertions; three more assertions the
rename had dragged onto changed lines (two `JSON.parse` sites, one node:sqlite
row read) became annotations and an explicit row mapping.
Verified
--------
* Audit reports zero violations; confirmed the rule genuinely fires by
planting a probe violation.
* node config/scripts/run-typecheck-projects-in-parallel.mjs exits 0.
* Vitest over src/shared, src/main/github/project-view, the annotate module,
the repo-icon components and the Chromium SameSite electron spec: all green.
* All 66 removed "shape" identifiers grepped repo-wide across every file type;
none survive.
* node config/scripts/generate-rpc-params-catalog.mjs --check exits 0.
* node --check on every changed .mjs; oxfmt clean on all changed files.
* `pnpm run check:code-quality:changed` reports 0 findings.
Not machine-verified: the 3 mobile/ files (its Vitest run cannot resolve
`expo/tsconfig.base.json` in this worktree), and the WSL- and Playwright-gated
specs. All are rename- or comment-only hunks, read in full.
188 lines
7.1 KiB
TypeScript
188 lines
7.1 KiB
TypeScript
import type { SshConnection } from './ssh-connection'
|
|
import {
|
|
getProcessOutputFields,
|
|
iterateProcessOutputLines
|
|
} from '../../shared/process-output-field-scanner'
|
|
import { parseUnameToRelayPlatform, type RelayPlatform } from './relay-protocol'
|
|
import { execCommand } from './ssh-relay-deploy-helpers'
|
|
import { isSshExecTimeout, isUnconfirmedSshCommandTermination } from './ssh-relay-exec-command'
|
|
import { isSshSessionLimitError } from './ssh-session-limit-error'
|
|
import { getRemoteHostPlatform, type RemoteHostPlatform } from './ssh-remote-platform'
|
|
import { powerShellCommand } from './ssh-remote-powershell'
|
|
|
|
const PLATFORM_PROBE_MARKER = '__ORCA_REMOTE_PLATFORM__'
|
|
const MAX_UNAME_FIELD_CHARS = 64
|
|
const MAX_THROWN_OUTPUT_CHARS = 200
|
|
const MAX_LOGGED_OUTPUT_CHARS = 1000
|
|
|
|
type PlatformProbeOutcome =
|
|
| { kind: 'detected'; platform: RelayPlatform }
|
|
| { kind: 'unsupported'; uname: string }
|
|
| { kind: 'unparsed'; output: string }
|
|
| { kind: 'failed'; error: unknown }
|
|
|
|
export async function detectRemoteHostPlatform(
|
|
conn: SshConnection,
|
|
options?: { signal?: AbortSignal }
|
|
): Promise<RemoteHostPlatform | null> {
|
|
const uname = await detectUnamePlatform(conn, options?.signal)
|
|
if (uname.kind === 'detected') {
|
|
return getRemoteHostPlatform(uname.platform)
|
|
}
|
|
if (uname.kind === 'failed' && shouldAbandonAfterUnameProbe(uname.error)) {
|
|
throw uname.error
|
|
}
|
|
const windows = await detectWindowsPlatform(conn, options?.signal)
|
|
if (windows.kind === 'detected') {
|
|
return getRemoteHostPlatform(windows.platform)
|
|
}
|
|
// Why: only the PowerShell probe can settle a uname the parser cannot map
|
|
// (Cygwin, say), so a refused or timed-out channel leaves it unsettled.
|
|
const windowsProbeNeverRan = windows.kind === 'failed' && isTransportFailure(windows.error)
|
|
if ((uname.kind === 'unsupported' && !windowsProbeNeverRan) || windows.kind === 'unsupported') {
|
|
const reported = uname.kind === 'unsupported' ? uname.uname : probeUname(windows)
|
|
console.warn(`[ssh-relay] Remote reported an unsupported platform: ${reported}`)
|
|
return null
|
|
}
|
|
console.warn(
|
|
`[ssh-relay] Remote platform detection failed (uname probe: ${uname.kind}, PowerShell probe: ${windows.kind}). ` +
|
|
`Remote output: "${summarizeProbeOutput(probeEvidence(uname) || probeEvidence(windows), MAX_LOGGED_OUTPUT_CHARS)}"`
|
|
)
|
|
throw undetectedPlatformError(uname, windows)
|
|
}
|
|
|
|
// Why: an unconfirmed close still holds the sshd session slot, so a second
|
|
// probe only burns another exec timeout before being refused too.
|
|
function shouldAbandonAfterUnameProbe(error: unknown): boolean {
|
|
return (
|
|
(error instanceof Error && error.name === 'AbortError') ||
|
|
isUnconfirmedSshCommandTermination(error)
|
|
)
|
|
}
|
|
|
|
/** Precedence: transport failure from either probe, then uname, then PowerShell. */
|
|
function undetectedPlatformError(
|
|
uname: PlatformProbeOutcome,
|
|
windows: PlatformProbeOutcome
|
|
): Error {
|
|
for (const outcome of [uname, windows]) {
|
|
if (outcome.kind === 'failed' && isTransportFailure(outcome.error)) {
|
|
return wrapProbeError(outcome.error)
|
|
}
|
|
}
|
|
if (uname.kind === 'failed') {
|
|
return wrapProbeError(uname.error)
|
|
}
|
|
if (uname.kind === 'unparsed') {
|
|
return unrecognizedOutputError(uname.output)
|
|
}
|
|
if (windows.kind === 'failed') {
|
|
return wrapProbeError(windows.error)
|
|
}
|
|
return unrecognizedOutputError(probeOutput(windows))
|
|
}
|
|
|
|
// Why: a refused or timed-out channel explains the failure better than the
|
|
// other probe's mundane non-zero exit (e.g. "sh: not found" on Windows).
|
|
function isTransportFailure(error: unknown): boolean {
|
|
return (
|
|
isSshSessionLimitError(error) ||
|
|
isUnconfirmedSshCommandTermination(error) ||
|
|
isSshExecTimeout(error)
|
|
)
|
|
}
|
|
|
|
function wrapProbeError(error: unknown): Error {
|
|
const message = error instanceof Error ? error.message : String(error)
|
|
return new Error(`Could not detect the remote platform: ${message}`, { cause: error })
|
|
}
|
|
|
|
function unrecognizedOutputError(output: string): Error {
|
|
return new Error(
|
|
`Remote platform probe returned no recognizable output. Remote output: "${summarizeProbeOutput(output, MAX_THROWN_OUTPUT_CHARS)}"`
|
|
)
|
|
}
|
|
|
|
function probeOutput(outcome: PlatformProbeOutcome): string {
|
|
return outcome.kind === 'unparsed' ? outcome.output : ''
|
|
}
|
|
|
|
function probeUname(outcome: PlatformProbeOutcome): string {
|
|
return outcome.kind === 'unsupported' ? outcome.uname : ''
|
|
}
|
|
|
|
function probeEvidence(outcome: PlatformProbeOutcome): string {
|
|
return probeOutput(outcome) || probeUname(outcome)
|
|
}
|
|
|
|
// Why: the marker is printed last, so the tail holds the evidence; collapsing
|
|
// CR/LF keeps a Windows banner from becoming a multi-line renderer message.
|
|
function summarizeProbeOutput(output: string, maxChars: number): string {
|
|
const collapsed = output.replace(/\s+/gu, ' ').trim()
|
|
return collapsed.length > maxChars ? `…${collapsed.slice(-maxChars)}` : collapsed
|
|
}
|
|
|
|
async function detectUnamePlatform(
|
|
conn: SshConnection,
|
|
signal?: AbortSignal
|
|
): Promise<PlatformProbeOutcome> {
|
|
try {
|
|
// Why: Remote startup output may omit its trailing newline and must not absorb the marker.
|
|
const command = `printf '\\n%s ' '${PLATFORM_PROBE_MARKER}'; uname -sm`
|
|
const output = signal
|
|
? await execCommand(conn, command, { signal })
|
|
: await execCommand(conn, command)
|
|
return parseRemotePlatformOutput(output)
|
|
} catch (error) {
|
|
signal?.throwIfAborted()
|
|
return { kind: 'failed', error }
|
|
}
|
|
}
|
|
|
|
async function detectWindowsPlatform(
|
|
conn: SshConnection,
|
|
signal?: AbortSignal
|
|
): Promise<PlatformProbeOutcome> {
|
|
try {
|
|
const script = [
|
|
'$arch = $env:PROCESSOR_ARCHITECTURE',
|
|
'try { $runtimeArch = [System.Runtime.InteropServices.RuntimeInformation]::OSArchitecture.ToString(); if ($runtimeArch) { $arch = $runtimeArch } } catch {}',
|
|
'if (-not $arch) { $arch = $env:PROCESSOR_ARCHITECTURE }',
|
|
// Why: Remote startup output may omit its trailing newline and must not absorb the marker.
|
|
`Write-Output ("\`n${PLATFORM_PROBE_MARKER} Windows " + $arch)`
|
|
].join('; ')
|
|
const output = await execCommand(conn, powerShellCommand(script), {
|
|
wrapCommand: false,
|
|
...(signal ? { signal } : {})
|
|
})
|
|
return parseRemotePlatformOutput(output)
|
|
} catch (error) {
|
|
signal?.throwIfAborted()
|
|
return { kind: 'failed', error }
|
|
}
|
|
}
|
|
|
|
function parseRemotePlatformOutput(output: string): PlatformProbeOutcome {
|
|
let unsupportedUname = ''
|
|
// Why: SSH startup noise can resemble valid probe output and select the wrong relay.
|
|
for (const line of iterateProcessOutputLines(output)) {
|
|
const parts = getProcessOutputFields(line, 3)
|
|
if (parts.length < 3 || parts[0] !== PLATFORM_PROBE_MARKER) {
|
|
continue
|
|
}
|
|
const platform = parseUnameToRelayPlatform(parts[1], parts[2])
|
|
if (platform) {
|
|
return { kind: 'detected', platform }
|
|
}
|
|
unsupportedUname = `${clampUnameField(parts[1])} ${clampUnameField(parts[2])}`
|
|
}
|
|
return unsupportedUname
|
|
? { kind: 'unsupported', uname: unsupportedUname }
|
|
: { kind: 'unparsed', output }
|
|
}
|
|
|
|
// Why: a single field can be kilobytes — the scanner reads up to 4096 chars.
|
|
function clampUnameField(field: string): string {
|
|
return field.length > MAX_UNAME_FIELD_CHARS ? `${field.slice(0, MAX_UNAME_FIELD_CHARS)}…` : field
|
|
}
|