fix(browse): windowsHide sweep — flag every residual child_process site + full-census tripwire (#2160, #2415)

Add windowsHide:true at every remaining direct child_process call in
browse/src that could flash a console window on Windows:

- project-slug.ts (execSync gstack-slug)
- browser-skills.ts (cp.spawnSync git rev-parse)
- security-sidecar-client.ts (spawn — the LONG-LIVED Node sidecar, whose
  missing flag parked a console window on the taskbar for the daemon's
  whole lifetime)
- find-security-sidecar.ts (execFileSync node --version)
- meta-commands.ts (execSync git rev-parse in inbox + the osascript
  activate call)
- browse-client.ts (cp.spawnSync git rev-parse)
- file-permissions.ts (execFileSync whoami.exe — Windows-only, ran bare)
- cli.ts (nodeSpawn osascript)

windows-spawn-hide.test.ts gains a SWEEP test on top of the existing
needles: it censuses EVERY child_process binding in src/ (static imports
incl. aliases, `await import()` / require destructures, and `import * as
cp` namespaces — 15 call sites across 10 files today) and fails CI on any
call without windowsHide within its options window. Exemptions carry
reasons — the one today is domain-skill-commands' interactive $EDITOR
spawn (stdio:'inherit'; CREATE_NO_WINDOW would detach a console editor
into an invisible console).

Tests: windows-spawn-hide 5 pass; file-permissions 19 pass; browse-client
28 pass; browser-skill-commands 29 pass (81/81 combined).

Fixes the app-side half of #2160; closes out #2415's residuals.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Garry Tan
2026-08-16 10:59:06 -07:00
co-authored by Claude Fable 5
parent 7171f10364
commit 7686eb212d
10 changed files with 77 additions and 7 deletions
+65
View File
@@ -62,4 +62,69 @@ describe('windowsHide on Windows-reachable spawns (#1835)', () => {
// spawn's options object carries the full env wiring before the flag.
expectHideNearEvery(SRC('terminal-agent-control.ts'), '(Bun as any).spawn(', 700);
});
test('SWEEP: every direct child_process call in src/ passes windowsHide (#2160, #2415)', () => {
// Full-census tripwire: a NEW child_process call site without windowsHide
// fails CI. Each exemption carries a reason — an interactive console
// child must NOT get CREATE_NO_WINDOW.
const EXEMPT: Array<{ file: string; needle: string; reason: string }> = [
{
file: 'domain-skill-commands.ts',
needle: 'spawnSync(editor',
reason: "interactive $EDITOR with stdio:'inherit' — windowsHide would detach a console editor into an invisible console",
},
];
const srcDir = path.join(import.meta.dir, '../src');
const offenders: string[] = [];
for (const file of fs.readdirSync(srcDir).filter((f) => f.endsWith('.ts'))) {
const raw = fs.readFileSync(path.join(srcDir, file), 'utf-8');
if (!raw.includes('child_process')) continue;
// Strip comments so documented history doesn't trip the census.
const code = raw.replace(/\/\*[\s\S]*?\*\//g, '').replace(/^\s*\/\/.*$/gm, '');
// Collect the callable names this file binds to child_process:
// import { spawn as nodeSpawn } from 'child_process'
// const { execSync } = await import('child_process') / require(...)
// import * as cp from 'child_process' → cp.<fn>( pattern
const names = new Set<string>();
const namespaces = new Set<string>();
const importRe = /import\s*\{([^}]*)\}\s*from\s*['"](?:node:)?child_process['"]/g;
const dynRe = /(?:const|let|var)\s*\{([^}]*)\}\s*=\s*(?:await\s+import\(|require\()['"](?:node:)?child_process['"]\)/g;
const nsRe = /import\s*\*\s*as\s*(\w+)\s*from\s*['"](?:node:)?child_process['"]/g;
for (const m of code.matchAll(importRe)) {
for (const part of m[1].split(',')) {
const alias = part.split(/\s+as\s+/).map((s) => s.trim()).filter(Boolean);
const name = alias[alias.length - 1];
if (name && /^(spawn|spawnSync|exec|execSync|execFile|execFileSync|nodeSpawn|cpSpawn)/.test(alias[0].trim())) names.add(name);
}
}
for (const m of code.matchAll(dynRe)) {
for (const part of m[1].split(',')) {
const alias = part.split(':').map((s) => s.trim()).filter(Boolean);
const name = alias[alias.length - 1];
if (name && /^(spawn|spawnSync|exec|execSync|execFile|execFileSync)/.test(alias[0].trim())) names.add(name);
}
}
for (const m of code.matchAll(nsRe)) namespaces.add(m[1]);
const patterns: RegExp[] = [];
for (const n of names) patterns.push(new RegExp(`(?<![.\\w'"\`])${n}\\(`, 'g'));
for (const ns of namespaces) {
patterns.push(new RegExp(`(?<![\\w'"\`])${ns}\\.(?:spawn|spawnSync|exec|execSync|execFile|execFileSync)\\(`, 'g'));
}
for (const re of patterns) {
for (const m of code.matchAll(re)) {
const slice = code.slice(m.index!, m.index! + 700);
const exempt = EXEMPT.some((e) => e.file === file && slice.startsWith(e.needle));
if (exempt) continue;
if (!/windowsHide:\s*true/.test(slice)) {
offenders.push(`${file}: ${slice.split('\n')[0].slice(0, 100)}`);
}
}
}
}
expect(offenders).toEqual([]);
});
});