v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)

* fix(browse): prepare reliable cookie import wave for validation

* ci: sequence quality and behavior for validation branch

* fix(browse): isolate Windows qualification and preserve native diagnostics

* test(browse): cover cookie workflow quality and isolate Windows user paths

* test(browse): trace native member startup and initialize fresh folders

* fix(browse): keep Windows member stdin alive through EOF

* fix(browse): latch native timeouts and compare contained Edge startup

* test(browse): verify native version metadata and actual Windows argv

* test(browse): qualify Dia import on isolated macOS CI

* fix(browse): require picker origin for session mutations

* fix(browse): bound credential reads through stream completion

* test(browse): inspect owned Windows process arguments natively

* test(evals): preserve passing coverage during cookie repair reruns

* test(browse): isolate Dia qualification in a fresh macOS account

* test(browse): pass bounded integer timeouts to native Mac probes

* test(browse): distinguish Windows profile initialization from containment

* test(browse): await descendant pipe readiness before parent exit

* test(browse): initialize and restore isolated macOS Keychain state

* test(browse): initialize Windows fixture folders before qualification

* test(ci): pin the same Node runtime across Windows checks

* test(browse): distinguish native macOS browser preflight stages

* test(browse): isolate Windows descendant console lifetime

* test(browse): preserve native receipts and identify fixture lock holders

* test(browse): prepare dependency resolution before native Mac worker startup

* test(ci): include lock and close checks in native diagnostics

* test(browse): preserve native owner probe stages and subprocess deadlines

* fix(browse): classify Chromium profile-in-use exit precisely

* test(browse): retain Mac qualification evidence through cleanup failures

* test(browse): bound Mac fixture paths and retire its owned user domain

* test(browse): accept vanished fixture entries without weakening cleanup

* test(browse): identify probe-created macOS user domains safely

* test(browse): observe Mac user domains without targeting them first

* test(browse): use passive fresh-user ownership throughout Mac qualification

* test(browse): distinguish profile and registered-home Keychain lookups

* test(browse): qualify Dia under one registered account home

* test(browse): identify Dia startup and owned process-group failures

* test(browse): classify bounded Dia startup diagnostics without leaking output

* fix(test): preserve native Mac sandboxing and reap owned browser children

* fix(browse): preserve Chromium sandboxing for native profile imports

* test(browse): inspect signed Mach-O architecture without launching Xcode tools

* test(browse): sample pending Dia startup and reap on all cleanup paths

* test(browse): compare protected Dia launches in fresh Bun and Node accounts

* test(browse): inspect isolated Mac GUI readiness without browser access

* v1.90.0.0 fix: bind cookie picker actions to their document

* test: validate cookie guards and fit nested launch fixtures

* ci: configure the bundled Chromium sandbox helper

* fix(browse): classify Playwright authentication timeouts

* test: retain bounded Windows lifecycle diagnostics

* test(cso): reuse bounded NTFS precision candidates

* test(review): handle explicit preservation choices safely

* test(browse): remove owned fixture directories with explicit primitives

* test(review): distinguish descriptive reuse from edit commitments

* test: admit only the approved unscored cookie workflow refusal

* test: keep the Office Hours judge mock export-complete

* fix: keep dependency-free CI planners independent of the model SDK

* test: observe the exact holder after a native fixture unlink failure

* fix: start seeded PTY observations at owned readiness

* test: acquire identity-bound Windows deletion admission before profile resets

* test: preserve qualified Git index bits without authorizing mutations
This commit is contained in:
Garry Tan
2026-09-25 12:06:45 -04:00
committed by GitHub
parent 730a1017d1
commit a84b0b5b6d
111 changed files with 14996 additions and 1057 deletions
+114
View File
@@ -1,5 +1,7 @@
import { describe, test, expect, afterAll, setDefaultTimeout } from 'bun:test';
import * as path from 'path';
import * as fs from 'node:fs';
import * as os from 'node:os';
// Every test here spawnSync's a `node` child; Windows CI cold-start (AV scan,
// first-touch of node.exe) alone can blow bun's 5s default — observed 5,007ms
@@ -204,6 +206,118 @@ describe('bun-polyfill', () => {
expect(result.stdout.toString().trim()).toBe('1048576:0');
}, 15000);
test('cancelled replay readers release inherited pipes after the direct child exits', () => {
const root = fs.realpathSync(fs.mkdtempSync(path.join(os.tmpdir(), 'polyfill-cancel-')));
const marker = path.join(root, 'descendant.pid');
const pidPath = path.join(root, 'spawned.pid');
expect(fs.realpathSync(root)).toBe(root);
try {
const descendantScript = `
const fs = require('node:fs');
fs.writeSync(1, 'fixture-stdout');
fs.writeSync(2, 'fixture-stderr');
fs.writeFileSync(${JSON.stringify(marker + '.tmp')}, JSON.stringify({ pid: process.pid, stdout: true, stderr: true }));
fs.renameSync(${JSON.stringify(marker + '.tmp')}, ${JSON.stringify(marker)});
setInterval(() => {}, 1000);
`;
const childScript = `
const { spawn } = require('node:child_process');
const fs = require('node:fs');
const descendant = spawn(process.execPath, ['-e', ${JSON.stringify(descendantScript)}],
{ stdio: ['ignore', 'inherit', 'inherit'], windowsHide: true, detached: process.platform === 'win32' });
fs.writeFileSync(${JSON.stringify(pidPath)}, String(descendant.pid));
const deadline = Date.now() + 5000;
const ready = () => {
if (fs.existsSync(${JSON.stringify(marker)})) process.exit(0);
if (descendant.exitCode !== null || Date.now() >= deadline) process.exit(1);
setTimeout(ready, 10);
};
ready();
`;
const script = `
const childProcess = require('node:child_process');
const originalSpawn = childProcess.spawn;
let direct;
childProcess.spawn = (...args) => { direct = originalSpawn(...args); return direct; };
require(${JSON.stringify(polyfillPath)});
let stage = 'spawn';
let directExitCode;
let markerValid = false;
let stdoutAck = false;
let stderrAck = false;
let descendantAlive = false;
let checkErrorCode = null;
(async () => {
const proc = Bun.spawn([process.execPath, '-e', ${JSON.stringify(childScript)}],
{ stdio: ['ignore', 'pipe', 'pipe'] });
if (!direct) throw new Error('capture_missing');
const stdout = proc.stdout.getReader();
const stderr = proc.stderr.getReader();
const stdoutRead = stdout.read();
const stderrRead = stderr.read();
stage = 'direct_exit';
directExitCode = await new Promise((resolve, reject) => { direct.once('exit', resolve); direct.once('error', reject); });
let readyPid;
try {
const fs = require('node:fs');
const marker = JSON.parse(fs.readFileSync(${JSON.stringify(marker)}, 'utf8'));
readyPid = marker.pid;
markerValid = Number.isSafeInteger(readyPid) && readyPid > 0
&& String(readyPid) === fs.readFileSync(${JSON.stringify(pidPath)}, 'utf8');
stdoutAck = marker.stdout === true;
stderrAck = marker.stderr === true;
} catch (error) { checkErrorCode = typeof error.code === 'string' ? error.code : 'invalid_marker'; }
if (markerValid) {
try { process.kill(readyPid, 0); descendantAlive = true; }
catch (error) { checkErrorCode = typeof error.code === 'string' ? error.code : 'liveness_error'; }
}
if (!markerValid || !stdoutAck || !stderrAck || !descendantAlive) throw new Error('descendant_not_ready');
stage = 'pending_check';
await new Promise(resolve => setImmediate(resolve));
let settled = false;
proc.exited.then(() => { settled = true; });
await new Promise(resolve => setImmediate(resolve));
if (settled) throw new Error('Inherited pipes unexpectedly closed before cancellation');
stage = 'cancel';
await Promise.all([stdout.cancel(), stderr.cancel()]);
const reads = await Promise.all([stdoutRead, stderrRead]);
stage = 'await_exited';
let timer;
const code = await Promise.race([proc.exited, new Promise((_, reject) =>
{ timer = setTimeout(() => reject(new Error('cancel did not settle exited')), 5000); })])
.finally(() => clearTimeout(timer));
console.log(JSON.stringify({ code, directExitCode, reads: reads.map(read => read.done), descendantAlive: (() => {
try { process.kill(JSON.parse(require('node:fs').readFileSync(${JSON.stringify(marker)}, 'utf8')).pid, 0); return true; }
catch { return false; }
})() }));
})().catch(error => {
const reason = error.message === 'Inherited pipes unexpectedly closed before cancellation' ? 'early_pipes'
: error.message === 'cancel did not settle exited' ? 'cancel_stalled'
: error.message === 'capture_missing' ? 'capture_missing'
: error.message === 'descendant_not_ready' ? 'descendant_not_ready' : 'unexpected';
console.error(JSON.stringify({ stage, reason, directExitCode, markerValid, stdoutAck, stderrAck,
descendantAlive, checkErrorCode, errorCode: typeof error.code === 'string' ? error.code : null }));
process.exitCode = 1;
});
`;
const result = Bun.spawnSync(['node', '-e', script], { stdout: 'pipe', stderr: 'pipe', timeout: 30_000 });
const errorOutput = result.stderr.toString().trim();
let diagnostic: object | null = null;
try { if (errorOutput) diagnostic = JSON.parse(errorOutput); }
catch { diagnostic = { stage: 'unframed', stderrBytes: Buffer.byteLength(errorOutput) }; }
expect({ exitCode: result.exitCode, diagnostic }).toEqual({ exitCode: 0, diagnostic: null });
expect(JSON.parse(result.stdout.toString())).toEqual({ code: 0, directExitCode: 0, reads: [true, true], descendantAlive: true });
} finally {
if (fs.existsSync(pidPath)) {
const pidText = fs.readFileSync(pidPath, 'utf8');
if (/^[1-9]\d*$/.test(pidText)) {
try { process.kill(Number(pidText)); } catch (error: any) { if (error.code !== 'ESRCH') throw error; }
}
}
fs.rmSync(root, { recursive: true, force: true });
}
});
test('Bun.serve creates an HTTP server that responds', async () => {
const result = Bun.spawnSync(['node', '-e', `
require(${JSON.stringify(polyfillPath)});