mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-28 07:32:14 +02:00
v1.90.0.0 feat: make browser cookie imports explicit and safe (#2964)
* fix(browse): prepare reliable cookie import wave for validation * ci: sequence quality and behavior for validation branch * fix(browse): isolate Windows qualification and preserve native diagnostics * test(browse): cover cookie workflow quality and isolate Windows user paths * test(browse): trace native member startup and initialize fresh folders * fix(browse): keep Windows member stdin alive through EOF * fix(browse): latch native timeouts and compare contained Edge startup * test(browse): verify native version metadata and actual Windows argv * test(browse): qualify Dia import on isolated macOS CI * fix(browse): require picker origin for session mutations * fix(browse): bound credential reads through stream completion * test(browse): inspect owned Windows process arguments natively * test(evals): preserve passing coverage during cookie repair reruns * test(browse): isolate Dia qualification in a fresh macOS account * test(browse): pass bounded integer timeouts to native Mac probes * test(browse): distinguish Windows profile initialization from containment * test(browse): await descendant pipe readiness before parent exit * test(browse): initialize and restore isolated macOS Keychain state * test(browse): initialize Windows fixture folders before qualification * test(ci): pin the same Node runtime across Windows checks * test(browse): distinguish native macOS browser preflight stages * test(browse): isolate Windows descendant console lifetime * test(browse): preserve native receipts and identify fixture lock holders * test(browse): prepare dependency resolution before native Mac worker startup * test(ci): include lock and close checks in native diagnostics * test(browse): preserve native owner probe stages and subprocess deadlines * fix(browse): classify Chromium profile-in-use exit precisely * test(browse): retain Mac qualification evidence through cleanup failures * test(browse): bound Mac fixture paths and retire its owned user domain * test(browse): accept vanished fixture entries without weakening cleanup * test(browse): identify probe-created macOS user domains safely * test(browse): observe Mac user domains without targeting them first * test(browse): use passive fresh-user ownership throughout Mac qualification * test(browse): distinguish profile and registered-home Keychain lookups * test(browse): qualify Dia under one registered account home * test(browse): identify Dia startup and owned process-group failures * test(browse): classify bounded Dia startup diagnostics without leaking output * fix(test): preserve native Mac sandboxing and reap owned browser children * fix(browse): preserve Chromium sandboxing for native profile imports * test(browse): inspect signed Mach-O architecture without launching Xcode tools * test(browse): sample pending Dia startup and reap on all cleanup paths * test(browse): compare protected Dia launches in fresh Bun and Node accounts * test(browse): inspect isolated Mac GUI readiness without browser access * v1.90.0.0 fix: bind cookie picker actions to their document * test: validate cookie guards and fit nested launch fixtures * ci: configure the bundled Chromium sandbox helper * fix(browse): classify Playwright authentication timeouts * test: retain bounded Windows lifecycle diagnostics * test(cso): reuse bounded NTFS precision candidates * test(review): handle explicit preservation choices safely * test(browse): remove owned fixture directories with explicit primitives * test(review): distinguish descriptive reuse from edit commitments * test: admit only the approved unscored cookie workflow refusal * test: keep the Office Hours judge mock export-complete * fix: keep dependency-free CI planners independent of the model SDK * test: observe the exact holder after a native fixture unlink failure * fix: start seeded PTY observations at owned readiness * test: acquire identity-bound Windows deletion admission before profile resets * test: preserve qualified Git index bits without authorizing mutations
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
import { describe, test, expect, afterAll, setDefaultTimeout } from 'bun:test';
|
||||
import * as path from 'path';
|
||||
import * as fs from 'node:fs';
|
||||
import * as os from 'node:os';
|
||||
|
||||
// Every test here spawnSync's a `node` child; Windows CI cold-start (AV scan,
|
||||
// first-touch of node.exe) alone can blow bun's 5s default — observed 5,007ms
|
||||
@@ -204,6 +206,118 @@ describe('bun-polyfill', () => {
|
||||
expect(result.stdout.toString().trim()).toBe('1048576:0');
|
||||
}, 15000);
|
||||
|
||||
test('cancelled replay readers release inherited pipes after the direct child exits', () => {
|
||||
const root = fs.realpathSync(fs.mkdtempSync(path.join(os.tmpdir(), 'polyfill-cancel-')));
|
||||
const marker = path.join(root, 'descendant.pid');
|
||||
const pidPath = path.join(root, 'spawned.pid');
|
||||
expect(fs.realpathSync(root)).toBe(root);
|
||||
try {
|
||||
const descendantScript = `
|
||||
const fs = require('node:fs');
|
||||
fs.writeSync(1, 'fixture-stdout');
|
||||
fs.writeSync(2, 'fixture-stderr');
|
||||
fs.writeFileSync(${JSON.stringify(marker + '.tmp')}, JSON.stringify({ pid: process.pid, stdout: true, stderr: true }));
|
||||
fs.renameSync(${JSON.stringify(marker + '.tmp')}, ${JSON.stringify(marker)});
|
||||
setInterval(() => {}, 1000);
|
||||
`;
|
||||
const childScript = `
|
||||
const { spawn } = require('node:child_process');
|
||||
const fs = require('node:fs');
|
||||
const descendant = spawn(process.execPath, ['-e', ${JSON.stringify(descendantScript)}],
|
||||
{ stdio: ['ignore', 'inherit', 'inherit'], windowsHide: true, detached: process.platform === 'win32' });
|
||||
fs.writeFileSync(${JSON.stringify(pidPath)}, String(descendant.pid));
|
||||
const deadline = Date.now() + 5000;
|
||||
const ready = () => {
|
||||
if (fs.existsSync(${JSON.stringify(marker)})) process.exit(0);
|
||||
if (descendant.exitCode !== null || Date.now() >= deadline) process.exit(1);
|
||||
setTimeout(ready, 10);
|
||||
};
|
||||
ready();
|
||||
`;
|
||||
const script = `
|
||||
const childProcess = require('node:child_process');
|
||||
const originalSpawn = childProcess.spawn;
|
||||
let direct;
|
||||
childProcess.spawn = (...args) => { direct = originalSpawn(...args); return direct; };
|
||||
require(${JSON.stringify(polyfillPath)});
|
||||
let stage = 'spawn';
|
||||
let directExitCode;
|
||||
let markerValid = false;
|
||||
let stdoutAck = false;
|
||||
let stderrAck = false;
|
||||
let descendantAlive = false;
|
||||
let checkErrorCode = null;
|
||||
(async () => {
|
||||
const proc = Bun.spawn([process.execPath, '-e', ${JSON.stringify(childScript)}],
|
||||
{ stdio: ['ignore', 'pipe', 'pipe'] });
|
||||
if (!direct) throw new Error('capture_missing');
|
||||
const stdout = proc.stdout.getReader();
|
||||
const stderr = proc.stderr.getReader();
|
||||
const stdoutRead = stdout.read();
|
||||
const stderrRead = stderr.read();
|
||||
stage = 'direct_exit';
|
||||
directExitCode = await new Promise((resolve, reject) => { direct.once('exit', resolve); direct.once('error', reject); });
|
||||
let readyPid;
|
||||
try {
|
||||
const fs = require('node:fs');
|
||||
const marker = JSON.parse(fs.readFileSync(${JSON.stringify(marker)}, 'utf8'));
|
||||
readyPid = marker.pid;
|
||||
markerValid = Number.isSafeInteger(readyPid) && readyPid > 0
|
||||
&& String(readyPid) === fs.readFileSync(${JSON.stringify(pidPath)}, 'utf8');
|
||||
stdoutAck = marker.stdout === true;
|
||||
stderrAck = marker.stderr === true;
|
||||
} catch (error) { checkErrorCode = typeof error.code === 'string' ? error.code : 'invalid_marker'; }
|
||||
if (markerValid) {
|
||||
try { process.kill(readyPid, 0); descendantAlive = true; }
|
||||
catch (error) { checkErrorCode = typeof error.code === 'string' ? error.code : 'liveness_error'; }
|
||||
}
|
||||
if (!markerValid || !stdoutAck || !stderrAck || !descendantAlive) throw new Error('descendant_not_ready');
|
||||
stage = 'pending_check';
|
||||
await new Promise(resolve => setImmediate(resolve));
|
||||
let settled = false;
|
||||
proc.exited.then(() => { settled = true; });
|
||||
await new Promise(resolve => setImmediate(resolve));
|
||||
if (settled) throw new Error('Inherited pipes unexpectedly closed before cancellation');
|
||||
stage = 'cancel';
|
||||
await Promise.all([stdout.cancel(), stderr.cancel()]);
|
||||
const reads = await Promise.all([stdoutRead, stderrRead]);
|
||||
stage = 'await_exited';
|
||||
let timer;
|
||||
const code = await Promise.race([proc.exited, new Promise((_, reject) =>
|
||||
{ timer = setTimeout(() => reject(new Error('cancel did not settle exited')), 5000); })])
|
||||
.finally(() => clearTimeout(timer));
|
||||
console.log(JSON.stringify({ code, directExitCode, reads: reads.map(read => read.done), descendantAlive: (() => {
|
||||
try { process.kill(JSON.parse(require('node:fs').readFileSync(${JSON.stringify(marker)}, 'utf8')).pid, 0); return true; }
|
||||
catch { return false; }
|
||||
})() }));
|
||||
})().catch(error => {
|
||||
const reason = error.message === 'Inherited pipes unexpectedly closed before cancellation' ? 'early_pipes'
|
||||
: error.message === 'cancel did not settle exited' ? 'cancel_stalled'
|
||||
: error.message === 'capture_missing' ? 'capture_missing'
|
||||
: error.message === 'descendant_not_ready' ? 'descendant_not_ready' : 'unexpected';
|
||||
console.error(JSON.stringify({ stage, reason, directExitCode, markerValid, stdoutAck, stderrAck,
|
||||
descendantAlive, checkErrorCode, errorCode: typeof error.code === 'string' ? error.code : null }));
|
||||
process.exitCode = 1;
|
||||
});
|
||||
`;
|
||||
const result = Bun.spawnSync(['node', '-e', script], { stdout: 'pipe', stderr: 'pipe', timeout: 30_000 });
|
||||
const errorOutput = result.stderr.toString().trim();
|
||||
let diagnostic: object | null = null;
|
||||
try { if (errorOutput) diagnostic = JSON.parse(errorOutput); }
|
||||
catch { diagnostic = { stage: 'unframed', stderrBytes: Buffer.byteLength(errorOutput) }; }
|
||||
expect({ exitCode: result.exitCode, diagnostic }).toEqual({ exitCode: 0, diagnostic: null });
|
||||
expect(JSON.parse(result.stdout.toString())).toEqual({ code: 0, directExitCode: 0, reads: [true, true], descendantAlive: true });
|
||||
} finally {
|
||||
if (fs.existsSync(pidPath)) {
|
||||
const pidText = fs.readFileSync(pidPath, 'utf8');
|
||||
if (/^[1-9]\d*$/.test(pidText)) {
|
||||
try { process.kill(Number(pidText)); } catch (error: any) { if (error.code !== 'ESRCH') throw error; }
|
||||
}
|
||||
}
|
||||
fs.rmSync(root, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
test('Bun.serve creates an HTTP server that responds', async () => {
|
||||
const result = Bun.spawnSync(['node', '-e', `
|
||||
require(${JSON.stringify(polyfillPath)});
|
||||
|
||||
Reference in New Issue
Block a user