Files
gstack/browse/test/windows-spawn-hide.test.ts
T
Garry TanandClaude Fable 5 7171f10364 fix(browse): isProcessAlive uses signal-0 on every platform — no more tasklist probe (#1952)
Replace the Windows tasklist shell-out in isProcessAlive with
process.kill(pid, 0), unifying all platforms on the POSIX idiom. Node maps
signal-0 to an OpenProcess existence check on Windows — and the Windows
daemon runs under Node (dist/server-node.mjs + bun-polyfill, the documented
oven-sh/bun#4253 fallback) — so the probe is portable.

Why the shell-out had to go, beyond the cosmetic conhost flash the watchdog
blinked into the foreground every 60s (#1952): a Bun.spawnSync that hits
its timeout still RETURNS with partial stdout, so the `.includes()` PID
match answered "dead" for LIVE processes under load — the false-negative
half of the #2414/#2295 leak chain. Signal 0 spawns nothing, cannot time
out, and is ~5 orders of magnitude faster (measurements in #2414). EPERM
still reports alive (process exists, we just can't signal it).

Layered on the post-#2414-absorb shape: test 3 in
process-liveness-windows.test.ts now asserts the probe is subprocess-free
on ANY platform (win32 exemption dropped), test 4's static tripwire loses
its error-handling.ts exemption (a `tasklist … PID eq` existence probe
anywhere in src/ now fails CI), and windows-spawn-hide.test.ts drops its
tasklist-in-error-handling needle (nothing spawns, which is stronger than
hiding the window).

Tests: process-liveness-windows + windows-spawn-hide + error-handling —
17 pass, 0 fail.

Fixes #1952.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-16 10:59:05 -07:00

66 lines
2.9 KiB
TypeScript

/**
* Static tripwire for #1835: child spawns reachable on Windows must pass
* windowsHide, or every daemon relaunch / taskkill / icacls / powershell
* invocation flashes a black console window (and can steal focus).
*
* Source-level, same style as server-auth.test.ts / cdp-session-cleanup.test.ts:
* cheap, deterministic, runs on every platform.
*/
import { describe, expect, test } from 'bun:test';
import * as fs from 'fs';
import * as path from 'path';
const SRC = (f: string) => fs.readFileSync(path.join(import.meta.dir, '../src', f), 'utf-8');
/** Every occurrence of `needle` in `src` must have `windowsHide` within the
* next `window` chars (the spawn's options object). */
function expectHideNearEvery(src: string, needle: string, window = 400): void {
let idx = src.indexOf(needle);
expect(idx).toBeGreaterThanOrEqual(0);
while (idx !== -1) {
const slice = src.slice(idx, idx + window);
expect(slice).toMatch(/windowsHide:\s*true/);
idx = src.indexOf(needle, idx + needle.length);
}
}
describe('windowsHide on Windows-reachable spawns (#1835)', () => {
test('daemon launch paths in cli.ts pass windowsHide', () => {
const cli = SRC('cli.ts');
// Installed path: node -e launcher — both the outer spawnSync and the
// inner detached daemon spawn (inside the launcher code string).
expect(cli).toContain('detached:true,windowsHide:true');
expectHideNearEvery(cli, "'-e', launcherCode]");
// Dev fallback: detached bun spawn.
expectHideNearEvery(cli, "nodeSpawn('bun'");
// taskkill (killServer).
expectHideNearEvery(cli, "'taskkill'");
});
test('Windows-only process probes pass windowsHide', () => {
// isProcessAlive no longer spawns anything (signal-0 on every platform,
// #1952) — process-liveness-windows.test.ts pins that it stays
// subprocess-free, which is stronger than hiding a window.
// powershell DPAPI + tasklist in cookie import.
const cookie = SRC('cookie-import-browser.ts');
expectHideNearEvery(cookie, "'powershell'");
expectHideNearEvery(cookie, "'tasklist'");
});
test('icacls calls in file-permissions.ts pass windowsHide', () => {
const perms = SRC('file-permissions.ts');
expect((perms.match(/'icacls'/g) || []).length).toBeGreaterThanOrEqual(3);
expectHideNearEvery(perms, "'icacls'");
});
test('terminal-agent respawn in terminal-agent-control.ts passes windowsHide', () => {
// The CLI cold-start + v1.44 watchdog respawn path. On Windows it runs
// through the Node polyfill (dist/bun-polyfill.cjs) whose host default is
// the opposite of Bun's — a visible console window on every watchdog
// respawn is the symptom when the flag is dropped. Wider window: the
// spawn's options object carries the full env wiring before the flag.
expectHideNearEvery(SRC('terminal-agent-control.ts'), '(Bun as any).spawn(', 700);
});
});