mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-26 09:52:11 +03:00
fix(build): v3.8.48 hotfix — npm tarball head-response-guard (#7065), electron win spawn, Sonar gate zeroed (#7055)
* fix(build): spawn npx.cmd through a shell in the electron better-sqlite3 rebuild Node's CVE-2024-27980 hardening makes spawnSync of .cmd/.bat shims fail with status null unless shell:true — the v3.8.47 tag build died on the Windows job with 'better-sqlite3 rebuild against electron 43.1.0 failed (exit null)'. Extracted the spawn plan into electronRebuildPlan.mjs (pure, import-safe) with a regression test; args are fixed literals, no untrusted input reaches the shell. * fix(build): ship head-response-guard.cjs in the npm tarball (#7065) The prepublish prune allowlist (pack-artifact-policy.ts) lacked head-response-guard.cjs, so assembleStandalone copied it and the prune deleted it — every boot of the published 3.8.47 crashed with ERR_MODULE_NOT_FOUND (3rd occurrence of this class; tls-options/3.8.41). Also added to PACK_ARTIFACT_REQUIRED_PATHS so check:pack-artifact fails loudly, plus a closure test that derives every server-ws.mjs sibling import and asserts both lists cover it. * fix(ci): zero the Sonar quality-gate findings on new code - ci.yml sonarqube job: download the coverage artifact into coverage/ so lcov.info lands where sonar.javascript.lcov.reportPaths points — the upload strips the common coverage/ prefix, so 'path: .' left new-code coverage at 0% on every scan - kiro auto-import: await the async isCloudEnabled() gate (S6544 — a bare truthiness check on the Promise made syncToCloud run even with cloud sync disabled) - stream.ts: real JSON fallback in the reasoning-split clone (S3923 — both ternary branches called structuredClone, the promised fallback was dead) - codex executor: handle the async reader.cancel() rejection (S4822) - deterministic localeCompare sorts (S2871 x2) - classify-pr-changes.mjs: confine the argv list file to the workspace (jssecurity:S8707 path-traversal guard) + behavioral tests - Dockerfile: rebuild better-sqlite3 with npm's bundled node-gyp instead of npx --yes (docker:S6505 — no on-demand registry install) * chore(ci): make the Sonar quality gate informational (wait=false) The org's SonarCloud FREE plan cannot associate a custom quality gate — only the built-in Sonar way (80% new coverage) applies, which no full-cycle release PR can realistically meet. The scan still uploads (dashboard, PR decoration); the CI job just no longer fails on the gate. A tuned 'OmniRoute way' gate (coverage >=60, duplication <=5) is already configured in the org for the day the plan is upgraded — re-enable wait=true then. * chore(release): v3.8.48 hotfix bump + changelog (npm 3.8.47 unbootable, #7065) * test: align pack-artifact + dockerfile guards to the corrected contracts pack-artifact-policy.test.ts encoded the pre-#7065 REQUIRED list (without head-response-guard.cjs) and dockerfile-better-sqlite3-node-gyp-6700.test.ts asserted the npx invocation the Sonar fix replaced with npm's bundled node-gyp — both now assert the corrected behavior.
This commit is contained in:
committed by
GitHub
parent
e8950ded39
commit
7ee5bbc64d
17
scripts/build/electronRebuildPlan.mjs
Normal file
17
scripts/build/electronRebuildPlan.mjs
Normal file
@@ -0,0 +1,17 @@
|
||||
/**
|
||||
* Spawn plan for the better-sqlite3 Electron-ABI rebuild (pure — import-safe for tests).
|
||||
*
|
||||
* On Windows, `npx.cmd` MUST be spawned through a shell: since Node's
|
||||
* CVE-2024-27980 hardening, spawning `.cmd`/`.bat` shims without `shell: true`
|
||||
* fails outright (spawnSync returns `status: null`), which broke the v3.8.47
|
||||
* tag build ("better-sqlite3 rebuild against electron 43.1.0 failed (exit null)").
|
||||
* The args are a fixed literal list — no untrusted input reaches the shell.
|
||||
*/
|
||||
export function buildRebuildSpawnPlan(platform) {
|
||||
const win = platform === "win32";
|
||||
return {
|
||||
command: win ? "npx.cmd" : "npx",
|
||||
args: ["--yes", "node-gyp", "rebuild"],
|
||||
shell: win,
|
||||
};
|
||||
}
|
||||
@@ -35,6 +35,10 @@ export const APP_STAGING_ALLOWED_EXACT_PATHS: string[] = [
|
||||
".env.example",
|
||||
"BUILD_SHA",
|
||||
"docs/openapi.yaml",
|
||||
// #7065: imported by dist/server-ws.mjs; assembleStandalone copies it but without
|
||||
// this bare entry the prepublish prune deleted it → every `omniroute` boot of the
|
||||
// published 3.8.47 crashed with ERR_MODULE_NOT_FOUND (same class as tls-options/3.8.41).
|
||||
"head-response-guard.cjs",
|
||||
"http-method-guard.cjs",
|
||||
"open-sse/mcp-server/server.js",
|
||||
// LLMLingua ONNX worker — esbuild'd standalone .js spawned via worker_threads
|
||||
@@ -152,6 +156,8 @@ export const PACK_ARTIFACT_REQUIRED_PATHS: string[] = [
|
||||
// #5452: regression guard — make check:pack-artifact fail loudly if the TLS
|
||||
// opt-in sidecar (imported by dist/server-ws.mjs) ever vanishes from the tarball.
|
||||
"dist/tls-options.mjs",
|
||||
// #7065: regression guard for the HEAD response guard (dist/server-ws.mjs import).
|
||||
"dist/head-response-guard.cjs",
|
||||
"dist/webdav-handler.mjs",
|
||||
"bin/cli/program.mjs",
|
||||
"bin/mcp-server.mjs",
|
||||
|
||||
@@ -5,6 +5,7 @@ import { basename, dirname, join, relative } from "node:path";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { spawnSync } from "node:child_process";
|
||||
import { assembleStandalone } from "./assembleStandalone.mjs";
|
||||
import { buildRebuildSpawnPlan } from "./electronRebuildPlan.mjs";
|
||||
|
||||
const __filename = fileURLToPath(import.meta.url);
|
||||
const __dirname = dirname(__filename);
|
||||
@@ -122,12 +123,16 @@ function rebuildBetterSqlite3ForElectron(standaloneNodeModules) {
|
||||
rmSync(join(destMod, "build"), { recursive: true, force: true });
|
||||
|
||||
console.log(`[electron] rebuilding better-sqlite3 against electron ${electronVersion} ABI…`);
|
||||
const plan = buildRebuildSpawnPlan(process.platform);
|
||||
const result = spawnSync(
|
||||
process.platform === "win32" ? "npx.cmd" : "npx",
|
||||
["--yes", "node-gyp", "rebuild"],
|
||||
plan.command,
|
||||
plan.args,
|
||||
{
|
||||
cwd: destMod,
|
||||
stdio: "inherit",
|
||||
// .cmd shims must go through a shell on Windows (CVE-2024-27980 hardening
|
||||
// makes a shell-less spawn fail with status null); args are fixed literals.
|
||||
shell: plan.shell,
|
||||
// Compile against the Electron headers (not Node's) so the .node lands in
|
||||
// build/Release with the Electron NODE_MODULE_VERSION. No shell interpolation.
|
||||
env: {
|
||||
|
||||
@@ -32,7 +32,7 @@ if (!fs.existsSync(OPENAPI_PATH)) {
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
const implementedPaths = collectApiRouteUrlPaths(ROOT).sort();
|
||||
const implementedPaths = collectApiRouteUrlPaths(ROOT).sort((a, b) => a.localeCompare(b));
|
||||
const raw = yaml.load(fs.readFileSync(OPENAPI_PATH, "utf-8"));
|
||||
const documentedPaths = new Set(Object.keys(raw.paths || {}));
|
||||
|
||||
|
||||
@@ -91,8 +91,17 @@ function main() {
|
||||
const listPath = process.argv[2];
|
||||
let files;
|
||||
if (listPath && listPath !== "-") {
|
||||
// Both CI callers pass a workspace-relative file (changed-files.txt); confine
|
||||
// the argument to the working directory so a stray/hostile path can never
|
||||
// read outside the checkout (path-traversal guard).
|
||||
const resolved = path.resolve(process.cwd(), listPath);
|
||||
const rel = path.relative(process.cwd(), resolved);
|
||||
if (rel.startsWith("..") || path.isAbsolute(rel)) {
|
||||
console.error(`[classify-pr-changes] list path escapes the workspace: ${listPath}`);
|
||||
process.exit(1);
|
||||
}
|
||||
files = fs
|
||||
.readFileSync(listPath, "utf8")
|
||||
.readFileSync(resolved, "utf8")
|
||||
.split(/\r?\n/)
|
||||
.map((s) => s.trim())
|
||||
.filter(Boolean);
|
||||
|
||||
Reference in New Issue
Block a user