mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-09-30 01:51:20 +00:00
Merge branch 'main' into fix/fts-non-fatal-in-analyze
This commit is contained in:
commit
65853e4df5
21 changed files with 376 additions and 91 deletions
|
|
@ -77,6 +77,7 @@ function findCanonicalRepoRoot(cwd) {
|
|||
timeout: 2000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (result.error || result.status !== 0) return null;
|
||||
const commonDir = (result.stdout || '').trim();
|
||||
|
|
@ -200,6 +201,7 @@ function runGitNexusCli(args, cwd, timeout) {
|
|||
timeout,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
|
||||
|
|
@ -210,6 +212,7 @@ function runGitNexusCli(args, cwd, timeout) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 3000,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
useDirectBinary = which.status === 0;
|
||||
} catch {
|
||||
|
|
@ -222,6 +225,7 @@ function runGitNexusCli(args, cwd, timeout) {
|
|||
timeout,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
// npx fallback needs shell on Windows since npx is a .cmd script
|
||||
|
|
@ -230,6 +234,7 @@ function runGitNexusCli(args, cwd, timeout) {
|
|||
timeout: timeout + 5000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
|
||||
|
|
@ -318,6 +323,7 @@ function handlePostToolUse(input) {
|
|||
timeout: 3000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
currentHead = (headResult.stdout || '').trim();
|
||||
} catch {
|
||||
|
|
|
|||
|
|
@ -109,6 +109,7 @@ function hasGitNexusServerOwnerWindows(dbPathAbs, myPid) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 6000,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
env: { ...process.env, GITNEXUS_HOOK_RM_TARGET: dbPathAbs },
|
||||
},
|
||||
);
|
||||
|
|
@ -192,6 +193,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 1000,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (lsof.error) return lsof.error.code === 'ETIMEDOUT';
|
||||
|
||||
|
|
@ -203,6 +205,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 500,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (ps.error) {
|
||||
if (ps.error.code === 'ETIMEDOUT') return true;
|
||||
|
|
|
|||
|
|
@ -58,6 +58,7 @@ function findCanonicalRepoRoot(cwd) {
|
|||
timeout: 2000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (result.error || result.status !== 0) return null;
|
||||
const commonDir = (result.stdout || '').trim();
|
||||
|
|
@ -201,6 +202,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) {
|
|||
timeout,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
return spawnSync(isWin ? 'npx.cmd' : 'npx', ['-y', 'gitnexus', ...args], {
|
||||
|
|
@ -208,6 +210,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) {
|
|||
timeout: timeout + 5000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -77,6 +77,7 @@ function findCanonicalRepoRoot(cwd) {
|
|||
timeout: 2000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (result.error || result.status !== 0) return null;
|
||||
const commonDir = (result.stdout || '').trim();
|
||||
|
|
@ -218,6 +219,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) {
|
|||
timeout,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
// On Windows, invoke npx.cmd directly (no shell needed)
|
||||
|
|
@ -226,6 +228,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) {
|
|||
timeout: timeout + 5000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
}
|
||||
|
||||
|
|
@ -315,6 +318,7 @@ function handlePostToolUse(input) {
|
|||
timeout: 3000,
|
||||
cwd,
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
currentHead = (headResult.stdout || '').trim();
|
||||
} catch {
|
||||
|
|
|
|||
|
|
@ -109,6 +109,7 @@ function hasGitNexusServerOwnerWindows(dbPathAbs, myPid) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 6000,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
env: { ...process.env, GITNEXUS_HOOK_RM_TARGET: dbPathAbs },
|
||||
},
|
||||
);
|
||||
|
|
@ -192,6 +193,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 1000,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (lsof.error) return lsof.error.code === 'ETIMEDOUT';
|
||||
|
||||
|
|
@ -203,6 +205,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) {
|
|||
encoding: 'utf-8',
|
||||
timeout: 500,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (ps.error) {
|
||||
if (ps.error.code === 'ETIMEDOUT') return true;
|
||||
|
|
|
|||
|
|
@ -312,6 +312,7 @@ const runRespawnedAnalyze = (
|
|||
|
||||
const child = spawn(process.execPath, [...args], {
|
||||
stdio: ['inherit', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
env,
|
||||
});
|
||||
|
||||
|
|
|
|||
|
|
@ -54,6 +54,7 @@ function resolveGitnexusBin(): string | null {
|
|||
encoding: 'utf-8',
|
||||
timeout: 5000,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
});
|
||||
const lines = output
|
||||
.split('\n')
|
||||
|
|
@ -532,6 +533,7 @@ async function setupCodex(result: SetupResult): Promise<void> {
|
|||
const entry = getMcpEntry();
|
||||
await execFileAsync('codex', ['mcp', 'add', 'gitnexus', '--', entry.command, ...entry.args], {
|
||||
shell: process.platform === 'win32',
|
||||
windowsHide: true,
|
||||
});
|
||||
result.configured.push('Codex');
|
||||
return;
|
||||
|
|
|
|||
|
|
@ -519,7 +519,7 @@ const wikiCommandImpl = async (inputPath?: string, options?: WikiCommandOptions)
|
|||
console.log(' Save and close the editor when done.\n');
|
||||
|
||||
try {
|
||||
execFileSync(editor, [treeFile], { stdio: 'inherit' });
|
||||
execFileSync(editor, [treeFile], { stdio: 'inherit', windowsHide: true });
|
||||
} catch {
|
||||
console.log(` Could not open editor. Please edit manually:\n ${treeFile}\n`);
|
||||
console.log(' Then run `gitnexus wiki` to continue.\n');
|
||||
|
|
@ -655,7 +655,7 @@ const wikiCommandImpl = async (inputPath?: string, options?: WikiCommandOptions)
|
|||
|
||||
function hasGhCLI(): boolean {
|
||||
try {
|
||||
execSync('gh --version', { stdio: 'ignore' });
|
||||
execSync('gh --version', { stdio: 'ignore', windowsHide: true });
|
||||
return true;
|
||||
} catch {
|
||||
return false;
|
||||
|
|
@ -699,7 +699,7 @@ function publishGist(htmlPath: string): { url: string; rawUrl: string } | null {
|
|||
const output = execFileSync(
|
||||
'gh',
|
||||
['gist', 'create', htmlPath, '--desc', 'Repository Wiki — generated by GitNexus', '--public'],
|
||||
{ encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'] },
|
||||
{ encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'], windowsHide: true },
|
||||
).trim();
|
||||
|
||||
// `gh gist create` prints the gist URL as a line in the output. Find the
|
||||
|
|
|
|||
|
|
@ -78,7 +78,11 @@ function isCudaAvailable(): boolean {
|
|||
// Primary: query the dynamic linker cache — covers all architectures,
|
||||
// distro layouts, and custom install paths registered with ldconfig
|
||||
try {
|
||||
const out = execFileSync('ldconfig', ['-p'], { timeout: 3000, encoding: 'utf-8' });
|
||||
const out = execFileSync('ldconfig', ['-p'], {
|
||||
timeout: 3000,
|
||||
encoding: 'utf-8',
|
||||
windowsHide: true,
|
||||
});
|
||||
if (out.includes('libcublasLt.so.12')) return true;
|
||||
} catch {
|
||||
// ldconfig not available (e.g. non-standard container)
|
||||
|
|
|
|||
|
|
@ -26,6 +26,7 @@ export function checkStaleness(repoPath: string, lastCommit: string): StalenessI
|
|||
cwd: repoPath,
|
||||
encoding: 'utf-8',
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
}).trim();
|
||||
|
||||
const commitsBehind = parseInt(result, 10) || 0;
|
||||
|
|
@ -59,6 +60,7 @@ export async function checkStalenessAsync(
|
|||
const { stdout } = await execFileAsync('git', ['rev-list', '--count', `${lastCommit}..HEAD`], {
|
||||
cwd: repoPath,
|
||||
encoding: 'utf-8',
|
||||
windowsHide: true,
|
||||
});
|
||||
|
||||
const commitsBehind = parseInt(stdout.trim(), 10) || 0;
|
||||
|
|
@ -90,6 +92,7 @@ function commitsAheadOfIndexed(siblingPath: string, indexedCommit: string): numb
|
|||
cwd: siblingPath,
|
||||
encoding: 'utf-8',
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
}).trim();
|
||||
return parseInt(result, 10) || 0;
|
||||
} catch {
|
||||
|
|
|
|||
|
|
@ -525,6 +525,7 @@ const ensureReadOnlyConnectionUsable = async (
|
|||
dbPath: string,
|
||||
handle: LbugConnectionHandle,
|
||||
): Promise<LbugConnectionHandle> => {
|
||||
let shadowReplayErr: unknown;
|
||||
try {
|
||||
await queryAndDrain(handle.conn, READ_ONLY_SHADOW_REPLAY_PROBE);
|
||||
return handle;
|
||||
|
|
@ -537,11 +538,25 @@ const ensureReadOnlyConnectionUsable = async (
|
|||
await closeLbugConnection(handle);
|
||||
throw err;
|
||||
}
|
||||
shadowReplayErr = err;
|
||||
}
|
||||
|
||||
await closeLbugConnection(handle);
|
||||
|
||||
const writable = await openLbugConnection(lbug, dbPath);
|
||||
let writable: LbugConnectionHandle;
|
||||
try {
|
||||
writable = await openLbugConnection(lbug, dbPath);
|
||||
} catch (openErr) {
|
||||
const code = extractErrnoCode(openErr);
|
||||
if (code === 'EROFS' || code === 'EACCES' || code === 'EPERM') {
|
||||
throw new Error(
|
||||
shadowSidecarRecoveryMessage(dbPath, shadowReplayErr) +
|
||||
'\n The workspace appears to be read-only — mount it read-write to perform shadow replay recovery,' +
|
||||
' or re-run `gitnexus analyze` on a writable filesystem to rebuild the index.',
|
||||
);
|
||||
}
|
||||
throw openErr;
|
||||
}
|
||||
let missingShadowError: unknown;
|
||||
try {
|
||||
await queryAndDrain(writable.conn, READ_ONLY_SHADOW_REPLAY_PROBE);
|
||||
|
|
@ -691,94 +706,112 @@ const doInitLbug = async (dbPath: string, readOnly: boolean = false) => {
|
|||
ensuredFTSIndexes.clear();
|
||||
}
|
||||
|
||||
// LadybugDB stores the database as a single file (not a directory).
|
||||
// If the path already exists, it must be a valid LadybugDB database file.
|
||||
// Remove stale empty directories or files from older versions.
|
||||
try {
|
||||
const stat = await fs.lstat(dbPath);
|
||||
if (stat.isSymbolicLink()) {
|
||||
// Never follow symlinks — just remove the link itself
|
||||
await fs.unlink(dbPath);
|
||||
} else if (stat.isDirectory()) {
|
||||
// Verify path is within expected storage directory before deleting
|
||||
const realPath = await fs.realpath(dbPath);
|
||||
const parentDir = path.dirname(dbPath);
|
||||
const realParent = await fs.realpath(parentDir);
|
||||
if (!realPath.startsWith(realParent + path.sep) && realPath !== realParent) {
|
||||
throw new Error(
|
||||
`Refusing to delete ${dbPath}: resolved path ${realPath} is outside storage directory`,
|
||||
);
|
||||
}
|
||||
// Old-style directory database or empty leftover - remove it
|
||||
await fs.rm(dbPath, { recursive: true, force: true });
|
||||
}
|
||||
// If it's a file, assume it's an existing LadybugDB database - LadybugDB will open it
|
||||
} catch (err) {
|
||||
if (!isMissingFileError(err)) {
|
||||
throw err;
|
||||
}
|
||||
// Path doesn't exist, which is what LadybugDB wants for a new database
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Cross-process critical section: acquire init lock, clean orphan sidecars,
|
||||
// and open the database. The lock prevents a TOCTOU race where another
|
||||
// process could create a fresh DB between our access() check and the
|
||||
// unlink() of stale sidecars.
|
||||
// Read-only fast path: skip all filesystem mutations (path cleanup, init
|
||||
// lock, orphan sidecar removal, mkdir) so the open succeeds on read-only
|
||||
// filesystems such as Docker `:ro` bind mounts. The init lock exists to
|
||||
// prevent a TOCTOU race during DB *creation* — read-only opens never
|
||||
// create databases and don't need the lock.
|
||||
// ---------------------------------------------------------------------------
|
||||
const releaseInitLock = await acquireInitLock(dbPath);
|
||||
try {
|
||||
// Crash-recovery cleanup: if the main DB file is missing, stale sidecars
|
||||
// from an interrupted run can block fresh opens indefinitely.
|
||||
try {
|
||||
await fs.access(dbPath);
|
||||
} catch (err) {
|
||||
if (isMissingFileError(err)) {
|
||||
// `.shadow` is documented by LadybugDB checkpointing and `.wal.checkpoint`
|
||||
// was observed in the #1618 crash loop that motivated this recovery path.
|
||||
const orphanSidecars = [`${dbPath}.shadow`, `${dbPath}.wal.checkpoint`];
|
||||
for (const sidecar of orphanSidecars) {
|
||||
try {
|
||||
await fs.unlink(sidecar);
|
||||
logger.warn(
|
||||
`GitNexus: removed orphan sidecar ${path.basename(sidecar)} (no main DB file present)`,
|
||||
);
|
||||
} catch (err) {
|
||||
if (isMissingFileError(err)) {
|
||||
continue;
|
||||
}
|
||||
const code = extractErrnoCode(err);
|
||||
logger.warn(
|
||||
`GitNexus: failed to remove orphan sidecar ${path.basename(sidecar)} (${code ?? 'UNKNOWN'}) while main DB file is missing; LadybugDB open may still fail: ${summarizeError(err)}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
const code = extractErrnoCode(err);
|
||||
logger.warn(
|
||||
`GitNexus: unable to verify main DB file before orphan sidecar cleanup (${code ?? 'UNKNOWN'}); skipping cleanup: ${summarizeError(err)}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// Ensure parent directory exists
|
||||
const parentDir = path.dirname(dbPath);
|
||||
await fs.mkdir(parentDir, { recursive: true });
|
||||
if (readOnly) {
|
||||
await preflightLbugSidecars(dbPath, {
|
||||
mode: readOnly ? 'read-only' : 'write',
|
||||
mode: 'read-only',
|
||||
logger,
|
||||
allowQuarantine: true,
|
||||
allowQuarantine: false,
|
||||
});
|
||||
|
||||
const opened = readOnly
|
||||
? await openLbugConnection(lbug, dbPath, { readOnly: true })
|
||||
: await openLbugConnection(lbug, dbPath);
|
||||
const usable = readOnly ? await ensureReadOnlyConnectionUsable(dbPath, opened) : opened;
|
||||
const opened = await openLbugConnection(lbug, dbPath, { readOnly: true });
|
||||
const usable = await ensureReadOnlyConnectionUsable(dbPath, opened);
|
||||
db = usable.db;
|
||||
conn = usable.conn;
|
||||
currentDbReadOnly = readOnly;
|
||||
} finally {
|
||||
await releaseInitLock();
|
||||
currentDbReadOnly = true;
|
||||
} else {
|
||||
// LadybugDB stores the database as a single file (not a directory).
|
||||
// If the path already exists, it must be a valid LadybugDB database file.
|
||||
// Remove stale empty directories or files from older versions.
|
||||
try {
|
||||
const stat = await fs.lstat(dbPath);
|
||||
if (stat.isSymbolicLink()) {
|
||||
// Never follow symlinks — just remove the link itself
|
||||
await fs.unlink(dbPath);
|
||||
} else if (stat.isDirectory()) {
|
||||
// Verify path is within expected storage directory before deleting
|
||||
const realPath = await fs.realpath(dbPath);
|
||||
const parentDir = path.dirname(dbPath);
|
||||
const realParent = await fs.realpath(parentDir);
|
||||
if (!realPath.startsWith(realParent + path.sep) && realPath !== realParent) {
|
||||
throw new Error(
|
||||
`Refusing to delete ${dbPath}: resolved path ${realPath} is outside storage directory`,
|
||||
);
|
||||
}
|
||||
// Old-style directory database or empty leftover - remove it
|
||||
await fs.rm(dbPath, { recursive: true, force: true });
|
||||
}
|
||||
// If it's a file, assume it's an existing LadybugDB database - LadybugDB will open it
|
||||
} catch (err) {
|
||||
if (!isMissingFileError(err)) {
|
||||
throw err;
|
||||
}
|
||||
// Path doesn't exist, which is what LadybugDB wants for a new database
|
||||
}
|
||||
|
||||
// -------------------------------------------------------------------------
|
||||
// Cross-process critical section: acquire init lock, clean orphan sidecars,
|
||||
// and open the database. The lock prevents a TOCTOU race where another
|
||||
// process could create a fresh DB between our access() check and the
|
||||
// unlink() of stale sidecars.
|
||||
// -------------------------------------------------------------------------
|
||||
const releaseInitLock = await acquireInitLock(dbPath);
|
||||
try {
|
||||
// Crash-recovery cleanup: if the main DB file is missing, stale sidecars
|
||||
// from an interrupted run can block fresh opens indefinitely.
|
||||
try {
|
||||
await fs.access(dbPath);
|
||||
} catch (err) {
|
||||
if (isMissingFileError(err)) {
|
||||
// `.shadow` is documented by LadybugDB checkpointing and `.wal.checkpoint`
|
||||
// was observed in the #1618 crash loop that motivated this recovery path.
|
||||
const orphanSidecars = [`${dbPath}.shadow`, `${dbPath}.wal.checkpoint`];
|
||||
for (const sidecar of orphanSidecars) {
|
||||
try {
|
||||
await fs.unlink(sidecar);
|
||||
logger.warn(
|
||||
`GitNexus: removed orphan sidecar ${path.basename(sidecar)} (no main DB file present)`,
|
||||
);
|
||||
} catch (err) {
|
||||
if (isMissingFileError(err)) {
|
||||
continue;
|
||||
}
|
||||
const code = extractErrnoCode(err);
|
||||
logger.warn(
|
||||
`GitNexus: failed to remove orphan sidecar ${path.basename(sidecar)} (${code ?? 'UNKNOWN'}) while main DB file is missing; LadybugDB open may still fail: ${summarizeError(err)}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
} else {
|
||||
const code = extractErrnoCode(err);
|
||||
logger.warn(
|
||||
`GitNexus: unable to verify main DB file before orphan sidecar cleanup (${code ?? 'UNKNOWN'}); skipping cleanup: ${summarizeError(err)}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
// Ensure parent directory exists
|
||||
const parentDir = path.dirname(dbPath);
|
||||
await fs.mkdir(parentDir, { recursive: true });
|
||||
await preflightLbugSidecars(dbPath, {
|
||||
mode: 'write',
|
||||
logger,
|
||||
allowQuarantine: true,
|
||||
});
|
||||
|
||||
const opened = await openLbugConnection(lbug, dbPath);
|
||||
db = opened.db;
|
||||
conn = opened.conn;
|
||||
currentDbReadOnly = false;
|
||||
} finally {
|
||||
await releaseInitLock();
|
||||
}
|
||||
}
|
||||
|
||||
if (!readOnly) {
|
||||
|
|
|
|||
|
|
@ -332,6 +332,7 @@ export async function runFullAnalysis(
|
|||
{
|
||||
cwd: repoPath,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
encoding: 'utf8',
|
||||
},
|
||||
);
|
||||
|
|
|
|||
|
|
@ -36,7 +36,7 @@ let cachedCursorBin: string | null | undefined;
|
|||
export function detectCursorCLI(): string | null {
|
||||
if (cachedCursorBin !== undefined) return cachedCursorBin;
|
||||
try {
|
||||
execSync('agent --version', { stdio: 'ignore' });
|
||||
execSync('agent --version', { stdio: 'ignore', windowsHide: true });
|
||||
cachedCursorBin = 'agent';
|
||||
} catch {
|
||||
cachedCursorBin = null;
|
||||
|
|
@ -109,6 +109,7 @@ export async function callCursorLLM(
|
|||
const child = spawn(cursorBin, args, {
|
||||
cwd: config.workingDirectory || process.cwd(),
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
env: {
|
||||
...process.env,
|
||||
// Ensure non-interactive mode
|
||||
|
|
|
|||
|
|
@ -884,7 +884,12 @@ export class WikiGenerator {
|
|||
|
||||
private getCurrentCommit(): string {
|
||||
try {
|
||||
return execSync('git rev-parse HEAD', { cwd: this.repoPath }).toString().trim();
|
||||
return execSync('git rev-parse HEAD', {
|
||||
cwd: this.repoPath,
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
} catch {
|
||||
return '';
|
||||
}
|
||||
|
|
@ -899,6 +904,7 @@ export class WikiGenerator {
|
|||
execFileSync('git', ['merge-base', '--is-ancestor', fromCommit, toCommit], {
|
||||
cwd: this.repoPath,
|
||||
stdio: 'ignore',
|
||||
windowsHide: true,
|
||||
});
|
||||
return true;
|
||||
} catch {
|
||||
|
|
@ -916,6 +922,7 @@ export class WikiGenerator {
|
|||
try {
|
||||
const output = execFileSync('git', ['diff', `${fromCommit}..${toCommit}`, '--name-only'], {
|
||||
cwd: this.repoPath,
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
|
|
|
|||
|
|
@ -2404,6 +2404,7 @@ export class LocalBackend {
|
|||
cwd: diffCwd,
|
||||
encoding: 'utf-8',
|
||||
maxBuffer: 256 * 1024 * 1024,
|
||||
windowsHide: true,
|
||||
});
|
||||
} catch (err: any) {
|
||||
return { error: `Git diff failed: ${err.message}` };
|
||||
|
|
@ -2680,6 +2681,7 @@ export class LocalBackend {
|
|||
timeout: 5000,
|
||||
// Avoid ENOBUFS on large repos: rg -l can list many files.
|
||||
maxBuffer: 256 * 1024 * 1024,
|
||||
windowsHide: true,
|
||||
});
|
||||
const files = output
|
||||
.trim()
|
||||
|
|
|
|||
|
|
@ -304,6 +304,7 @@ export function getRemoteOriginUrl(cwd: string): Promise<string | null> {
|
|||
const proc = spawn('git', ['config', '--get', 'remote.origin.url'], {
|
||||
cwd,
|
||||
stdio: ['ignore', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
env: { ...process.env, GIT_TERMINAL_PROMPT: '0' },
|
||||
});
|
||||
let stdout = '';
|
||||
|
|
@ -427,6 +428,7 @@ function runGit(args: string[], cwd?: string): Promise<void> {
|
|||
const proc = spawn('git', args, {
|
||||
cwd,
|
||||
stdio: ['ignore', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
env: {
|
||||
...process.env,
|
||||
// Prevent git from prompting for credentials (hangs the process)
|
||||
|
|
|
|||
|
|
@ -6,7 +6,11 @@ import path from 'path';
|
|||
|
||||
export const isGitRepo = (repoPath: string): boolean => {
|
||||
try {
|
||||
execSync('git rev-parse --is-inside-work-tree', { cwd: repoPath, stdio: 'ignore' });
|
||||
execSync('git rev-parse --is-inside-work-tree', {
|
||||
cwd: repoPath,
|
||||
stdio: 'ignore',
|
||||
windowsHide: true,
|
||||
});
|
||||
return true;
|
||||
} catch {
|
||||
return false;
|
||||
|
|
@ -23,6 +27,7 @@ export const getCurrentCommit = (repoPath: string): string => {
|
|||
// "fatal: not a git repository" to stderr, which leaks to the user's
|
||||
// terminal even though the error is caught here (#1172).
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
|
|
@ -60,6 +65,7 @@ export const getRemoteUrl = (repoPath: string): string | undefined => {
|
|||
raw = execSync('git config --get remote.origin.url', {
|
||||
cwd: repoPath,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
|
|
@ -100,6 +106,7 @@ export const getGitRoot = (fromPath: string): string | null => {
|
|||
cwd: fromPath,
|
||||
// Suppress stderr -- see getCurrentCommit comment and #1172.
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
|
|
@ -142,6 +149,7 @@ export const getCanonicalRepoRoot = (fromPath: string): string | null => {
|
|||
const commonDir = execSync('git rev-parse --path-format=absolute --git-common-dir', {
|
||||
cwd: fromPath,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
|
|
@ -245,6 +253,7 @@ export const getRemoteOriginUrl = (repoPath: string): string | null => {
|
|||
const url = execSync('git config --get remote.origin.url', {
|
||||
cwd: repoPath,
|
||||
stdio: ['ignore', 'pipe', 'ignore'],
|
||||
windowsHide: true,
|
||||
})
|
||||
.toString()
|
||||
.trim();
|
||||
|
|
|
|||
29
gitnexus/test/integration/lbug-readonly-init.test.ts
Normal file
29
gitnexus/test/integration/lbug-readonly-init.test.ts
Normal file
|
|
@ -0,0 +1,29 @@
|
|||
/**
|
||||
* Integration Tests: read-only doInitLbug path (#1783)
|
||||
*
|
||||
* Verifies that read-only LadybugDB opens skip filesystem mutations
|
||||
* (init lock, orphan sidecar cleanup, mkdir) so they work on read-only
|
||||
* filesystems such as Docker :ro bind mounts.
|
||||
*/
|
||||
import fs from 'fs/promises';
|
||||
import { it, expect } from 'vitest';
|
||||
import { withTestLbugDB } from '../helpers/test-indexed-db.js';
|
||||
import { _initLockPathForTest } from '../../src/core/lbug/lbug-adapter.js';
|
||||
|
||||
withTestLbugDB('lbug-readonly-init', (handle) => {
|
||||
it('read-only open never creates lbug.init.lock on disk', async () => {
|
||||
const { dbPath } = handle;
|
||||
const lockPath = _initLockPathForTest(dbPath);
|
||||
|
||||
const adapter = await import('../../src/core/lbug/lbug-adapter.js');
|
||||
await adapter.closeLbug();
|
||||
|
||||
await expect(fs.access(lockPath)).rejects.toMatchObject({ code: 'ENOENT' });
|
||||
|
||||
await adapter.withLbugDb(dbPath, async () => {}, { readOnly: true });
|
||||
|
||||
await expect(fs.access(lockPath)).rejects.toMatchObject({ code: 'ENOENT' });
|
||||
|
||||
await adapter.closeLbug();
|
||||
});
|
||||
});
|
||||
|
|
@ -31,6 +31,7 @@ describe('git utilities', () => {
|
|||
expect(mockExecSync).toHaveBeenCalledWith('git rev-parse --is-inside-work-tree', {
|
||||
cwd: '/project',
|
||||
stdio: 'ignore',
|
||||
windowsHide: true,
|
||||
});
|
||||
});
|
||||
|
||||
|
|
|
|||
|
|
@ -94,6 +94,7 @@ function runGit(dir: string, args: string[]) {
|
|||
cwd: dir,
|
||||
encoding: 'utf-8',
|
||||
stdio: ['pipe', 'pipe', 'pipe'],
|
||||
windowsHide: true,
|
||||
});
|
||||
if (result.status !== 0) {
|
||||
const message = result.stderr || result.stdout || result.error?.message || 'unknown error';
|
||||
|
|
@ -220,6 +221,176 @@ describe('Shell injection regression', () => {
|
|||
}
|
||||
});
|
||||
|
||||
// ─── Source code regression: windowsHide:true on every spawn-family call ───
|
||||
|
||||
/**
|
||||
* Every ``spawn`` / ``spawnSync`` / ``execFile`` / ``execFileSync`` /
|
||||
* ``execFileAsync`` / ``execSync`` call in the hook layer **and the
|
||||
* core/CLI/MCP/server source tree** must pass ``windowsHide: true``
|
||||
* in its options object. Without it, Node's ``child_process`` module
|
||||
* asks ``CreateProcess`` to use ``STARTF_USESHOWWINDOW`` with
|
||||
* ``SW_SHOWDEFAULT`` and a black console window flashes onto the
|
||||
* user's desktop for each call. Under active Claude Code / MCP /
|
||||
* gitnexus-serve use that's a near-continuous stream of pop-ups —
|
||||
* unusable in practice on Windows.
|
||||
*
|
||||
* ``windowsHide`` is a no-op on POSIX (silently dropped), so the
|
||||
* flag is safe to require unconditionally. ``stdio: 'inherit'``
|
||||
* callers (interactive editors etc.) are unaffected — windowsHide
|
||||
* only suppresses NEW console allocation; an inherited parent
|
||||
* console isn't touched.
|
||||
*
|
||||
* The check is source-level rather than behavioural because:
|
||||
* - the flag's effect is observable only on Windows;
|
||||
* - GitHub Actions runs vitest on Linux for these tests;
|
||||
* - regressing this is easy (every new spawn site has to remember
|
||||
* the flag), and a runtime check on a Windows-only CI leg would
|
||||
* still let a PR land on the main branch first.
|
||||
*
|
||||
* The pre-existing fix at ``src/core/lbug/extension-loader.ts:96``
|
||||
* established the convention. This test enforces it everywhere.
|
||||
*/
|
||||
describe('windowsHide regression', () => {
|
||||
// Hook-layer files. Adding a new hook file MUST be reflected here.
|
||||
const HOOK_FILES: Array<readonly [string, string]> = [
|
||||
['gitnexus/hooks/claude/gitnexus-hook.cjs', CJS_HOOK],
|
||||
[
|
||||
'gitnexus/hooks/claude/hook-db-lock-probe.cjs',
|
||||
path.resolve(__dirname, '..', '..', 'hooks', 'claude', 'hook-db-lock-probe.cjs'),
|
||||
],
|
||||
['gitnexus-claude-plugin/hooks/gitnexus-hook.js', PLUGIN_HOOK],
|
||||
[
|
||||
'gitnexus-claude-plugin/hooks/hook-db-lock-probe.cjs',
|
||||
path.resolve(
|
||||
__dirname,
|
||||
'..',
|
||||
'..',
|
||||
'..',
|
||||
'gitnexus-claude-plugin',
|
||||
'hooks',
|
||||
'hook-db-lock-probe.cjs',
|
||||
),
|
||||
],
|
||||
[
|
||||
'gitnexus-cursor-integration/hooks/gitnexus-hook.cjs',
|
||||
path.resolve(
|
||||
__dirname,
|
||||
'..',
|
||||
'..',
|
||||
'..',
|
||||
'gitnexus-cursor-integration',
|
||||
'hooks',
|
||||
'gitnexus-hook.cjs',
|
||||
),
|
||||
],
|
||||
];
|
||||
|
||||
// Source-tree files. Every file that imports a spawn-family
|
||||
// function from ``child_process`` belongs here. Discovered via
|
||||
// grep -rn "from 'child_process'" -- gitnexus/src/
|
||||
// plus the explicit ``await import('child_process')`` callers in
|
||||
// local-backend.ts.
|
||||
const SRC_FILES: Array<readonly [string, string]> = [
|
||||
[
|
||||
'gitnexus/src/cli/analyze.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'cli', 'analyze.ts'),
|
||||
],
|
||||
['gitnexus/src/cli/setup.ts', path.resolve(__dirname, '..', '..', 'src', 'cli', 'setup.ts')],
|
||||
['gitnexus/src/cli/wiki.ts', path.resolve(__dirname, '..', '..', 'src', 'cli', 'wiki.ts')],
|
||||
[
|
||||
'gitnexus/src/core/embeddings/embedder.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'core', 'embeddings', 'embedder.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/core/git-staleness.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'core', 'git-staleness.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/core/lbug/extension-loader.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'core', 'lbug', 'extension-loader.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/core/run-analyze.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'core', 'run-analyze.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/core/wiki/cursor-client.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'core', 'wiki', 'cursor-client.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/core/wiki/generator.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'core', 'wiki', 'generator.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/mcp/local/local-backend.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'mcp', 'local', 'local-backend.ts'),
|
||||
],
|
||||
[
|
||||
'gitnexus/src/server/git-clone.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'server', 'git-clone.ts'),
|
||||
],
|
||||
// New post-upstream-merge (May 2026 sync):
|
||||
[
|
||||
'gitnexus/src/storage/git.ts',
|
||||
path.resolve(__dirname, '..', '..', 'src', 'storage', 'git.ts'),
|
||||
],
|
||||
];
|
||||
|
||||
/**
|
||||
* Strip pure-comment lines so prose mentions of ``spawn`` /
|
||||
* ``exec`` don't inflate the call count.
|
||||
*/
|
||||
function stripComments(source: string): string {
|
||||
return source
|
||||
.split('\n')
|
||||
.filter((l) => {
|
||||
const t = l.trim();
|
||||
return !t.startsWith('//') && !t.startsWith('*') && !t.startsWith('/*');
|
||||
})
|
||||
.join('\n');
|
||||
}
|
||||
|
||||
/**
|
||||
* Count spawn-family invocations. The regex matches ``spawn(``,
|
||||
* ``spawnSync(``, ``execFile(``, ``execFileSync(``,
|
||||
* ``execFileAsync(``, ``execSync(`` as function calls — not
|
||||
* destructures (``const { spawn } = ...``), not method calls
|
||||
* (``.exec(``), not bare ``exec()`` (which collides with regex
|
||||
* ``.exec()``; we explicitly drop it).
|
||||
*/
|
||||
function countSpawnCalls(codeSource: string): number {
|
||||
const re =
|
||||
/(^|[^a-zA-Z0-9_$.])(spawn|spawnSync|execFile|execFileSync|execFileAsync|execSync)\s*\(/gm;
|
||||
let count = 0;
|
||||
while (re.exec(codeSource) !== null) {
|
||||
count++;
|
||||
}
|
||||
return count;
|
||||
}
|
||||
|
||||
for (const [label, file] of [...HOOK_FILES, ...SRC_FILES]) {
|
||||
it(`${label}: every spawn-family options object contains windowsHide: true`, () => {
|
||||
// The file must exist — silent-skip would mask a deletion.
|
||||
expect(fs.existsSync(file)).toBe(true);
|
||||
const source = fs.readFileSync(file, 'utf-8');
|
||||
const codeSource = stripComments(source);
|
||||
|
||||
const spawnCount = countSpawnCalls(codeSource);
|
||||
const hideCount = (codeSource.match(/windowsHide\s*:\s*true/g) ?? []).length;
|
||||
|
||||
// Sanity: catch a refactor that accidentally deletes every
|
||||
// spawn call (which would otherwise make the equality below
|
||||
// trivially true at 0 == 0).
|
||||
expect(spawnCount).toBeGreaterThan(0);
|
||||
// One windowsHide per spawn-family call. We don't try to
|
||||
// match brace structure — a same-count proxy is sufficient
|
||||
// because every spawn site in these files passes an options
|
||||
// object literal (no helper indirection).
|
||||
expect(hideCount).toBe(spawnCount);
|
||||
});
|
||||
}
|
||||
});
|
||||
|
||||
// ─── Source code regression: .cmd extensions for Windows ─────────────
|
||||
|
||||
describe('Windows .cmd extension handling', () => {
|
||||
|
|
|
|||
|
|
@ -74,7 +74,7 @@ describe('setupCommand codex execution', () => {
|
|||
expect(execFileMock).toHaveBeenCalledWith(
|
||||
'codex',
|
||||
['mcp', 'add', 'gitnexus', '--', 'cmd', '/c', 'npx', '-y', NPX_REF, 'mcp'],
|
||||
{ shell: true },
|
||||
{ shell: true, windowsHide: true },
|
||||
expect.any(Function),
|
||||
);
|
||||
});
|
||||
|
|
@ -89,7 +89,7 @@ describe('setupCommand codex execution', () => {
|
|||
expect(execFileMock).toHaveBeenCalledWith(
|
||||
'codex',
|
||||
['mcp', 'add', 'gitnexus', '--', 'cmd', '/c', 'npx', '-y', NPX_REF, 'mcp'],
|
||||
{ shell: true },
|
||||
{ shell: true, windowsHide: true },
|
||||
expect.any(Function),
|
||||
);
|
||||
});
|
||||
|
|
@ -104,7 +104,7 @@ describe('setupCommand codex execution', () => {
|
|||
expect(execFileMock).toHaveBeenCalledWith(
|
||||
'codex',
|
||||
['mcp', 'add', 'gitnexus', '--', 'npx', '-y', NPX_REF, 'mcp'],
|
||||
{ shell: false },
|
||||
{ shell: false, windowsHide: true },
|
||||
expect.any(Function),
|
||||
);
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue