diff --git a/gitnexus-claude-plugin/hooks/gitnexus-hook.js b/gitnexus-claude-plugin/hooks/gitnexus-hook.js index 7ff03e430..91c20c9d2 100644 --- a/gitnexus-claude-plugin/hooks/gitnexus-hook.js +++ b/gitnexus-claude-plugin/hooks/gitnexus-hook.js @@ -77,6 +77,7 @@ function findCanonicalRepoRoot(cwd) { timeout: 2000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); if (result.error || result.status !== 0) return null; const commonDir = (result.stdout || '').trim(); @@ -200,6 +201,7 @@ function runGitNexusCli(args, cwd, timeout) { timeout, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } @@ -210,6 +212,7 @@ function runGitNexusCli(args, cwd, timeout) { encoding: 'utf-8', timeout: 3000, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); useDirectBinary = which.status === 0; } catch { @@ -222,6 +225,7 @@ function runGitNexusCli(args, cwd, timeout) { timeout, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } // npx fallback needs shell on Windows since npx is a .cmd script @@ -230,6 +234,7 @@ function runGitNexusCli(args, cwd, timeout) { timeout: timeout + 5000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } @@ -318,6 +323,7 @@ function handlePostToolUse(input) { timeout: 3000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); currentHead = (headResult.stdout || '').trim(); } catch { diff --git a/gitnexus-claude-plugin/hooks/hook-db-lock-probe.cjs b/gitnexus-claude-plugin/hooks/hook-db-lock-probe.cjs index 783cd0804..752c114a7 100644 --- a/gitnexus-claude-plugin/hooks/hook-db-lock-probe.cjs +++ b/gitnexus-claude-plugin/hooks/hook-db-lock-probe.cjs @@ -109,6 +109,7 @@ function hasGitNexusServerOwnerWindows(dbPathAbs, myPid) { encoding: 'utf-8', timeout: 6000, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, env: { ...process.env, GITNEXUS_HOOK_RM_TARGET: dbPathAbs }, }, ); @@ -192,6 +193,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) { encoding: 'utf-8', timeout: 1000, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }); if (lsof.error) return lsof.error.code === 'ETIMEDOUT'; @@ -203,6 +205,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) { encoding: 'utf-8', timeout: 500, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }); if (ps.error) { if (ps.error.code === 'ETIMEDOUT') return true; diff --git a/gitnexus-cursor-integration/hooks/gitnexus-hook.cjs b/gitnexus-cursor-integration/hooks/gitnexus-hook.cjs index 74c5587b3..ab495be84 100644 --- a/gitnexus-cursor-integration/hooks/gitnexus-hook.cjs +++ b/gitnexus-cursor-integration/hooks/gitnexus-hook.cjs @@ -58,6 +58,7 @@ function findCanonicalRepoRoot(cwd) { timeout: 2000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); if (result.error || result.status !== 0) return null; const commonDir = (result.stdout || '').trim(); @@ -201,6 +202,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) { timeout, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } return spawnSync(isWin ? 'npx.cmd' : 'npx', ['-y', 'gitnexus', ...args], { @@ -208,6 +210,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) { timeout: timeout + 5000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } diff --git a/gitnexus/hooks/claude/gitnexus-hook.cjs b/gitnexus/hooks/claude/gitnexus-hook.cjs index e39fcf8e1..9793bd7bc 100755 --- a/gitnexus/hooks/claude/gitnexus-hook.cjs +++ b/gitnexus/hooks/claude/gitnexus-hook.cjs @@ -77,6 +77,7 @@ function findCanonicalRepoRoot(cwd) { timeout: 2000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); if (result.error || result.status !== 0) return null; const commonDir = (result.stdout || '').trim(); @@ -218,6 +219,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) { timeout, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } // On Windows, invoke npx.cmd directly (no shell needed) @@ -226,6 +228,7 @@ function runGitNexusCli(cliPath, args, cwd, timeout) { timeout: timeout + 5000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); } @@ -315,6 +318,7 @@ function handlePostToolUse(input) { timeout: 3000, cwd, stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); currentHead = (headResult.stdout || '').trim(); } catch { diff --git a/gitnexus/hooks/claude/hook-db-lock-probe.cjs b/gitnexus/hooks/claude/hook-db-lock-probe.cjs index 783cd0804..752c114a7 100644 --- a/gitnexus/hooks/claude/hook-db-lock-probe.cjs +++ b/gitnexus/hooks/claude/hook-db-lock-probe.cjs @@ -109,6 +109,7 @@ function hasGitNexusServerOwnerWindows(dbPathAbs, myPid) { encoding: 'utf-8', timeout: 6000, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, env: { ...process.env, GITNEXUS_HOOK_RM_TARGET: dbPathAbs }, }, ); @@ -192,6 +193,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) { encoding: 'utf-8', timeout: 1000, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }); if (lsof.error) return lsof.error.code === 'ETIMEDOUT'; @@ -203,6 +205,7 @@ function unixLsofPsFindGitNexusServer(dbPathAbs, myPid) { encoding: 'utf-8', timeout: 500, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }); if (ps.error) { if (ps.error.code === 'ETIMEDOUT') return true; diff --git a/gitnexus/src/cli/analyze.ts b/gitnexus/src/cli/analyze.ts index 32ceaca62..c9d370f7f 100644 --- a/gitnexus/src/cli/analyze.ts +++ b/gitnexus/src/cli/analyze.ts @@ -312,6 +312,7 @@ const runRespawnedAnalyze = ( const child = spawn(process.execPath, [...args], { stdio: ['inherit', 'pipe', 'pipe'], + windowsHide: true, env, }); diff --git a/gitnexus/src/cli/setup.ts b/gitnexus/src/cli/setup.ts index fe9d86f52..915c19dec 100644 --- a/gitnexus/src/cli/setup.ts +++ b/gitnexus/src/cli/setup.ts @@ -54,6 +54,7 @@ function resolveGitnexusBin(): string | null { encoding: 'utf-8', timeout: 5000, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }); const lines = output .split('\n') @@ -532,6 +533,7 @@ async function setupCodex(result: SetupResult): Promise { const entry = getMcpEntry(); await execFileAsync('codex', ['mcp', 'add', 'gitnexus', '--', entry.command, ...entry.args], { shell: process.platform === 'win32', + windowsHide: true, }); result.configured.push('Codex'); return; diff --git a/gitnexus/src/cli/wiki.ts b/gitnexus/src/cli/wiki.ts index 6211d371c..97ac8fc6e 100644 --- a/gitnexus/src/cli/wiki.ts +++ b/gitnexus/src/cli/wiki.ts @@ -519,7 +519,7 @@ const wikiCommandImpl = async (inputPath?: string, options?: WikiCommandOptions) console.log(' Save and close the editor when done.\n'); try { - execFileSync(editor, [treeFile], { stdio: 'inherit' }); + execFileSync(editor, [treeFile], { stdio: 'inherit', windowsHide: true }); } catch { console.log(` Could not open editor. Please edit manually:\n ${treeFile}\n`); console.log(' Then run `gitnexus wiki` to continue.\n'); @@ -655,7 +655,7 @@ const wikiCommandImpl = async (inputPath?: string, options?: WikiCommandOptions) function hasGhCLI(): boolean { try { - execSync('gh --version', { stdio: 'ignore' }); + execSync('gh --version', { stdio: 'ignore', windowsHide: true }); return true; } catch { return false; @@ -699,7 +699,7 @@ function publishGist(htmlPath: string): { url: string; rawUrl: string } | null { const output = execFileSync( 'gh', ['gist', 'create', htmlPath, '--desc', 'Repository Wiki — generated by GitNexus', '--public'], - { encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'] }, + { encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'], windowsHide: true }, ).trim(); // `gh gist create` prints the gist URL as a line in the output. Find the diff --git a/gitnexus/src/core/embeddings/embedder.ts b/gitnexus/src/core/embeddings/embedder.ts index 72ddcbd70..d2e9d0aff 100644 --- a/gitnexus/src/core/embeddings/embedder.ts +++ b/gitnexus/src/core/embeddings/embedder.ts @@ -78,7 +78,11 @@ function isCudaAvailable(): boolean { // Primary: query the dynamic linker cache — covers all architectures, // distro layouts, and custom install paths registered with ldconfig try { - const out = execFileSync('ldconfig', ['-p'], { timeout: 3000, encoding: 'utf-8' }); + const out = execFileSync('ldconfig', ['-p'], { + timeout: 3000, + encoding: 'utf-8', + windowsHide: true, + }); if (out.includes('libcublasLt.so.12')) return true; } catch { // ldconfig not available (e.g. non-standard container) diff --git a/gitnexus/src/core/git-staleness.ts b/gitnexus/src/core/git-staleness.ts index c90cef85e..2d6a1f8ec 100644 --- a/gitnexus/src/core/git-staleness.ts +++ b/gitnexus/src/core/git-staleness.ts @@ -26,6 +26,7 @@ export function checkStaleness(repoPath: string, lastCommit: string): StalenessI cwd: repoPath, encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }).trim(); const commitsBehind = parseInt(result, 10) || 0; @@ -59,6 +60,7 @@ export async function checkStalenessAsync( const { stdout } = await execFileAsync('git', ['rev-list', '--count', `${lastCommit}..HEAD`], { cwd: repoPath, encoding: 'utf-8', + windowsHide: true, }); const commitsBehind = parseInt(stdout.trim(), 10) || 0; @@ -90,6 +92,7 @@ function commitsAheadOfIndexed(siblingPath: string, indexedCommit: string): numb cwd: siblingPath, encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }).trim(); return parseInt(result, 10) || 0; } catch { diff --git a/gitnexus/src/core/lbug/lbug-adapter.ts b/gitnexus/src/core/lbug/lbug-adapter.ts index 5e2a34601..b0f1d3ec0 100644 --- a/gitnexus/src/core/lbug/lbug-adapter.ts +++ b/gitnexus/src/core/lbug/lbug-adapter.ts @@ -525,6 +525,7 @@ const ensureReadOnlyConnectionUsable = async ( dbPath: string, handle: LbugConnectionHandle, ): Promise => { + let shadowReplayErr: unknown; try { await queryAndDrain(handle.conn, READ_ONLY_SHADOW_REPLAY_PROBE); return handle; @@ -537,11 +538,25 @@ const ensureReadOnlyConnectionUsable = async ( await closeLbugConnection(handle); throw err; } + shadowReplayErr = err; } await closeLbugConnection(handle); - const writable = await openLbugConnection(lbug, dbPath); + let writable: LbugConnectionHandle; + try { + writable = await openLbugConnection(lbug, dbPath); + } catch (openErr) { + const code = extractErrnoCode(openErr); + if (code === 'EROFS' || code === 'EACCES' || code === 'EPERM') { + throw new Error( + shadowSidecarRecoveryMessage(dbPath, shadowReplayErr) + + '\n The workspace appears to be read-only — mount it read-write to perform shadow replay recovery,' + + ' or re-run `gitnexus analyze` on a writable filesystem to rebuild the index.', + ); + } + throw openErr; + } let missingShadowError: unknown; try { await queryAndDrain(writable.conn, READ_ONLY_SHADOW_REPLAY_PROBE); @@ -691,94 +706,112 @@ const doInitLbug = async (dbPath: string, readOnly: boolean = false) => { ensuredFTSIndexes.clear(); } - // LadybugDB stores the database as a single file (not a directory). - // If the path already exists, it must be a valid LadybugDB database file. - // Remove stale empty directories or files from older versions. - try { - const stat = await fs.lstat(dbPath); - if (stat.isSymbolicLink()) { - // Never follow symlinks — just remove the link itself - await fs.unlink(dbPath); - } else if (stat.isDirectory()) { - // Verify path is within expected storage directory before deleting - const realPath = await fs.realpath(dbPath); - const parentDir = path.dirname(dbPath); - const realParent = await fs.realpath(parentDir); - if (!realPath.startsWith(realParent + path.sep) && realPath !== realParent) { - throw new Error( - `Refusing to delete ${dbPath}: resolved path ${realPath} is outside storage directory`, - ); - } - // Old-style directory database or empty leftover - remove it - await fs.rm(dbPath, { recursive: true, force: true }); - } - // If it's a file, assume it's an existing LadybugDB database - LadybugDB will open it - } catch (err) { - if (!isMissingFileError(err)) { - throw err; - } - // Path doesn't exist, which is what LadybugDB wants for a new database - } - // --------------------------------------------------------------------------- - // Cross-process critical section: acquire init lock, clean orphan sidecars, - // and open the database. The lock prevents a TOCTOU race where another - // process could create a fresh DB between our access() check and the - // unlink() of stale sidecars. + // Read-only fast path: skip all filesystem mutations (path cleanup, init + // lock, orphan sidecar removal, mkdir) so the open succeeds on read-only + // filesystems such as Docker `:ro` bind mounts. The init lock exists to + // prevent a TOCTOU race during DB *creation* — read-only opens never + // create databases and don't need the lock. // --------------------------------------------------------------------------- - const releaseInitLock = await acquireInitLock(dbPath); - try { - // Crash-recovery cleanup: if the main DB file is missing, stale sidecars - // from an interrupted run can block fresh opens indefinitely. - try { - await fs.access(dbPath); - } catch (err) { - if (isMissingFileError(err)) { - // `.shadow` is documented by LadybugDB checkpointing and `.wal.checkpoint` - // was observed in the #1618 crash loop that motivated this recovery path. - const orphanSidecars = [`${dbPath}.shadow`, `${dbPath}.wal.checkpoint`]; - for (const sidecar of orphanSidecars) { - try { - await fs.unlink(sidecar); - logger.warn( - `GitNexus: removed orphan sidecar ${path.basename(sidecar)} (no main DB file present)`, - ); - } catch (err) { - if (isMissingFileError(err)) { - continue; - } - const code = extractErrnoCode(err); - logger.warn( - `GitNexus: failed to remove orphan sidecar ${path.basename(sidecar)} (${code ?? 'UNKNOWN'}) while main DB file is missing; LadybugDB open may still fail: ${summarizeError(err)}`, - ); - } - } - } else { - const code = extractErrnoCode(err); - logger.warn( - `GitNexus: unable to verify main DB file before orphan sidecar cleanup (${code ?? 'UNKNOWN'}); skipping cleanup: ${summarizeError(err)}`, - ); - } - } - - // Ensure parent directory exists - const parentDir = path.dirname(dbPath); - await fs.mkdir(parentDir, { recursive: true }); + if (readOnly) { await preflightLbugSidecars(dbPath, { - mode: readOnly ? 'read-only' : 'write', + mode: 'read-only', logger, - allowQuarantine: true, + allowQuarantine: false, }); - const opened = readOnly - ? await openLbugConnection(lbug, dbPath, { readOnly: true }) - : await openLbugConnection(lbug, dbPath); - const usable = readOnly ? await ensureReadOnlyConnectionUsable(dbPath, opened) : opened; + const opened = await openLbugConnection(lbug, dbPath, { readOnly: true }); + const usable = await ensureReadOnlyConnectionUsable(dbPath, opened); db = usable.db; conn = usable.conn; - currentDbReadOnly = readOnly; - } finally { - await releaseInitLock(); + currentDbReadOnly = true; + } else { + // LadybugDB stores the database as a single file (not a directory). + // If the path already exists, it must be a valid LadybugDB database file. + // Remove stale empty directories or files from older versions. + try { + const stat = await fs.lstat(dbPath); + if (stat.isSymbolicLink()) { + // Never follow symlinks — just remove the link itself + await fs.unlink(dbPath); + } else if (stat.isDirectory()) { + // Verify path is within expected storage directory before deleting + const realPath = await fs.realpath(dbPath); + const parentDir = path.dirname(dbPath); + const realParent = await fs.realpath(parentDir); + if (!realPath.startsWith(realParent + path.sep) && realPath !== realParent) { + throw new Error( + `Refusing to delete ${dbPath}: resolved path ${realPath} is outside storage directory`, + ); + } + // Old-style directory database or empty leftover - remove it + await fs.rm(dbPath, { recursive: true, force: true }); + } + // If it's a file, assume it's an existing LadybugDB database - LadybugDB will open it + } catch (err) { + if (!isMissingFileError(err)) { + throw err; + } + // Path doesn't exist, which is what LadybugDB wants for a new database + } + + // ------------------------------------------------------------------------- + // Cross-process critical section: acquire init lock, clean orphan sidecars, + // and open the database. The lock prevents a TOCTOU race where another + // process could create a fresh DB between our access() check and the + // unlink() of stale sidecars. + // ------------------------------------------------------------------------- + const releaseInitLock = await acquireInitLock(dbPath); + try { + // Crash-recovery cleanup: if the main DB file is missing, stale sidecars + // from an interrupted run can block fresh opens indefinitely. + try { + await fs.access(dbPath); + } catch (err) { + if (isMissingFileError(err)) { + // `.shadow` is documented by LadybugDB checkpointing and `.wal.checkpoint` + // was observed in the #1618 crash loop that motivated this recovery path. + const orphanSidecars = [`${dbPath}.shadow`, `${dbPath}.wal.checkpoint`]; + for (const sidecar of orphanSidecars) { + try { + await fs.unlink(sidecar); + logger.warn( + `GitNexus: removed orphan sidecar ${path.basename(sidecar)} (no main DB file present)`, + ); + } catch (err) { + if (isMissingFileError(err)) { + continue; + } + const code = extractErrnoCode(err); + logger.warn( + `GitNexus: failed to remove orphan sidecar ${path.basename(sidecar)} (${code ?? 'UNKNOWN'}) while main DB file is missing; LadybugDB open may still fail: ${summarizeError(err)}`, + ); + } + } + } else { + const code = extractErrnoCode(err); + logger.warn( + `GitNexus: unable to verify main DB file before orphan sidecar cleanup (${code ?? 'UNKNOWN'}); skipping cleanup: ${summarizeError(err)}`, + ); + } + } + + // Ensure parent directory exists + const parentDir = path.dirname(dbPath); + await fs.mkdir(parentDir, { recursive: true }); + await preflightLbugSidecars(dbPath, { + mode: 'write', + logger, + allowQuarantine: true, + }); + + const opened = await openLbugConnection(lbug, dbPath); + db = opened.db; + conn = opened.conn; + currentDbReadOnly = false; + } finally { + await releaseInitLock(); + } } if (!readOnly) { diff --git a/gitnexus/src/core/run-analyze.ts b/gitnexus/src/core/run-analyze.ts index 5fc180eb1..6518a5245 100644 --- a/gitnexus/src/core/run-analyze.ts +++ b/gitnexus/src/core/run-analyze.ts @@ -332,6 +332,7 @@ export async function runFullAnalysis( { cwd: repoPath, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, encoding: 'utf8', }, ); diff --git a/gitnexus/src/core/wiki/cursor-client.ts b/gitnexus/src/core/wiki/cursor-client.ts index bf85f4183..cc24bdc4d 100644 --- a/gitnexus/src/core/wiki/cursor-client.ts +++ b/gitnexus/src/core/wiki/cursor-client.ts @@ -36,7 +36,7 @@ let cachedCursorBin: string | null | undefined; export function detectCursorCLI(): string | null { if (cachedCursorBin !== undefined) return cachedCursorBin; try { - execSync('agent --version', { stdio: 'ignore' }); + execSync('agent --version', { stdio: 'ignore', windowsHide: true }); cachedCursorBin = 'agent'; } catch { cachedCursorBin = null; @@ -109,6 +109,7 @@ export async function callCursorLLM( const child = spawn(cursorBin, args, { cwd: config.workingDirectory || process.cwd(), stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, env: { ...process.env, // Ensure non-interactive mode diff --git a/gitnexus/src/core/wiki/generator.ts b/gitnexus/src/core/wiki/generator.ts index 7bb8049c2..b17ad3006 100644 --- a/gitnexus/src/core/wiki/generator.ts +++ b/gitnexus/src/core/wiki/generator.ts @@ -884,7 +884,12 @@ export class WikiGenerator { private getCurrentCommit(): string { try { - return execSync('git rev-parse HEAD', { cwd: this.repoPath }).toString().trim(); + return execSync('git rev-parse HEAD', { + cwd: this.repoPath, + windowsHide: true, + }) + .toString() + .trim(); } catch { return ''; } @@ -899,6 +904,7 @@ export class WikiGenerator { execFileSync('git', ['merge-base', '--is-ancestor', fromCommit, toCommit], { cwd: this.repoPath, stdio: 'ignore', + windowsHide: true, }); return true; } catch { @@ -916,6 +922,7 @@ export class WikiGenerator { try { const output = execFileSync('git', ['diff', `${fromCommit}..${toCommit}`, '--name-only'], { cwd: this.repoPath, + windowsHide: true, }) .toString() .trim(); diff --git a/gitnexus/src/mcp/local/local-backend.ts b/gitnexus/src/mcp/local/local-backend.ts index 331cffb2c..83c3f023f 100644 --- a/gitnexus/src/mcp/local/local-backend.ts +++ b/gitnexus/src/mcp/local/local-backend.ts @@ -2404,6 +2404,7 @@ export class LocalBackend { cwd: diffCwd, encoding: 'utf-8', maxBuffer: 256 * 1024 * 1024, + windowsHide: true, }); } catch (err: any) { return { error: `Git diff failed: ${err.message}` }; @@ -2680,6 +2681,7 @@ export class LocalBackend { timeout: 5000, // Avoid ENOBUFS on large repos: rg -l can list many files. maxBuffer: 256 * 1024 * 1024, + windowsHide: true, }); const files = output .trim() diff --git a/gitnexus/src/server/git-clone.ts b/gitnexus/src/server/git-clone.ts index 0ced1213a..d92e9c28f 100644 --- a/gitnexus/src/server/git-clone.ts +++ b/gitnexus/src/server/git-clone.ts @@ -304,6 +304,7 @@ export function getRemoteOriginUrl(cwd: string): Promise { const proc = spawn('git', ['config', '--get', 'remote.origin.url'], { cwd, stdio: ['ignore', 'pipe', 'pipe'], + windowsHide: true, env: { ...process.env, GIT_TERMINAL_PROMPT: '0' }, }); let stdout = ''; @@ -427,6 +428,7 @@ function runGit(args: string[], cwd?: string): Promise { const proc = spawn('git', args, { cwd, stdio: ['ignore', 'pipe', 'pipe'], + windowsHide: true, env: { ...process.env, // Prevent git from prompting for credentials (hangs the process) diff --git a/gitnexus/src/storage/git.ts b/gitnexus/src/storage/git.ts index 75e6e91d3..16ebe039a 100644 --- a/gitnexus/src/storage/git.ts +++ b/gitnexus/src/storage/git.ts @@ -6,7 +6,11 @@ import path from 'path'; export const isGitRepo = (repoPath: string): boolean => { try { - execSync('git rev-parse --is-inside-work-tree', { cwd: repoPath, stdio: 'ignore' }); + execSync('git rev-parse --is-inside-work-tree', { + cwd: repoPath, + stdio: 'ignore', + windowsHide: true, + }); return true; } catch { return false; @@ -23,6 +27,7 @@ export const getCurrentCommit = (repoPath: string): string => { // "fatal: not a git repository" to stderr, which leaks to the user's // terminal even though the error is caught here (#1172). stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }) .toString() .trim(); @@ -60,6 +65,7 @@ export const getRemoteUrl = (repoPath: string): string | undefined => { raw = execSync('git config --get remote.origin.url', { cwd: repoPath, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }) .toString() .trim(); @@ -100,6 +106,7 @@ export const getGitRoot = (fromPath: string): string | null => { cwd: fromPath, // Suppress stderr -- see getCurrentCommit comment and #1172. stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }) .toString() .trim(); @@ -142,6 +149,7 @@ export const getCanonicalRepoRoot = (fromPath: string): string | null => { const commonDir = execSync('git rev-parse --path-format=absolute --git-common-dir', { cwd: fromPath, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }) .toString() .trim(); @@ -245,6 +253,7 @@ export const getRemoteOriginUrl = (repoPath: string): string | null => { const url = execSync('git config --get remote.origin.url', { cwd: repoPath, stdio: ['ignore', 'pipe', 'ignore'], + windowsHide: true, }) .toString() .trim(); diff --git a/gitnexus/test/integration/lbug-readonly-init.test.ts b/gitnexus/test/integration/lbug-readonly-init.test.ts new file mode 100644 index 000000000..1d79ac39c --- /dev/null +++ b/gitnexus/test/integration/lbug-readonly-init.test.ts @@ -0,0 +1,29 @@ +/** + * Integration Tests: read-only doInitLbug path (#1783) + * + * Verifies that read-only LadybugDB opens skip filesystem mutations + * (init lock, orphan sidecar cleanup, mkdir) so they work on read-only + * filesystems such as Docker :ro bind mounts. + */ +import fs from 'fs/promises'; +import { it, expect } from 'vitest'; +import { withTestLbugDB } from '../helpers/test-indexed-db.js'; +import { _initLockPathForTest } from '../../src/core/lbug/lbug-adapter.js'; + +withTestLbugDB('lbug-readonly-init', (handle) => { + it('read-only open never creates lbug.init.lock on disk', async () => { + const { dbPath } = handle; + const lockPath = _initLockPathForTest(dbPath); + + const adapter = await import('../../src/core/lbug/lbug-adapter.js'); + await adapter.closeLbug(); + + await expect(fs.access(lockPath)).rejects.toMatchObject({ code: 'ENOENT' }); + + await adapter.withLbugDb(dbPath, async () => {}, { readOnly: true }); + + await expect(fs.access(lockPath)).rejects.toMatchObject({ code: 'ENOENT' }); + + await adapter.closeLbug(); + }); +}); diff --git a/gitnexus/test/unit/git.test.ts b/gitnexus/test/unit/git.test.ts index 1bebf4143..9d3a424c9 100644 --- a/gitnexus/test/unit/git.test.ts +++ b/gitnexus/test/unit/git.test.ts @@ -31,6 +31,7 @@ describe('git utilities', () => { expect(mockExecSync).toHaveBeenCalledWith('git rev-parse --is-inside-work-tree', { cwd: '/project', stdio: 'ignore', + windowsHide: true, }); }); diff --git a/gitnexus/test/unit/hooks.test.ts b/gitnexus/test/unit/hooks.test.ts index a0ef2b8cb..141519c4d 100644 --- a/gitnexus/test/unit/hooks.test.ts +++ b/gitnexus/test/unit/hooks.test.ts @@ -94,6 +94,7 @@ function runGit(dir: string, args: string[]) { cwd: dir, encoding: 'utf-8', stdio: ['pipe', 'pipe', 'pipe'], + windowsHide: true, }); if (result.status !== 0) { const message = result.stderr || result.stdout || result.error?.message || 'unknown error'; @@ -220,6 +221,176 @@ describe('Shell injection regression', () => { } }); +// ─── Source code regression: windowsHide:true on every spawn-family call ─── + +/** + * Every ``spawn`` / ``spawnSync`` / ``execFile`` / ``execFileSync`` / + * ``execFileAsync`` / ``execSync`` call in the hook layer **and the + * core/CLI/MCP/server source tree** must pass ``windowsHide: true`` + * in its options object. Without it, Node's ``child_process`` module + * asks ``CreateProcess`` to use ``STARTF_USESHOWWINDOW`` with + * ``SW_SHOWDEFAULT`` and a black console window flashes onto the + * user's desktop for each call. Under active Claude Code / MCP / + * gitnexus-serve use that's a near-continuous stream of pop-ups — + * unusable in practice on Windows. + * + * ``windowsHide`` is a no-op on POSIX (silently dropped), so the + * flag is safe to require unconditionally. ``stdio: 'inherit'`` + * callers (interactive editors etc.) are unaffected — windowsHide + * only suppresses NEW console allocation; an inherited parent + * console isn't touched. + * + * The check is source-level rather than behavioural because: + * - the flag's effect is observable only on Windows; + * - GitHub Actions runs vitest on Linux for these tests; + * - regressing this is easy (every new spawn site has to remember + * the flag), and a runtime check on a Windows-only CI leg would + * still let a PR land on the main branch first. + * + * The pre-existing fix at ``src/core/lbug/extension-loader.ts:96`` + * established the convention. This test enforces it everywhere. + */ +describe('windowsHide regression', () => { + // Hook-layer files. Adding a new hook file MUST be reflected here. + const HOOK_FILES: Array = [ + ['gitnexus/hooks/claude/gitnexus-hook.cjs', CJS_HOOK], + [ + 'gitnexus/hooks/claude/hook-db-lock-probe.cjs', + path.resolve(__dirname, '..', '..', 'hooks', 'claude', 'hook-db-lock-probe.cjs'), + ], + ['gitnexus-claude-plugin/hooks/gitnexus-hook.js', PLUGIN_HOOK], + [ + 'gitnexus-claude-plugin/hooks/hook-db-lock-probe.cjs', + path.resolve( + __dirname, + '..', + '..', + '..', + 'gitnexus-claude-plugin', + 'hooks', + 'hook-db-lock-probe.cjs', + ), + ], + [ + 'gitnexus-cursor-integration/hooks/gitnexus-hook.cjs', + path.resolve( + __dirname, + '..', + '..', + '..', + 'gitnexus-cursor-integration', + 'hooks', + 'gitnexus-hook.cjs', + ), + ], + ]; + + // Source-tree files. Every file that imports a spawn-family + // function from ``child_process`` belongs here. Discovered via + // grep -rn "from 'child_process'" -- gitnexus/src/ + // plus the explicit ``await import('child_process')`` callers in + // local-backend.ts. + const SRC_FILES: Array = [ + [ + 'gitnexus/src/cli/analyze.ts', + path.resolve(__dirname, '..', '..', 'src', 'cli', 'analyze.ts'), + ], + ['gitnexus/src/cli/setup.ts', path.resolve(__dirname, '..', '..', 'src', 'cli', 'setup.ts')], + ['gitnexus/src/cli/wiki.ts', path.resolve(__dirname, '..', '..', 'src', 'cli', 'wiki.ts')], + [ + 'gitnexus/src/core/embeddings/embedder.ts', + path.resolve(__dirname, '..', '..', 'src', 'core', 'embeddings', 'embedder.ts'), + ], + [ + 'gitnexus/src/core/git-staleness.ts', + path.resolve(__dirname, '..', '..', 'src', 'core', 'git-staleness.ts'), + ], + [ + 'gitnexus/src/core/lbug/extension-loader.ts', + path.resolve(__dirname, '..', '..', 'src', 'core', 'lbug', 'extension-loader.ts'), + ], + [ + 'gitnexus/src/core/run-analyze.ts', + path.resolve(__dirname, '..', '..', 'src', 'core', 'run-analyze.ts'), + ], + [ + 'gitnexus/src/core/wiki/cursor-client.ts', + path.resolve(__dirname, '..', '..', 'src', 'core', 'wiki', 'cursor-client.ts'), + ], + [ + 'gitnexus/src/core/wiki/generator.ts', + path.resolve(__dirname, '..', '..', 'src', 'core', 'wiki', 'generator.ts'), + ], + [ + 'gitnexus/src/mcp/local/local-backend.ts', + path.resolve(__dirname, '..', '..', 'src', 'mcp', 'local', 'local-backend.ts'), + ], + [ + 'gitnexus/src/server/git-clone.ts', + path.resolve(__dirname, '..', '..', 'src', 'server', 'git-clone.ts'), + ], + // New post-upstream-merge (May 2026 sync): + [ + 'gitnexus/src/storage/git.ts', + path.resolve(__dirname, '..', '..', 'src', 'storage', 'git.ts'), + ], + ]; + + /** + * Strip pure-comment lines so prose mentions of ``spawn`` / + * ``exec`` don't inflate the call count. + */ + function stripComments(source: string): string { + return source + .split('\n') + .filter((l) => { + const t = l.trim(); + return !t.startsWith('//') && !t.startsWith('*') && !t.startsWith('/*'); + }) + .join('\n'); + } + + /** + * Count spawn-family invocations. The regex matches ``spawn(``, + * ``spawnSync(``, ``execFile(``, ``execFileSync(``, + * ``execFileAsync(``, ``execSync(`` as function calls — not + * destructures (``const { spawn } = ...``), not method calls + * (``.exec(``), not bare ``exec()`` (which collides with regex + * ``.exec()``; we explicitly drop it). + */ + function countSpawnCalls(codeSource: string): number { + const re = + /(^|[^a-zA-Z0-9_$.])(spawn|spawnSync|execFile|execFileSync|execFileAsync|execSync)\s*\(/gm; + let count = 0; + while (re.exec(codeSource) !== null) { + count++; + } + return count; + } + + for (const [label, file] of [...HOOK_FILES, ...SRC_FILES]) { + it(`${label}: every spawn-family options object contains windowsHide: true`, () => { + // The file must exist — silent-skip would mask a deletion. + expect(fs.existsSync(file)).toBe(true); + const source = fs.readFileSync(file, 'utf-8'); + const codeSource = stripComments(source); + + const spawnCount = countSpawnCalls(codeSource); + const hideCount = (codeSource.match(/windowsHide\s*:\s*true/g) ?? []).length; + + // Sanity: catch a refactor that accidentally deletes every + // spawn call (which would otherwise make the equality below + // trivially true at 0 == 0). + expect(spawnCount).toBeGreaterThan(0); + // One windowsHide per spawn-family call. We don't try to + // match brace structure — a same-count proxy is sufficient + // because every spawn site in these files passes an options + // object literal (no helper indirection). + expect(hideCount).toBe(spawnCount); + }); + } +}); + // ─── Source code regression: .cmd extensions for Windows ───────────── describe('Windows .cmd extension handling', () => { diff --git a/gitnexus/test/unit/setup-codex.test.ts b/gitnexus/test/unit/setup-codex.test.ts index 5951c9325..9ede4a67b 100644 --- a/gitnexus/test/unit/setup-codex.test.ts +++ b/gitnexus/test/unit/setup-codex.test.ts @@ -74,7 +74,7 @@ describe('setupCommand codex execution', () => { expect(execFileMock).toHaveBeenCalledWith( 'codex', ['mcp', 'add', 'gitnexus', '--', 'cmd', '/c', 'npx', '-y', NPX_REF, 'mcp'], - { shell: true }, + { shell: true, windowsHide: true }, expect.any(Function), ); }); @@ -89,7 +89,7 @@ describe('setupCommand codex execution', () => { expect(execFileMock).toHaveBeenCalledWith( 'codex', ['mcp', 'add', 'gitnexus', '--', 'cmd', '/c', 'npx', '-y', NPX_REF, 'mcp'], - { shell: true }, + { shell: true, windowsHide: true }, expect.any(Function), ); }); @@ -104,7 +104,7 @@ describe('setupCommand codex execution', () => { expect(execFileMock).toHaveBeenCalledWith( 'codex', ['mcp', 'add', 'gitnexus', '--', 'npx', '-y', NPX_REF, 'mcp'], - { shell: false }, + { shell: false, windowsHide: true }, expect.any(Function), );