mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-05 02:43:32 +00:00
* feat(storage): add configurable index storage and content retention tiers Rebase #3060 onto current origin/main. Keep GITNEXUS_STORAGE_PATH, GITNEXUS_STORAGE_ROOT, and GITNEXUS_CONTENT_RETENTION, and fold in main's FTS skip, embed-session, and help-text updates. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Keep legacy registry rows on the local storage fallback, resolve symlinks before the destructive-path guard, and align hook lookup with CLI branch slugs, branch-slot metadata, and longest-path match. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Only list swept upload directories after a successful removal so callers cannot treat a permission or transient rm failure as gone. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Document that getStoragePath may consult registered storage while this module still does not mutate the global registry. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(storage): close review findings for external indexes and retention Re-inspect ownership under the analyze lock, fail-closed when the registry file is missing, and keep skip-git hook discovery plus retention fields on HTTP/MCP list surfaces. /api/file stays 410 unless contentRetention is full. Co-authored-by: Cursor <cursoragent@cursor.com> * chore(autofix): apply prettier + eslint fixes via /autofix command * Address PR review feedback (#3060) Treat lock-only index dirs as empty, honor HTTP --force storage policy, and prefer registered plus branch-aware slots in hooks and augment. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3060) Keep hook fallbacks inside the current worktree, compare foreign-local slots canonically, and make storage fixtures survive ownership validation. Co-authored-by: Cursor <cursoragent@cursor.com> * Fix macOS hook test expecting realpath'd registry paths. resolveHookRepo returns the written registry path, not a filesystem realpath, so the assertion must match that. * Address gitnexus-check warnings on hook install docs and slot tests. The Cursor troubleshooting list omitted registry-query.cjs, and the writable-slot test only checked that isDirectory exists instead of that the path is a directory. * Align the HTTP catalog source-scan with skippable resolveRepo validation. resolveRepo lists fresh repos with validate: options.validateStorage !== false so DELETE can skip prune; the test still required a literal validate: true. * Harden storage path sinks so CodeQL path-injection and ReDoS alerts clear. Contain every filesystem probe inside the resolved storage slot with the inline path.relative idiom, reject filesystem-root slots, and trim slot basenames in linear time. * Settle bridge stamps before writing so CI size/mtime matches stay stable. LadybugDB can still flush into bridge.lbug after close+rename; persist whole-millisecond mtimes and wait for consecutive stats to agree so a freshly written pair matches. * Type the settled bridge stat as fs.Stats so tsc does not see bigint. Awaited<ReturnType<typeof fsp.stat>> collapsed the bigint overload and broke prepare/typecheck on CI. * Keep the bridge mtime stamp exact so same-size swaps still fail the pair check. Co-authored-by: Cursor <cursoragent@cursor.com> * Wrap the bridge stamp predicate so prettier --check stays green. Co-authored-by: Cursor <cursoragent@cursor.com> * Require a quiet interval before stamping a settled bridge file. Co-authored-by: Cursor <cursoragent@cursor.com> * Reuse shared storage and settle helpers instead of local copies. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
109 lines
4.5 KiB
TypeScript
109 lines
4.5 KiB
TypeScript
/**
|
|
* #2112 boundary audit — the analyze-worker → parent IPC projection.
|
|
*
|
|
* The forked analyze worker reports completion over default-JSON child_process
|
|
* IPC. `AnalyzeResult.pipelineResult` carries the live `KnowledgeGraph` (closure
|
|
* methods, getter-materialized arrays) and can transitively hold a BigInt or a
|
|
* circular reference — all of which break `JSON.stringify` (the IPC serializer):
|
|
* methods drop silently, BigInt/circular THROW. `projectAnalyzeResultForIpc`
|
|
* strips `pipelineResult` to an explicit JSON-safe allowlist so the boundary is
|
|
* safe by construction. These tests pin that contract.
|
|
*/
|
|
import { describe, it, expect } from 'vitest';
|
|
|
|
import { projectAnalyzeResultForIpc } from '../../src/server/analyze-worker-ipc.js';
|
|
import type { AnalyzeResult } from '../../src/core/run-analyze.js';
|
|
import { createKnowledgeGraph } from '../../src/core/graph/graph.js';
|
|
|
|
/**
|
|
* An `AnalyzeResult` whose `pipelineResult` is hostile to JSON in all three
|
|
* ways the real `KnowledgeGraph` can be: a method (dropped), a circular ref
|
|
* (throws), and a BigInt (throws).
|
|
*/
|
|
function hostileResult(): AnalyzeResult {
|
|
const graph: Record<string, unknown> = {
|
|
nodes: [{ id: 'a', label: 'Function', properties: { name: 'a' } }],
|
|
relationships: [],
|
|
forEachNode: () => {}, // own function property — JSON drops it silently
|
|
bigCount: 10n, // BigInt — JSON.stringify throws
|
|
};
|
|
graph.self = graph; // circular — JSON.stringify throws
|
|
return {
|
|
repoName: 'demo',
|
|
repoPath: '/repos/demo',
|
|
storagePath: '/repos/demo/.gitnexus',
|
|
stats: { files: 3, nodes: 1, edges: 0 },
|
|
alreadyUpToDate: false,
|
|
ftsSkipped: true,
|
|
pipelineResult: { graph, repoPath: '/repos/demo', totalFileCount: 3 },
|
|
};
|
|
}
|
|
|
|
describe('#2112: analyze-worker IPC projection', () => {
|
|
it('drops pipelineResult and preserves the scalar fields the parent consumes', () => {
|
|
const projected = projectAnalyzeResultForIpc(hostileResult());
|
|
expect(projected).toEqual({
|
|
repoName: 'demo',
|
|
repoPath: '/repos/demo',
|
|
stats: { files: 3, nodes: 1, edges: 0 },
|
|
alreadyUpToDate: false,
|
|
ftsRepairedOnly: undefined,
|
|
ftsSkipped: true,
|
|
});
|
|
expect('pipelineResult' in projected).toBe(false);
|
|
});
|
|
|
|
it('the projection is JSON-serializable (survives the default child_process IPC channel)', () => {
|
|
const projected = projectAnalyzeResultForIpc(hostileResult());
|
|
// The real failure mode: process.send runs JSON.stringify under the hood.
|
|
expect(() => JSON.stringify(projected)).not.toThrow();
|
|
const roundTripped = JSON.parse(JSON.stringify(projected));
|
|
expect(roundTripped.repoName).toBe('demo');
|
|
expect(roundTripped.stats.nodes).toBe(1);
|
|
});
|
|
|
|
it('anchors the hazard: serializing the RAW result throws (the bug the projection prevents)', () => {
|
|
// Without the projection, `send({type:'complete', result})` would throw a
|
|
// TypeError in the worker, get caught, and mis-report this success as a
|
|
// failure. This assertion documents why the projection exists.
|
|
expect(() => JSON.stringify(hostileResult())).toThrow(TypeError);
|
|
});
|
|
|
|
it('drops a REAL KnowledgeGraph from pipelineResult — the payload stays tiny (graph not materialized)', () => {
|
|
// The synthetic cases above use a hand-built hostile object; this uses the
|
|
// real createKnowledgeGraph the server path actually puts in pipelineResult,
|
|
// whose nodes/relationships getters would materialize the whole graph into
|
|
// arrays under JSON.stringify. The projection must drop it entirely.
|
|
const graph = createKnowledgeGraph();
|
|
for (let i = 0; i < 50; i++) {
|
|
graph.addNode({
|
|
id: `n${i}`,
|
|
label: 'Function',
|
|
properties: { name: `n${i}`, filePath: 'x.ts' },
|
|
});
|
|
}
|
|
graph.addRelationship({ id: 'n0->n1', source: 'n0', target: 'n1', type: 'CALLS' });
|
|
const result: AnalyzeResult = {
|
|
repoName: 'demo',
|
|
repoPath: '/r',
|
|
storagePath: '/r/.gitnexus',
|
|
stats: { nodes: 50, edges: 1 },
|
|
pipelineResult: {
|
|
graph,
|
|
repoPath: '/r',
|
|
totalFileCount: 50,
|
|
resolutionOutcomes: [],
|
|
usedWorkerPool: true,
|
|
},
|
|
};
|
|
const projected = projectAnalyzeResultForIpc(result);
|
|
expect('pipelineResult' in projected).toBe(false);
|
|
const json = JSON.stringify(projected);
|
|
// A materialized 50-node graph would be thousands of bytes; the projection
|
|
// is just the scalar fields, so this stays small.
|
|
expect(json.length).toBeLessThan(300);
|
|
const rt = JSON.parse(json);
|
|
expect(rt.repoName).toBe('demo');
|
|
expect(rt.stats.nodes).toBe(50);
|
|
});
|
|
});
|