fix(profiles): make evaluator permissions and Windows checks portable

This commit is contained in:
haelyra
2026-09-27 17:03:28 -04:00
parent 0765f7a2ca
commit 874883c728
3 changed files with 9 additions and 5 deletions
+4 -2
View File
@@ -489,9 +489,11 @@ function syntheticEnvironments(root) {
function checkArguments(cwd, file = CHECK_FILE, writable = false) {
const major = Number(process.versions.node.split('.')[0]);
const flag = major >= 22 ? '--permission' : major >= 20 ? '--experimental-permission' : null;
return flag ? [flag, `--allow-fs-read=${cwd}`, `--allow-fs-read=${path.join(cwd, '*')}`,
// A directory grant covers its children. Node 20.20.2 can abort in its native
// permission radix tree when the same directory is also granted as "cwd/*".
return flag ? [flag, `--allow-fs-read=${cwd}`,
// Stepped graders exercise stateful apps (persistence); single-step graders stay read-only.
...(writable ? [`--allow-fs-write=${cwd}`, `--allow-fs-write=${path.join(cwd, '*')}`] : []), file] : [file];
...(writable ? [`--allow-fs-write=${cwd}`] : []), file] : [file];
}
// The hidden grader enters the workspace only after the agent exits, and runs read-only where Node supports it.
+3 -1
View File
@@ -64,6 +64,8 @@ test('provider failure is distinct from successful task completion', () => withF
test('isolated native launches replace every provider home without mutating the parent environment', () => withFixture(repoRoot => {
const nativeEnvironment = nativeFixture(repoRoot);
const before = { ...process.env };
// Windows may expose the inherited key as Path while process.env resolves PATH case-insensitively.
const inheritedPath = process.env.PATH;
let called = false;
const result = launchTaskContext({ repoRoot, task: input, nativeEnvironment, execute(command, args, options) {
called = true;
@@ -73,7 +75,7 @@ test('isolated native launches replace every provider home without mutating the
assert.equal(options.env.HOME, nativeEnvironment.home);
assert.equal(options.env.USERPROFILE, nativeEnvironment.home);
assert.equal(options.env.CODEX_HOME, nativeEnvironment.codexHome);
assert.equal(options.env.PATH, before.PATH);
assert.equal(options.env.PATH, inheritedPath);
for (const key of ['AWS_ACCESS_KEY_ID', 'OPENAI_API_KEY', 'ANTHROPIC_API_KEY', 'HTTP_PROXY', 'NODE_OPTIONS']) {
assert.equal(options.env[key], undefined);
}
+2 -2
View File
@@ -67,8 +67,8 @@ test('native prepare verifies exact installed bytes and returns isolated session
assert.equal(result.active, false);
assert.equal(result.storeRevision, 1);
assert.equal(result.providerVersion, '0.154.0');
assert.ok(result.home.startsWith(`${options.nativeRoot}/`));
assert.ok(result.codexHome.startsWith(`${result.home}/`));
assert.equal(path.dirname(path.dirname(result.home)), path.join(options.nativeRoot, 'generations'));
assert.equal(path.dirname(result.codexHome), result.home);
assert.equal(result.discovery, 'verified');
assert.equal(result.selectedIds.length, 3);
assert.equal(dependency.calls.filter(call => call.args[1] === 'add').length, 1);