From 6ac4d2e6ab43ecfa51d921e6229351d8caebacf3 Mon Sep 17 00:00:00 2001 From: 0xdhx Date: Sat, 8 Aug 2026 05:58:35 -0500 Subject: [PATCH] fix(#3156): bound the cold-require probe the rebase turned into a violation Post-rebase validity finding, not a new defect. The base range added local/no-unbounded-spawn (#3143, 2afe17bb) and then DELETED its allowlist (#3148, 9faacc0c), so the cold-require probe this PR added in 4bc6b0a2 -- legal when written -- is now an error. Bounded at 30s: a cold require is sub-second, so that is ~30x headroom and still fails loudly rather than hanging a lane. Also routes this round's own teardown through cleanup() instead of raw fs.rmSync, per local/no-raw-rmsync-in-tests, which carries the Windows-EBUSY retry budget. eslint clean on the file. --- tests/helpers-process-isolation.test.cjs | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/tests/helpers-process-isolation.test.cjs b/tests/helpers-process-isolation.test.cjs index 083d09d23..2f1db0ea7 100644 --- a/tests/helpers-process-isolation.test.cjs +++ b/tests/helpers-process-isolation.test.cjs @@ -24,7 +24,9 @@ describe('#2665: the built-lib require is deferred', () => { "const needle = path.join('gsd-core', 'bin', 'lib', 'capability-registry.cjs');", 'process.stdout.write(String(Object.keys(require.cache).some((m) => m.endsWith(needle))));', ].join('\n'); - const r = spawnSync(process.execPath, ['-e', src], { encoding: 'utf8' }); + // Bounded per local/no-unbounded-spawn (#3143): a cold require is sub-second, + // so 30s is ~30x headroom and still fails loudly instead of hanging a lane. + const r = spawnSync(process.execPath, ['-e', src], { encoding: 'utf8', timeout: 30_000 }); assert.strictEqual(r.status, 0, `probe failed: ${r.stderr}`); return r.stdout === 'true'; }; @@ -347,7 +349,7 @@ describe('#3156: a raw installer spawn cannot write into the ambient HOME', () = const fs = require('node:fs'); const os = require('node:os'); const { execFileSync } = require('node:child_process'); - const { installSpawnEnv } = require('./helpers.cjs'); + const { installSpawnEnv, cleanup } = require('./helpers.cjs'); const { installerEnv } = require('./helpers/install-shared.cjs'); const INSTALL_PATH = path.join(__dirname, '..', 'bin', 'install.js'); @@ -403,8 +405,8 @@ describe('#3156: a raw installer spawn cannot write into the ambient HOME', () = if (realHome === undefined) delete process.env.HOME; else process.env.HOME = realHome; if (realUserProfile === undefined) delete process.env.USERPROFILE; else process.env.USERPROFILE = realUserProfile; - fs.rmSync(canaryHome, { recursive: true, force: true }); - fs.rmSync(projectDir, { recursive: true, force: true }); + cleanup(canaryHome); + cleanup(projectDir); } }); });