refactor: drop 12 runtimes, keep Claude, Codex, OpenCode, Cursor, ZCode, Antigravity
Removes kilo, kimi, kimi-code, copilot, windsurf, augment, trae, qwen, hermes, cline, codebuddy and pi end to end: capability descriptors, installer branches and converters (bin/install.js 14.9k -> 11.2k lines), TypeScript converters, hook surfaces and runtime homes, review lanes qwen/kimi-code, the two pi migrations, Kimi payload normalization in the hook guards, dead hostBehaviors vocabulary, launcher home probes, fixtures, runtime-specific tests and the prose that presented them as supported. Installer output for the six kept runtimes is byte-identical to before the prune. The Kimi tool-vocabulary tests in workflow-guard, read-guard and read-injection-scanner are left in place pending a decision.
This commit is contained in:
@@ -239,23 +239,19 @@ describe('#2665: live-config hermeticity guard', () => {
|
||||
|
||||
test('artifact parents are DERIVED from the registry, not hand-listed', () => {
|
||||
// Round 5's adversarial review refuted the completeness claim of the
|
||||
// hand-list: it missed Kilo's SINGULAR `command/`, `workflows/`, and hermes'
|
||||
// `skills/msd` -- a whole directory whose name carries no `msd-` prefix, so
|
||||
// no prefix rule could ever reach it.
|
||||
// hand-list: a fixed `msd-` prefix cannot reach artifacts whose layout
|
||||
// declares a different prefix.
|
||||
const { parents, owned } = artifactTargets();
|
||||
// NB: `workflows` is declared only in LOCAL scope (windsurf), so it is
|
||||
// deliberately NOT a global config-root parent -- the derivation walks
|
||||
// artifactLayout.global only.
|
||||
for (const p of ['agents', 'commands', 'command', 'skills', 'hooks', 'plugins', 'scripts', 'extensions']) {
|
||||
// NB: the derivation walks artifactLayout.global only.
|
||||
for (const p of ['agents', 'commands', 'skills', 'hooks', 'plugins', 'scripts', 'extensions']) {
|
||||
assert.ok(p in parents, `expected derived parent ${p} in ${JSON.stringify(Object.keys(parents))}`);
|
||||
}
|
||||
// kimi's kimi-agents layout declares prefix `msd` (no hyphen); a fixed `msd-`
|
||||
// A runtime layout may declare the dotted `msd.` prefix; a fixed `msd-`
|
||||
// scan cannot see agents/msd.yaml, which is the defect this derivation closes.
|
||||
assert.ok(
|
||||
parents.agents.includes('msd'),
|
||||
`agents must carry kimi's bare 'msd' prefix; got ${JSON.stringify(parents.agents)}`,
|
||||
parents.agents.includes('msd.'),
|
||||
`agents must carry the 'msd.' prefix; got ${JSON.stringify(parents.agents)}`,
|
||||
);
|
||||
assert.ok(owned.includes('skills/msd'), `expected hermes skills/msd in ${JSON.stringify(owned)}`);
|
||||
// Exact MSD filenames only — never the shared directories that contain them.
|
||||
for (const o of ['scripts/fix-slash-commands.cjs', 'hooks/managed-hooks-registry.cjs']) {
|
||||
assert.ok(owned.includes(o), `expected owned nested ${o} in ${JSON.stringify(owned)}`);
|
||||
@@ -268,19 +264,17 @@ describe('#2665: live-config hermeticity guard', () => {
|
||||
test('detects leaks a single hardcoded msd- prefix cannot see', () => {
|
||||
const root = tmpRoot();
|
||||
try {
|
||||
for (const d of ['skills/msd', 'agents', 'plugins', 'command', 'extensions']) {
|
||||
for (const d of ['agents', 'plugins', 'extensions']) {
|
||||
fs.mkdirSync(path.join(root, ...d.split('/')), { recursive: true });
|
||||
}
|
||||
const before = snapshotLiveConfig([root]);
|
||||
const future = new Date(Date.now() + 10000);
|
||||
// kimi declares prefix `msd` (no hyphen) and writes agents/msd.yaml;
|
||||
// pi writes extensions/msd.js. A fixed `msd-` scan sees neither.
|
||||
// A dotted `msd.` prefix (agents/msd.yaml, extensions/msd.js) is invisible
|
||||
// to a fixed `msd-` scan.
|
||||
const leaks = [
|
||||
['skills', 'msd', 'executor.md'],
|
||||
['agents', 'msd.yaml'],
|
||||
['extensions', 'msd.js'],
|
||||
['plugins', 'msd-core.js'],
|
||||
['command', 'msd-plan.md'],
|
||||
];
|
||||
for (const seg of leaks) {
|
||||
const f = path.join(root, ...seg);
|
||||
@@ -290,7 +284,7 @@ describe('#2665: live-config hermeticity guard', () => {
|
||||
}
|
||||
|
||||
const hit = diffLiveConfig(before, snapshotLiveConfig([root])).map((v) => v.path);
|
||||
for (const expected of ['skills/msd', 'agents/msd.yaml', 'extensions/msd.js', 'plugins/msd-core.js', 'command/msd-plan.md']) {
|
||||
for (const expected of ['agents/msd.yaml', 'extensions/msd.js', 'plugins/msd-core.js']) {
|
||||
const abs = path.join(root, ...expected.split('/'));
|
||||
assert.ok(hit.includes(abs), `${expected} leaked undetected; got ${JSON.stringify(hit)}`);
|
||||
}
|
||||
@@ -339,15 +333,11 @@ describe('#2665: live-config hermeticity guard', () => {
|
||||
// The MISSED finding from round 5's review: B3 closed this for the registry
|
||||
// roots and left the identical hole in resolveExtraWatchTargets.
|
||||
const targets = resolveExtraWatchTargets({
|
||||
env: { MSD_HOME: '/ambient-msd-home', KIMI_SHARE_DIR: '/ambient-kimi' },
|
||||
env: { MSD_HOME: '/ambient-msd-home' },
|
||||
os: { homedir: () => '/fallback-home' },
|
||||
});
|
||||
assert.ok(targets.includes(path.resolve('/ambient-msd-home/.msd')), 'ambient $MSD_HOME/.msd');
|
||||
assert.ok(targets.includes(path.resolve('/fallback-home/.msd')), 'HOME-derived .msd fallback');
|
||||
assert.ok(
|
||||
targets.some((t) => t === path.resolve('/fallback-home/.kimi/config.toml')),
|
||||
`HOME-derived kimi fallback missing from ${JSON.stringify(targets)}`,
|
||||
);
|
||||
});
|
||||
|
||||
test('detects a DELETED top-level MSD entry', () => {
|
||||
@@ -477,25 +467,19 @@ describe('#2665: live-config hermeticity guard', () => {
|
||||
|
||||
// ── Round 3: the write surfaces that are not runtime config ROOTS ───────────
|
||||
describe('#2665: guard watches non-root write surfaces', () => {
|
||||
test('resolveExtraWatchTargets covers $MSD_HOME/.msd and kimi config.toml', () => {
|
||||
test('resolveExtraWatchTargets covers $MSD_HOME/.msd', () => {
|
||||
const home = tmpRoot();
|
||||
const share = tmpRoot();
|
||||
try {
|
||||
const targets = resolveExtraWatchTargets({
|
||||
env: { MSD_HOME: home, KIMI_SHARE_DIR: share },
|
||||
env: { MSD_HOME: home },
|
||||
os: { homedir: () => home },
|
||||
});
|
||||
assert.ok(
|
||||
targets.includes(path.resolve(path.join(home, '.msd'))),
|
||||
`expected $MSD_HOME/.msd in ${JSON.stringify(targets)}`,
|
||||
);
|
||||
assert.ok(
|
||||
targets.some((t) => t === path.resolve(path.join(share, 'config.toml'))),
|
||||
`expected kimi config.toml in ${JSON.stringify(targets)}`,
|
||||
);
|
||||
} finally {
|
||||
cleanup(home);
|
||||
cleanup(share);
|
||||
}
|
||||
});
|
||||
|
||||
@@ -538,31 +522,6 @@ describe('#2665: guard watches non-root write surfaces', () => {
|
||||
}
|
||||
});
|
||||
|
||||
test('#2755: kimi-code config.toml is watched — named, not enumeration-relative', () => {
|
||||
// The test above derives its expectation FROM the descriptor array, so it
|
||||
// passes for whatever that array happens to contain and cannot see a
|
||||
// descriptor that was never added — the enumeration-relative scope boundary
|
||||
// this suite already calls out one layer down. #2755 landed kimi-code's
|
||||
// `~/.kimi-code` (KIMI_CODE_HOME) on `next` as an inline literal inside
|
||||
// resolveKimiHooksTomlDir's body; until it was hoisted into
|
||||
// NON_REGISTRY_CONFIG_HOME_DESCRIPTORS the guard watched Kimi CLI's
|
||||
// config.toml and not Kimi Code's. Naming the path is what makes dropping
|
||||
// the descriptor fail loudly instead of quietly shrinking the expectation.
|
||||
const home = tmpRoot();
|
||||
const codeHome = tmpRoot();
|
||||
try {
|
||||
const env = { MSD_HOME: home, KIMI_CODE_HOME: codeHome };
|
||||
const targets = resolveExtraWatchTargets({ env, os: { homedir: () => home } });
|
||||
assert.ok(
|
||||
targets.includes(path.resolve(path.join(codeHome, 'config.toml'))),
|
||||
`expected kimi-code config.toml in ${JSON.stringify(targets)}`,
|
||||
);
|
||||
} finally {
|
||||
cleanup(home);
|
||||
cleanup(codeHome);
|
||||
}
|
||||
});
|
||||
|
||||
test('MSD_HOME falls back to homedir when unset', () => {
|
||||
const home = tmpRoot();
|
||||
try {
|
||||
@@ -591,21 +550,6 @@ describe('#2665: guard watches non-root write surfaces', () => {
|
||||
}
|
||||
});
|
||||
|
||||
test('detects a [[hooks]] write into kimi config.toml', () => {
|
||||
const share = tmpRoot();
|
||||
try {
|
||||
const target = path.join(share, 'config.toml');
|
||||
const before = snapshotLiveConfig([], [target]);
|
||||
fs.writeFileSync(target, '[[hooks]]\n');
|
||||
|
||||
const violations = diffLiveConfig(before, snapshotLiveConfig([], [target]));
|
||||
assert.strictEqual(violations.length, 1);
|
||||
assert.strictEqual(violations[0].kind, 'created');
|
||||
} finally {
|
||||
cleanup(share);
|
||||
}
|
||||
});
|
||||
|
||||
test('NEGATIVE CONTROL: without the extras both leaks are silent', () => {
|
||||
const home = tmpRoot();
|
||||
try {
|
||||
|
||||
Reference in New Issue
Block a user