run.spec.ts 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348
  1. import { mkdtempSync, readFileSync, statSync } from 'node:fs'
  2. import { tmpdir } from 'node:os'
  3. import { dirname, join } from 'node:path'
  4. import { describe, expect, it, vi } from 'vitest'
  5. import { killGroup, OutputCollector, runBash } from '@deepseek-ai/dsh-bash-local'
  6. import type { RunningBash } from '@deepseek-ai/dsh-bash-local'
  7. const { failNextClose } = vi.hoisted(() => ({ failNextClose: { value: false } }))
  8. vi.mock('node:fs', async (importOriginal) => {
  9. const actual = await importOriginal<typeof import('node:fs')>()
  10. return {
  11. ...actual,
  12. closeSync(fd: number): void {
  13. if (failNextClose.value) {
  14. failNextClose.value = false
  15. throw Object.assign(new Error('simulated EIO on close'), { code: 'EIO' })
  16. }
  17. actual.closeSync(fd)
  18. },
  19. }
  20. })
  21. const spillDir = mkdtempSync(join(tmpdir(), 'dsh-bash-spec-'))
  22. function spec(command: string, overrides: Partial<Parameters<typeof runBash>[0]> = {}) {
  23. return {
  24. command,
  25. cwd: process.cwd(),
  26. timeoutMs: 0,
  27. maxOutputBytes: 64_000,
  28. ...overrides,
  29. }
  30. }
  31. /** Poll until a pid no longer exists (kill(pid, 0) throws ESRCH). */
  32. async function waitGone(pid: number, timeoutMs = 5_000): Promise<void> {
  33. const deadline = Date.now() + timeoutMs
  34. while (Date.now() < deadline) {
  35. try {
  36. process.kill(pid, 0)
  37. } catch {
  38. return
  39. }
  40. await new Promise(resolve => setTimeout(resolve, 20))
  41. }
  42. throw new Error(`pid ${pid} still alive after ${timeoutMs}ms`)
  43. }
  44. async function waitForStdout(running: RunningBash, expected: string, timeoutMs = 5_000): Promise<void> {
  45. const deadline = Date.now() + timeoutMs
  46. while (Date.now() < deadline) {
  47. if (running.stdout.snapshot().text.includes(expected)) return
  48. await new Promise(resolve => setTimeout(resolve, 20))
  49. }
  50. throw new Error(`stdout did not include ${JSON.stringify(expected)} after ${timeoutMs}ms`)
  51. }
  52. describe('runBash', () => {
  53. it('captures stdout on success', async () => {
  54. const result = await runBash(spec('echo hello')).done
  55. expect(result.exitCode).toBe(0)
  56. expect(result.signal).toBeNull()
  57. expect(result.timedOut).toBe(false)
  58. expect(result.aborted).toBe(false)
  59. expect(result.stdout.text).toBe('hello\n')
  60. expect(result.stdout.truncated).toBe(false)
  61. expect(result.stderr.text).toBe('')
  62. })
  63. it('captures stderr separately', async () => {
  64. const result = await runBash(spec('echo oops >&2')).done
  65. expect(result.exitCode).toBe(0)
  66. expect(result.stdout.text).toBe('')
  67. expect(result.stderr.text).toBe('oops\n')
  68. })
  69. it('captures both streams', async () => {
  70. const result = await runBash(spec('echo out; echo err >&2')).done
  71. expect(result.stdout.text).toBe('out\n')
  72. expect(result.stderr.text).toBe('err\n')
  73. })
  74. it('reports non-zero exit codes', async () => {
  75. const result = await runBash(spec('exit 42')).done
  76. expect(result.exitCode).toBe(42)
  77. expect(result.signal).toBeNull()
  78. })
  79. it('applies model-friendly env overrides', async () => {
  80. const result = await runBash(spec('echo "$NO_COLOR/$TERM/$PAGER"')).done
  81. expect(result.stdout.text).toBe('1/dumb/cat\n')
  82. })
  83. it('runs in the requested cwd', async () => {
  84. const result = await runBash(spec('pwd', { cwd: '/tmp' })).done
  85. expect(result.stdout.text.trim()).toMatch(/\/tmp$/)
  86. })
  87. it('kills with SIGTERM on timeout', async () => {
  88. const start = Date.now()
  89. const result = await runBash(spec('sleep 60', { timeoutMs: 100 })).done
  90. expect(Date.now() - start).toBeLessThan(5_000)
  91. expect(result.timedOut).toBe(true)
  92. expect(result.signal).toBe('SIGTERM')
  93. expect(result.exitCode).toBeNull()
  94. })
  95. it('escalates to SIGKILL when SIGTERM is trapped', async () => {
  96. const running = runBash(spec('trap \'\' TERM; echo ready; sleep 60'), { graceMs: 200 })
  97. await waitForStdout(running, 'ready\n')
  98. running.kill()
  99. const result = await running.done
  100. expect(result.signal).toBe('SIGKILL')
  101. })
  102. it('kills the whole process group (grandchildren die too)', async () => {
  103. // The subshell writes the sleep's pid then waits on it; killing the
  104. // group must take the sleep down with bash.
  105. const pidFile = join(spillDir, `grandchild-${Date.now()}.pid`)
  106. const running = runBash(spec(`sleep 60 & echo $! > ${pidFile}; wait`))
  107. await new Promise(resolve => setTimeout(resolve, 300))
  108. const grandchild = Number(readFileSync(pidFile, 'utf8').trim())
  109. expect(grandchild).toBeGreaterThan(0)
  110. running.kill()
  111. const result = await running.done
  112. expect(result.signal).toBe('SIGTERM')
  113. await waitGone(grandchild)
  114. })
  115. it('aborts via AbortSignal mid-run', async () => {
  116. const controller = new AbortController()
  117. const running = runBash(spec('sleep 60', { signal: controller.signal }))
  118. setTimeout(() => { controller.abort('user cancelled') }, 50)
  119. const result = await running.done
  120. expect(result.aborted).toBe(true)
  121. expect(result.signal).toBe('SIGTERM')
  122. })
  123. it('throws when the signal is already aborted before spawn', () => {
  124. const controller = new AbortController()
  125. controller.abort('too late')
  126. expect(() => runBash(spec('echo hi', { signal: controller.signal })))
  127. .toThrow(/aborted before spawn: too late/)
  128. })
  129. it('rejects with a spawn error for a nonexistent cwd', async () => {
  130. await expect(runBash(spec('echo hi', { cwd: '/nonexistent-dir-dsh-test' })).done)
  131. .rejects.toThrow(/ENOENT/)
  132. })
  133. it('kill() is idempotent (second call does not restart escalation)', async () => {
  134. const running = runBash(spec('sleep 60'))
  135. running.kill()
  136. running.kill()
  137. const result = await running.done
  138. expect(result.signal).toBe('SIGTERM')
  139. })
  140. })
  141. describe('output truncation and spill', () => {
  142. it('keeps the tail and spills the full stream to disk', async () => {
  143. // 200 numbered lines of ~10 bytes; cap at 500 bytes keeps a late tail.
  144. const result = await runBash(
  145. spec('for i in $(seq 1 200); do printf "line-%04d\\n" $i; done', { maxOutputBytes: 500 }),
  146. { spillDir },
  147. ).done
  148. expect(result.stdout.truncated).toBe(true)
  149. expect(result.stdout.text.length).toBeLessThanOrEqual(500)
  150. expect(result.stdout.text).toContain('line-0200')
  151. expect(result.stdout.text).not.toContain('line-0001')
  152. expect(result.stdout.spillPath).toBeDefined()
  153. const full = readFileSync(result.stdout.spillPath!, 'utf8')
  154. expect(full).toContain('line-0001')
  155. expect(full).toContain('line-0200')
  156. })
  157. it('does not truncate output exactly at the cap', async () => {
  158. const result = await runBash(
  159. spec('printf "%.0sx" $(seq 1 500)', { maxOutputBytes: 500 }),
  160. { spillDir },
  161. ).done
  162. expect(result.stdout.truncated).toBe(false)
  163. expect(result.stdout.text.length).toBe(500)
  164. expect(result.stdout.spillPath).toBeUndefined()
  165. })
  166. it('settles with the tail and no spill path when final spill close fails', async () => {
  167. failNextClose.value = true
  168. const result = await runBash(
  169. spec('for i in $(seq 1 200); do printf "line-%04d\\n" $i; done', { maxOutputBytes: 500 }),
  170. { spillDir },
  171. ).done
  172. expect(failNextClose.value).toBe(false)
  173. expect(result.exitCode).toBe(0)
  174. expect(result.stdout.truncated).toBe(true)
  175. expect(result.stdout.text).toContain('line-0200')
  176. expect(result.stdout.spillPath).toBeUndefined()
  177. })
  178. })
  179. describe('OutputCollector', () => {
  180. it('keeps the tail of a single oversized chunk', () => {
  181. const collector = new OutputCollector(10, 'test', spillDir)
  182. collector.push(Buffer.from('0123456789abcdef'))
  183. const out = collector.finalize()
  184. expect(out.text).toBe('6789abcdef')
  185. expect(out.truncated).toBe(true)
  186. expect(readFileSync(out.spillPath!, 'utf8')).toBe('0123456789abcdef')
  187. })
  188. it('readFrom returns increments and flags lossy reads', () => {
  189. const collector = new OutputCollector(10, 'test', spillDir)
  190. collector.push(Buffer.from('aaaaa'))
  191. const first = collector.readFrom(0)
  192. expect(first.text).toBe('aaaaa')
  193. expect(first.lossy).toBe(false)
  194. expect(first.nextOffset).toBe(5)
  195. collector.push(Buffer.from('bbbbb'))
  196. const second = collector.readFrom(first.nextOffset)
  197. expect(second.text).toBe('bbbbb')
  198. expect(second.lossy).toBe(false)
  199. // Push enough to slide the window past the last offset.
  200. collector.push(Buffer.from('c'.repeat(20)))
  201. const third = collector.readFrom(second.nextOffset)
  202. expect(third.lossy).toBe(true)
  203. expect(third.text).toBe('c'.repeat(10))
  204. expect(third.spillPath).toBeDefined()
  205. })
  206. it('tracks totalBytes across drops', () => {
  207. const collector = new OutputCollector(4, 'test', spillDir)
  208. collector.push(Buffer.from('aaaa'))
  209. collector.push(Buffer.from('bbbb'))
  210. expect(collector.totalBytes).toBe(8)
  211. expect(collector.finalize().text).toBe('bbbb')
  212. })
  213. it('contains close failures and drops the spill path', () => {
  214. const collector = new OutputCollector(4, 'closefail', spillDir)
  215. collector.push(Buffer.from('aaaa'))
  216. collector.push(Buffer.from('bbbb'))
  217. expect(collector.snapshot().spillPath).toBeDefined()
  218. failNextClose.value = true
  219. let out: ReturnType<typeof collector.finalize>
  220. expect(() => { out = collector.finalize() }).not.toThrow()
  221. expect(failNextClose.value).toBe(false)
  222. expect(out!.text).toBe('bbbb')
  223. expect(out!.truncated).toBe(true)
  224. expect(out!.spillPath).toBeUndefined()
  225. })
  226. })
  227. describe('killGroup', () => {
  228. it('ignores non-positive pids', () => {
  229. expect(() => { killGroup(-1, 'SIGTERM') }).not.toThrow()
  230. expect(() => { killGroup(0, 'SIGTERM') }).not.toThrow()
  231. })
  232. it('swallows ESRCH for vanished groups', async () => {
  233. const running = runBash(spec('true'))
  234. await running.done
  235. expect(() => { killGroup(running.pid, 'SIGTERM') }).not.toThrow()
  236. })
  237. })
  238. describe('abort edge cases', () => {
  239. it('reports a fallback reason for reason-less pre-aborted signals', () => {
  240. // Real AbortControllers always set a DOMException reason; signal-like
  241. // objects from other libraries may not — the fallback covers them.
  242. const bare = {
  243. aborted: true,
  244. reason: undefined,
  245. addEventListener() {},
  246. removeEventListener() {},
  247. } as unknown as AbortSignal
  248. expect(() => runBash(spec('echo hi', { signal: bare })))
  249. .toThrow(/aborted before spawn: aborted/)
  250. })
  251. it('reports an externally self-killed command without the timeout marker', async () => {
  252. const result = await runBash(spec('kill -TERM $$')).done
  253. expect(result.signal).toBe('SIGTERM')
  254. expect(result.timedOut).toBe(false)
  255. expect(result.aborted).toBe(false)
  256. })
  257. })
  258. describe('review fixes: env scrubbing and spill hardening', () => {
  259. it('scrubs credential-shaped env vars from child processes', async () => {
  260. process.env.DSH_TEST_API_KEY = 'super-secret'
  261. process.env.DSH_TEST_TOKEN = 'also-secret'
  262. process.env.DSH_TEST_PLAIN = 'visible'
  263. try {
  264. const result = await runBash(spec('echo "[${DSH_TEST_API_KEY:-absent}|${DSH_TEST_TOKEN:-absent}|${DSH_TEST_PLAIN:-absent}]"')).done
  265. expect(result.stdout.text.trim()).toBe('[absent|absent|visible]')
  266. } finally {
  267. delete process.env.DSH_TEST_API_KEY
  268. delete process.env.DSH_TEST_TOKEN
  269. delete process.env.DSH_TEST_PLAIN
  270. }
  271. })
  272. it('creates spill files with owner-only permissions and random names', async () => {
  273. const result = await runBash(
  274. spec('for i in $(seq 1 200); do printf "line-%04d\\n" $i; done', { maxOutputBytes: 500 }),
  275. { spillDir },
  276. ).done
  277. const path = result.stdout.spillPath!
  278. expect(path).toMatch(/dsh-bash-\d+-\d+-[0-9a-f]{12}-stdout\.log$/)
  279. const mode = statSync(path).mode & 0o777
  280. expect(mode).toBe(0o600)
  281. })
  282. it('defaults spills into a private per-process directory', async () => {
  283. const result = await runBash(
  284. spec('for i in $(seq 1 200); do printf "line-%04d\\n" $i; done', { maxOutputBytes: 500 }),
  285. ).done
  286. const dir = dirname(result.stdout.spillPath!)
  287. expect(dir).toMatch(/dsh-bash-/)
  288. const mode = statSync(dir).mode & 0o777
  289. expect(mode).toBe(0o700)
  290. })
  291. it('killGroup never throws, even for EPERM-style failures', () => {
  292. const spy = vi.spyOn(process, 'kill').mockImplementation(() => {
  293. throw Object.assign(new Error('EPERM'), { code: 'EPERM' })
  294. })
  295. try {
  296. expect(() => { killGroup(12345, 'SIGTERM') }).not.toThrow()
  297. } finally {
  298. spy.mockRestore()
  299. }
  300. })
  301. it('honors AbortSignal on background-style runs (no timeout)', async () => {
  302. const controller = new AbortController()
  303. const running = runBash(spec('sleep 60', { timeoutMs: 0, signal: controller.signal }))
  304. setTimeout(() => { controller.abort() }, 50)
  305. const result = await running.done
  306. expect(result.aborted).toBe(true)
  307. expect(result.signal).toBe('SIGTERM')
  308. })
  309. })