mirror of
https://github.com/MoonshotAI/kimi-code.git
synced 2026-08-20 14:16:22 +00:00
* ci: run unit tests on windows * fix(migration-legacy): align workdir bucket key with agent-core computeWorkdirBucket used a local node:path-based resolve that yields backslash-separated paths on Windows, while agent-core's encodeWorkDirKey uses pathe (forward slashes on every platform). The SHA-256 inputs diverged, so migrated sessions were written to a bucket that the session picker never reads, making them invisible on Windows. Alias computeWorkdirBucket to encodeWorkDirKey so both sides stay byte-identical, drop the local slugify copy, and update the workdir-bucket test reference accordingly. * test(acp-adapter): expect platform-native separators in e2e-fs path The e2e-fs test asserted the fs/readTextFile wire path as the raw POSIX targetPath, but AcpKaos.toClientPath converts '/' to '\' when the inner LocalKaos reports pathClass 'win32' (Windows). On Windows the wire path became '\Users\test\x.ts' and the assertion failed. Mirror toClientPath in the test: expect backslash separators on win32 and the raw path otherwise. Implementation is unchanged. * test(sdk): normalize workDir and skillDir paths in session tests SessionStore.create/list and the skill loader normalize paths through pathe (forward slashes). The SDK tests compared the resulting workDir and skill loaded-dir against raw mkdtemp / node:path strings, which use backslashes on Windows (and node:fs realpath also returns backslashes for the skill dir), failing three toMatchObject assertions. Build the expected paths with agent-core's normalizeWorkDir so they match the internal pathe representation on every platform. The skill dir keeps its realpath() (the loader realpaths the root) and only normalizes separators. * test(skill): normalize realpath to forward slashes in scanner tests resolveSkillRoots normalizes every root.path through fs.realpath followed by replacing backslashes with forward slashes (scanner.ts). The scanner tests compared root.path against node:fs realpath directly, which returns backslashes on Windows, so twenty assertions failed (toEqual / toContain / toHaveLength) even though the resolved paths were identical. Wrap realpath at the top of the test file to mirror the implementation's normalization, so every comparison uses the same forward-slash form on every platform. * test: skip Unix-only permission tests on Windows The Unix file-permission assertions (mode bits like 0o600 / 0o700 and chmod 000 making a path unreadable) have no equivalent on Windows, which uses ACLs; fs.chmod there can only toggle the read-only bit. These six tests failed on Windows with mismatched mode values or a missing 40411. Skip them on win32 via it.skipIf(process.platform === 'win32'): oauth FileTokenStorage (0600 file, 0700 dir), agent-core BackgroundTaskPersistence (0700 tasks dir), agent-core createPerIdJsonStore (0700 subdir), migration-legacy atomicWrite (0600 file), and server fs:browse (chmod 000 -> 40411). * test(tui): make platform-sensitive assertions cross-platform The TUI implementations are already platform-aware (pathe-style paths, pathToFileURL, quoteShellArg cmd/POSIX quoting, Alt+V on Windows for paste expansion), but the tests hard-coded POSIX expectations and failed on Windows. Align the assertions with the implementation's platform behavior: footer-goal-badge matches the '[goal' badge prefix instead of /goal/ (toolbar tips contain '/goal'); tool-call expects backslash relative paths on win32; plan-box builds the file:// URL via pathToFileURL; custom-editor sends Alt+V on win32 for paste expansion; file-mention-provider normalizes the expected description to forward slashes; kimi-tui-startup builds the resume command with quoteShellArg; kimi-tui-message-flow builds the expected install path with resolve(). * test: align path assertions with pathe on Windows Several test suites asserted paths produced by node:path/node:os/node:fs against values that agent-core, node-sdk and kaos normalize through pathe (forward slashes). On Windows the two forms diverge (backslashes vs forward slashes), failing about 19 assertions. Mirror the implementation's normalization in the assertions via a local toPosix helper (or agent-core's normalizeWorkDir), so expected paths use forward slashes on every platform: kaos LocalKaos, node-sdk export/list/resume/config/transport sessions, cli FileMentionProvider, and agent-core skill-session. * test(native): build path expectations with node:path.resolve paths.mjs builds every path with node:path.resolve, which yields backslash-separated absolute paths on Windows. The path-helpers tests asserted against template strings that mixed the backslash appRoot with forward-slash segments, so Object.is failed on Windows even though the strings looked identical. Build the expectations with the same resolve(appRoot, ...) helper so the separators match on every platform. * fix: make Windows CI tests pass across all packages Fix the remaining Windows CI failures so the Windows test job can go green. The changes fall into a few categories: - Path separators: agent-core/node-sdk/kaos normalize paths via pathe (forward slashes); align test expectations and a couple of implementations (native cache base, workspace registry) with that. - Platform-only services: skip launchd/systemd manager suites on win32 (Windows uses schtasks). - Process/signal lifecycle: skip or relax tests that rely on POSIX signals / SIGTERM semantics that Windows does not support. - Hook shell syntax: rewrite hook test commands from POSIX shell (single quotes, semicolons, stderr redirects, if/then/fi) to node -e / .cjs files that run under cmd.exe. - CRLF: make Bash tool description stripping tolerate CRLF line endings. - Misc: realpath short-name divergence, port-retry timing, telemetry spawn, fs-watch timing, snapshot path normalization, etc. * fix: remove unused basename import in workspaceRegistryService Fix lint error (no-unused-vars): basename from node:path is no longer used after switching to posixBasename from pathe. * fix: align resume harness pathClass and wait for banner state on Windows Two more Windows CI fixes: - createResumeNoSideEffectKaos now reports pathClass 'win32' on Windows so tool descriptions (e.g. Glob's Windows note) match the live agent in expectResumeMatches, fixing usage/description deep-equal drift. - kimi-tui-startup once-banner test now waits for writeBannerDisplayState to land before asserting, since the atomic write can lag behind the render on Windows. * fix: resolve remaining Windows unit test failures Make the new Windows CI job green across agent-core, kaos, node-sdk and server: - Align the resume harness kaos pathClass with the live agent so platform-conditional tool descriptions (Glob's Windows note) match in expectResumeMatches instead of drifting on win32. - Rewrite hook commands in agent-core tests as cross-platform node one-liners; single-quote echo, >&2 and ';' do not work under cmd.exe. - Add .gitattributes enforcing LF so raw-imported templates (e.g. the compaction instruction) produce byte-identical token counts on Windows and POSIX. - Terminate the full process tree on Windows in both the hook runner and kaos (taskkill /T /F) so grandchildren cannot outlive their parent and keep the cwd locked. - Normalize workDir path separators in two kimi-sdk session tests to match the stored canonical form. - Avoid cmd.exe arg-quoting pitfalls in the kaos cmd.exe test, and run the Windows process-tree kill test from a script file with the pid path passed via argv. - Give the first fs-git e2e test more time on Windows and retry the temp-dir cleanup; skip the fs-watch overflow-burst assertion on Windows where fs-event coalescing prevents the single-window spike. * ci: retrigger checks * fix: resolve remaining Windows failures after merging main - Terminate the spawned git/gh process tree on Windows in FsGitService (taskkill /T /F on timeout) so a timed-out 'gh pr view' cannot leave a grandchild holding the workspace cwd, which made the fs-git e2e cleanup fail with EPERM. - Give the fs:git_status e2e suite a longer timeout on Windows and retry the temp-dir cleanup longer to ride out the slower child-process teardown. - Make the third-party plugin install trust test assert the resolved install path via node:path so it matches the Windows-resolved path (D:\tmp\...) as well as the POSIX one. * fix: align workspace registry roots and harden fs-git cleanup on Windows - workspace-registry test: compare normalized (forward-slash) roots, since the registry and session index both store workDir via pathe.resolve (forward slashes on every platform). realpath() yields backslashes on Windows and diverged from the stored root. - fs-git e2e: bump the temp-dir cleanup retries and the afterEach timeout, since Windows child-process teardown after server.close() is asynchronous and can keep the workspace cwd locked for several seconds. * test: stub openUrl in kimi-tui-message-flow feedback tests The /feedback command falls back to openUrl(FEEDBACK_ISSUE_URL) when submission fails, which spawned a real browser window on every test run. Mock #/utils/open-url (matching the existing login/message-replay/server test convention) so the suite never opens a browser. * test: harden fs-git e2e cleanup against Windows cwd locks On Windows, git/gh child processes and the session core process can outlive server.close() and keep the temp workspace as their cwd, so rmSync fails with EPERM even after a long retry. Add rmSyncRobust that retries and, if the cwd is still locked, swallows EPERM/EBUSY on Windows — the OS reclaims the temp dir and a cleanup hiccup must not fail an otherwise-passing test. * test: harden server e2e cleanup against async teardown races server.close() does not fully await the server's asynchronous teardown, so on a loaded CI runner the temp home/workspace dirs can still be held or written to when the afterEach rmSync runs, failing with EPERM (Windows) or ENOTEMPTY (Linux). Use a rmSyncRobust helper (retry + swallow EPERM/EBUSY/ENOTEMPTY) in the fs-git and question e2e cleanup. Also fix a leftover `throw err` (renamed to `throw error`) that broke the typecheck.
214 lines
7.9 KiB
TypeScript
214 lines
7.9 KiB
TypeScript
/**
|
|
* FileTokenStorage tests — round-trip persistence + permission checks.
|
|
*
|
|
* Scope guards: tokens never leak to process.env or other files; permission
|
|
* 0600 is enforced; corrupted files return undefined rather than throwing.
|
|
*/
|
|
|
|
import { chmodSync, mkdirSync, readFileSync, rmSync, statSync, writeFileSync } from 'node:fs';
|
|
import { tmpdir } from 'node:os';
|
|
import { join } from 'node:path';
|
|
|
|
import { afterEach, beforeEach, describe, expect, it } from 'vitest';
|
|
|
|
import { FileTokenStorage } from '../src/storage';
|
|
import type { TokenInfo } from '../src/types';
|
|
|
|
function makeTmpDir(): string {
|
|
const dir = join(
|
|
tmpdir(),
|
|
`kimi-storage-test-${Date.now()}-${Math.random().toString(36).slice(2)}`,
|
|
);
|
|
mkdirSync(dir, { recursive: true });
|
|
return dir;
|
|
}
|
|
|
|
function sampleToken(overrides: Partial<TokenInfo> = {}): TokenInfo {
|
|
return {
|
|
accessToken: 'at-abc',
|
|
refreshToken: 'rt-xyz',
|
|
expiresAt: 1_700_000_000,
|
|
scope: 'read write',
|
|
tokenType: 'Bearer',
|
|
expiresIn: 3600,
|
|
...overrides,
|
|
};
|
|
}
|
|
|
|
describe('FileTokenStorage', () => {
|
|
let dir: string;
|
|
let storage: FileTokenStorage;
|
|
|
|
beforeEach(() => {
|
|
dir = makeTmpDir();
|
|
storage = new FileTokenStorage(dir);
|
|
});
|
|
|
|
afterEach(() => {
|
|
rmSync(dir, { recursive: true, force: true });
|
|
});
|
|
|
|
it('returns undefined when no token exists', async () => {
|
|
expect(await storage.load('kimi-code')).toBeUndefined();
|
|
});
|
|
|
|
it('round-trips a token via save/load', async () => {
|
|
const token = sampleToken();
|
|
await storage.save('kimi-code', token);
|
|
const loaded = await storage.load('kimi-code');
|
|
expect(loaded).toEqual(token);
|
|
});
|
|
|
|
it('persists tokens in snake_case JSON (Python-compatible)', async () => {
|
|
const token = sampleToken();
|
|
await storage.save('kimi-code', token);
|
|
const raw = readFileSync(join(dir, 'kimi-code.json'), 'utf-8');
|
|
const parsed = JSON.parse(raw) as Record<string, unknown>;
|
|
expect(parsed['access_token']).toBe('at-abc');
|
|
expect(parsed['refresh_token']).toBe('rt-xyz');
|
|
expect(parsed['expires_at']).toBe(1_700_000_000);
|
|
expect(parsed['token_type']).toBe('Bearer');
|
|
expect(parsed['expires_in']).toBe(3600);
|
|
expect(parsed['accessToken']).toBeUndefined();
|
|
});
|
|
|
|
it.skipIf(process.platform === 'win32')('writes the credentials file with mode 0600', async () => {
|
|
await storage.save('kimi-code', sampleToken());
|
|
const stat = statSync(join(dir, 'kimi-code.json'));
|
|
// eslint-disable-next-line no-bitwise
|
|
expect(stat.mode & 0o777).toBe(0o600);
|
|
});
|
|
|
|
it('remove() deletes the file; load() then returns undefined', async () => {
|
|
await storage.save('kimi-code', sampleToken());
|
|
await storage.remove('kimi-code');
|
|
expect(await storage.load('kimi-code')).toBeUndefined();
|
|
});
|
|
|
|
it('remove() is idempotent when file is absent', async () => {
|
|
await expect(storage.remove('never-existed')).resolves.toBeUndefined();
|
|
});
|
|
|
|
it('save() overwrites an existing token atomically', async () => {
|
|
await storage.save('kimi-code', sampleToken({ accessToken: 'first' }));
|
|
await storage.save('kimi-code', sampleToken({ accessToken: 'second' }));
|
|
const loaded = await storage.load('kimi-code');
|
|
expect(loaded?.accessToken).toBe('second');
|
|
});
|
|
|
|
it('load() returns undefined on corrupt JSON (does not throw)', async () => {
|
|
const file = join(dir, 'kimi-code.json');
|
|
writeFileSync(file, '{ not json', 'utf-8');
|
|
chmodSync(file, 0o600);
|
|
expect(await storage.load('kimi-code')).toBeUndefined();
|
|
});
|
|
|
|
it('load() returns undefined on malformed payload (not a dict)', async () => {
|
|
const file = join(dir, 'kimi-code.json');
|
|
writeFileSync(file, '["array", "instead"]', 'utf-8');
|
|
chmodSync(file, 0o600);
|
|
expect(await storage.load('kimi-code')).toBeUndefined();
|
|
});
|
|
|
|
it('load() tolerates missing numeric fields by defaulting to 0', async () => {
|
|
const file = join(dir, 'kimi-code.json');
|
|
writeFileSync(file, JSON.stringify({ access_token: 'a', refresh_token: 'r' }), 'utf-8');
|
|
chmodSync(file, 0o600);
|
|
const token = await storage.load('kimi-code');
|
|
expect(token?.expiresAt).toBe(0);
|
|
expect(token?.expiresIn).toBe(0);
|
|
});
|
|
|
|
it('list() returns all stored token names', async () => {
|
|
await storage.save('kimi-code', sampleToken());
|
|
await storage.save('other-provider', sampleToken());
|
|
const names = await storage.list();
|
|
expect(names.toSorted()).toEqual(['kimi-code', 'other-provider']);
|
|
});
|
|
|
|
it('list() ignores non-JSON files in the credentials dir', async () => {
|
|
await storage.save('kimi-code', sampleToken());
|
|
writeFileSync(join(dir, 'kimi-code.lock'), 'lock', 'utf-8');
|
|
writeFileSync(join(dir, 'readme.txt'), 'readme', 'utf-8');
|
|
const names = await storage.list();
|
|
expect(names).toEqual(['kimi-code']);
|
|
});
|
|
|
|
it.skipIf(process.platform === 'win32')('creates the credentials dir with mode 0700 if missing', async () => {
|
|
const freshDir = join(dir, 'nested', 'sub');
|
|
const s = new FileTokenStorage(freshDir);
|
|
await s.save('kimi-code', sampleToken());
|
|
const stat = statSync(freshDir);
|
|
// eslint-disable-next-line no-bitwise
|
|
expect(stat.mode & 0o777).toBe(0o700);
|
|
});
|
|
|
|
it('refuses path-traversal names on save (B1)', async () => {
|
|
await expect(storage.save('../../etc/passwd', sampleToken())).rejects.toThrow(
|
|
/Invalid token name/,
|
|
);
|
|
});
|
|
|
|
it('refuses path-traversal names on load', async () => {
|
|
await expect(storage.load('../etc/passwd')).rejects.toThrow(/Invalid token name/);
|
|
});
|
|
|
|
it('refuses path-traversal names on remove', async () => {
|
|
await expect(storage.remove('../etc/passwd')).rejects.toThrow(/Invalid token name/);
|
|
});
|
|
|
|
it('refuses leading-dot names (hidden file abuse)', async () => {
|
|
await expect(storage.save('.hidden', sampleToken())).rejects.toThrow(/Invalid token name/);
|
|
});
|
|
|
|
it('refuses empty name', async () => {
|
|
await expect(storage.save('', sampleToken())).rejects.toThrow(/Invalid token name/);
|
|
});
|
|
|
|
// ── atomic save leaves no .tmp sibling ────────────────────────────────
|
|
|
|
it('save() leaves no *.tmp.* sibling once the rename completes', async () => {
|
|
// Atomic save must clean up its temp artefact after rename. Uses
|
|
// `target.tmp.<pid>.<rand>` then renameSync; this test asserts the
|
|
// resulting directory contains only the canonical file.
|
|
await storage.save('kimi-code', sampleToken());
|
|
const { readdirSync } = await import('node:fs');
|
|
const entries = readdirSync(dir);
|
|
const tmps = entries.filter((name) => name.startsWith('kimi-code.json.tmp.'));
|
|
expect(tmps).toEqual([]);
|
|
expect(entries).toContain('kimi-code.json');
|
|
});
|
|
|
|
it('save() + load() preserves expires_in and expires_at roundtrip', async () => {
|
|
// The wire format records both `expires_at` and `expires_in`; the
|
|
// load path must restore both fields without loss.
|
|
const token = sampleToken({ expiresAt: 1_800_000_000, expiresIn: 7200 });
|
|
await storage.save('kimi-code', token);
|
|
const loaded = await storage.load('kimi-code');
|
|
expect(loaded?.expiresAt).toBe(1_800_000_000);
|
|
expect(loaded?.expiresIn).toBe(7200);
|
|
});
|
|
|
|
it('load() of a wire payload missing scope/token_type uses safe defaults', async () => {
|
|
// A legacy file written without the optional `scope` / `token_type`
|
|
// fields must still load; the defaults come from `tokenFromWire`.
|
|
const file = join(dir, 'kimi-code.json');
|
|
writeFileSync(
|
|
file,
|
|
JSON.stringify({
|
|
access_token: 'a',
|
|
refresh_token: 'r',
|
|
expires_at: 1,
|
|
expires_in: 60,
|
|
}),
|
|
'utf-8',
|
|
);
|
|
chmodSync(file, 0o600);
|
|
const loaded = await storage.load('kimi-code');
|
|
expect(loaded?.accessToken).toBe('a');
|
|
expect(loaded?.refreshToken).toBe('r');
|
|
// Defaults should be strings (empty / 'Bearer'), never undefined.
|
|
expect(typeof loaded?.scope).toBe('string');
|
|
expect(typeof loaded?.tokenType).toBe('string');
|
|
});
|
|
});
|