* fix(integration-tests): make the project typecheckable and fix what that found
`tsc -p integration-tests/tsconfig.json` could not run at all. The config
carried a `"//"` documentation key inside `compilerOptions.paths`, and every
value there must be an array, so tsc aborted with TS5063 before checking a
single file. Nothing in CI runs it either, so the directory has been
unchecked for its whole life -- which is how PR #8620 shipped an
`integration-tests/cli/qwen-serve-streaming.test.ts` that referenced an
undeclared `REPO_ROOT`, swallowed the ReferenceError in a bare catch, and
reported a green skip for a security regression test.
Moving that note out of `paths` exposed 404 errors. Three more config
defects accounted for 353 of them:
- `composite: true` is inherited from the root config for the packages that
are actually referenced. Composite requires every file in the program to
appear in `include`, and these tests import package sources by relative
path, so it produced 324 TS6307. Nothing references this project and it
emits nothing, so it is now `composite: false`.
- The root `lib` is ES2023 only. The suite drives browser-side code in
`terminal-capture/` and pulls SDK sources that name `WebSocket` and
`HeadersInit`, so 21 identifiers resolved to nothing. Now DOM +
DOM.Iterable + ES2023, matching packages/cli.
- Workspace packages resolved through `packages/core/dist` via a project
reference, so with core unbuilt the checker reported a dozen members as
missing from `Storage` that are right there in the source. They now
resolve from source through `paths`, mirroring packages/cli, and the
reference is gone.
node-pty declares `types` at the top level but its `exports` map is a bare
string with no `types` condition, so nodenext never reached the
declarations and every pty handle degraded to `any` -- which is what
silently untyped the `data` and `exitCode` callbacks in test-helper.ts. It
now resolves through `paths` as well. `@types/jsdom` is added for the one
file that uses it; DefinitelyTyped has no release matching jsdom 26 (it
jumps 21 -> 27), so this pins the current 28.x.
Two real defects fell out of the remaining 51:
- write_file.test.ts built a detailed tool-call failure message and passed
it to `toBeTruthy()`, which takes no arguments. It was discarded on every
failure, leaving only a bare literal.
- Two terminal-capture scenarios set `gif: true` inside `streaming`, where
the runner never reads it. It is a scenario-level switch.
The rest was making an existing `undefined` visible. `readToolLogs()`
promised `name: string` for fields copied straight out of telemetry
attributes that nothing validates; the stdout fallback can promise them,
the telemetry branch cannot, and claiming otherwise just moved the
`undefined` past the type checker into the assertions.
This is type resolution only. `integration-tests/vitest.config.ts` keeps
its own hardcoded aliases onto the built SDK bundle, so the suite still
exercises the published-bundle shape at runtime.
Not wired into CI here, but not for cost reasons: a cold run of
`tsc -p integration-tests/tsconfig.json` takes about 106s on an idle
developer box. The program is 2679 files, of which 103 are integration
tests and roughly 1100 are package sources their own projects already
check, so there is duplicated work available to reclaim by resolving the
packages from their built declarations -- but at ~106s it is already cheap
enough to gate on as-is.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
* fix(integration-tests): isolate jsdom types and complete source-resolution paths
Address review round 1:
- external-context: override `types` to ["node"]. The root @types/jsdom
entered its program through vitest's optional jsdom types and injected
lib dom, flipping @types/node's fetch globals to DOM variants whose
ReadableStream is not async-iterable (TS2504 in http-client.ts), which
failed every CI job during the npm ci prepare build.
- integration-tests tsconfig: explicit nodenext paths entries for every
workspace subpath the program imports (sdk/daemon, 19 acp-bridge
subpaths, core goalWire/memoryScopes/userPromptSubmitContext, webui
daemon-react-sdk, channel-base); drop the dead `*` wildcards; include
**/*.tsx. Typechecks green with the source packages' dists removed.
- Relax noPropertyAccessFromIndexSignature in integration-tests and
revert the six bracket-access rewrites it forced in SDK sources.
- channel-plugin: import channels/base from src and map
@qwen-code/channel-base to source so both declarations agree.
- qwen-serve-streaming: asAccepted delegates to the SDK's exported
isNonBlockingAccepted type predicate instead of a drifted copy.
- sleep-interception: tighten blocked predicates to success === false
and fix the comment describing them.
- Declare jsdom at the root next to @types/jsdom.
* fix(integration-tests): complete source-resolution paths and restore single channel-base instance
Address review round 2:
- Map the eight builtin channel adapters and web-templates to source.
channel-registry.ts and html.ts still resolved them through their
exports maps to dist, so the typecheck's build-independence was
incomplete: on a tree without built dists it failed with the exact
9 x TS2307 the maintainer verification measured.
- channel-plugin.test.ts: import @qwen-code/channel-base by bare
specifier instead of a relative src path. At runtime the test and
plugin-example now resolve the same dist/index.js through the
exports map, restoring the single ChannelBase / SessionRouter
instance the relative src import silently split; type resolution
still maps to source through paths, and vitest.config.ts keeps
pointing e2e runs at the built bundles.
---------
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
Co-authored-by: Shaojin Wen <shaojin.wensj@alibaba-inc.com>
Co-authored-by: qwen-code-dev-bot <qwen-code-dev@service.alibaba.com>
Co-authored-by: qwen-code-dev-bot <qwen-code-dev-bot@users.noreply.github.com>
* add http/async/function type
* fix url error
* resolve comment
* align cc non blocking error
* fix hookRunner for async
* fix(hooks): update hook type validation to support http and function types
- Change validated hook types from ['command', 'plugin'] to ['command', 'http', 'function']
- Add validation for HTTP hooks requiring url field
- Add validation for function hooks requiring callback field
- Add comprehensive test coverage for all hook type validations
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
* fix(hooks): align SSRF protection with Claude Code behavior
- Allow 127.0.0.0/8 (loopback) for local dev hooks
- Allow localhost hostname for local dev hooks
- Allow ::1 (IPv6 loopback) for local dev hooks
- Add 100.64.0.0/10 (CGNAT) to blocked ranges (RFC 6598)
- Update tests to match Claude Code's ssrfGuard.ts behavior
This fixes HTTP hooks failing to connect to local dev servers.
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
* refactor(hooks): align HTTP hook security with Claude Code behavior
- Add CRLF/NUL sanitization for env var interpolation (header injection)
- Implement combined abort signal (external signal + timeout)
- Upgrade SSRF protection to DNS-level with ssrfGuard
- Allow loopback (127.0.0.0/8, ::1) for local dev hooks
- Block CGNAT (100.64.0.0/10) and IPv6 private ranges
- Increase default HTTP hook timeout to 10 minutes
- Fix VS Code hooks schema to support http type
- Add url, headers, allowedEnvVars, async, once, statusMessage, shell fields
- Note: "function" type is SDK-only (callback cannot be serialized to JSON)
* feat(hooks): enhance Function Hook with messages, skillRoot, shell, and matcher support
- Add MessagesProvider for automatic conversation history passing to function hooks
- Add FunctionHookContext with messages, toolUseID, and signal
- Add skillRoot support for skill-scoped session hooks
- Add shell parameter support for command hooks (bash/powershell)
- Add regex matcher support for hook pattern matching
- Add statusMessage to CommandHookConfig
- Change default function hook timeout from 60s to 5s
- Add comprehensive unit tests for all new features
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>
* add session hook for skill
* fix function hook parsing
* refactor ui for http hook/async hook/function hook
* update doc and add integration test
* change telemetryn type and refactor SSRF
* fix project level bug
---------
Co-authored-by: Qwen-Coder <qwen-coder@alibabacloud.com>