Fix managed process helper command serialization
This commit is contained in:
@@ -20,7 +20,7 @@ Protocol structs live in `protocol/`. Local runtime types live in `runtime/` or
|
||||
|
||||
## Safety Rules
|
||||
|
||||
Run must enforce scoped paths and never expose raw host paths, local secrets, or unrestricted command execution to platform_web or plugins. Do not apply game-specific redaction to plugin-declared game records or SQL query rows: return those bounded typed fields faithfully through Platform channels. Supervised stdout/stderr and plugin-declared file tails are opaque verbatim channels: do not inspect, parse, filter, redact, truncate by content, normalize, correlate, transform, or special-case their payloads. Run only assigns transport metadata, spools, and forwards the exact body bytes. A plugin companion may consume its declared raw stream, parse it, and derive its own typed users or business records after receipt; Run neither performs nor repeats that plugin work. This pass-through rule does not grant plugins or the browser a direct host-path, credential, key, or socket API outside that log channel.
|
||||
Run must enforce scoped paths and never expose raw host paths, local secrets, or unrestricted command execution to platform_web or plugins. Do not apply game-specific redaction to plugin-declared game records or SQL query rows: return those bounded typed fields faithfully through Platform channels. Supervised stdout/stderr and plugin-declared file tails are opaque verbatim channels: do not inspect, parse, filter, redact, truncate by content, normalize, correlate, transform, or special-case their payloads. Run only assigns transport metadata, spools, and forwards the exact body bytes. A plugin-owned component may consume its declared raw stream, parse it, and derive its own typed users or business records after receipt; Run neither performs nor repeats that plugin work. This pass-through rule does not grant plugins or the browser a direct host-path, credential, key, or socket API outside that log channel.
|
||||
|
||||
## Generic Executor Boundary
|
||||
|
||||
|
||||
@@ -926,7 +926,7 @@ type ProcessCommand struct {
|
||||
JobID string
|
||||
Capability string
|
||||
Action string
|
||||
OutputLine func(string, string)
|
||||
OutputLine func(string, string) `json:"-"`
|
||||
}
|
||||
|
||||
type ProcessResult struct {
|
||||
|
||||
@@ -569,6 +569,22 @@ func TestOSProcessSupervisorRelaysRawCarriageReturn(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestProcessCommandJSONOmitsOutputCallback(t *testing.T) {
|
||||
body, err := json.Marshal(ProcessCommand{
|
||||
WorkDir: "/workspace",
|
||||
Args: []string{"cmd.exe", "/d", "/c", "call", "start.cmd"},
|
||||
OutputLine: func(stream string, line string) {
|
||||
panic(stream + line)
|
||||
},
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatalf("marshal process command with output callback: %v", err)
|
||||
}
|
||||
if strings.Contains(string(body), "OutputLine") || strings.Contains(string(body), "func") {
|
||||
t.Fatalf("output callback leaked into helper JSON: %s", body)
|
||||
}
|
||||
}
|
||||
|
||||
type recordingLogSink struct {
|
||||
mu sync.Mutex
|
||||
lines []string
|
||||
|
||||
Reference in New Issue
Block a user