Fix managed process helper command serialization
This commit is contained in:
@@ -20,7 +20,7 @@ Protocol structs live in `protocol/`. Local runtime types live in `runtime/` or
|
|||||||
|
|
||||||
## Safety Rules
|
## Safety Rules
|
||||||
|
|
||||||
Run must enforce scoped paths and never expose raw host paths, local secrets, or unrestricted command execution to platform_web or plugins. Do not apply game-specific redaction to plugin-declared game records or SQL query rows: return those bounded typed fields faithfully through Platform channels. Supervised stdout/stderr and plugin-declared file tails are opaque verbatim channels: do not inspect, parse, filter, redact, truncate by content, normalize, correlate, transform, or special-case their payloads. Run only assigns transport metadata, spools, and forwards the exact body bytes. A plugin companion may consume its declared raw stream, parse it, and derive its own typed users or business records after receipt; Run neither performs nor repeats that plugin work. This pass-through rule does not grant plugins or the browser a direct host-path, credential, key, or socket API outside that log channel.
|
Run must enforce scoped paths and never expose raw host paths, local secrets, or unrestricted command execution to platform_web or plugins. Do not apply game-specific redaction to plugin-declared game records or SQL query rows: return those bounded typed fields faithfully through Platform channels. Supervised stdout/stderr and plugin-declared file tails are opaque verbatim channels: do not inspect, parse, filter, redact, truncate by content, normalize, correlate, transform, or special-case their payloads. Run only assigns transport metadata, spools, and forwards the exact body bytes. A plugin-owned component may consume its declared raw stream, parse it, and derive its own typed users or business records after receipt; Run neither performs nor repeats that plugin work. This pass-through rule does not grant plugins or the browser a direct host-path, credential, key, or socket API outside that log channel.
|
||||||
|
|
||||||
## Generic Executor Boundary
|
## Generic Executor Boundary
|
||||||
|
|
||||||
|
|||||||
@@ -926,7 +926,7 @@ type ProcessCommand struct {
|
|||||||
JobID string
|
JobID string
|
||||||
Capability string
|
Capability string
|
||||||
Action string
|
Action string
|
||||||
OutputLine func(string, string)
|
OutputLine func(string, string) `json:"-"`
|
||||||
}
|
}
|
||||||
|
|
||||||
type ProcessResult struct {
|
type ProcessResult struct {
|
||||||
|
|||||||
@@ -569,6 +569,22 @@ func TestOSProcessSupervisorRelaysRawCarriageReturn(t *testing.T) {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func TestProcessCommandJSONOmitsOutputCallback(t *testing.T) {
|
||||||
|
body, err := json.Marshal(ProcessCommand{
|
||||||
|
WorkDir: "/workspace",
|
||||||
|
Args: []string{"cmd.exe", "/d", "/c", "call", "start.cmd"},
|
||||||
|
OutputLine: func(stream string, line string) {
|
||||||
|
panic(stream + line)
|
||||||
|
},
|
||||||
|
})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatalf("marshal process command with output callback: %v", err)
|
||||||
|
}
|
||||||
|
if strings.Contains(string(body), "OutputLine") || strings.Contains(string(body), "func") {
|
||||||
|
t.Fatalf("output callback leaked into helper JSON: %s", body)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
type recordingLogSink struct {
|
type recordingLogSink struct {
|
||||||
mu sync.Mutex
|
mu sync.Mutex
|
||||||
lines []string
|
lines []string
|
||||||
|
|||||||
Reference in New Issue
Block a user