Fix managed process helper command serialization

This commit is contained in:
npc0-hue
2026-09-03 01:10:49 +08:00
parent 8de49f2dd3
commit 8ac45cf999
3 changed files with 18 additions and 2 deletions
+1 -1
View File
@@ -20,7 +20,7 @@ Protocol structs live in `protocol/`. Local runtime types live in `runtime/` or
## Safety Rules ## Safety Rules
Run must enforce scoped paths and never expose raw host paths, local secrets, or unrestricted command execution to platform_web or plugins. Do not apply game-specific redaction to plugin-declared game records or SQL query rows: return those bounded typed fields faithfully through Platform channels. Supervised stdout/stderr and plugin-declared file tails are opaque verbatim channels: do not inspect, parse, filter, redact, truncate by content, normalize, correlate, transform, or special-case their payloads. Run only assigns transport metadata, spools, and forwards the exact body bytes. A plugin companion may consume its declared raw stream, parse it, and derive its own typed users or business records after receipt; Run neither performs nor repeats that plugin work. This pass-through rule does not grant plugins or the browser a direct host-path, credential, key, or socket API outside that log channel. Run must enforce scoped paths and never expose raw host paths, local secrets, or unrestricted command execution to platform_web or plugins. Do not apply game-specific redaction to plugin-declared game records or SQL query rows: return those bounded typed fields faithfully through Platform channels. Supervised stdout/stderr and plugin-declared file tails are opaque verbatim channels: do not inspect, parse, filter, redact, truncate by content, normalize, correlate, transform, or special-case their payloads. Run only assigns transport metadata, spools, and forwards the exact body bytes. A plugin-owned component may consume its declared raw stream, parse it, and derive its own typed users or business records after receipt; Run neither performs nor repeats that plugin work. This pass-through rule does not grant plugins or the browser a direct host-path, credential, key, or socket API outside that log channel.
## Generic Executor Boundary ## Generic Executor Boundary
+1 -1
View File
@@ -926,7 +926,7 @@ type ProcessCommand struct {
JobID string JobID string
Capability string Capability string
Action string Action string
OutputLine func(string, string) OutputLine func(string, string) `json:"-"`
} }
type ProcessResult struct { type ProcessResult struct {
+16
View File
@@ -569,6 +569,22 @@ func TestOSProcessSupervisorRelaysRawCarriageReturn(t *testing.T) {
} }
} }
func TestProcessCommandJSONOmitsOutputCallback(t *testing.T) {
body, err := json.Marshal(ProcessCommand{
WorkDir: "/workspace",
Args: []string{"cmd.exe", "/d", "/c", "call", "start.cmd"},
OutputLine: func(stream string, line string) {
panic(stream + line)
},
})
if err != nil {
t.Fatalf("marshal process command with output callback: %v", err)
}
if strings.Contains(string(body), "OutputLine") || strings.Contains(string(body), "func") {
t.Fatalf("output callback leaked into helper JSON: %s", body)
}
}
type recordingLogSink struct { type recordingLogSink struct {
mu sync.Mutex mu sync.Mutex
lines []string lines []string