Skip to content

test: verify installed archive imports and hostile refusals - #102

Merged
qisoft merged 2 commits into
mainfrom
test/40-installed-archive-boundary
Oct 8, 2026
Merged

qisoft merged 2 commits into
mainfrom
test/40-installed-archive-boundary

Conversation

@qisoft

@qisoft qisoft commented Oct 8, 2026 •

Copy link
Copy Markdown
Owner

Installed archive coverage previously generated an archive and reopened its Receipt, without importing it through the bundled quarantine/import service. The new explicit proof generates that archive in the ZIP executable, imports it into a fresh Library, compares retained envelope/records, and reopens the durable result.

Duplicate import, picker cancellation and eight hostile archive categories must leave hashes of every Library file unchanged. The corpus covers traversal, symlinks, name collisions, executable content, hash mismatch, unsupported versions, oversized entries and encryption. Native host assertions also preserve an external file marker and reject traversal output. Application execution uses an OS-only environment; diagnostics contain fixed stages and summary counts. Fixed archive selection exercises the module interface and does not establish native Open/Save dialog acceptance.

Validation: 79 targeted archive/service tests passed; types, lint, format, contract schemas, main build and discovery of all 24 packaged tests passed. Native execution is GitHub CI only and remains pending.

Refs #40, #61.

Summary by CodeRabbit

  • Tests
    • Expanded packaged-app verification of archive imports, covering successful imports, duplicate and cancellation handling, rejection of eight unsafe or invalid archives, and preservation of library contents after reopening.
    • Added integration coverage for archive-import behavior and unchanged library data after rejected or cancelled imports.
  • Documentation
    • Updated archive verification guidance for CI and local testing.

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 5a90173b-7f58-44da-8f3a-fd81f99ad29f
📥 Commits

Reviewing files that changed from the base of the PR and between f7b6053 and 7bc7520.

📒 Files selected for processing (2)
  • apps/desktop/src/main/packaged-sidecar-proof.ts
  • apps/desktop/src/main/sidecar-native-broker.ts

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

The packaged app now supports an archive-proof argument. The proof checks archive import, library state after duplicate, cancellation, and rejected imports, and project persistence after reopening. Fixture-based and installed-app tests verify the results. The change also updates sidecar failure diagnostics.

Changes

Archive proof journey

Layer / File(s) Summary
Archive cases and fixture
apps/desktop/src/main/packaged-archive-proof-constants.ts, tests/support/archive-proof-fixture.ts
Eight archive cases map to expected result codes. The fixture creates a signed archive and variants for traversal, links, filename collision, executable content, hash mismatch, future version, oversized declared size, and encryption.
Archive proof checks
apps/desktop/src/main/packaged-archive-proof.ts
The proof compares imported content with the archive, checks library state after duplicate, cancellation, and rejected imports, and verifies the project after reopening. It hashes regular library files and throws on special files or failed checks.
Packaged-app verification
apps/desktop/src/main/index.ts, tests/archive-proof.test.ts, tests/packaged/archives.spec.ts, docs/development/portable-project-archive.md
The packaged app runs the export proof before the archive proof when given the archive-proof argument. Tests validate proof results and installed-app behavior. The documentation describes the verification scope and platform limits.

Sidecar failure diagnostics

Layer / File(s) Summary
Capture sidecar failure details
apps/desktop/src/main/sidecar-native-broker.ts, apps/desktop/src/main/packaged-sidecar-proof.ts
Sidecar process errors include exit code and signal in their cause. The lifecycle probe records elapsed time and deadline status, and includes available exit details in diagnostics when evidence reading fails.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~25 minutes

Change: Other

Sequence Diagram(s)

sequenceDiagram
  participant PackagedApp as Packaged app
  participant Proof as runPackagedArchiveProof
  participant Import as Archive import
  participant Library as Project library
  PackagedApp->>Proof: Run archive proof with user-data directory
  Proof->>Import: Import prepared archive
  Import->>Library: Add imported project
  Proof->>Library: Check duplicate and cancellation state
  Proof->>Import: Submit configured rejection cases
  Import->>Library: Preserve state for rejected cases
  Proof->>Library: Reopen and verify project
Loading

Merge Risk: ⚪ Minimal · up to 7bc75

The sidecar probe reports child exit details on the applicable failure path. No merge-blocking behavior regression is established in the reviewed changes.

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 25.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 4 functions across 8 files. Write docstrings for the functions missing them to satisfy the coverage threshold.
✅ Passed checks (4 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly summarizes the primary change: testing installed archive imports and hostile archive refusals. It is concise and specific.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@qisoft

qisoft commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@qisoft

qisoft commented Oct 8, 2026

Copy link
Copy Markdown
Owner Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

@qisoft
qisoft merged commit b94e217 into main Oct 8, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant