Files
clawhub/scripts/security/run-codex-scan-worker.source-test.mjs
Vincent Koc b15bd52506 fix(security): prevent package scans from exhausting worker memory (#3393)
* fix(security): scope SkillSpector to bundled roots

* fix(security): bound bundled SkillSpector scans

* chore(security): format SkillSpector worker changes

* fix(security): import path separator for scan roots
2026-08-04 14:53:24 +08:00

28 lines
1.4 KiB
JavaScript

import assert from "node:assert/strict";
import { readFileSync } from "node:fs";
import test from "node:test";
const source = readFileSync(new URL("./run-codex-scan-worker.ts", import.meta.url), "utf8");
const functionStart = source.indexOf("async function runBundledSkillSpector(");
const functionEnd = source.indexOf("\nconst REQUIRED_CLAWHUB_RESULT_KEYS", functionStart);
const functionSource = source.slice(functionStart, functionEnd);
test("bundled SkillSpector roots share one deadline", () => {
const deadlineIndex = functionSource.indexOf(
"const deadlineMs = Date.now() + clawScanTimeoutMs();",
);
const loopIndex = functionSource.indexOf("for (const [index, scanInput]");
assert.ok(deadlineIndex >= 0, "expected a shared deadline");
assert.ok(loopIndex > deadlineIndex, "deadline must be captured before the per-root loop");
assert.match(functionSource, /const remainingMs = deadlineMs - Date\.now\(\);/);
});
test("expired budgets fail before starting another root", () => {
const expiryIndex = functionSource.indexOf("if (remainingMs <= 0)");
const commandIndex = functionSource.indexOf('await runCommand("skillspector"');
assert.ok(expiryIndex >= 0, "expected an exhausted-budget guard");
assert.ok(commandIndex > expiryIndex, "budget guard must run before SkillSpector");
assert.match(functionSource, /timeoutMs: remainingMs/);
assert.doesNotMatch(functionSource, /timeoutMs: clawScanTimeoutMs\(\)/);
});