Home

mweinbach / agent-coworker

publicmweinbach/agent-coworker
Overview Code History Branches Pull requestsIssuesInsights
main
HomeOverview Code PRsIssues

test: cover mutation TOCTOU, import normalize, and credential redaction

open
Stack 2/2
#342 opened by cursor[bot]cursor/missing-test-coverage-f6e0→main
Conversation0
cursor[bot]
Commits
0
Files changed…
opened this pull request
Author
· last week

Risky behavior now covered

  • File mutations reject sandbox read-only / no-project-write, aborted turns, mid-write content drift, and symlink path rebinds; failed late mutate gates roll back created directories.
  • Conversation import normalizes seconds-vs-millis timestamps, drops empty chat items, keeps tool errors, truncates oversized text with warnings, and keeps fingerprints stable.
  • Imported feeds get a sanitized banner, map tool errors to output-error, and count/preview only user/assistant messages.
  • Structured diagnostic payloads redact secret keys (including nested/circular graphs) and still redact standalone Bearer values under non-secret keys.
  • Partial-turn salvage prefers responseMessages on the actual error and ignores invalid provider-state shapes.
  • Backup path locks serialize same-path work, release after failures, and allow distinct paths to overlap.
  • Corrupt session DBs are quarantined by rename (the original path is gone); missing files fail closed; private dir/file modes are 0700/0600.
  • Restricted-realm sealing strips process, Bun, fetch, and require.
  • Extension sources reject blank input, non-GitHub hosts, and javascript: URLs; an existing local owner/repo path is not treated as GitHub.
  • Runtime diagnostics results reject extras, negatives, fractional counters, unknown phases, and percent > 100. Does not lock ready: true plus error.

Test files added

  • test/tools/mutationGuard.test.ts
  • test/import.conversations.normalize.test.ts
  • test/import.conversations.snapshot.test.ts
  • test/diagnostics.credentials.test.ts
  • test/session.partialTurnError.test.ts
  • test/sessionBackup.locking.test.ts
  • test/sessionDb.fileHardening.test.ts
  • test/utils.restrictedRealm.test.ts
  • test/extensions.source.test.ts
  • test/jsonrpc.runtime-diagnostics-schema-rejects.test.ts

Why this reduces regression risk

These helpers sit on write, import, backup, secret, and install paths and had no dedicated tests on main. A silent change there can overwrite the wrong file, corrupt imports, leak credentials, tear backups, or install from the wrong source. The new cases lock fail-closed behavior rather than implementation details.

Does not duplicate open coverage PRs #331–#341. Main tip is still e2d5f95e.

Validation

  • Targeted 35 tests + platform-boundary: green
  • bun run check and bun run typecheck: clean
  • Isolated targeted files are the evidence (full suite historically truncates late on this host)
Open in Web View Automation 
This branch can’t be merged automatically yet
Branch comparison failed — verify branches still exist in storage.
0 approving reviews
None yet
Checks
No checks recorded
Fast-forward
Source must contain the target branch tip
main ← cursor/missing-test-coverage-f6e0

Sign in to comment.

Stack

2/2
1

Merge readiness

Checking mergeability after the indexing worker computes the current branch state.

Autopilot

Debug

Reviews

Approved0
ReviewersNone yet

Configure an OpenRouter key in repository settings.

Update README.md

#125 mobile-fixes ← main

Updated 4 months ago

merged
2

test: cover mutation TOCTOU, import normalize, and credential redaction

#342 main ← cursor/missing-test-coverage-f6e0

Updated last week

open