11 Commits

Author SHA1 Message Date
roboomp a6521f07ed fix(auth): guarded config-value resolvers against case-insensitive env hijack
On Windows process.env/Bun.env lookups are case-insensitive, so the
"env var name, else literal" resolvers turned a literal /login key like
`public` (OpenCode Zen's free key) into the built-in PUBLIC=C:\Users\Public,
sending `Authorization: Bearer C:\Users\Public` and 401ing every request.

Added `$envExact` in pi-utils, which trusts an env lookup only when an
exact-case key is enumerated (the only case-preserving signal on Windows;
the getter and hasOwnProperty/getOwnPropertyDescriptor traps are all
case-insensitive there). Wired it into all three resolvers:
resolve-config-value.ts, model-registry.ts, and auth-storage.ts.

Fixes #7361
2026-08-02 06:53:18 +00:00
can1357 f13f9b1228 fix(utils): recognize underscore Bun test entrypoints 2026-08-01 20:14:39 +02:00
can1357 5b2aefe584 Merge PR #7263: fix(tui): prevent test env from suppressing interactive launch (@roboomp)
# Conflicts:
#	packages/utils/test/env.test.ts
2026-08-01 20:14:08 +02:00
roboomp 9f9c9758a1 fix(tui): prevented test env from suppressing interactive launch
Scoped test-runtime detection to explicit runner markers and Bun test entrypoints, so application NODE_ENV/BUN_ENV values no longer make ProcessTerminal headless.

Added subprocess regression coverage and propagated the private marker to test children.

Fixes #7261
2026-08-01 11:39:57 +00:00
pi3123 96a206440c Add unit tests for getDbBusyTimeoutMs 2026-07-31 20:04:30 -07:00
can1357 532e4c318c fix(utils): filter NODE_ENV dotenv files and keep escaped quotes in dotenv values
- filterChildShellEnv now also filters Bun-autoloaded .env.{NODE_ENV||development}
  entries, closing the .env.production/.env.development leak into child shells.
- parseEnvLine skips backslash-escaped quotes when locating the closing
  delimiter, restoring baseline/Bun-literal handling of values like JSON="{\"a\":1}"
  that the new parser truncated.
- Adds a parseEnvFile regression test for escaped quotes.
2026-07-28 10:58:59 +02:00
roboomp b9f1c32f69 fix(utils): parsed dotenv with bun-compatible syntax
Handled export prefixes and quote-aware inline comments when parsing dotenv files, and filtered child shells by launcher provenance so injected values are dropped regardless of value formatting.

Covered export and inline-comment forms in unit and shell-filter tests.

Fixes #6813
2026-07-27 15:37:13 +00:00
can1357 961e7c10d3 feat(utils): added isMacosMallocStackLoggingEnvName() function
- Added isMacosMallocStackLoggingEnvName() function to identify MallocStackLogging and MallocStackLoggingNoCompact variables. Updated filterProcessEnv() and Bun.env initialization to skip these variables during environment filtering. Added test case to verify malloc stack logging toggles are dropped instead of forwarded.
2026-06-12 15:46:52 +02:00
can1357 9d457f73d9 test: migrated test imports to package subpath exports
- Replaced relative `../src` imports with `@oh-my-pi/pi-ai` and `@oh-my-pi/pi-agent-core` subpaths.
2026-06-08 19:03:55 +02:00
can1357 4b6be0b0df fix(utils): preserve Windows env names with parentheses
The Bun.env scrub and filterProcessEnv used isValidEnvName (strict shell
identifier shape), which deleted standard Windows variables like
ProgramFiles(x86) and CommonProgramFiles(x86). procmgr.ts imports this
module before resolving the shell and reads Bun.env['ProgramFiles(x86)']
to find Git Bash under 32-bit Program Files, so installations that only
had Git there were no longer discovered and failed with 'No bash shell
found'.

The unsafe cases for native execve are '=' or NUL in names and NUL in
values, not parentheses. Introduce isSafeEnvName covering exactly those
cases and use it for the in-place Bun.env scrub and the spawn-env
filter. Keep isValidEnvName (strict) for dotenv parsing, where strict
shell-identifier shape is the right contract.
2026-05-17 13:43:00 +02:00
Vilmos Nebehaj 98405e16de fix(utils): ignore unsafe dotenv entries 2026-05-17 13:43:00 +02:00