fix(review): address PR #1713 review findings

- base-commit-capture.ts: shell-quote integration branch with a real
  single-quoted POSIX literal instead of JSON.stringify (not shell-safe).
- TaskCard.tsx: memo compares full workspaceWorktrees values, not just key
  sets, so a same-key worktreePath/branch change re-renders.
- TaskDetailModal.tsx: gate/render workspace summary off hydrated workingTask.
- worktree-acquisition.ts: null the singular worktree/branch columns in the
  workspaceWorktrees write so isWorkspaceTask stays true; wrap non-fatal
  post-acquire observability so logEntry/audit can't re-escalate to fatal.
- agent-tools.ts: register sub-repo worktree via onAcquired unconditionally
  (idempotent) so a resumed/already-acquired path is tracked after restart.
- executor.ts: DB liveness fallback also checks task.workspaceWorktrees paths.
- executor-workspace.test.ts: root non-git assertion runs in fx.rootDir (".").

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
gsxdsm
2026-06-22 00:22:48 -07:00
parent d5fa8654f7
commit 9f0492e69f
7 changed files with 96 additions and 26 deletions

View File

@@ -39,10 +39,19 @@ export async function resolveCapturedBaseCommitSha(
integrationBranch: string = "main",
): Promise<string | undefined> {
const branch = integrationBranch.trim() || "main";
// Shell-quote defensively; integration branch names are normalized upstream
// but may carry slashes (e.g. "release/2026-06") that are valid in refs.
const localRef = JSON.stringify(branch);
const originRef = JSON.stringify(`origin/${branch}`);
/*
FNXC:Workspace 2026-06-22-09:00:
Shell-quote with a real single-quoted POSIX literal, NOT JSON.stringify. A
JSON double-quoted string still lets bash expand `$(...)`, backticks, and `$VAR`
inside it; JSON.stringify is not a shell-quoting function. Git ref names can't
legally contain backticks so there's no live injection path today, but
single-quoting is the idiomatic safe form and stays correct if a caller ever
passes a less-constrained string. A single quote inside the value is escaped as
the standard `'\''` close-reopen sequence.
*/
const shellSingleQuote = (value: string): string => `'${value.replace(/'/g, "'\\''")}'`;
const localRef = shellSingleQuote(branch);
const originRef = shellSingleQuote(`origin/${branch}`);
let baseCommitSha: string | undefined;
try {
const { stdout } = await execAsync(