release: git-arboretum 3.4.0 (visibilité temps réel, historisation), desktop 0.2.0 (Windows, logo), vscode 0.4.1, site 0.4.0
CI / Build & test (Node 22) (push) Successful in 11m12s
CI / Build & test (Node 24) (push) Successful in 10m14s
CI / No em/en dashes (push) Successful in 3s
Deploy site (production) / build-and-deploy (push) Successful in 19s
CI / Pack & boot smoke (Node 22) (push) Has been cancelled

Tout est additif : PROTOCOL_VERSION inchangé, aucune rupture d'API.

Temps réel réellement armé
- `pinSession` n'était appelé nulle part : une session vivante épingle désormais le watcher FS de son
  worktree (`WorktreeManager.syncSessionPin` + `resolveWorktreeForCwd`), donc un worktree où un agent
  écrit se rafraîchit même si personne ne le regarde (mesuré ~350 ms).
- Les abonnements `watch` sortent de `GitPanel`, démonté dès qu'on quitte son onglet, ce qui coupait le
  seul abonnement de toute l'app : `composables/useWatchedWorktrees.ts` (monté dans App.vue) suit le
  worktree actif et les dépôts dépliés, borné à 40.
- Une coupure WS ne laisse plus l'UI sur des listes périmées : rechargement complet au retour.
- `worktree_changes` alimente `worktrees.changeVersion`, consommé par l'arbre de fichiers, le diff
  (son `:version` était câblé à 0) et l'éditeur, qui recharge un tampon propre ou lève la bannière de
  conflit avant la sauvegarde au lieu d'attendre le 409.

Corrélation session ↔ worktree par contenance (`@arboretum/shared/path-match.ts`)
- Un terminal lancé dans un sous-répertoire (« Démarrer le projet ») ou une session de groupe reliée
  par `--add-dir` apparaissent enfin sous leur worktree ; le worktree le plus spécifique gagne.
- Règle unique partagée par le daemon, le web et l'extension.

Historisation
- `commitLog` / `commitDiff` purs, `GET /repos/:id/worktrees/log` et `diff?commit=` (hash strictement
  validé, mêmes bornes que les diffs de fichiers).
- `CommitHistory.vue` sous le panneau Git : commits, marquage des non poussés, diff déplié sur place.

Visibilité
- Compteurs git complets sur chaque worktree de l'arbre et du panneau Groupes (ils n'existaient qu'en
  barre de statut, pour le seul worktree actif), avec upstream et dernier commit en infobulle ;
  `locked`, `prunable` et un dépôt invalide sont désormais visibles.
- Le panneau Groupes montre sa composition réelle (dépôts, worktrees, sessions) et teinte l'explorateur.

Polish visuel
- Les toasts d'erreur, persistants, s'empilaient derrière les modals : téléportés au-dessus.
- Sur mobile, ouvrir un terminal ou changer d'activité n'avait aucun effet visible.
- Tailles de panneaux clampées sur la fenêtre, barres d'onglets sans scrollbar parasite, états de
  chargement et d'erreur dans les trois panneaux, accessibilité des 11 modals centralisée dans
  ModalHost, splitters au clavier, numéros de diff collants, `window.confirm` remplacé.

Windows (daemon et packaging)
- `where.exe`, PowerShell comme shell de lancement, askpass `.cmd` (clone/push HTTPS par PAT),
  `taskkill /T`, `%APPDATA%`, `arboretum install` via tâche planifiée.
- Scripts de build exécutables sur un hôte Windows (`npm.cmd`, extraction sans `unzip` ni `bash`).
- Job CI `windows-latest` conditionné par ENABLE_WINDOWS_BUILD ; procédure runner dans docs/CI_RUNNERS.md.

Logo Debian : cause racine
- Une icône unique de 895×895 atterrissait dans `hicolor/895x895`, répertoire absent d'`index.theme`
  donc ignoré par la spécification freedesktop ; et `executableName` dérivait du nom scopé du paquet
  (`@arboretumdesktop`). Jeu d'icônes standard généré + `executableName: arboretum`, plus
  `deb.synopsis` (description courte vide dans apt) et `Section: devel`.
- Runtime Node embarqué élagué : 205 → 118 Mo.
- Auto-update réparé : la release flottante `desktop-latest` que les binaires interrogent n'existait pas.

Doc et vitrine
- README/README.fr : installation par plateforme, mode serveur web (nginx, LAN), dépannage, variables
  d'environnement, flags manquants.
- Doc in-app réécrite (elle renvoyait aux pages Worktrees et Sessions supprimées).
- Section « Accès distant » dans les Réglages ; le 403 BAD_ORIGIN nomme le flag à ajouter.
- Site : prérequis et registre npm privé (le `npx` affiché renvoyait un 404), téléchargements réels par
  plateforme, section « trois façons de l'utiliser », navigation complétée, 16 clés i18n mortes purgées.

Vérifications : 483 tests unitaires, 14 acceptances E2E vertes (dont p14/p15 nouvelles), captures de
rendu sans erreur console (nouveau `verify-ui.mjs`), .deb reconstruit et contrôlé (icônes aux tailles
standard, entrée .desktop valide).
This commit is contained in:
2026-08-04 13:02:11 +02:00
parent a7e04278fd
commit 63f2697745
127 changed files with 4232 additions and 577 deletions
+38
View File
@@ -3,6 +3,44 @@
Notable changes to `@johanleroy/git-arboretum` (the Arboretum daemon). The VS Code
extension keeps its own changelog in `packages/vscode/CHANGELOG.md`.
## 3.4.0
Visibility release: the real-time machinery is now actually armed, worktrees show what they are worth,
and history is served. Fully additive, no protocol version bump.
- **Real-time that no longer depends on which panel is open.** A live session now pins the FS watcher of
its worktree, so a worktree an agent is writing into refreshes on its own even when nobody is looking at
it (`pinSession` existed but was never called). On the client side, `watch` subscriptions moved out of
the Git panel, which was unmounted as soon as you left its tab, taking the app's only subscription with
it; they now follow what you actually look at (active worktree plus expanded repositories).
- **Reconnection no longer loses state.** The protocol replays nothing, so every event missed during a
WebSocket outage was lost for good. The client reloads repos, worktrees, sessions and settings whenever
the connection comes back.
- **Session correlation by containment.** A terminal started in a *subdirectory* of a worktree (which
"Start the project" allows) and a group session covering a worktree through `--add-dir` are now listed
under that worktree, instead of vanishing from the tree. The rule lives in `@arboretum/shared`, shared by
the daemon, the web UI and the VS Code extension; the most specific worktree wins.
- **History API.** `GET /api/v1/repos/:id/worktrees/log` serves the branch commits with the count of
unpushed ones, and `GET .../worktrees/diff?commit=<hash>` the full diff of a commit (hash strictly
validated, same size limits as file diffs). The UI unfolds them in place under the Git panel.
- **Full git counters where they matter.** `ahead`/`behind`, staged, unstaged and conflict counts were
only visible in the status bar, for the active worktree. They are now on every worktree row of the tree
and of the Groups panel, with upstream and last commit in the tooltip. `locked`, `prunable` and an
invalid repository are surfaced too.
- **Groups show their composition.** A group lists its repositories with their worktrees and git state,
its sessions (live and recent) and the directories a group session spans. Its colour tints those repos
in the explorer.
- **Actionable `403 BAD_ORIGIN`.** The error now names the exact `--allow-origin` flag to add, and logs
it. It is the first wall of any LAN or reverse-proxy access.
- **Windows support in the daemon.** `where.exe` for CLI discovery, PowerShell as the project launch
shell, a `.cmd` askpass so token-based HTTPS clone/push works, `taskkill /T` for process-tree
termination, `%APPDATA%` for the data directory, and `arboretum install` registering a scheduled task.
- **UI fixes.** Error toasts were painted behind modals (they are sticky, so they piled up invisible);
on mobile, opening a terminal or switching activity had no visible effect; the dock could push the
status bar out of the viewport; panels showed "nothing here" instead of a loading or error state;
modals had no dialog role, focus trap or focus restore; the splitters are now keyboard operable; diff
line numbers stay pinned while scrolling.
## 3.3.0
"Start the project": boot a project's long-running commands (dev server, API, database) in one click. Fully additive, no protocol or API change.
+2 -2
View File
@@ -1,7 +1,7 @@
{
"name": "@johanleroy/git-arboretum",
"version": "3.3.0",
"description": "Self-hosted web dashboard for git worktrees and the Claude Code sessions running on them",
"version": "3.4.0",
"description": "Self-hosted multi-project AI IDE for git worktrees and the Claude Code sessions running on them",
"license": "MIT",
"type": "module",
"author": "Johan LEROY <contact@johanleroy.fr>",
+174
View File
@@ -0,0 +1,174 @@
#!/usr/bin/env node
// Acceptation P14 (sans navigateur, sans quota Claude) : temps réel « armé ». Vrai daemon + vrai repo
// git tmp + vrai client WS. Couvre les trois trous de visibilité corrigés :
// 1. une session vivante épingle le watcher FS de SON worktree → les compteurs git d'un worktree
// secondaire restent temps réel même si AUCUN client ne le regarde (avant : point « modifié » figé
// sur le dernier listing REST) ;
// 2. corrélation par contenance : un terminal lancé dans un SOUS-répertoire du worktree y est
// rattaché (« Démarrer le projet »), et pas au checkout principal ;
// 3. `watch` explicite → `worktree_changes` ciblé sur ce worktree secondaire.
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, rmSync, writeFileSync, mkdirSync, appendFileSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
import { createRequire } from 'node:module';
const require = createRequire(import.meta.url);
const WebSocket = require('ws');
const PORT = 7554;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p14-'));
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
mkdirSync(join(repo, 'packages', 'api'), { recursive: true });
writeFileSync(join(repo, 'README.md'), '# demo\n');
writeFileSync(join(repo, 'packages', 'api', 'index.js'), 'console.log(1)\n');
git('add', '-A');
git('commit', '-m', 'init');
const srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
function wsClient(cookie) {
const ws = new WebSocket(`ws://127.0.0.1:${PORT}/ws`, { headers: { Origin: ORIGIN, Cookie: cookie } });
const state = { msgs: [] };
ws.on('message', (data, isBinary) => {
if (!isBinary) state.msgs.push(JSON.parse(String(data)));
});
const waitMsg = async (pred, timeout = 8000) => {
const t0 = Date.now();
while (Date.now() - t0 < timeout) {
const m = state.msgs.find(pred);
if (m) return m;
await sleep(50);
}
return null;
};
return { ws, state, waitMsg, send: (m) => ws.send(JSON.stringify(m)) };
}
const j = (path, method, cookie, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
try {
await sleep(1500);
const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0];
check('boot + token bootstrap', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? '';
check('login → cookie', login.status === 200);
const c = wsClient(cookie);
await new Promise((res, rej) => (c.ws.on('open', res), c.ws.on('error', rej)));
c.send({ type: 'hello', protocol: 1 });
await c.waitMsg((m) => m.type === 'hello_ok');
c.send({ type: 'sub', topics: ['worktrees', 'sessions'] });
const addRepo = await j('/api/v1/repos', 'POST', cookie, { path: repo });
const repoId = (await addRepo.json()).repo.id;
check('POST /repos → 201', addRepo.status === 201 && !!repoId);
// ---- worktree secondaire (feature) avec un sous-répertoire ----
const created = await j(`/api/v1/repos/${repoId}/worktrees`, 'POST', cookie, { branch: 'feature/live', runHooks: false });
const wtPath = (await created.json()).worktree?.path;
check('POST /worktrees → worktree secondaire créé', created.status === 201 && !!wtPath);
const subDir = join(wtPath, 'packages', 'api');
// ---- 2. corrélation par contenance : session lancée DANS un sous-répertoire ----
const sess = await j('/api/v1/sessions', 'POST', cookie, { cwd: subDir, command: 'bash' });
const session = (await sess.json()).session;
check('POST /sessions (cwd = sous-répertoire) → 201', sess.status === 201 && !!session?.id);
await sleep(600);
const list = await (await j('/api/v1/worktrees', 'GET', cookie)).json();
const secondary = (list.worktrees ?? []).find((w) => w.path === wtPath);
const main = (list.worktrees ?? []).find((w) => w.isMain);
check(
'la session du sous-répertoire est rattachée au worktree secondaire',
(secondary?.sessions ?? []).some((s) => s.id === session.id),
`sessions=${(secondary?.sessions ?? []).length}`,
);
check(
'elle n’est PAS rattachée au checkout principal (désambiguïsation)',
!(main?.sessions ?? []).some((s) => s.id === session.id),
);
// ---- 1. session vivante → watcher épinglé SANS aucun watch client ----
// Aucun `watch` n'a été envoyé : seul `pinSession` peut produire cet événement.
await sleep(900); // laisse chokidar finir son scan initial
c.state.msgs.length = 0;
const t0 = Date.now();
appendFileSync(join(wtPath, 'README.md'), 'edited by the agent\n');
const upd = await c.waitMsg((m) => m.type === 'worktree_update' && m.worktree?.path === wtPath && m.worktree?.git?.dirtyCount > 0, 6000);
check('worktree secondaire non regardé : worktree_update reçu (pinSession)', !!upd, upd ? `${Date.now() - t0}ms` : 'timeout');
check('les compteurs git du worktree secondaire sont frais', (upd?.worktree?.git?.unstagedCount ?? 0) >= 1);
// ---- pas de worktree_changes sans watch (le détail reste ciblé) ----
const changesWithoutWatch = c.state.msgs.find((m) => m.type === 'worktree_changes');
check('sans watch : aucun worktree_changes (push ciblé préservé)', !changesWithoutWatch);
// ---- 3. watch explicite → worktree_changes ciblé ----
c.send({ type: 'watch', repoId, path: wtPath });
await sleep(900);
c.state.msgs.length = 0;
writeFileSync(join(wtPath, 'live.txt'), 'live\n');
const changesMsg = await c.waitMsg((m) => m.type === 'worktree_changes' && m.path === wtPath, 6000);
check('watch → worktree_changes ciblé sur le worktree secondaire', !!changesMsg);
c.send({ type: 'unwatch', repoId, path: wtPath });
await j(`/api/v1/sessions/${session.id}`, 'DELETE', cookie);
await sleep(500);
// ---- contraposée : le temps réel reste PILOTÉ (ni session, ni watch → pas de surveillance) ----
// Un watcher déjà ouvert est volontairement conservé en cache (évincé par la LRU) : on vérifie donc
// sur un worktree neuf, jamais épinglé ni regardé, qu'aucun événement n'est émis.
const idle = await j(`/api/v1/repos/${repoId}/worktrees`, 'POST', cookie, { branch: 'feature/idle', runHooks: false });
const idlePath = (await idle.json()).worktree?.path;
check('POST /worktrees → second worktree (sans session)', idle.status === 201 && !!idlePath);
await sleep(700);
c.state.msgs.length = 0;
writeFileSync(join(idlePath, 'unwatched.txt'), 'x\n');
const idleMsg = await c.waitMsg((m) => m.type === 'worktree_update' && m.worktree?.path === idlePath, 2500);
check('worktree sans session ni watch → aucune surveillance (coût piloté par l’attention)', !idleMsg);
c.ws.close();
} catch (err) {
check('exception', false, String(err));
} finally {
srv.kill('SIGTERM');
await sleep(1500);
check('arrêt propre du daemon (SIGTERM)', srv.exitCode === 0 || srv.signalCode === null || srv.exitCode === null);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? '\nACCEPTANCE P14: ALL GREEN' : `\nACCEPTANCE P14: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
+117
View File
@@ -0,0 +1,117 @@
#!/usr/bin/env node
// Acceptation P15 (sans navigateur, sans quota Claude) : historisation. Vrai daemon + vrai repo git
// tmp. Couvre GET /worktrees/log (ordre, champs, limit/skip, marquage non poussé) et la forme
// `diff?commit=` (diff unifié complet d'un commit, hash invalide et inconnu rejetés).
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, rmSync, writeFileSync, appendFileSync, mkdirSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname } from 'node:path';
import { fileURLToPath } from 'node:url';
const PORT = 7555;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
const tmp = mkdtempSync(join(tmpdir(), 'arb-accept-p15-'));
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
writeFileSync(join(repo, 'README.md'), '# demo\n');
git('add', '-A');
git('commit', '-m', 'init');
// un sujet contenant un guillemet et un caractère accentué : piège classique de parsing
appendFileSync(join(repo, 'README.md'), 'deuxième ligne\n');
git('commit', '-am', 'ajoute la « deuxième » ligne');
writeFileSync(join(repo, 'feature.txt'), 'contenu de la feature\n');
git('add', '-A');
git('commit', '-m', 'ajoute feature.txt');
const srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 'a.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
const j = (path, method, cookie, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: cookie, ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
try {
await sleep(1500);
const token = /arb_[0-9a-f]+/.exec(srvOut)?.[0];
check('boot + token bootstrap', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const cookie = login.headers.get('set-cookie')?.split(';')[0] ?? '';
check('login → cookie', login.status === 200);
const addRepo = await j('/api/v1/repos', 'POST', cookie, { path: repo });
const repoId = (await addRepo.json()).repo.id;
check('POST /repos → 201', addRepo.status === 201 && !!repoId);
const enc = encodeURIComponent(repo);
// ---- GET /log : ordre, champs, sujet non trivial ----
const log = await (await j(`/api/v1/repos/${repoId}/worktrees/log?path=${enc}`, 'GET', cookie)).json();
const subjects = (log.commits ?? []).map((c) => c.subject);
check('GET /log : 3 commits, du plus récent au plus ancien', subjects.length === 3 && subjects[0] === 'ajoute feature.txt' && subjects[2] === 'init');
check('GET /log : sujet accentué et guillemets préservés', subjects[1] === 'ajoute la « deuxième » ligne');
const head = log.commits?.[0];
check('GET /log : champs hash/shortHash/auteur/date remplis', /^[0-9a-f]{40}$/.test(head?.hash ?? '') && (head?.shortHash?.length ?? 0) >= 7 && head?.author === 'Test' && !Number.isNaN(Date.parse(head?.date ?? '')));
check('GET /log : branche locale sans remote → hasUpstream=false', log.hasUpstream === false && log.unpushedCount === 0);
// ---- limit / skip ----
const page = await (await j(`/api/v1/repos/${repoId}/worktrees/log?path=${enc}&limit=1&skip=1`, 'GET', cookie)).json();
check('GET /log : limit + skip bornent la fenêtre', page.commits?.length === 1 && page.commits[0].subject === 'ajoute la « deuxième » ligne');
const bad = await j(`/api/v1/repos/${repoId}/worktrees/log?path=${enc}&limit=abc`, 'GET', cookie);
check('GET /log : limit non numérique → 400', bad.status === 400);
const noPath = await j(`/api/v1/repos/${repoId}/worktrees/log`, 'GET', cookie);
check('GET /log : path manquant → 400', noPath.status === 400);
// ---- diff d'un commit ----
const cd = await (await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=${head.hash}`, 'GET', cookie)).json();
check('GET /diff?commit= : diff unifié du commit', typeof cd.diff === 'string' && cd.diff.includes('feature.txt') && cd.diff.includes('+contenu de la feature'));
check('GET /diff?commit= : ni binaire ni tronqué', cd.binary === false && cd.tooLarge === false);
const shortHash = await (await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=${head.shortHash}`, 'GET', cookie)).json();
check('GET /diff?commit= : hash court accepté', typeof shortHash.diff === 'string' && shortHash.diff.includes('feature.txt'));
const invalid = await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=${encodeURIComponent('--upload-pack=x')}`, 'GET', cookie);
check('GET /diff?commit= : révision non hexadécimale refusée', invalid.status === 400);
const unknown = await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&commit=deadbeef`, 'GET', cookie);
check('GET /diff?commit= : commit inconnu → 404', unknown.status === 404);
const neither = await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}`, 'GET', cookie);
check('GET /diff : ni file ni commit → 400', neither.status === 400);
// ---- la forme fichier reste intacte (non-régression P7/P9) ----
appendFileSync(join(repo, 'README.md'), 'travail en cours\n');
const fileDiff = await (await j(`/api/v1/repos/${repoId}/worktrees/diff?path=${enc}&file=README.md`, 'GET', cookie)).json();
check('GET /diff?file= : toujours fonctionnel', typeof fileDiff.diff === 'string' && fileDiff.diff.includes('+travail en cours'));
} catch (err) {
check('exception', false, String(err));
} finally {
srv.kill('SIGTERM');
await sleep(1500);
check('arrêt propre du daemon (SIGTERM)', srv.exitCode === 0 || srv.signalCode === null || srv.exitCode === null);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? '\nACCEPTANCE P15: ALL GREEN' : `\nACCEPTANCE P15: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
+232
View File
@@ -0,0 +1,232 @@
#!/usr/bin/env node
// Vérification VISUELLE de la SPA authentifiée, sans Playwright : daemon temporaire isolé + Chromium
// headless piloté en CDP + cookie de session injecté. Produit des captures PNG (thème sombre et clair,
// largeurs desktop et mobile) et échoue si une erreur console / exception Vue survient.
//
// Usage : node packages/server/scripts/verify-ui.mjs [dossier-de-sortie]
// Prérequis : `npm run build` puis `node packages/server/scripts/copy-web.mjs` (le daemon sert la SPA
// depuis packages/server/public, que le build NE rafraîchit PAS).
import { spawn, execFileSync } from 'node:child_process';
import { mkdtempSync, mkdirSync, rmSync, writeFileSync, existsSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join, dirname, resolve as resolvePath } from 'node:path';
import { fileURLToPath } from 'node:url';
import { createRequire } from 'node:module';
const require = createRequire(import.meta.url);
const WebSocket = require('ws');
const PORT = 7998;
const CDP_PORT = 9333;
const ORIGIN = `http://127.0.0.1:${PORT}`;
const serverDir = join(dirname(fileURLToPath(import.meta.url)), '..');
const outDir = resolvePath(process.argv[2] ?? join(serverDir, '..', '..', '.ui-shots'));
const sleep = (ms) => new Promise((r) => setTimeout(r, ms));
const results = [];
const check = (name, ok, detail = '') => {
results.push({ name, ok, detail });
console.log(`${ok ? '✅' : '❌'} ${name}${detail ? `: ${detail}` : ''}`);
};
function findChromium() {
for (const bin of ['chromium', 'chromium-browser', 'google-chrome', 'google-chrome-stable']) {
try {
return execFileSync('which', [bin]).toString().trim();
} catch {
/* essai suivant */
}
}
return null;
}
/** Client CDP minimal : un seul socket, corrélation par id, sessionId pour la cible attachée. */
function cdp(url) {
const ws = new WebSocket(url, { perMessageDeflate: false, maxPayload: 256 * 1024 * 1024 });
let nextId = 1;
const pending = new Map();
const events = [];
ws.on('message', (raw) => {
const msg = JSON.parse(String(raw));
if (msg.id && pending.has(msg.id)) {
const { resolve, reject } = pending.get(msg.id);
pending.delete(msg.id);
msg.error ? reject(new Error(JSON.stringify(msg.error))) : resolve(msg.result);
return;
}
if (msg.method) events.push(msg);
});
const ready = new Promise((res, rej) => (ws.on('open', res), ws.on('error', rej)));
const send = (method, params = {}, sessionId) =>
new Promise((resolve, reject) => {
const id = nextId++;
pending.set(id, { resolve, reject });
ws.send(JSON.stringify({ id, method, params, ...(sessionId ? { sessionId } : {}) }));
setTimeout(() => pending.has(id) && (pending.delete(id), reject(new Error(`CDP timeout: ${method}`))), 30_000);
});
return { ws, ready, send, events };
}
const tmp = mkdtempSync(join(tmpdir(), 'arb-verify-ui-'));
mkdirSync(outDir, { recursive: true });
let srv = null;
let browser = null;
try {
// La SPA servie vient de packages/server/public : garde-fou contre la vérification d'un ancien build.
const publicIndex = join(serverDir, 'public', 'index.html');
check('SPA copiée dans packages/server/public', existsSync(publicIndex), publicIndex);
// --- dépôt de démonstration : un checkout principal, un worktree de feature, du travail en cours ---
const repo = join(tmp, 'demo-repo');
mkdirSync(repo, { recursive: true });
const git = (...args) => execFileSync('git', args, { cwd: repo, stdio: 'pipe' });
git('init', '-b', 'main');
git('config', 'user.email', 'test@arboretum.dev');
git('config', 'user.name', 'Test');
writeFileSync(join(repo, 'README.md'), '# demo\n');
mkdirSync(join(repo, 'src'), { recursive: true });
writeFileSync(join(repo, 'src', 'app.ts'), 'export const version = 1\n');
git('add', '-A');
git('commit', '-m', 'commit initial');
writeFileSync(join(repo, 'src', 'app.ts'), 'export const version = 2\n');
srv = spawn(
'node',
[join(serverDir, 'dist', 'index.js'), '--port', String(PORT), '--db', join(tmp, 't.db'), '--claude-home', join(tmp, 'claude'), '--no-discover'],
{ env: { ...process.env, XDG_DATA_HOME: join(tmp, 'xdg'), ARBORETUM_LOG: 'warn' }, stdio: ['ignore', 'pipe', 'pipe'] },
);
let srvOut = '';
srv.stdout.on('data', (d) => (srvOut += d));
srv.stderr.on('data', (d) => (srvOut += d));
for (let i = 0; i < 60 && !/arb_[0-9a-f]{16,}/.test(srvOut); i++) await sleep(150);
const token = /arb_[0-9a-f]{16,}/.exec(srvOut)?.[0];
check('daemon temporaire démarré + token', !!token);
const login = await fetch(`${ORIGIN}/api/v1/auth/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json', Origin: ORIGIN },
body: JSON.stringify({ token }),
});
const setCookie = login.headers.getSetCookie?.() ?? [];
const sessionCookie = setCookie.map((c) => c.split(';')[0]).find((c) => c.startsWith('arb_session='));
check('login → cookie de session', !!sessionCookie);
const cookieValue = sessionCookie?.slice('arb_session='.length) ?? '';
const j = (path, method, body) =>
fetch(`${ORIGIN}${path}`, {
method,
headers: { Origin: ORIGIN, Cookie: sessionCookie ?? '', ...(body ? { 'Content-Type': 'application/json' } : {}) },
...(body ? { body: JSON.stringify(body) } : {}),
});
const repoId = (await (await j('/api/v1/repos', 'POST', { path: repo })).json()).repo?.id;
check('dépôt de démonstration enregistré', !!repoId);
const wtRes = await (await j(`/api/v1/repos/${repoId}/worktrees`, 'POST', { branch: 'feature/demo', runHooks: false })).json();
check('worktree de feature créé', !!wtRes.worktree?.path);
// du travail non commité dans le worktree de feature, pour peupler les compteurs git de l'arbre
if (wtRes.worktree?.path) writeFileSync(join(wtRes.worktree.path, 'wip.txt'), 'travail en cours\n');
const groupRes = await (await j('/api/v1/groups', 'POST', { label: 'Démo', color: '#34d399', repoIds: [repoId] })).json();
check('groupe de démonstration créé', !!groupRes.group?.id);
const sess = await (await j('/api/v1/sessions', 'POST', { cwd: repo, command: 'bash' })).json();
check('session bash de démonstration', !!sess.session?.id);
// --- Chromium headless en CDP ---
const chromeBin = findChromium();
check('Chromium disponible', !!chromeBin, chromeBin ?? 'introuvable');
if (!chromeBin) throw new Error('Chromium introuvable : impossible de vérifier le rendu');
browser = spawn(
chromeBin,
[
'--headless=new',
`--remote-debugging-port=${CDP_PORT}`,
`--user-data-dir=${join(tmp, 'chrome')}`,
'--no-first-run',
'--no-default-browser-check',
'--disable-gpu',
'--hide-scrollbars',
],
{ stdio: ['ignore', 'pipe', 'pipe'] },
);
let wsUrl = null;
for (let i = 0; i < 80 && !wsUrl; i++) {
await sleep(200);
try {
wsUrl = (await (await fetch(`http://127.0.0.1:${CDP_PORT}/json/version`)).json()).webSocketDebuggerUrl;
} catch {
/* pas encore prêt */
}
}
check('Chromium en écoute CDP', !!wsUrl);
const client = cdp(wsUrl);
await client.ready;
// État de vue injecté avant le premier paint : on veut des captures qui MONTRENT le contenu
// (arbre déplié, worktree actif), pas un IDE vide.
const expanded = JSON.stringify(JSON.stringify([repoId]));
const context = JSON.stringify(JSON.stringify({ repoId, wtPath: repo }));
const seedExplorer = `localStorage.setItem('arb.ide.expandedRepos', ${expanded});localStorage.setItem('arb.ide.context', ${context});`;
const seedGit = `${seedExplorer}localStorage.setItem('arb.ide.activity', '"git"');localStorage.setItem('arb.history.open', 'true');`;
const shots = [
{ name: 'ide-dark-desktop', theme: 'dark', width: 1440, height: 900, seed: seedExplorer },
{ name: 'ide-light-desktop', theme: 'light', width: 1440, height: 900, seed: seedExplorer },
{ name: 'git-dark-desktop', theme: 'dark', width: 1440, height: 900, seed: seedGit },
{ name: 'git-light-desktop', theme: 'light', width: 1440, height: 900, seed: seedGit },
{ name: 'ide-dark-mobile', theme: 'dark', width: 390, height: 844, seed: seedExplorer },
{ name: 'ide-light-mobile', theme: 'light', width: 390, height: 844, seed: seedExplorer },
{ name: 'dashboard-dark-mobile', theme: 'dark', width: 390, height: 844, path: '/dashboard' },
];
for (const shot of shots) {
const { targetId } = await client.send('Target.createTarget', { url: 'about:blank' });
const { sessionId } = await client.send('Target.attachToTarget', { targetId, flatten: true });
await client.send('Runtime.enable', {}, sessionId);
await client.send('Log.enable', {}, sessionId);
await client.send('Network.enable', {}, sessionId);
await client.send('Emulation.setDeviceMetricsOverride', { width: shot.width, height: shot.height, deviceScaleFactor: 1, mobile: shot.width < 500 }, sessionId);
await client.send('Network.setCookie', { name: 'arb_session', value: cookieValue, domain: '127.0.0.1', path: '/', httpOnly: true }, sessionId);
// Thème : la SPA lit `arb.theme` avant le premier paint (script anti-FOUC).
await client.send('Page.enable', {}, sessionId);
await client.send(
'Page.addScriptToEvaluateOnNewDocument',
{ source: `localStorage.setItem('arb.theme', ${JSON.stringify(JSON.stringify(shot.theme))});${shot.seed ?? ''}` },
sessionId,
);
const before = client.events.length;
await client.send('Page.navigate', { url: `${ORIGIN}${shot.path ?? '/ide'}` }, sessionId);
await sleep(3500); // laisse le temps au bootstrap REST + WS et au rendu
const text = await client.send('Runtime.evaluate', { expression: 'document.body.innerText', returnByValue: true }, sessionId);
const rendered = String(text.result?.value ?? '');
check(`${shot.name} : page rendue`, rendered.length > 20, `${rendered.length} caractères`);
const errs = client.events
.slice(before)
.filter((e) => e.sessionId === sessionId)
.filter((e) => (e.method === 'Runtime.consoleAPICalled' && e.params?.type === 'error') || e.method === 'Runtime.exceptionThrown')
.map((e) => e.params?.exceptionDetails?.text ?? (e.params?.args ?? []).map((a) => a.value ?? a.description).join(' '))
// Les erreurs réseau des favicons/manifest en headless ne concernent pas l'app.
.filter((m) => m && !/favicon|manifest\.webmanifest/i.test(m));
check(`${shot.name} : aucune erreur console`, errs.length === 0, errs.slice(0, 3).join(' | '));
const { data } = await client.send('Page.captureScreenshot', { format: 'png', captureBeyondViewport: false }, sessionId);
const file = join(outDir, `${shot.name}.png`);
writeFileSync(file, Buffer.from(data, 'base64'));
check(`${shot.name} : capture écrite`, true, file);
await client.send('Target.closeTarget', { targetId });
}
client.ws.close();
} catch (err) {
check('exception', false, String(err));
} finally {
browser?.kill('SIGTERM');
srv?.kill('SIGTERM');
await sleep(1200);
rmSync(tmp, { recursive: true, force: true });
const failed = results.filter((r) => !r.ok);
console.log(failed.length === 0 ? `\nVERIFY UI: ALL GREEN (captures dans ${outDir})` : `\nVERIFY UI: ${failed.length} FAILURE(S)`);
process.exit(failed.length === 0 ? 0 : 1);
}
+6 -1
View File
@@ -183,7 +183,12 @@ export function buildApp(config: Config, db: Db, serverVersion: string): AppBund
if (!isApi && !isWs) return; // statique : public (la SPA gère son écran de login)
const origin = req.headers.origin;
if (origin && !allowedOrigins.has(origin)) {
return reply.status(403).send({ error: { code: 'BAD_ORIGIN', message: `Origin not allowed: ${origin}` } });
// Message ACTIONNABLE : c'est le premier mur de tout accès non-loopback (LAN, reverse proxy,
// Tailscale). Un « Origin not allowed » sec laissait chercher pendant des heures, alors que la
// correction tient en un flag. Le log serveur porte la même consigne.
const hint = `Origin not allowed: ${origin}. Restart the daemon with --allow-origin ${origin} (repeatable) to permit it.`;
req.log.warn({ origin, allowed: [...allowedOrigins] }, hint);
return reply.status(403).send({ error: { code: 'BAD_ORIGIN', message: hint } });
}
req.authContext = authenticate(req);
if (req.routeOptions.config.public) return;
+53 -6
View File
@@ -12,7 +12,7 @@ import { AuthService } from '../auth/service.js';
const SERVICE_NAME = 'arboretum';
const LAUNCHD_LABEL = 'fr.lidge.arboretum';
export type SupportedPlatform = 'linux' | 'darwin';
export type SupportedPlatform = 'linux' | 'darwin' | 'win32';
export interface InstallFlags {
port?: string | undefined;
@@ -29,15 +29,31 @@ export interface InstallFlags {
// ─── Fonctions pures (génération de contenu / chemins) ────────────────────────────────
/** macOS (launchd) et Linux (systemd) uniquement ; sinon throw avec un message pédagogique. */
/**
* Superviseur par plateforme : systemd (Linux), launchd (macOS), Planificateur de tâches (Windows).
* Toujours en tant qu'utilisateur, jamais en root/SYSTEM.
*/
export function detectPlatform(platform: NodeJS.Platform = process.platform): SupportedPlatform {
if (platform === 'linux' || platform === 'darwin') return platform;
if (platform === 'linux' || platform === 'darwin' || platform === 'win32') return platform;
throw new Error(
`Automatic service installation is supported on Linux (systemd) and macOS (launchd) only.\n` +
`On ${platform}, run \`arboretum\` manually or set up your own supervisor.`,
`Automatic service installation is supported on Linux (systemd), macOS (launchd) and Windows ` +
`(Task Scheduler) only.\nOn ${platform}, run \`arboretum\` manually or set up your own supervisor.`,
);
}
/** Nom de la tâche planifiée Windows (visible dans taskschd.msc). */
export const WINDOWS_TASK_NAME = 'Arboretum';
/**
* Arguments `schtasks /Create` d'une tâche « au démarrage de session utilisateur ». `/RL LIMITED`
* garde les privilèges de l'utilisateur (jamais d'élévation), `/F` rend la commande idempotente.
* `/TR` attend UNE chaîne de commande : chaque token à espaces est donc quoté.
*/
export function windowsCreateArgs(input: { taskName: string; exec: string; scriptArgs: string[] }): string[] {
const command = [input.exec, ...input.scriptArgs].map(quoteIfNeeded).join(' ');
return ['/Create', '/TN', input.taskName, '/TR', command, '/SC', 'ONLOGON', '/RL', 'LIMITED', '/F'];
}
export function parseInstallArgs(argv: string[]): InstallFlags {
const { values } = parseArgs({
args: argv,
@@ -207,7 +223,8 @@ export function printUsage(version: string): void {
Usage:
arboretum [flags] Start the daemon (default)
arboretum serve [flags] Start the daemon (explicit alias)
arboretum install [flags] Install & start a user service (systemd on Linux, launchd on macOS)
arboretum install [flags] Install & start a user service (systemd on Linux, launchd on macOS,
Task Scheduler on Windows)
arboretum uninstall Stop & remove the user service
arboretum status Show the service status
arboretum help Show this help
@@ -218,6 +235,9 @@ Daemon flags:
--allow-origin <url> Additional allowed Origin (repeatable)
--db <path> SQLite database path
--vapid-contact <mailto|url> VAPID contact subject for Web Push
--claude-home <path> Override the Claude install root (default ~/.claude)
--print-token Print the access token on start (bootstrap it if missing)
--no-discover Disable repository auto-discovery (startup + periodic scan)
--i-know-this-exposes-a-terminal Acknowledge a non-loopback bind (avoid, prefer Tailscale Serve)
Install flags (daemon flags above are propagated to the service):
@@ -301,6 +321,23 @@ export async function runInstall(argv: string[]): Promise<void> {
return;
}
if (platform === 'win32') {
// Windows : Planificateur de tâches, déclenchement à l'ouverture de session. Pas de service NT
// (il tournerait hors session utilisateur, donc sans accès au profil ni au CLI `claude`).
const createArgs = windowsCreateArgs({ taskName: WINDOWS_TASK_NAME, exec, scriptArgs });
if (flags.dryRun) {
console.log(`# commands:\nschtasks ${createArgs.join(' ')}`);
if (!flags.noEnable) console.log(`schtasks /Run /TN ${WINDOWS_TASK_NAME}`);
return;
}
bootstrapToken(serviceArgs);
run('schtasks.exe', createArgs, { check: true });
console.log(`Registered scheduled task "${WINDOWS_TASK_NAME}" (runs at logon).`);
if (!flags.noEnable) run('schtasks.exe', ['/Run', '/TN', WINDOWS_TASK_NAME], { check: true });
console.log(`\nArboretum task installed. Manage it with: schtasks /Query /TN ${WINDOWS_TASK_NAME}`);
return;
}
// macOS (launchd)
const logs = launchdLogPaths();
const programArguments = [exec, ...scriptArgs];
@@ -352,6 +389,12 @@ export async function runUninstall(argv: string[]): Promise<void> {
console.log('Arboretum service removed.');
return;
}
if (platform === 'win32') {
run('schtasks.exe', ['/End', '/TN', WINDOWS_TASK_NAME]); // best-effort : arrête l'instance courante
run('schtasks.exe', ['/Delete', '/TN', WINDOWS_TASK_NAME, '/F']);
console.log('Arboretum scheduled task removed.');
return;
}
const plistPath = launchAgentPlistPath(flags.label);
const uid = process.getuid?.() ?? 0;
run('launchctl', ['bootout', `gui/${uid}/${flags.label}`]); // best-effort
@@ -371,6 +414,10 @@ export async function runStatus(argv: string[]): Promise<void> {
process.exitCode = code;
return;
}
if (platform === 'win32') {
process.exitCode = run('schtasks.exe', ['/Query', '/TN', WINDOWS_TASK_NAME, '/V', '/FO', 'LIST']);
return;
}
const uid = process.getuid?.() ?? 0;
const code = run('launchctl', ['print', `gui/${uid}/${flags.label}`]);
console.log(`\nLogs: ${launchdLogPaths().out}`);
+16 -1
View File
@@ -25,6 +25,21 @@ export interface Config {
autoDiscover: boolean;
}
/**
* Racine des données applicatives, par plateforme. `XDG_DATA_HOME` reste prioritaire partout (l'app de
* bureau s'en sert pour isoler ses données). Sinon : `%APPDATA%` sur Windows (`~/.local/share` n'y a
* aucun sens et n'est ni sauvegardé ni migré par l'OS), `~/.local/share` ailleurs.
*/
export function defaultDataRoot(
platform: NodeJS.Platform = process.platform,
env: NodeJS.ProcessEnv = process.env,
home: string = homedir(),
): string {
if (env.XDG_DATA_HOME) return env.XDG_DATA_HOME;
if (platform === 'win32') return env.APPDATA ?? join(home, 'AppData', 'Roaming');
return join(home, '.local', 'share');
}
export function loadConfig(argv = process.argv.slice(2)): Config {
const { values } = parseArgs({
args: argv,
@@ -55,7 +70,7 @@ export function loadConfig(argv = process.argv.slice(2)): Config {
);
}
const dataDir = join(process.env.XDG_DATA_HOME ?? join(homedir(), '.local', 'share'), 'arboretum');
const dataDir = join(defaultDataRoot(), 'arboretum');
mkdirSync(dataDir, { recursive: true });
// La DB contient des secrets (server_secret, clé privée VAPID, hashs de tokens) : le dossier de
// données ne doit jamais être lisible par d'autres utilisateurs du système. chmod best-effort
+57 -23
View File
@@ -1,5 +1,5 @@
import { execFileSync } from 'node:child_process';
import { accessSync, constants } from 'node:fs';
import { accessSync, constants, existsSync } from 'node:fs';
export interface SpawnSpec {
file: string;
@@ -13,7 +13,7 @@ export interface SpawnOptions {
resume?: { claudeSessionId: string; fork?: boolean };
/** répertoires supplémentaires à relier dans une seule session (P6) : `--add-dir <path>` répété. */
addDirs?: string[];
/** chemin explicite du binaire `claude` (réglage UI) ; sinon résolution via PATH (`which`). */
/** chemin explicite du binaire `claude` (réglage UI) ; sinon résolution via le PATH. */
claudeBinPath?: string | null;
/**
* Lancement de projet (« Démarrer le projet ») : au lieu de `bash --norc`, lance le shell de
@@ -22,6 +22,8 @@ export interface SpawnOptions {
* (PATH minimal, cf. resolveClaudeBin) : sinon `npm`/`docker` seraient introuvables. Ignoré pour claude.
*/
login?: boolean;
/** plateforme cible (injectable pour les tests) ; défaut `process.platform`. */
platform?: NodeJS.Platform;
}
/** Diagnostic de résolution du binaire `claude` (exposé en lecture dans Réglages). */
@@ -36,16 +38,32 @@ export interface ClaudeBinDiagnostic {
let cachedClaudeBin: string | null = null;
/**
* Commande de recherche dans le PATH selon la plateforme : `which` n'existe PAS sur Windows, c'est
* `where.exe` (qui peut renvoyer plusieurs lignes, la première étant la retenue).
*/
export function whichCommand(platform: NodeJS.Platform = process.platform): { file: string; args: string[] } {
return platform === 'win32' ? { file: 'where.exe', args: ['claude'] } : { file: 'which', args: ['claude'] };
}
/** Recherche `claude` dans le PATH (sans throw). null si absent. */
function findClaudeOnPath(): string | null {
function findClaudeOnPath(platform: NodeJS.Platform = process.platform): string | null {
const { file, args } = whichCommand(platform);
try {
return execFileSync('which', ['claude'], { encoding: 'utf8' }).trim() || null;
const out = execFileSync(file, args, { encoding: 'utf8' });
// `where.exe` liste toutes les correspondances : on garde la première.
return out.split(/\r?\n/).map((l) => l.trim()).find((l) => l.length > 0) ?? null;
} catch {
return null;
}
}
function isExecutable(path: string): boolean {
/**
* « Est-ce lançable ? ». Sur Windows, le bit d'exécution POSIX n'a aucun sens (NTFS n'en a pas) et
* `accessSync(X_OK)` y répond au hasard : on se contente donc de l'existence du fichier.
*/
function isExecutable(path: string, platform: NodeJS.Platform = process.platform): boolean {
if (platform === 'win32') return existsSync(path);
try {
accessSync(path, constants.X_OK);
return true;
@@ -57,9 +75,9 @@ function isExecutable(path: string): boolean {
/**
* Résout le binaire `claude`. Si `configuredPath` est fourni (réglage UI), il est utilisé tel quel
* (validé exécutable, message clair sinon) et JAMAIS mis en cache (modifiable à chaud). Sinon :
* `which claude`, mis en cache. Un service systemd/launchd démarre avec un PATH minimal sans
* ~/.local/bin → `which claude` y échoue ; d'où le réglage de chemin explicite (et le PATH figé par
* `arboretum install`).
* recherche dans le PATH (`which` / `where.exe`), mise en cache. Un service systemd/launchd démarre
* avec un PATH minimal sans ~/.local/bin → la recherche y échoue ; d'où le réglage de chemin explicite
* (et le PATH figé par `arboretum install`).
*/
export function resolveClaudeBin(configuredPath?: string | null): string {
if (configuredPath) {
@@ -92,32 +110,48 @@ export function diagnoseClaudeBin(configuredPath?: string | null): ClaudeBinDiag
const KNOWN_LOGIN_SHELLS = new Set(['bash', 'zsh', 'fish']);
/**
* Shell de login pour « Démarrer le projet » : `$SHELL` s'il est un shell interactif connu
* (bash/zsh/fish), sinon fallback `bash`. Évite qu'un `$SHELL` exotique (dash…) sorte aussitôt
* avec `-l -i` et laisse un terminal vide.
* Shell interactif pour « Démarrer le projet ».
*
* POSIX : `$SHELL -l -i` s'il fait partie des shells connus supportant ces options (bash/zsh/fish),
* sinon `bash` (un `$SHELL=dash` sortirait aussitôt avec `-l -i`, laissant un terminal vide).
*
* Windows : PowerShell, en restant attaché après la commande auto-tapée (`-NoExit`), avec repli sur
* `cmd.exe /K`. `%COMSPEC%` n'est PAS utilisé comme shell de lancement : il pointe cmd.exe, qui ne
* charge aucun profil utilisateur. La commande est ensuite auto-tapée par le PtyManager, exactement
* comme sous POSIX · le mécanisme est indépendant du shell.
*/
function loginShell(): string {
const shell = process.env.SHELL;
if (shell && KNOWN_LOGIN_SHELLS.has(shell.split('/').pop() ?? '')) return shell;
return 'bash';
export function resolveInteractiveShell(
platform: NodeJS.Platform = process.platform,
env: NodeJS.ProcessEnv = process.env,
): { file: string; args: string[] } {
if (platform === 'win32') {
const pwsh = env.ARBORETUM_SHELL ?? 'powershell.exe';
return { file: pwsh, args: ['-NoLogo', '-NoExit'] };
}
const shell = env.SHELL;
const file = shell && KNOWN_LOGIN_SHELLS.has(shell.split('/').pop() ?? '') ? shell : 'bash';
return { file, args: ['-l', '-i'] };
}
/** Shell non interactif « neutre » (terminal simple, hors lancement de projet). */
export function resolvePlainShell(platform: NodeJS.Platform = process.platform): { file: string; args: string[] } {
if (platform === 'win32') return { file: 'powershell.exe', args: ['-NoLogo', '-NoExit'] };
return { file: 'bash', args: ['--norc'] };
}
/** Module volontairement abstrait : le plan B « BYO API key / Agent SDK » se brancherait ici. */
export function buildSpawnSpec(opts: SpawnOptions): SpawnSpec {
const platform = opts.platform ?? process.platform;
const env: NodeJS.ProcessEnv = {
...process.env,
TERM: 'xterm-256color',
COLORTERM: 'truecolor',
};
if (opts.command === 'bash') {
// Lancement de projet : shell de login interactif de l'utilisateur (charge PATH/nvm/asdf).
// `-l` (login) exécute les profils, `-i` (interactif) reste attaché après la commande auto-tapée.
// On n'utilise `$SHELL` que s'il fait partie des shells interactifs connus supportant `-l -i`
// (bash/zsh/fish) ; sinon fallback bash (ex. `$SHELL=dash` sortirait avec `-l -i`).
if (opts.login) {
return { file: loginShell(), args: ['-l', '-i'], env };
}
return { file: 'bash', args: ['--norc'], env };
// `'bash'` désigne « le shell de la machine », pas littéralement bash : le contrat d'API reste
// stable (claude|bash) et c'est ici qu'on choisit le shell réel par plateforme.
const { file, args } = opts.login ? resolveInteractiveShell(platform) : resolvePlainShell(platform);
return { file, args, env };
}
const args: string[] = [];
if (opts.resume) {
+31 -4
View File
@@ -7,9 +7,33 @@ import { resolve, sep, join } from 'node:path';
import chokidar, { type FSWatcher } from 'chokidar';
import { resolveGitDir } from './git.js';
const DEFAULT_MAX_WATCHERS = 32;
// Plafond du pool : l'arbre de projets peut désormais « regarder » tous les worktrees des dépôts
// dépliés (et non plus le seul worktree du panneau Git), il faut donc de la marge. Les entrées
// épinglées (session vivante, checkout principal) ne sont jamais évincées, cf. evictIfNeeded.
const DEFAULT_MAX_WATCHERS = 64;
const DEBOUNCE_MS = 200;
/**
* Répertoires lourds ignorés en plus de `.git` : ils concentrent l'essentiel des descripteurs inotify
* sans jamais rien apprendre sur le statut git. Liste volontairement CONSERVATRICE (pas de `dist`,
* `build`, `out` ni `vendor`, qui sont versionnés dans certains projets : les ignorer ferait manquer
* un vrai changement).
*/
const IGNORED_DIRS = [
'node_modules',
'.venv',
'venv',
'__pycache__',
'.turbo',
'.cache',
'.pnpm-store',
'coverage',
'.next',
'.nuxt',
'.output',
'target',
];
export interface FsWatcherEvents {
/** le contenu d'un worktree surveillé a changé (édition, staging, checkout externe…). */
worktree_fs_change: [{ repoId: string; path: string }];
@@ -33,11 +57,14 @@ interface WatchEntry {
/**
* Ignore tout sous `.git/` SAUF `HEAD` et `index` (⇒ on détecte le `git checkout` externe et le
* staging) ainsi que `node_modules`. chokidar n'ignore pas le dossier `.git` lui-même afin de
* pouvoir descendre jusqu'à `HEAD`/`index`, mais saute ses sous-dossiers volumineux (objects…).
* staging) ainsi que les répertoires de `IGNORED_DIRS`. chokidar n'ignore pas le dossier `.git`
* lui-même afin de pouvoir descendre jusqu'à `HEAD`/`index`, mais saute ses sous-dossiers
* volumineux (objects…).
*/
export function isIgnoredPath(p: string): boolean {
if (p.includes(`${sep}node_modules${sep}`) || p.endsWith(`${sep}node_modules`)) return true;
for (const dir of IGNORED_DIRS) {
if (p.includes(`${sep}${dir}${sep}`) || p.endsWith(`${sep}${dir}`)) return true;
}
if (p.includes(`${sep}.git${sep}`)) {
return !(p.endsWith(`${sep}HEAD`) || p.endsWith(`${sep}index`));
}
+30 -10
View File
@@ -1,7 +1,7 @@
// Préparation d'un environnement d'authentification git ÉPHÉMÈRE (P12). HTTPS (pat/app_password) :
// les identifiants sont fournis via GIT_ASKPASS (script 0o700 lisant deux variables d'env), JAMAIS
// dans l'URL ni dans `.git/config`. GIT_TERMINAL_PROMPT=0 (pas d'invite bloquante). Le script est
// supprimé en `finally` ; le secret ne transite que par l'env du process enfant (jamais loggé).
// les identifiants sont fournis via GIT_ASKPASS (script à permissions restreintes lisant deux variables
// d'env), JAMAIS dans l'URL ni dans `.git/config`. GIT_TERMINAL_PROMPT=0 (pas d'invite bloquante). Le
// script est supprimé en `finally` ; le secret ne transite que par l'env du process enfant (jamais loggé).
import { mkdtemp, writeFile, rm, chmod } from 'node:fs/promises';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
@@ -11,20 +11,40 @@ import type { GitAuth } from './git-clients/index.js';
// Identité HTTPS par défaut quand l'utilisateur n'a pas fourni de username (token-as-password).
const SERVICE_DEFAULT_USER: Record<GitService, string> = { github: 'x-access-token', gitlab: 'oauth2', gitea: 'oauth2' };
const ASKPASS_SH = "#!/bin/sh\ncase \"$1\" in\n Username*) printf '%s' \"$ARB_GIT_USER\" ;;\n *) printf '%s' \"$ARB_GIT_PASS\" ;;\nesac\n";
// Équivalent Windows : git appelle GIT_ASKPASS avec l'invite en argument. `echo` de cmd.exe ajoute un
// saut de ligne que git tolère (il trime la réponse). `~1` = premier argument sans les guillemets.
const ASKPASS_CMD = [
'@echo off',
'echo %~1 | findstr /b /i "Username" >nul',
'if %errorlevel%==0 (echo %ARB_GIT_USER%) else (echo %ARB_GIT_PASS%)',
'',
].join('\r\n');
/**
* Nom et contenu du script askpass selon la plateforme. Un `.sh` avec shebang n'est PAS exécutable sur
* Windows : sans cette variante `.cmd`, tout clone/push HTTPS par jeton y échouait silencieusement
* (git n'obtenait aucun identifiant et abandonnait, GIT_TERMINAL_PROMPT étant à 0).
*/
export function askpassScript(platform: NodeJS.Platform = process.platform): { name: string; content: string; mode: number } {
return platform === 'win32'
? { name: 'askpass.cmd', content: ASKPASS_CMD, mode: 0o700 }
: { name: 'askpass.sh', content: ASKPASS_SH, mode: 0o700 };
}
export async function withGitAuth<T>(
service: GitService,
auth: GitAuth,
fn: (env: NodeJS.ProcessEnv) => Promise<T>,
): Promise<T> {
const dir = await mkdtemp(join(tmpdir(), 'arb-gitauth-'));
const askpass = join(dir, 'askpass.sh');
const script = askpassScript();
const askpass = join(dir, script.name);
const user = auth.username || SERVICE_DEFAULT_USER[service];
await writeFile(
askpass,
"#!/bin/sh\ncase \"$1\" in\n Username*) printf '%s' \"$ARB_GIT_USER\" ;;\n *) printf '%s' \"$ARB_GIT_PASS\" ;;\nesac\n",
{ mode: 0o700 },
);
await chmod(askpass, 0o700);
await writeFile(askpass, script.content, { mode: script.mode });
// chmod best-effort : sans effet sur NTFS (comme ailleurs dans le code, cf. config.ts).
await chmod(askpass, script.mode).catch(() => {});
const env: NodeJS.ProcessEnv = {
...process.env,
GIT_ASKPASS: askpass,
+76 -1
View File
@@ -2,7 +2,7 @@
// les chemins/refs utilisateur. Fonctions pures sans état, prenant un cwd déjà validé par l'appelant.
import { execFile, spawn } from 'node:child_process';
import { resolve, sep } from 'node:path';
import type { WorktreeGitStatus, WorktreeBranchAction, WorktreeBranchMode, FileChange } from '@arboretum/shared';
import type { WorktreeGitStatus, WorktreeBranchAction, WorktreeBranchMode, FileChange, CommitEntry } from '@arboretum/shared';
const GIT_TIMEOUT_MS = 10_000;
// `push` peut dialoguer avec un remote (réseau) : on lui laisse une marge bien plus large.
@@ -502,6 +502,81 @@ export async function lastCommit(worktreePath: string): Promise<{ hash: string;
return { hash: r.stdout.slice(0, idx), subject: r.stdout.slice(idx + 1).replace(/\n$/, '') };
}
const MAX_LOG_LIMIT = 200;
/**
* Hash de commit : hexadécimal, 4 à 64 caractères. Bornage strict AVANT de le passer à git · un
* identifiant libre ouvrirait la porte à des révisions arbitraires ou à des options déguisées (`-…`).
*/
export function isValidCommitish(hash: string): boolean {
return /^[0-9a-f]{4,64}$/i.test(hash);
}
/**
* Découpe la sortie de `git log -z --format=<n champs séparés par NUL>` en enregistrements. Isolée et
* pure pour être testable sans dépôt : c'est le point délicat (avec `-z`, les séparateurs de champs et
* d'enregistrements sont tous des NUL, il faut donc compter les champs).
*/
export function parseLogZ(stdout: string, fieldsPerCommit: number): string[][] {
const fields = stdout.split('\0');
const out: string[][] = [];
for (let i = 0; i + fieldsPerCommit - 1 < fields.length; i += fieldsPerCommit) {
const rec = fields.slice(i, i + fieldsPerCommit);
if ((rec[0] ?? '').trim() === '') continue;
out.push(rec);
}
return out;
}
/**
* Historique de la branche du worktree. `-z` + champs séparés par NUL : un sujet contenant un saut de
* ligne ne peut pas casser le parsing. `unpushedCount` = commits de tête pas encore poussés
* (`@{u}..HEAD`) ; `hasUpstream: false` signifie qu'AUCUN commit n'est publié (branche purement locale),
* ce que l'UI marque en bloc plutôt que de compter tout l'historique.
*/
export async function commitLog(
worktreePath: string,
opts: { limit?: number; skip?: number } = {},
): Promise<{ commits: CommitEntry[]; unpushedCount: number; hasUpstream: boolean }> {
const limit = Math.min(Math.max(1, Math.trunc(opts.limit ?? 30)), MAX_LOG_LIMIT);
const skip = Math.max(0, Math.trunc(opts.skip ?? 0));
const r = await gitRaw(worktreePath, [
'log',
`--max-count=${limit}`,
`--skip=${skip}`,
'-z',
'--format=%H%x00%h%x00%an%x00%aI%x00%s',
]);
if (r.code !== 0) return { commits: [], unpushedCount: 0, hasUpstream: false }; // dépôt sans commit
const commits: CommitEntry[] = parseLogZ(r.stdout, 5).map((f) => ({
hash: (f[0] ?? '').trim(),
shortHash: f[1] ?? '',
author: f[2] ?? '',
date: f[3] ?? '',
subject: (f[4] ?? '').replace(/\n$/, ''),
}));
const upstream = await gitRaw(worktreePath, ['rev-parse', '--abbrev-ref', '--symbolic-full-name', '@{u}']);
if (upstream.code !== 0) return { commits, unpushedCount: 0, hasUpstream: false };
const count = await gitRaw(worktreePath, ['rev-list', '--count', '@{u}..HEAD']);
return { commits, unpushedCount: count.code === 0 ? Number(count.stdout.trim()) || 0 : 0, hasUpstream: true };
}
/**
* Diff complet d'un commit (`git show`), borné exactement comme `fileDiff` : refus des binaires,
* troncature au-delà de MAX_DIFF_BYTES. Le résultat étant un diff unifié, il passe dans le même
* parseur et la même vue que les diffs de fichiers.
*/
export async function commitDiff(worktreePath: string, hash: string): Promise<{ diff: string; binary: boolean; tooLarge: boolean }> {
if (!isValidCommitish(hash)) throw new Error(`Invalid commit hash: ${hash}`);
const out = await gitRaw(worktreePath, ['show', '--no-color', '--format=', hash]);
if (out.code !== 0) throw new Error(`Unknown commit: ${hash}`);
const raw = out.stdout;
const binary = /^Binary files .* differ$/m.test(raw) || raw.includes('GIT binary patch');
if (binary) return { diff: '', binary: true, tooLarge: false };
if (raw.length > MAX_DIFF_BYTES) return { diff: raw.slice(0, MAX_DIFF_BYTES), binary: false, tooLarge: true };
return { diff: raw, binary: false, tooLarge: false };
}
/** true si le HEAD courant n'est pas encore poussé (amend autorisé). Sans upstream → true. */
export async function isUnpushed(worktreePath: string): Promise<boolean> {
try {
+13 -5
View File
@@ -1,4 +1,5 @@
import { EventEmitter } from 'node:events';
import { execFile } from 'node:child_process';
import { existsSync, statSync } from 'node:fs';
import { randomUUID } from 'node:crypto';
import { homedir } from 'node:os';
@@ -372,17 +373,24 @@ export class PtyManager extends EventEmitter<PtyManagerEvents> {
const s = this.live.get(id);
if (!s || s.exited) return false;
try {
process.kill(s.proc.pid, 'SIGTERM');
// Windows n'a pas de signaux : node-pty traduit `kill()` en fermeture de la pseudo-console, ce
// qui laisse échapper les petits-enfants (un `npm run dev` lancé dans le shell). Le SIGKILL
// différé est donc remplacé par un `taskkill /T` qui tue l'ARBRE complet.
if (process.platform === 'win32') s.proc.kill();
else process.kill(s.proc.pid, 'SIGTERM');
} catch {
return false;
}
s.killTimer ??= setTimeout(() => {
if (!s.exited) {
try {
if (s.exited) return;
try {
if (process.platform === 'win32') {
execFile('taskkill.exe', ['/PID', String(s.proc.pid), '/T', '/F'], () => {});
} else {
process.kill(s.proc.pid, 'SIGKILL');
} catch {
/* déjà mort */
}
} catch {
/* déjà mort */
}
}, KILL_GRACE_MS);
return true;
+33
View File
@@ -0,0 +1,33 @@
// Adaptateur serveur de la corrélation session ↔ worktree : la RÈGLE vit dans `@arboretum/shared`
// (`path-match.ts`, partagée avec le front et l'extension) ; ici on se contente de normaliser les
// chemins avec `resolve()` avant de la lui passer, puisque le serveur manipule des chemins venant de
// git, de la base et de requêtes (fins de slash, `..`, chemins relatifs au cwd du process).
import { resolve } from 'node:path';
import {
containsPath as sharedContains,
findWorktreeForCwd as sharedFind,
sessionBelongsToWorktree as sharedBelongs,
} from '@arboretum/shared';
export function containsPath(parent: string, child: string): boolean {
return sharedContains(resolve(parent), resolve(child));
}
export function sessionBelongsToWorktree(
session: { cwd: string; addedDirs?: string[] },
worktreePath: string,
others: string[] = [],
): boolean {
return sharedBelongs(
{ cwd: resolve(session.cwd), ...(session.addedDirs ? { addedDirs: session.addedDirs.map((d) => resolve(d)) } : {}) },
resolve(worktreePath),
others.map((p) => resolve(p)),
);
}
export function findWorktreeForCwd<T extends { path: string }>(cwd: string, worktrees: T[]): T | null {
// On résout une copie pour la comparaison, puis on renvoie l'objet d'origine (le chemin brut est ce
// que le reste du code attend, notamment les clés du watcher FS).
const normalized = worktrees.map((w) => ({ w, path: resolve(w.path) }));
return sharedFind(resolve(cwd), normalized)?.w ?? null;
}
+99 -13
View File
@@ -28,6 +28,8 @@ import {
amendCommit,
cleanFiles,
commitAll,
commitDiff,
commitLog,
commitStaged,
defaultBranch,
fetchRemote,
@@ -38,6 +40,7 @@ import {
isSafeRelativePath,
isUnpushed,
isValidBranchName,
isValidCommitish,
listBranches,
listChanges,
listWorktrees,
@@ -53,7 +56,8 @@ import {
type ParsedWorktree,
} from './git.js';
import type { FsWatcherService } from './fs-watcher.js';
import type { FileChange, FileDiffResponse } from '@arboretum/shared';
import { findWorktreeForCwd, sessionBelongsToWorktree } from './session-match.js';
import type { CommitDiffResponse, FileChange, FileDiffResponse, WorktreeLogResponse } from '@arboretum/shared';
const FACTS_TTL_MS = 2500;
const HOOK_TIMEOUT_MS = 5 * 60_000;
@@ -153,6 +157,8 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
private readonly locks = new Map<string, Promise<unknown>>();
/** Scan de découverte en cours : coalesce boot + bouton + périodique sur un seul scan. */
private scanInFlight: Promise<DiscoverReposResponse> | null = null;
/** Worktree épinglé au watcher FS pour chaque session vivante (clé = id de session). */
private readonly pinnedSessions = new Map<string, { repoId: string; path: string }>();
constructor(
private readonly db: Db,
@@ -170,6 +176,46 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
if (row) void this.emitWorktree(row, path).catch(() => {});
this.emit('worktree_changes', { repoId, path });
});
// Une session vivante rend son worktree « actif » : on épingle son watcher FS pour que les
// compteurs git restent temps réel même si aucun client ne regarde ce worktree. C'est le cas
// nominal du travail en CLI : l'agent écrit dans un worktree de feature pendant qu'on regarde
// ailleurs. Sans cette épingle, le point « modifié » de l'arbre restait figé sur le dernier
// listing REST.
this.ptyManager.on('session_update', (s) => {
void this.syncSessionPin(s).catch(() => {});
});
}
/** Épingle (session vivante) ou libère (session terminée) le watcher FS du worktree d'une session. */
private async syncSessionPin(s: SessionSummary): Promise<void> {
if (!this.fsWatcher) return;
const pinned = this.pinnedSessions.get(s.id);
if (!s.live) {
if (!pinned) return;
this.pinnedSessions.delete(s.id);
this.fsWatcher.unpinSession(pinned.repoId, pinned.path);
return;
}
if (pinned) return; // déjà épinglé : `session_update` bat au rythme de l'activité
const target = await this.resolveWorktreeForCwd(s.cwd);
if (!target) return; // session hors de tout repo enregistré
this.pinnedSessions.set(s.id, target);
this.fsWatcher.pinSession(target.repoId, target.path);
}
/**
* Worktree connu (tous repos non masqués) contenant ce cwd, le plus spécifique. Un worktree lié vit
* souvent HORS de l'arborescence de son repo : on ne peut donc pas écarter un repo sur son seul
* chemin, il faut ses worktrees réels (servis par le cache court partagé avec les listings).
*/
private async resolveWorktreeForCwd(cwd: string): Promise<{ repoId: string; path: string } | null> {
const rows = this.db.prepare('SELECT id, path FROM repos WHERE hidden = 0').all() as unknown as Array<{ id: string; path: string }>;
const candidates: Array<{ repoId: string; path: string }> = [];
for (const row of rows) {
const facts = await this.repoFacts(row).catch(() => []);
for (const f of facts) candidates.push({ repoId: row.id, path: f.w.path });
}
return findWorktreeForCwd(cwd, candidates);
}
// ---- repos ----
@@ -336,20 +382,28 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
// ---- worktrees ----
/**
* Sessions (managées + découvertes) dont le cwd correspond à ce chemin de worktree.
* Sessions (managées + découvertes) rattachées à ce worktree : cwd dans le worktree (y compris un
* sous-répertoire de « Démarrer le projet ») ou worktree relié en `--add-dir` par une session de
* groupe · voir `sessionBelongsToWorktree`. `siblings` = les autres worktrees du repo, indispensables
* pour qu'un worktree imbriqué ne voie pas ses sessions attribuées aussi au checkout principal.
* Les sessions explicitement masquées (`hidden`) sont exclues, cohérent avec `/api/v1/sessions`
* (sans quoi le masquage était ignoré dans les fiches worktree). Le tri managées/externes est laissé
* au client (interrupteur « afficher les externes »), qui dispose du champ `source`. La garde de
* suppression réclame en revanche TOUTES les sessions vivantes (`includeHidden`) pour rester sûre.
*/
private sessionsForCwd(path: string, opts?: { includeHidden?: boolean }): SessionSummary[] {
const rp = resolve(path);
private sessionsForCwd(path: string, opts?: { includeHidden?: boolean; siblings?: string[] }): SessionSummary[] {
return mergeSessions(this.ptyManager.list(), this.discovery.list())
.filter((s) => resolve(s.cwd) === rp)
.filter((s) => sessionBelongsToWorktree(s, path, opts?.siblings ?? []))
.filter((s) => opts?.includeHidden || !s.hidden);
}
private toSummary(repoId: string, repoPath: string, w: ParsedWorktree, status: WorktreeGitStatus): WorktreeSummary {
private toSummary(
repoId: string,
repoPath: string,
w: ParsedWorktree,
status: WorktreeGitStatus,
siblings: string[] = [],
): WorktreeSummary {
return {
repoId,
path: w.path,
@@ -360,11 +414,11 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
prunable: w.prunable,
isMain: resolve(w.path) === resolve(repoPath),
git: status,
sessions: this.sessionsForCwd(w.path),
sessions: this.sessionsForCwd(w.path, { siblings }),
};
}
private async repoFacts(row: RepoRow, noCache = false): Promise<Array<{ w: ParsedWorktree; status: WorktreeGitStatus }>> {
private async repoFacts(row: { id: string; path: string }, noCache = false): Promise<Array<{ w: ParsedWorktree; status: WorktreeGitStatus }>> {
const cached = this.factsCache.get(row.id);
if (!noCache && cached && Date.now() - cached.at < FACTS_TTL_MS) return cached.facts;
const parsed = (await listWorktrees(row.path)).filter((w) => !w.bare);
@@ -377,7 +431,8 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
const row = this.getRepoRow(repoId);
if (!row) return [];
const facts = await this.repoFacts(row, noCache);
return facts.map(({ w, status }) => this.toSummary(row.id, row.path, w, status));
const paths = facts.map(({ w }) => w.path);
return facts.map(({ w, status }) => this.toSummary(row.id, row.path, w, status, paths));
}
async listAllWorktrees(): Promise<WorktreeSummary[]> {
@@ -411,9 +466,19 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
}
private async emitWorktree(row: RepoRow, path: string): Promise<WorktreeSummary | null> {
const w = await this.findWorktree(row, path);
// On liste tous les worktrees du repo (et pas seulement celui visé) pour désambiguïser la
// corrélation des sessions entre worktrees imbriqués (cf. sessionsForCwd).
const all = (await listWorktrees(row.path)).filter((w) => !w.bare);
const rp = resolve(path);
const w = all.find((x) => resolve(x.path) === rp);
if (!w) return null;
const summary = this.toSummary(row.id, row.path, w, await worktreeStatus(w.path));
const summary = this.toSummary(
row.id,
row.path,
w,
await worktreeStatus(w.path),
all.map((x) => x.path),
);
this.emit('worktree_update', { repoId: row.id, worktree: summary });
return summary;
}
@@ -520,6 +585,25 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
return listChanges(w.path);
}
/** Historique de la branche du worktree (lecture, hors lock) : « ce qui a déjà été acté ». */
async getWorktreeLog(repoId: string, path: string, opts: { limit?: number; skip?: number }): Promise<WorktreeLogResponse> {
const { w } = await this.requireWorktree(repoId, path);
const { commits, unpushedCount, hasUpstream } = await commitLog(w.path, opts);
return { repoId, path: w.path, commits, unpushedCount, hasUpstream };
}
/** Diff unifié complet d'un commit (lecture, hors lock). Le hash est validé par la couche git. */
async getCommitDiff(repoId: string, path: string, hash: string): Promise<CommitDiffResponse> {
const { w } = await this.requireWorktree(repoId, path);
if (!isValidCommitish(hash)) throw httpError(400, 'BAD_COMMIT', 'Invalid commit hash');
try {
const d = await commitDiff(w.path, hash);
return { path: w.path, commit: hash, binary: d.binary, tooLarge: d.tooLarge, diff: d.diff };
} catch (err) {
throw httpError(404, 'NOT_FOUND', (err as Error).message);
}
}
/** Diff unifié d'un fichier (détecte untracked → `git diff --no-index`). Lecture, hors lock. */
async getFileDiff(repoId: string, path: string, file: string, staged: boolean): Promise<FileDiffResponse> {
const { w } = await this.requireWorktree(repoId, path);
@@ -813,8 +897,10 @@ export class WorktreeManager extends EventEmitter<WorktreeManagerEvents> {
const w = await this.findWorktree(row, path);
if (!w) throw httpError(404, 'NOT_FOUND', 'No such worktree under this repo');
if (resolve(w.path) === resolve(row.path)) throw httpError(400, 'IS_MAIN_WORKTREE', 'Cannot remove the main worktree');
// garde-fou : une session vivante tourne dans ce worktree → exiger une confirmation explicite.
if (!force && this.sessionsForCwd(w.path, { includeHidden: true }).some((s) => s.live)) {
// garde-fou : une session vivante tourne dans ce worktree (ou dans un de ses sous-répertoires, ou
// le relie en `--add-dir`) → exiger une confirmation explicite.
const siblings = (await listWorktrees(row.path)).map((x) => x.path);
if (!force && this.sessionsForCwd(w.path, { includeHidden: true, siblings }).some((s) => s.live)) {
throw httpError(409, 'SESSION_LIVE_IN_WORKTREE', 'A live session runs in this worktree: pass force to delete anyway');
}
return this.withLock(repoId, async () => {
+42 -4
View File
@@ -5,7 +5,9 @@
import type { FastifyInstance } from 'fastify';
import type {
WorktreeChangesResponse,
CommitDiffResponse,
FileDiffResponse,
WorktreeLogResponse,
WorktreeFilesRequest,
DiscardFilesRequest,
FetchWorktreeRequest,
@@ -33,12 +35,48 @@ export function registerGitRoutes(app: FastifyInstance, wt: WorktreeManager, db:
}
});
// Diff unifié d'un fichier (staged ou non ; untracked détecté côté manager).
// Historique de la branche du worktree (« ce qui a déjà été acté », + ce qui n'est pas poussé).
app.get('/api/v1/repos/:id/worktrees/log', async (req, reply) => {
const { id } = req.params as { id: string };
const q = req.query as { path?: string; limit?: string; skip?: string };
if (typeof q.path !== 'string' || q.path === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'path is required' } });
}
// Bornes appliquées côté couche git (limite dure) : ici on se contente de convertir.
const limit = q.limit !== undefined ? Number(q.limit) : undefined;
const skip = q.skip !== undefined ? Number(q.skip) : undefined;
if ((limit !== undefined && !Number.isFinite(limit)) || (skip !== undefined && !Number.isFinite(skip))) {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'limit and skip must be numbers' } });
}
try {
const res = await wt.getWorktreeLog(id, q.path, {
...(limit !== undefined ? { limit } : {}),
...(skip !== undefined ? { skip } : {}),
});
return reply.send(res satisfies WorktreeLogResponse);
} catch (err) {
return sendManagerError(reply, err);
}
});
// Diff unifié : d'un fichier (`file`), ou d'un commit entier (`commit`). Les deux formes renvoient un
// diff unifié, donc le même parseur et la même vue côté client.
app.get('/api/v1/repos/:id/worktrees/diff', async (req, reply) => {
const { id } = req.params as { id: string };
const q = req.query as { path?: string; file?: string; staged?: string };
if (typeof q.path !== 'string' || q.path === '' || typeof q.file !== 'string' || q.file === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'path and file are required' } });
const q = req.query as { path?: string; file?: string; staged?: string; commit?: string };
if (typeof q.path !== 'string' || q.path === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'path is required' } });
}
if (typeof q.commit === 'string' && q.commit !== '') {
try {
const res = await wt.getCommitDiff(id, q.path, q.commit);
return reply.send(res satisfies CommitDiffResponse);
} catch (err) {
return sendManagerError(reply, err);
}
}
if (typeof q.file !== 'string' || q.file === '') {
return reply.status(400).send({ error: { code: 'BAD_REQUEST', message: 'file or commit is required' } });
}
const staged = q.staged === '1' || q.staged === 'true';
try {
+31 -2
View File
@@ -12,6 +12,7 @@ import {
xmlEscape,
systemdUnitPath,
launchAgentPlistPath,
windowsCreateArgs,
} from '../src/cli/install.js';
describe('cli install · detectPlatform', () => {
@@ -20,9 +21,10 @@ describe('cli install · detectPlatform', () => {
expect(detectPlatform('darwin')).toBe('darwin');
});
it('rejette les autres plateformes avec un message clair', () => {
expect(() => detectPlatform('win32')).toThrow(/Linux \(systemd\) and macOS \(launchd\)/);
it('rejette les plateformes sans superviseur connu, avec un message clair', () => {
// win32 est désormais SUPPORTÉ (Planificateur de tâches) : cf. la suite dédiée plus bas.
expect(() => detectPlatform('freebsd')).toThrow(/freebsd/);
expect(() => detectPlatform('aix')).toThrow(/Task Scheduler/);
});
});
@@ -192,3 +194,30 @@ describe('cli install · chemins', () => {
);
});
});
describe('P14 · Windows (Planificateur de tâches)', () => {
it('detectPlatform accepte win32', () => {
expect(detectPlatform('win32')).toBe('win32');
expect(() => detectPlatform('freebsd')).toThrow(/Task Scheduler/);
});
it('windowsCreateArgs : tâche à l’ouverture de session, sans élévation, idempotente', () => {
const args = windowsCreateArgs({
taskName: 'Arboretum',
exec: 'C:\\Program Files\\nodejs\\node.exe',
scriptArgs: ['C:\\app\\dist\\index.js', '--port', '7317'],
});
expect(args).toEqual([
'/Create',
'/TN',
'Arboretum',
'/TR',
'"C:\\Program Files\\nodejs\\node.exe" C:\\app\\dist\\index.js --port 7317',
'/SC',
'ONLOGON',
'/RL',
'LIMITED',
'/F',
]);
});
});
+80
View File
@@ -32,6 +32,10 @@ import {
amendCommit,
lastCommit,
isUnpushed,
commitLog,
commitDiff,
isValidCommitish,
parseLogZ,
} from '../src/core/git.js';
import { appendFileSync } from 'node:fs';
@@ -318,3 +322,79 @@ describe('addWorktree : résolution auto (créer / réutiliser)', () => {
await expect(addWorktree(repo, { path: wt, branch: 'dup', mode: 'create' })).rejects.toBeDefined();
});
});
describe('P14 · historique (commitLog / commitDiff)', () => {
it('parseLogZ : découpe par paquets de champs et tolère un sujet multi-lignes', () => {
const stdout = ['h1', 's1', 'auteur', '2026-01-01T00:00:00Z', 'sujet\navec saut', 'h2', 's2', 'a2', 'd2', 'sujet 2'].join('\0');
const recs = parseLogZ(stdout, 5);
expect(recs).toHaveLength(2);
expect(recs[0]?.[4]).toBe('sujet\navec saut');
expect(recs[1]?.[0]).toBe('h2');
});
it('parseLogZ : ignore un enregistrement final vide (NUL de fin)', () => {
expect(parseLogZ(['h', 's', 'a', 'd', 'sub', ''].join('\0'), 5)).toHaveLength(1);
});
it('isValidCommitish : hex 4-64 uniquement (refuse une option déguisée)', () => {
expect(isValidCommitish('abc1234')).toBe(true);
expect(isValidCommitish('ABCDEF12')).toBe(true);
expect(isValidCommitish('abc')).toBe(false);
expect(isValidCommitish('--upload-pack=x')).toBe(false);
expect(isValidCommitish('HEAD')).toBe(false);
expect(isValidCommitish('main..HEAD')).toBe(false);
});
it('commitLog : ordre récent → ancien, champs remplis, sans upstream tout est local', async () => {
const repo = makeTmpRepo();
appendFileSync(join(repo, 'README.md'), 'second\n');
await commitAll(repo, 'deuxième commit');
const { commits, hasUpstream, unpushedCount } = await commitLog(repo);
expect(commits).toHaveLength(2);
expect(commits[0]?.subject).toBe('deuxième commit');
expect(commits[1]?.subject).toBe('init');
expect(commits[0]?.hash).toMatch(/^[0-9a-f]{40}$/);
expect(commits[0]?.shortHash.length).toBeGreaterThanOrEqual(7);
expect(commits[0]?.author).toBe('Test');
expect(Number.isNaN(Date.parse(commits[0]?.date ?? ''))).toBe(false);
// branche locale sans remote : aucun commit n'est publié
expect(hasUpstream).toBe(false);
expect(unpushedCount).toBe(0);
});
it('commitLog : limit et skip bornent la fenêtre', async () => {
const repo = makeTmpRepo();
for (const n of [1, 2, 3]) {
appendFileSync(join(repo, 'README.md'), `line ${n}\n`);
await commitAll(repo, `commit ${n}`);
}
expect((await commitLog(repo, { limit: 2 })).commits.map((c) => c.subject)).toEqual(['commit 3', 'commit 2']);
expect((await commitLog(repo, { limit: 1, skip: 2 })).commits.map((c) => c.subject)).toEqual(['commit 1']);
});
it('commitLog : dépôt sans aucun commit → liste vide, pas d’exception', async () => {
const dir = mkdtempSync(join(tmpdir(), 'arb-git-empty-'));
dirs.push(dir);
execFileSync('git', ['init', '-b', 'main'], { cwd: dir, stdio: 'pipe' });
const res = await commitLog(dir);
expect(res.commits).toEqual([]);
expect(res.hasUpstream).toBe(false);
});
it('commitDiff : diff unifié du commit demandé, hash invalide et inconnu rejetés', async () => {
const repo = makeTmpRepo();
writeFileSync(join(repo, 'nouveau.txt'), 'contenu\n');
await commitAll(repo, 'ajout fichier');
const [head] = (await commitLog(repo)).commits;
const d = await commitDiff(repo, head?.hash ?? '');
expect(d.binary).toBe(false);
expect(d.tooLarge).toBe(false);
expect(d.diff).toContain('nouveau.txt');
expect(d.diff).toContain('+contenu');
await expect(commitDiff(repo, 'HEAD')).rejects.toThrow(/Invalid commit hash/);
await expect(commitDiff(repo, 'deadbeef')).rejects.toThrow(/Unknown commit/);
});
});
@@ -0,0 +1,79 @@
import { describe, expect, it } from 'vitest';
import { containsPath, findWorktreeForCwd, sessionBelongsToWorktree } from '../src/core/session-match.js';
describe('containsPath', () => {
it('vrai pour le répertoire lui-même', () => {
expect(containsPath('/p/repo', '/p/repo')).toBe(true);
});
it('vrai pour un descendant', () => {
expect(containsPath('/p/repo', '/p/repo/packages/api')).toBe(true);
});
it('compare par segment, pas par préfixe de chaîne', () => {
// /p/repo ne contient PAS /p/repo-wt-feature (piège du startsWith nu)
expect(containsPath('/p/repo', '/p/repo-wt-feature')).toBe(false);
});
it('faux pour un ancêtre', () => {
expect(containsPath('/p/repo/api', '/p/repo')).toBe(false);
});
it('normalise les chemins non résolus', () => {
expect(containsPath('/p/repo', '/p/repo/./api/../api')).toBe(true);
});
});
describe('sessionBelongsToWorktree', () => {
it('rattache une session lancée à la racine du worktree', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/repo' }, '/p/repo')).toBe(true);
});
it('rattache une session lancée dans un sous-répertoire (« Démarrer le projet »)', () => {
// LaunchCommand.cwd autorise un sous-dossier : le terminal doit rester visible sous son worktree.
expect(sessionBelongsToWorktree({ cwd: '/p/repo/packages/api' }, '/p/repo')).toBe(true);
});
it('ne rattache pas une session d’un worktree frère', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/repo-wt-feat' }, '/p/repo')).toBe(false);
});
it('donne un worktree imbriqué au plus spécifique, pas au principal', () => {
const session = { cwd: '/p/repo/.worktrees/feat/src' };
const all = ['/p/repo', '/p/repo/.worktrees/feat'];
expect(sessionBelongsToWorktree(session, '/p/repo/.worktrees/feat', all)).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/repo', all)).toBe(false);
});
it('rattache une session de groupe via ses répertoires reliés', () => {
// cwd = parent commun (hors des repos), les worktrees couverts vivent dans addedDirs.
const session = { cwd: '/p', addedDirs: ['/p/api', '/p/web'] };
expect(sessionBelongsToWorktree(session, '/p/api')).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/web')).toBe(true);
expect(sessionBelongsToWorktree(session, '/p/docs')).toBe(false);
});
it('ignore un addedDirs absent', () => {
expect(sessionBelongsToWorktree({ cwd: '/p/api' }, '/p/api', [])).toBe(true);
});
});
describe('findWorktreeForCwd', () => {
const worktrees = [
{ repoId: 'r1', path: '/p/api' },
{ repoId: 'r1', path: '/p/api-wt-feat' },
{ repoId: 'r2', path: '/p/api/vendor/web' },
];
it('choisit le worktree le plus spécifique', () => {
expect(findWorktreeForCwd('/p/api/vendor/web/src', worktrees)?.repoId).toBe('r2');
});
it('choisit le worktree frère exact et non le préfixe de chaîne', () => {
expect(findWorktreeForCwd('/p/api-wt-feat/src', worktrees)?.path).toBe('/p/api-wt-feat');
});
it('renvoie null hors de tout worktree connu', () => {
expect(findWorktreeForCwd('/tmp/ailleurs', worktrees)).toBeNull();
});
});
@@ -0,0 +1,94 @@
// Support Windows du daemon : helpers purs, testés avec la plateforme INJECTÉE (ils doivent donc être
// vérifiables depuis Linux). Chacun corrige un point qui rendait le daemon inutilisable sur Windows.
import { describe, expect, it } from 'vitest';
import { buildSpawnSpec, resolveInteractiveShell, resolvePlainShell, whichCommand } from '../src/core/claude-launcher.js';
import { askpassScript } from '../src/core/git-auth.js';
import { defaultDataRoot } from '../src/config.js';
describe('recherche du binaire claude dans le PATH', () => {
it('utilise where.exe sur Windows, which ailleurs', () => {
expect(whichCommand('win32')).toEqual({ file: 'where.exe', args: ['claude'] });
expect(whichCommand('linux')).toEqual({ file: 'which', args: ['claude'] });
expect(whichCommand('darwin').file).toBe('which');
});
});
describe('shell de lancement', () => {
it('POSIX : $SHELL connu en login interactif, sinon bash', () => {
expect(resolveInteractiveShell('linux', { SHELL: '/usr/bin/zsh' })).toEqual({ file: '/usr/bin/zsh', args: ['-l', '-i'] });
expect(resolveInteractiveShell('linux', { SHELL: '/bin/dash' })).toEqual({ file: 'bash', args: ['-l', '-i'] });
expect(resolveInteractiveShell('linux', {})).toEqual({ file: 'bash', args: ['-l', '-i'] });
});
it('Windows : PowerShell qui reste attaché après la commande auto-tapée', () => {
const shell = resolveInteractiveShell('win32', {});
expect(shell.file).toBe('powershell.exe');
expect(shell.args).toContain('-NoExit');
});
it('Windows : le shell est surchargeable par ARBORETUM_SHELL', () => {
expect(resolveInteractiveShell('win32', { ARBORETUM_SHELL: 'pwsh.exe' }).file).toBe('pwsh.exe');
});
it('terminal simple : bash --norc sur POSIX, PowerShell sur Windows', () => {
expect(resolvePlainShell('linux')).toEqual({ file: 'bash', args: ['--norc'] });
expect(resolvePlainShell('win32').file).toBe('powershell.exe');
});
});
describe('buildSpawnSpec · plateforme injectée', () => {
it('command=bash sur Windows lance PowerShell (le contrat d’API reste claude|bash)', () => {
const spec = buildSpawnSpec({ command: 'bash', platform: 'win32' });
expect(spec.file).toBe('powershell.exe');
expect(spec.env.TERM).toBe('xterm-256color');
});
it('command=bash avec login sur Windows reste attaché', () => {
expect(buildSpawnSpec({ command: 'bash', login: true, platform: 'win32' }).args).toContain('-NoExit');
});
it('command=bash sur Linux inchangé', () => {
expect(buildSpawnSpec({ command: 'bash', platform: 'linux' })).toMatchObject({ file: 'bash', args: ['--norc'] });
});
});
describe('script askpass git', () => {
it('Windows : .cmd (un .sh à shebang n’y est pas exécutable)', () => {
const s = askpassScript('win32');
expect(s.name).toBe('askpass.cmd');
expect(s.content).toContain('@echo off');
expect(s.content).toContain('ARB_GIT_USER');
expect(s.content).toContain('ARB_GIT_PASS');
});
it('POSIX : .sh avec shebang', () => {
const s = askpassScript('linux');
expect(s.name).toBe('askpass.sh');
expect(s.content.startsWith('#!/bin/sh')).toBe(true);
expect(s.mode).toBe(0o700);
});
it('les deux variantes distinguent Username du mot de passe', () => {
for (const p of ['win32', 'linux'] as const) {
const c = askpassScript(p).content;
expect(c).toMatch(/Username/i);
}
});
});
describe('racine des données', () => {
it('XDG_DATA_HOME est prioritaire partout (l’app de bureau s’en sert pour isoler)', () => {
expect(defaultDataRoot('win32', { XDG_DATA_HOME: '/iso' }, '/home/u')).toBe('/iso');
expect(defaultDataRoot('linux', { XDG_DATA_HOME: '/iso' }, '/home/u')).toBe('/iso');
});
it('Windows : %APPDATA%, avec repli sur AppData/Roaming', () => {
expect(defaultDataRoot('win32', { APPDATA: 'C:\\Users\\u\\AppData\\Roaming' }, 'C:\\Users\\u')).toBe('C:\\Users\\u\\AppData\\Roaming');
expect(defaultDataRoot('win32', {}, '/home/u')).toBe('/home/u/AppData/Roaming');
});
it('POSIX : ~/.local/share', () => {
expect(defaultDataRoot('linux', {}, '/home/u')).toBe('/home/u/.local/share');
expect(defaultDataRoot('darwin', {}, '/Users/u')).toBe('/Users/u/.local/share');
});
});