Skip to content

Commit a81df4c

Browse files
committed
fix(sea): escape embedded fuse literals before injection
1 parent 00a8c87 commit a81df4c

2 files changed

Lines changed: 11 additions & 4 deletions

File tree

‎scripts/repo/cli-build/sea/build.mts‎

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,11 @@ import { resolveSeaTarget, SEA_TARGETS } from './targets.mts'
2323
const logger = getDefaultLogger()
2424

2525
export function createSeaEntry(payload: string): string {
26-
return `const path = require('node:path');\nconst { Module } = require('node:module');\nconst filename = path.resolve(path.dirname(process.env.SMOL_STUB_PATH || process.execPath), '..', 'cli.js');\nconst product = new Module(filename);\nproduct.filename = filename;\nproduct.paths = Module._nodeModulePaths(path.dirname(filename));\nproduct._compile(${JSON.stringify(payload)}, filename);\nproduct.exports.runCliProduct();\n`
26+
const encodedPayload = JSON.stringify(payload).replaceAll(
27+
'NODE_SEA_FUSE',
28+
'NODE_SEA_FU\\u0053E',
29+
)
30+
return `const path = require('node:path');\nconst { Module } = require('node:module');\nconst filename = path.resolve(path.dirname(process.env.SMOL_STUB_PATH || process.execPath), '..', 'cli.js');\nconst product = new Module(filename);\nproduct.filename = filename;\nproduct.paths = Module._nodeModulePaths(path.dirname(filename));\nproduct._compile(${encodedPayload}, filename);\nproduct.exports.runCliProduct();\n`
2731
}
2832

2933
export function createSeaLauncher(): string {

‎test/repo/unit/sea-package.test.mts‎

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,9 @@ describe('SEA package', () => {
3131
)
3232
})
3333
it('executes the embedded payload and starts the product', () => {
34+
const payload = 'NODE_SEA_FUSE_fce680ab2cc467b6e072b8b5df1996b2'
35+
const entry = createSeaEntry(payload)
36+
expect(entry.includes(payload)).toBe(false)
3437
let started = false
3538
let filename = ''
3639
class ProductModule {
@@ -42,12 +45,12 @@ describe('SEA package', () => {
4245
static _nodeModulePaths() {
4346
return []
4447
}
45-
_compile(payload: string, file: string) {
46-
expect(payload).toBe('example payload')
48+
_compile(compiled: string, file: string) {
49+
expect(compiled).toBe(payload)
4750
filename = file
4851
}
4952
}
50-
runInNewContext(createSeaEntry('example payload'), {
53+
runInNewContext(entry, {
5154
process: { execPath: '/example/dist/sea/socket-linux-x64', env: {} },
5255
require(name: string) {
5356
return name === 'node:module'

0 commit comments

Comments
 (0)