fix(lsp): address codex review round 3

Final review pass on the local provider:
- Tear the instance down when `initialize` REJECTS (utf-8 negotiation, malformed
  result), not only on abort, so a permanently-rejecting `ready` is never pooled.
- Use the group-aware SIGKILL on a framing failure so helpers are reached.
- Validate maxMessageBytes and maxDocumentBytes positive at load alongside the
  other byte caps.
- Fix the location renderer's outside-workspace check to match a `..` segment
  exactly, so an in-workspace path like `..generated/a.ts` stays relative.
- Document the accepted ancestor-directory symlink-swap TOCTOU under the
  trusted-host model (O_NOFOLLOW guards only the final component).
This commit is contained in:
Dudu-0223
2026-07-16 14:17:21 +08:00
parent 0f3f0efd9c
commit 43d419ac5c
7 changed files with 35 additions and 11 deletions

View File

@@ -114,8 +114,12 @@ export function apply(ctx: Context, config: Config): void {
// nonpositive value would let a server that ignores shutdown hang disposal forever. Fail at load.
assertPositiveInteger('shutdownTimeoutMs', resolved.shutdownTimeoutMs)
assertPositiveInteger('killGraceMs', resolved.killGraceMs)
// A nonpositive stderr cap defeats the retained-tail bound (`slice(-0)` keeps everything).
// Byte caps must be positive: a nonpositive stderr cap defeats the retained-tail bound
// (`slice(-0)` keeps everything), `maxMessageBytes: 0` makes every response fatal, and a bad
// document cap fails later in the read path instead of at load.
assertPositiveInteger('maxStderrBytes', resolved.maxStderrBytes)
assertPositiveInteger('maxMessageBytes', resolved.maxMessageBytes)
assertPositiveInteger('maxDocumentBytes', resolved.maxDocumentBytes)
const childEnv = buildChildEnv(resolved.env)
// Resolve the executable eagerly so a misconfigured command fails at load, not on first query.
const executable = resolveExecutable(resolved.command, childEnv)