Five defects traced to one fact: src/background/index.js read and wrote the module-level `state` singleton in src/shared/state.js, which the MV3 service worker never populates and which answered an unpopulated read out of DEFAULT_STATE in silence. Every previous fix added a loadState() before the access, and that is what produced the fifth: a load detaches the objects an in-flight handler is holding. So the reachability goes rather than a sixth call site. The background now has its own storage layer, src/background/state.js: getState() is a detached, normalized per-call read, and updateState() is a queued read-modify-write whose read is one storage round trip ahead of its write. Nothing in the background holds an in-memory copy of the profile. - Every handler takes one snapshot and answers from it, including the address it names: activeAddressOf(s) replaced a second, later storage read that could disagree with the first. - wallet_switchEthereumChain applies applyChainSwitchFields() (split out of chainSwitch.js, which keeps the singleton path for the popup) inside updateState() instead of calling onChainSwitch() on the singleton. - The remembered site decision is a read-modify-write, not a load-mutate-save around a prompt the user takes seconds to answer. - backgroundRefresh() refreshes a private copy of the wallets and applies the balances that came back by address, so it never publishes an object other in-flight work holds, and a wallet added or deleted during the round trip survives its write. - The transaction attempt takes its chain id and its endpoint from the same snapshot. They used to come from different moments, so a chain switch committed in between moved the endpoint under an artifact already verified against the old chain. getProvider(rpcUrl, networkId) now REQUIRES the network id and validates it against networks.js. That closes the cold-worker wrong-chain send at its shape rather than at one call site: the hint used to default to currentNetwork() off the unpopulated singleton, so the endpoint was the user's chain and ethers fixed chainId at 0x1, and the wallet's own verifySignedTx then refused every non-mainnet dApp send. refreshBalances(), lookupTokenInfo(), scanForAddresses() and resolveEnsName() carry the id through; balances.js no longer requires state.js at all. The prohibition is enforced mechanically, not by review: a custom ESLint rule walks the CommonJS require graph from every src/background/ file and fails the lint when src/shared/state.js is reachable, naming the chain. A re-export from any shared module cannot put the singleton back in the bundle unnoticed. Reading a persisted field of the singleton before any load now throws StateNotLoadedError instead of serving DEFAULT_STATE. Test stubs: chrome.storage.local is a serialization boundary, and eight files stubbed it with an aliasing get, so the object a module held and the object "storage" held were one object — an assertion could pass on a build that never wrote anything. They all go through tests/support/storageStub.js now, which structured-clones in both directions. closes #320
180 lines
6.6 KiB
JavaScript
180 lines
6.6 KiB
JavaScript
// ESLint flat config. Static analysis for make check; formatting stays with
|
|
// prettier (script/fmt-check), so nothing here touches style.
|
|
//
|
|
// The sources are CommonJS and are bundled per entrypoint by build.js, so the
|
|
// globals differ by tree and are declared per tree below. Getting that wrong in
|
|
// either direction defeats the point: too few globals buries a real no-undef in
|
|
// false positives, too many hides the next unimported identifier.
|
|
|
|
const js = require("@eslint/js");
|
|
const globals = require("globals");
|
|
const backgroundState = require("./script/lib/eslint/noStateSingletonInBackground");
|
|
|
|
// The extension APIs. MV3 Chrome exposes `chrome`; Firefox exposes both, and
|
|
// the code feature-detects between them.
|
|
const extensionGlobals = {
|
|
chrome: "readonly",
|
|
browser: "readonly",
|
|
};
|
|
|
|
const commonjs = {
|
|
ecmaVersion: 2024,
|
|
sourceType: "commonjs",
|
|
};
|
|
|
|
module.exports = [
|
|
{
|
|
ignores: ["dist/", "node_modules/"],
|
|
},
|
|
|
|
js.configs.recommended,
|
|
|
|
{
|
|
rules: {
|
|
// The two rules this config exists for. Both are already
|
|
// error-level in the recommended set; restated so a future
|
|
// recommended-set change cannot silently downgrade them.
|
|
"no-undef": "error",
|
|
// `_`-prefixed arguments are the deliberate "present for the
|
|
// interface, unused here" marker: the popup views share one
|
|
// init(ctx) signature and three of the eight do not read ctx.
|
|
// An unused catch binding is written `catch {`, which the repo
|
|
// already does, so caught errors stay checked.
|
|
"no-unused-vars": ["error", { argsIgnorePattern: "^_" }],
|
|
|
|
// Off tree-wide: it requires every rethrow to carry `{ cause }`,
|
|
// at 3 sites today (src/shared/balances.js 207 and 215,
|
|
// tests/e2e/firefox/run.js 131). That is a change to what the
|
|
// wallet's error paths actually throw, and it is a decision of its
|
|
// own rather than a side effect of turning a linter on — so it is
|
|
// off everywhere, including for new code, until that decision is
|
|
// made. Unlike no-useless-assignment below, this is not an
|
|
// accommodation of particular sites and must not be scoped to
|
|
// them.
|
|
"preserve-caught-error": "off",
|
|
},
|
|
},
|
|
|
|
// no-useless-assignment stays on everywhere except the two files that
|
|
// wipe decrypted key material: the `password = null` and
|
|
// `decryptedSecret = null` assignments after use are dead by construction
|
|
// — that is what a best-effort wipe is — and the rule's fix is to delete
|
|
// the wipe. 9 sites: approval.js 582, 593, 618, 648, 692, 703, 728, 764
|
|
// and confirmTx.js 459. Everything else in the tree is still checked, so
|
|
// an ordinary dead store elsewhere is still an error.
|
|
{
|
|
files: ["src/popup/views/approval.js", "src/popup/views/confirmTx.js"],
|
|
rules: {
|
|
"no-useless-assignment": "off",
|
|
},
|
|
},
|
|
|
|
// Popup and content scripts: page/window context.
|
|
{
|
|
files: ["src/popup/**/*.js", "src/content/**/*.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.browser, ...extensionGlobals },
|
|
},
|
|
},
|
|
|
|
// MV3 background: a service worker, with no window and no document.
|
|
//
|
|
// It also may not reach src/shared/state.js. That module's `state` export
|
|
// is a per-bundle singleton loaded once and mutated in place, which is the
|
|
// popup's lifetime and not the worker's: the worker is killed when idle,
|
|
// nothing loads state at module scope, and an unpopulated read used to be
|
|
// served DEFAULT_STATE silently. Five defects came from background code
|
|
// reading or writing it (https://git.eeqj.de/sneak/AutistMask/issues/324),
|
|
// and each point fix added a loadState() that created the next one. The
|
|
// rule below checks reachability through the whole require graph, not just
|
|
// the direct require, because a re-export from any shared module the
|
|
// background already pulls in would put the singleton back in the bundle
|
|
// with no background file naming it.
|
|
{
|
|
files: ["src/background/**/*.js"],
|
|
plugins: { background: backgroundState },
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.serviceworker, ...extensionGlobals },
|
|
},
|
|
rules: {
|
|
"background/no-state-singleton-in-background": "error",
|
|
},
|
|
},
|
|
|
|
// src/shared is bundled into both, so it may only use what both provide:
|
|
// the service worker globals are the intersection, plus the extension APIs.
|
|
{
|
|
files: ["src/shared/**/*.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.serviceworker, ...extensionGlobals },
|
|
},
|
|
},
|
|
|
|
// src/shared/ens.js is the documented exception to the line above: its own
|
|
// header says POPUP ONLY, it caches in localStorage, and only popup views
|
|
// require it. Linting it as a service worker would be wrong about the file.
|
|
{
|
|
files: ["src/shared/ens.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.browser, ...extensionGlobals },
|
|
},
|
|
},
|
|
|
|
// Unit tests, and the helpers they require: jest on node.
|
|
{
|
|
files: ["tests/**/*.test.js", "tests/support/**/*.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.node, ...globals.jest },
|
|
},
|
|
},
|
|
|
|
// The build script is a plain node program.
|
|
{
|
|
files: ["build.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.node },
|
|
},
|
|
},
|
|
|
|
// The helpers the script/ entrypoints call: plain node programs too, run
|
|
// from a shell script rather than from yarn, and never bundled.
|
|
{
|
|
files: ["script/lib/**/*.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.node },
|
|
},
|
|
},
|
|
|
|
// The e2e harnesses are node programs that also carry, inline, the
|
|
// callbacks they ship into the browser via page.evaluate — so both
|
|
// contexts really are present in the same file and both sets of globals
|
|
// are in scope somewhere in it.
|
|
{
|
|
files: ["tests/e2e/**/*.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: {
|
|
...globals.node,
|
|
...globals.browser,
|
|
...extensionGlobals,
|
|
},
|
|
},
|
|
},
|
|
|
|
// This config file itself.
|
|
{
|
|
files: ["eslint.config.js"],
|
|
languageOptions: {
|
|
...commonjs,
|
|
globals: { ...globals.node },
|
|
},
|
|
},
|
|
];
|