Skip to content

Latest commit

 

History

History
90 lines (71 loc) · 4.43 KB

File metadata and controls

90 lines (71 loc) · 4.43 KB

JavaScript source recovery

recover_javascript_sources / recover-javascript-sources derives readable modules from one explicitly selected UTF-8 JavaScript file or bundle. Use it on files returned by export_web_scripts or other local scripts. The operation never executes the selected or recovered application code.

Caller-supplied engine

The initial adapter is verified on Linux x64 with Wakaru 1.13.0. Set REA_WAKARU_COMMAND to the absolute path of an executable supplied by the caller. The adapter uses util-linux prlimit (default /usr/bin/prlimit; override with an absolute REA_JAVASCRIPT_PRLIMIT_COMMAND). REA does not install either tool. Engine configuration is checked only when recovery is requested; other REA capabilities remain available without it.

Unmodified upstream source is retained in third_party/wakaru, pinned to 6070266d24b32951fa2fe1d2dad5b4313bd5c81b (v1.13.0, Apache-2.0). The result reports the executed binary's exact path, SHA-256 and observed version. The audited source revision is distinct from executed_source_revision: null: a version string cannot prove which source produced a caller-supplied binary.

Recover and analyze

rea recover-javascript-sources /tmp/web-scripts/app.js /tmp/recovered-app --json
rea analyze-javascript-application /tmp/recovered-app/modules --json

MCP input:

{
  "path": "/tmp/web-scripts/app.js",
  "output_directory": "/tmp/recovered-app"
}

The output directory must be absent, absolute, and have an existing parent. The source is snapshotted in a private workspace, and the engine writes only to its own staging directory. Reported module paths, input identities, UTF-8 byte ranges, regular files and emitted map representations are validated before publication. REA writes verified bytes to an exclusively owned output tree and rolls it back on failure. It also checks that the original source and engine bytes remain unchanged before committing. The existing output is never overwritten.

Published contents:

  • inputs/bundle.js: exact original snapshot; its digest binds the Evidence.
  • modules/: derived modules and any upstream-emitted source maps.
  • reports/stdout.json and reports/provenance.json: exact producer reports.
  • manifest.json: identities, modules, transform choices, warnings and limitations.

The inline result includes complete file paths/digests/sizes, extraction ranges, warnings and analysis_input, directly usable as the arguments to analyze_javascript_application. Raw Evidence retains selected command arguments, reported input paths, exit status, stderr and reports; temporary paths are recorded as historical execution coordinates after their workspace is removed.

Transform choices and interpretation

extraction_mode defaults to structural (Wakaru --unpack=strict). heuristic uses --unpack=auto; inspection uses --unpack=inspect and can return finer, non-executable regions. rewrite_level accepts minimal, standard (default) and aggressive. Maps and provenance are requested in every operation.

Structural extraction can fall back to a single file. In the real fixtures, webpack 5 yields two modules; the esbuild scope-hoisted fixture remains one unknown-format script. Returned module counts and detected formats report those actual outcomes. A valid report with failed transformations returns partial with original warnings and files. An unusable report, inconsistent provenance, escaping path, symlink or missing module is an error, with owned cleanup.

Evidence confidence is derived. Extraction ranges are half-open UTF-8 byte offsets in the original snapshot, rather than rewritten line positions or a coverage assertion. Source maps are preserved without claiming independently verified mapping accuracy. Original variable names and arbitrary runtime equivalence remain unknown. No network fetching occurs.

Resource policy and verification

Each operation uses one worker, a 1 GiB address-space ceiling and a 120-second deadline; it accepts up to 64 MiB of input and 128 MiB/10000 entries of staged output, with 8 MiB per diagnostic/report stream. Exceeding a limit is an explicit failure with rollback. These limits apply per operation and do not claim aggregate host containment across concurrent callers.

See testing.md for the focused real Wakaru CLI/MCP lane and its source-owned compiler fixtures. Other host platforms and Bun/Vue recovery are not claimed by this adapter.