diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index 8a9131140..5e28c91fd 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -16,7 +16,7 @@ concurrency: cancel-in-progress: true jobs: - # Static lint: no source-grep tests in the test suite. + # Static lint: test-suite and PR-check contracts. # Runs once (not per matrix node version) since it is a file-content check. lint-tests: runs-on: ubuntu-latest @@ -33,6 +33,9 @@ jobs: - name: Lint — command contract (ADR-0002) shell: bash run: node scripts/lint-command-contract.cjs + - name: Lint — PR checks use projectDir + shell: bash + run: node scripts/lint-pr-check-project-dir.cjs test: runs-on: ${{ matrix.os }} diff --git a/package.json b/package.json index 1f64997f3..0a6ac5075 100644 --- a/package.json +++ b/package.json @@ -71,6 +71,7 @@ "lint:descriptions": "node scripts/lint-descriptions.cjs", "lint:skill-deps": "node scripts/lint-skill-deps.cjs", "lint:tests": "node scripts/lint-no-source-grep.cjs", + "lint:pr-checks": "node scripts/lint-pr-check-project-dir.cjs", "lint:changeset": "node scripts/changeset/lint.cjs", "changeset": "node scripts/changeset/new.cjs", "changelog:render": "node scripts/changeset/cli.cjs render", diff --git a/scripts/lint-pr-check-project-dir.cjs b/scripts/lint-pr-check-project-dir.cjs new file mode 100644 index 000000000..a3fd1a237 --- /dev/null +++ b/scripts/lint-pr-check-project-dir.cjs @@ -0,0 +1,98 @@ +#!/usr/bin/env node +'use strict'; + +const fs = require('fs'); +const path = require('path'); + +const ROOT = path.join(__dirname, '..'); + +const DEFAULT_RELATIVE_FILES = [ + '.github/workflows/test.yml', + '.github/workflows/pr-template-format.yml', + '.github/workflows/changeset-required.yml', + 'scripts/lint-no-source-grep.cjs', + 'scripts/lint-command-contract.cjs', + 'scripts/lint-skill-deps.cjs', + 'scripts/lint-descriptions.cjs', + 'scripts/lint-shell-command-projection-drift.cjs', + 'scripts/pr-template-policy.cjs', + 'scripts/changeset/lint.cjs', +]; + +function defaultFiles(rootDir = ROOT) { + return DEFAULT_RELATIVE_FILES + .map((file) => path.join(rootDir, file)) + .filter((file) => fs.existsSync(file)); +} + +function findForbiddenCwd(content, file = '') { + const findings = []; + const lines = content.split(/\r?\n/); + + lines.forEach((line, index) => { + const pattern = /\bcwd\b/g; + let match; + while ((match = pattern.exec(line)) !== null) { + findings.push({ + file, + line: index + 1, + column: match.index + 1, + source: line.trim(), + }); + } + }); + + return findings; +} + +function checkFiles(files, { rootDir = ROOT } = {}) { + const findings = []; + for (const file of files) { + const content = fs.readFileSync(file, 'utf8'); + const rel = path.relative(rootDir, file); + findings.push(...findForbiddenCwd(content, rel)); + } + return findings; +} + +function formatFindings(findings) { + const lines = [ + `ERROR lint-pr-check-project-dir: ${findings.length} forbidden cwd reference(s) found`, + '', + 'PR checkers must use projectDir for project roots; cwd is forbidden in this layer.', + '', + ]; + + for (const finding of findings) { + lines.push(` ${finding.file}:${finding.line}:${finding.column}`); + lines.push(` ${finding.source}`); + } + + return `${lines.join('\n')}\n`; +} + +function main(argv = process.argv.slice(2)) { + const files = argv.length > 0 ? argv.map((file) => path.resolve(file)) : defaultFiles(); + const findings = checkFiles(files); + + if (findings.length === 0) { + console.log(`ok lint-pr-check-project-dir: ${files.length} PR check files checked`); + return 0; + } + + process.stderr.write(formatFindings(findings)); + return 1; +} + +if (require.main === module) { + process.exit(main()); +} + +module.exports = { + DEFAULT_RELATIVE_FILES, + checkFiles, + defaultFiles, + findForbiddenCwd, + formatFindings, + main, +}; diff --git a/tests/feat-3251-command-aliases-manifest-coverage.test.cjs b/tests/feat-3251-command-aliases-manifest-coverage.test.cjs index 9904b2080..1003b0fc4 100644 --- a/tests/feat-3251-command-aliases-manifest-coverage.test.cjs +++ b/tests/feat-3251-command-aliases-manifest-coverage.test.cjs @@ -137,9 +137,9 @@ function createProject() { return dir; } -function runGsdTools(args, cwd) { +function runGsdTools(args, projectDir) { return spawnSync(process.execPath, [GSD_TOOLS, ...args], { - cwd, + cwd: projectDir, encoding: 'utf8', }); } diff --git a/tests/lint-pr-check-project-dir.test.cjs b/tests/lint-pr-check-project-dir.test.cjs new file mode 100644 index 000000000..cae74d40e --- /dev/null +++ b/tests/lint-pr-check-project-dir.test.cjs @@ -0,0 +1,121 @@ +'use strict'; + +const { describe, test } = require('node:test'); +const assert = require('node:assert/strict'); +const fs = require('fs'); +const os = require('os'); +const path = require('path'); +const { spawnSync } = require('child_process'); + +const ROOT = path.join(__dirname, '..'); +const LINT_SCRIPT = path.join(ROOT, 'scripts', 'lint-pr-check-project-dir.cjs'); + +const { + checkFiles, + defaultFiles, + findForbiddenCwd, + formatFindings, +} = require(LINT_SCRIPT); + +function createFixtureDir() { + return fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-pr-check-lint-')); +} + +function runLint(args = []) { + return spawnSync(process.execPath, [LINT_SCRIPT, ...args], { encoding: 'utf8' }); +} + +describe('lint-pr-check-project-dir', () => { + test('flags cwd parameters and shorthand properties', () => { + const findings = findForbiddenCwd( + [ + 'function runCheck(args, cwd) {', + ' return spawnSync(process.execPath, args, { cwd });', + '}', + ].join('\n'), + 'fixture.cjs', + ); + + assert.deepEqual( + findings.map((finding) => [finding.line, finding.column]), + [ + [1, 25], + [2, 46], + ], + ); + }); + + test('flags cwd option keys even when the value is projectDir', () => { + const findings = findForbiddenCwd( + [ + 'function runCheck(args, projectDir) {', + ' return spawnSync(process.execPath, args, { cwd: projectDir });', + '}', + ].join('\n'), + 'fixture.cjs', + ); + + assert.deepEqual(findings, [ + { + file: 'fixture.cjs', + line: 2, + column: 46, + source: 'return spawnSync(process.execPath, args, { cwd: projectDir });', + }, + ]); + }); + + test('allows projectDir project-root naming without cwd references', () => { + const findings = findForbiddenCwd( + [ + 'function checkProject(args, projectDir) {', + ' return runProjectCheck(args, projectDir);', + '}', + ].join('\n'), + 'fixture.cjs', + ); + + assert.deepEqual(findings, []); + }); + + test('formats diagnostics with file, line, and source', () => { + const output = formatFindings([ + { + file: 'scripts/example.cjs', + line: 12, + column: 7, + source: 'const cwd = projectDir;', + }, + ]); + + assert.match(output, /ERROR lint-pr-check-project-dir: 1 forbidden cwd reference/); + assert.match(output, /scripts\/example\.cjs:12:7/); + assert.match(output, /const cwd = projectDir;/); + assert.match(output, /projectDir/); + }); + + test('checks the real PR-check files without violations', () => { + const files = defaultFiles(ROOT); + assert.ok(files.length > 0, 'expected default PR-check files'); + assert.deepEqual(checkFiles(files, { rootDir: ROOT }), []); + }); + + test('CLI exits non-zero when a passed file contains cwd', () => { + const dir = createFixtureDir(); + try { + const file = path.join(dir, 'bad-check.cjs'); + fs.writeFileSync(file, 'const cwd = process.env.PROJECT_DIR;\n'); + + const result = runLint([file]); + + assert.notStrictEqual(result.status, 0); + } finally { + fs.rmSync(dir, { recursive: true, force: true }); + } + }); + + test('script parses without syntax errors', () => { + const result = spawnSync(process.execPath, ['--check', LINT_SCRIPT], { encoding: 'utf8' }); + assert.strictEqual(result.status, 0, result.stderr); + }); +});