From 94f99beb65442b74382bc4bb9ebc9611f6f830e8 Mon Sep 17 00:00:00 2001 From: Dave Date: Mon, 15 Jun 2026 22:38:50 -0400 Subject: [PATCH] enhance(#1279): add isNodeTestRed + violationFixture field - isNodeTestRed(out): pure helper, true iff TAP # fail >= 1 (mutation-pinned >= 1 boundary) - CheckDescriptor.violationFixture?: author-supplied known-bad subject for fail-first proof --- src/prohibition-enforcement.cts | 20 ++++++++++++++++++++ 1 file changed, 20 insertions(+) diff --git a/src/prohibition-enforcement.cts b/src/prohibition-enforcement.cts index b55bac702..9e9d487fb 100644 --- a/src/prohibition-enforcement.cts +++ b/src/prohibition-enforcement.cts @@ -64,6 +64,15 @@ export interface CheckDescriptor { target: string; rule?: string; failFirst?: boolean; + /** + * Author-supplied path to a KNOWN-BAD subject the prover runs the check against to machine-prove + * the check is fail-first (#1279). For `lint-rule`: a file whose content violates `rule` (the + * prover lints it and requires the rule id to appear). For `node-test`: a subject the negative + * test exercises via the `GSD_PROHIB_SUBJECT` env convention, expected to drive the test RED. + * A generic producer cannot synthesize a violation for an arbitrary check, so this is required to + * prove fail-first; ABSENT for node-test → the default prover fails closed (never attestation). + */ + violationFixture?: string; } /** @@ -162,6 +171,17 @@ export function parseNodeTestSummary(out: string): { tests: number; pass: number }; } +/** + * Pure: did a `node --test` run go RED on the violation fixture? True iff the TAP summary reports at + * least one failure (`# fail >= 1`). The default node-test prover requires this — a negative test + * that does NOT go red against a known-bad subject is toothless and must not prove fail-first. + * Mutation-pinned (`>= 1` boundary): a mutant flipping `>=`→`>` (or the threshold) is caught by the + * `# fail 1` unit case. An unparseable summary yields `fail: 0` → false (fail-closed for the prover). + */ +export function isNodeTestRed(out: string): boolean { + return parseNodeTestSummary(out).fail >= 1; +} + /** The names of REAL (run) tests from TAP `ok N - ` / `not ok N - ` lines. A line with a * `# SKIP` / `# TODO` directive is EXCLUDED — a skipped/todo negative test never executed, so it must * not count toward non-vacuity (#1259 m1). */