fix(#3271): delete 25 duplicated folded test suites and fix three runner defects found doing it (#3285)

* test(#3271): guard against a folded suite appearing twice in one host

Adds local/no-duplicate-fold-marker, an AST rule that reports the second and
every subsequent `folded:<name>` marker in a host file, plus RuleTester cases
and a tree-wide regression assertion.

Failing-first on purpose: the rule is registered at error and the 25 duplicated
regions are still present, so eslint and the new tree-wide test are RED. The
deletions land in the next commit.

The marker key is the whitespace-delimited token after `folded:` — not the
issue's `[a-z0-9-]*` slice, which truncates at `.` and false-positives on
tests/model-resolver.test.cjs where feat-443-effort-fast-mode.integration and
feat-443-effort-fast-mode are two distinct folded suites.

Refs #3271

* fix(#3271): delete 25 duplicated folded suites from three install hosts

Three consolidated install suites each carried a verbatim second copy of a
contiguous run of #1969 B1 folded blocks. Byte-identical, constant offset, and
green — each duplicated block registered and ran twice on every lane.

  tests/install.test.cjs                   5981-9937  (3957 lines, 18 blocks)
  tests/install-minimal-hooks.test.cjs     2734-4015  (1282 lines,  5 blocks)
  tests/install-write-confinement.test.cjs 1754-2321  ( 568 lines,  2 blocks)

Introduced by 6d072435d (#1975 re-applying #1970's hunks on a tree that already
had them, 2026-07-03) — one stale-base re-application, three files, one commit.
Verified by marker-count bisect: 1 at 4f779eda4 and 0cc7a1a42, 2 from 6d072435d
onward.

The later copy is deleted in each case, so every file returns to what its
authoring batch produced and blame on the surviving lines stays accurate.
local/no-duplicate-fold-marker, red on the previous commit, is now green.

tests/model-resolver.test.cjs is untouched: the issue lists it, but its two
blocks are folded from two different files and are not identical. It is a false
positive of the issue's own grep, whose `[a-z0-9-]*` key truncates at `.`.

Fixes #3271

* test(#3271): property-test marker identity and pin the alias non-goal

Three review findings, all fixed inline:

1. foldMarkerOf is a parser and carried no fast-check property test. Raised
   independently by the /code-review standards axis and the isolated adversarial
   pass; the file already establishes the fc.property-driving-ruleTester idiom
   for a sibling rule. Added, two arms over markers generated from [a-z0-9-._]:
   the same marker twice always reports exactly once against firstLine 1, and
   two distinct markers never collide. The alphabet includes `.` on purpose —
   an implementation keyed on the issue's [a-z0-9-]* slice passes arm 1 and
   fails arm 2, which is exactly the model-resolver false positive.

2. meta.docs.category was the novel value 'Test hygiene'; all 16 sibling local
   rules use 'Best Practices', 'Portability' or 'Reliability'. Now
   'Best Practices'.

3. A call through a further alias (const d = __foldDescribe) was unreported and
   undocumented — accidental rather than deliberate. It is now the fourth entry
   in the rule's documented non-goals, with the reason, and pinned by a valid
   RuleTester case so it cannot drift silently.

Refs #3271

* test(#3271): name the step and elapsed time when a baseline build fails

buildBaselineAtRef runs four bounded steps and, when one exceeded its bound,
threw a bare "spawnSync ETIMEDOUT" naming neither the step nor how long
anything took. Diagnosing one real failure took four separate experiments to
recover information the throw already had.

Each step is now timed, and any throw carries the breakdown: which step failed,
its elapsed time, the timings of every step that completed before it, all three
bounds, and the tail of the child's captured stdout/stderr.

The failure message is deliberately the carrier. On the remote runner the
captured output field comes back empty in failures.json while error and stack
survive verbatim, so the message is the only channel that reaches a reader of a
remote verdict.

Refs #3271

* fix(#3271): size the baseline generator bound for the machine it runs on

Instrumentation from a real remote-runner failure gave the breakdown:

  git-worktree-add=15.1s  npm-run-build-lib=19.8s  gen-emitted-baseline=FAILED@300.1s

Steps 1 and 2 are comfortable. Only the generator exceeds its bound, and it is
not hung — it needs more than 300s there.

Measured ladder for that step: ~22s idle in a container, ~39s end-to-end in a
clean container, ~142s with 8 CPU burners on 8 cores, and >300s under the real
suite. Its cost is 19 sequential installer spawns, and spawn latency is exactly
where a container degrades worst (3.9x slower than host, against 1.1x for file
IO) — which is why a CPU-only load test did not reproduce it and why four
earlier hypotheses (container slowness, network, shallow clone, CPU contention)
all measured clean.

The 300s bound was sized on an idle machine for a step that never runs on one.
Under the remote runner the on-disk baseline cache is structurally absent — CI
restores it via actions/cache keyed on github.event.pull_request.base.sha, a key
that exists only inside GitHub Actions — so this slow path runs on every remote
verification. The result: this gate has passed 0 times in 754 runs, failing 80
times and never once executing successfully.

Raised to the 600000ms ceiling that local/no-unbounded-spawn treats as the
largest meaningful bound; the other two bounds are untouched. This makes the
gate RUN, which is the point: the alternative considered and rejected was
degrading the timeout to a skip, and that was measured to turn the suite green
with the gate silently not running at all.

The real remedy is making the cache reachable from the remote runner so the
in-job build returns to being the rare fallback ADR-2719 §5 describes. That is a
gsd-test-runner change, not one this repo can make.

Refs #3271

* fix(#3271): tolerate an overlay source that vanishes mid-walk

Observed on the remote runner, three runs across three different branches:

  ENOENT: no such file or directory, link '/work/hooks/dist/gsd-config-reload.js'
    -> '/tmp/gsd-2930-overlay-6nOZay/hooks/dist/gsd-config-reload.js'

buildOverlayRepo enumerates names with readdirSync and then acts on each one, so
statSync, copyFileSync and linkSync all sit in a TOCTOU window. hooks/dist is
regenerated by an ATOMIC REPLACE (scripts/build-hooks.js unlinks and renames), so
any concurrently running test that rebuilds hooks retires a just-listed name
mid-walk and the overlay dies on it. linkOrCopyFile already tolerated EXDEV and
EPERM; ENOENT went straight through.

On ENOENT the source is now re-examined ONCE rather than slept on. An atomic
rename is a single syscall, so by the time the failure surfaces the successor is
either already in place (the retry succeeds) or the path has genuinely left the
tree, in which case there is nothing to mirror and the leaf is skipped. No sleep
and no spin: a timing-based wait here would be the very flake being fixed. Every
other errno still propagates untouched, so a real permission or IO fault stays a
hard failure.

Five tests hold the boundary: gone-for-good skips without retrying, mid-replace
retries exactly once and places the file, EACCES still throws, a real linkSync
ENOENT is injected by monkeypatching fs and restoring it in a finally (never a
mode-bit trick, which root bypasses), and isMissingPath accepts only ENOENT.

Refs #3271

* fix(#3271): order the timeout ladder inward-out and lock it

Two review blockers, both real.

The generator bound had been raised to 600000ms — exactly the whole-chunk timeout
in scripts/run-tests.cjs:973. A step bound equal to the chunk ceiling loses the
race: the chunk is killed first and the failure arrives as an opaque "no failed
step" kill, so the per-step diagnostic added a commit earlier was built and then
made unreachable in the same change.

Separately the #2767 test declared a per-test timeout of 300000ms, BELOW the
inner bound it was meant to permit, so it could still die at the exact 300s
ceiling this was supposed to lift — via node:test's timeout rather than
spawnSync's. Its sibling declared 900000ms, above the chunk ceiling, which is the
same opaque-kill hazard from the other direction.

The three bounds only produce a useful failure if they fire inward-out, so they
now do: step 360s, per-test 480s, chunk 600s. 360s is ~3x the passing observation
(91.6s / 115.8s) and 20% above the censored 300.1s timeout, while leaving 240s of
chunk headroom for every other file sharing it. Four tests lock the ordering,
including a drift guard on the exported values — without it, editing a call
site's literal timeout would leave the ordering assertions passing while the real
ladder inverted.

Also from review:

- err.gsdBaselineStep and err.gsdBaselineTimings were written and never read
  anywhere in the tree; only the rewritten message is consumed. Removed rather
  than kept as speculative surface.
- buildOverlayRepo discarded placeVanishableLeaf's boolean at both call sites, so
  a vanished leaf left the overlay with no accounting at all. It now collects the
  skipped paths and warns once. Not thrown: a source that left the tree really is
  not part of the snapshot, and throwing would reintroduce the crash the
  tolerance removes — but silence would let a dropped leaf resurface later as an
  unrelated missing-file assertion.
- The instrumentation commit shipped no test. One now drives a real failure and
  asserts the message names the step, its elapsed time, and the bounds.

Refs #3271

* chore(#3271): backfill the changeset PR number

* fix(#3271): bound a hook fan-out as its own class, not as a bare probe

CI failure on PR #3285, job full test (windows-latest, 22, shard 2/3) — every
other lane green, including windows-latest node 24 across all three shards:

  not ok 1 - blocks push when any to-be-pushed commit matches local blocked regex
    error: bash .githooks\pre-push failed — outcome=timed_out exitCode=null stderr=
    duration_ms: 15040.2168

A bound, not a hang: the test supplies stdin via input:, so the hook is not
blocked reading its ref list, and the duration lands exactly on the 15000ms
bound.

The site used PROBE_TIMEOUT_MS, which tests/helpers/timeouts.cjs documents as "a
single short CLI query or node -e probe against a temp fixture". This is not
that. It spawns bash running .githooks/pre-push, and the hook then invokes a MOCK
git that is itself a bash script, so one runHook is roughly four Git Bash spawns.
On Windows each is Defender-scanned and the first hook test in a file pays cold
start on top. That module's own docstring warns against precisely this: a call
site that differs from its class must not be forced onto a shared value that does
not describe it.

HOOK_FANOUT_TIMEOUT_MS is that missing class — 60000ms, 4x the bound that failed
and half INSTALL_TIMEOUT_MS, which is the right order: a hook fan-out is much
lighter than a full installer run and far heavier than reading back a version
string. Two tests lock the ordering against both neighbours, including one
asserting real margin over the censored 15040ms observation, since a bound that
merely matched what was measured would be the same defect again.

Scoped deliberately: the other ~360 runHook sites keep their current bounds. This
adds the norm and applies it where a real failure demonstrated the need, rather
than sweeping a value across sites with no evidence for any of them.

Refs #3271

---------

Co-authored-by: sim <sim@local>
This commit is contained in:
Tom Boucher
2026-08-09 23:41:44 -04:00
committed by GitHub
parent 95d0da9060
commit c28134ab39
18 changed files with 1435 additions and 6242 deletions

View File

@@ -0,0 +1,5 @@
---
type: Fixed
pr: 3285
---
**Twenty-five folded test suites no longer run twice on every CI lane** — three consolidated install suites each carried a verbatim second copy of a contiguous run of folded regression blocks (~5,800 lines), left behind by a stale-base re-application during the test-consolidation epic. Every duplicated block registered and passed twice, so nothing reported it, and a contributor fixing one of those regressions could edit one copy and leave the other asserting the old behavior with the suite still green. The duplicates are deleted, and a new `local/no-duplicate-fold-marker` ESLint rule fails the build if a folded suite ever appears twice in one host file again. (#3271)

View File

@@ -511,6 +511,8 @@ The prompt-level data/instruction isolation seam for untrusted web/document ingr
`RULESET.TESTS.no-source-grep=local/no-source-grep ESLint AST rule (eslint-rules/no-source-grep.cjs) rejects readFileSync of a source .cjs/.js/.ts path bound to a var later hit with .includes()/.match()/.startsWith()/.endsWith()/.indexOf()/.search(); error in tests/**/*.test.cjs, warn in gsd-core/bin/**/*.cjs + scripts/**/*.cjs (ADR 452 retired the old regex script, removed for good in #632)`
`RULESET.TESTS.no-source-grep.exemption=// allow-test-rule: <runtime-contract-is-the-product> with one-line justification; reserved for tests where the file content IS the product surface (STATE.md, config.toml, hooks.json, agent .md). Migration to typed-IR parser tracked in #2974.`
`RULESET.TESTS.no-source-grep.tmp-file-traps=reading tmp files written by the SUT in tests still trips lint; round-trip through CLI (e.g. frontmatter get) instead of readFileSync+.includes()`
`RULESET.TESTS.no-duplicate-fold-marker=local/no-duplicate-fold-marker ESLint AST rule (eslint-rules/no-duplicate-fold-marker.cjs, #3271) reports the 2nd and every later __foldDescribe("folded:<marker> ...") call carrying a marker already seen in the SAME file, naming the first occurrence's line; error in tests/**/*.cjs. The key is the WHITESPACE-delimited token after folded:, NOT a [a-z0-9-]* slice — a slice truncates at "." and collides feat-443-effort-fast-mode.integration with feat-443-effort-fast-mode (two distinct suites coexisting in tests/model-resolver.test.cjs), and NOT the whole title, so a re-fold under a different batch label ("B1 #1970" vs "B5 #1975") is still caught. Deliberately silent on: a __foldDescribe title with no folded: prefix (the alias is reused for one ordinary describe in tests/review-default-reviewers-workflow.test.cjs), a plain describe(), a non-literal title, and the same marker in two DIFFERENT files (the defect class is intra-file).`
`RULESET.TESTS.no-duplicate-fold-marker.why=consolidation epic #1969 folds are self-contained blocks, so a second verbatim copy parses, registers and PASSES twice — nothing reports it; #3271 found 25 such copies (~5,800 lines) in tests/install.test.cjs (18), tests/install-minimal-hooks.test.cjs (5) and tests/install-write-confinement.test.cjs (2), all from one stale-base re-application in 6d072435d (#1975 re-applying #1970's hunks, 2026-07-03). Ref DEFECT.GENERATIVE-FIX: the two copies drift apart silently when a contributor fixes one and leaves the other asserting the old behavior, with the suite still green.`
`RULESET.TESTS.escape-regex=new RegExp("prefix${var}") must escapeRegex(var); phase-id.cjs exports escapeRegex (core.cjs re-export spine retired in epic #1267); phase IDs like 5.1 contain . which is metacharacter`
`RULESET.TESTS.no-dead-regex-in-includes=src.includes("foo.*bar") is always false — .* is regex metacharacter not wildcard; use new RegExp(...).test(src) or delete`

View File

@@ -1,6 +1,6 @@
{
"schemaVersion": 1,
"count": 426,
"count": 428,
"classes": {
"ARCH": 1,
"CI": 2,
@@ -18,7 +18,7 @@
"PROC": 14,
"PROHIB": 10,
"RELEASE-NOTES": 31,
"RULESET": 55,
"RULESET": 57,
"SESSION": 9,
"WAVE": 5,
"WORKSTREAM": 5,
@@ -1940,6 +1940,16 @@
"klass": "RULESET",
"value": "src.includes(\"foo.*bar\") is always false — .* is regex metacharacter not wildcard; use new RegExp(...).test(src) or delete"
},
{
"id": "RULESET.TESTS.no-duplicate-fold-marker",
"klass": "RULESET",
"value": "local/no-duplicate-fold-marker ESLint AST rule (eslint-rules/no-duplicate-fold-marker.cjs, #3271) reports the 2nd and every later __foldDescribe(\"folded:<marker> ...\") call carrying a marker already seen in the SAME file, naming the first occurrence's line; error in tests/**/*.cjs. The key is the WHITESPACE-delimited token after folded:, NOT a [a-z0-9-]* slice — a slice truncates at \".\" and collides feat-443-effort-fast-mode.integration with feat-443-effort-fast-mode (two distinct suites coexisting in tests/model-resolver.test.cjs), and NOT the whole title, so a re-fold under a different batch label (\"B1 #1970\" vs \"B5 #1975\") is still caught. Deliberately silent on: a __foldDescribe title with no folded: prefix (the alias is reused for one ordinary describe in tests/review-default-reviewers-workflow.test.cjs), a plain describe(), a non-literal title, and the same marker in two DIFFERENT files (the defect class is intra-file)."
},
{
"id": "RULESET.TESTS.no-duplicate-fold-marker.why",
"klass": "RULESET",
"value": "consolidation epic #1969 folds are self-contained blocks, so a second verbatim copy parses, registers and PASSES twice — nothing reports it; #3271 found 25 such copies (~5,800 lines) in tests/install.test.cjs (18), tests/install-minimal-hooks.test.cjs (5) and tests/install-write-confinement.test.cjs (2), all from one stale-base re-application in 6d072435d (#1975 re-applying #1970's hunks, 2026-07-03). Ref DEFECT.GENERATIVE-FIX: the two copies drift apart silently when a contributor fixes one and leaves the other asserting the old behavior, with the suite still green."
},
{
"id": "RULESET.TESTS.no-source-grep",
"klass": "RULESET",

View File

@@ -55,6 +55,45 @@ identity ratchet (`npm run lint:regression-names`, part of `npm run lint:ci`):
`docs/INVENTORY.md`) must be regenerated **after** rebasing, never carried
through a rebase.
### A folded suite may appear only once per host
When a standalone file is folded into its owning module's test file, the moved
suite is wrapped in a self-contained block carrying a marker:
```javascript
// ────────────────────────────────────────────────────────────────────────
// Folded from tests/bug-376-claude-js-hook-gsd-rewriter.test.cjs — …
// ────────────────────────────────────────────────────────────────────────
{
const { describe: __foldDescribe } = require('node:test');
__foldDescribe("folded:bug-376-claude-js-hook-gsd-rewriter (…)", () => { … });
}
```
Because the block is self-contained, a **second verbatim copy in the same host
parses, registers, and passes — twice.** Nothing in a green suite reports it.
[#3271](https://github.com/open-gsd/gsd-core/issues/3271) found 25 such copies
(~5,800 lines) across three install suites, all from a single stale-base
re-application during the consolidation epic. The cost is not only wasted CI on
every lane: it is a `DEFECT.GENERATIVE-FIX` trap, because a contributor fixing
one of those regressions edits the copy they found and leaves the other
asserting the old behavior, with the suite still green.
`local/no-duplicate-fold-marker` (`eslint-rules/no-duplicate-fold-marker.cjs`,
error under `tests/**/*.cjs`) reports the second and every later occurrence of a
`folded:<marker>` title in one file, naming the line the first occurrence sits
on. **When it fires, delete the copy it points at** — the two blocks are the
same suite, so the fix is removal, never an `eslint-disable`.
It keys on the whitespace-delimited token after `folded:`, which matters in both
directions. A narrower key that stops at `.` would collide
`feat-443-effort-fast-mode.integration` with `feat-443-effort-fast-mode` — two
genuinely distinct suites that coexist in `tests/model-resolver.test.cjs`. Keying
on the *whole* title instead would let a re-fold under a different batch label
slip through, which is exactly the shape #3271 took. Titles without a `folded:`
prefix, non-literal titles, and the same marker appearing in two *different* host
files are all left alone.
The ratchet deliberately covers only `bug-*`. Files named `feat-NNNN-*` /
`enh-NNNN-*` are *feature* test files — one (or one per suite) per feature is
the sanctioned layout (see the #443 strategy below), not a one-off regression

View File

@@ -0,0 +1,184 @@
'use strict';
/**
* no-duplicate-fold-marker
*
* Flag a `folded:<name>` marker that appears more than once in the same file.
*
* Consolidation epic #1969 moved standalone regression suites into shared host
* files. Each moved suite is wrapped in a self-contained block:
*
* // ──────────────────────────────────────────────────────────────────────
* // Folded from tests/bug-376-claude-js-hook-gsd-rewriter.test.cjs — …
* // ──────────────────────────────────────────────────────────────────────
* {
* const { describe: __foldDescribe } = require('node:test');
* __foldDescribe("folded:bug-376-claude-js-hook-gsd-rewriter (… B1 #1970)", () => {
* …
* });
* }
*
* Because each block is self-contained, a second verbatim copy in the same host
* parses, registers, and PASSES — twice. Nothing reports it. #3271 found 25 such
* copies (~5,800 lines) across three suites, all introduced by one stale-base
* re-application in `6d072435d` (#1975 re-applying #1970's hunks).
*
* Two concrete costs, both invisible to a green suite:
* 1. Every duplicated block executes twice on every lane of the matrix.
* 2. DEFECT.GENERATIVE-FIX — a contributor fixing one of these regressions
* edits the copy they found and leaves the other asserting the old
* behavior. The suite stays green while the two copies disagree.
*
* ── What is keyed ─────────────────────────────────────────────────────────────
*
* The marker is the WHITESPACE-DELIMITED token after `folded:` in the title
* literal passed to the fold alias — NOT the whole title, and NOT a
* `[a-z0-9-]*` slice of it.
*
* "folded:bug-376-claude-js-hook-gsd-rewriter (consolidation epic #1969 B1 #1970)"
* → marker `bug-376-claude-js-hook-gsd-rewriter`
*
* Both halves of that definition are load-bearing:
*
* (a) Stopping at whitespace and NOT at `.` keeps
* `feat-443-effort-fast-mode.integration` distinct from
* `feat-443-effort-fast-mode`. Those are two different folded suites that
* coexist in tests/model-resolver.test.cjs; a `[a-z0-9-]*` key collides
* them and reports a duplicate that does not exist (#3271's own
* reproduction command has this bug).
*
* (b) Keying on the marker rather than the full title means a re-fold under a
* different batch label ("… B1 #1970" vs "… B5 #1975") is still caught.
* The batch label is provenance, not identity.
*
* ── What is deliberately NOT flagged ──────────────────────────────────────────
*
* - A `__foldDescribe` title without a `folded:` prefix. The alias is reused
* for at least one ordinary describe block
* (tests/review-default-reviewers-workflow.test.cjs). Those are not folds
* and carry no uniqueness obligation.
* - A plain `describe("folded:…")`. The convention this rule enforces is the
* fold alias; a bare `describe` with a colliding title is a different
* (and currently non-existent) shape.
* - A non-literal title (`__foldDescribe(name, …)`, template literal with a
* substitution). Nothing can be proven about it statically, so it is
* skipped rather than guessed at.
* - The SAME marker in two DIFFERENT files. The defect class is intra-file
* duplication — one host running one suite twice. Cross-file reuse would be
* a different question and is not decided here.
* - A call through an ALIAS of the alias (`const d = __foldDescribe; d("folded:a …")`).
* The rule keys on the callee identifier being literally `__foldDescribe`;
* resolving a further alias through scope would buy nothing today — every
* one of the 365 fold sites in the tree calls the alias directly, and zero
* rebind it — while adding a scope walk to a rule that currently needs none.
* If a rebinding ever appears, it is the rebinding that is the anomaly.
*
* The rule reports the SECOND and every subsequent occurrence, never the first,
* and names the line the first occurrence sits on — so the failure message
* points at both ends of the duplication.
*
* DEFECT category: DEFECT.GENERATIVE-FIX
*/
/** The `describe` alias that consolidation epic #1969 folds are wrapped in. */
const FOLD_ALIAS = '__foldDescribe';
/** Title prefix that marks a folded suite. */
const FOLD_PREFIX = 'folded:';
/**
* Extract the fold marker from a describe title.
*
* Returns the whitespace-delimited token following `folded:`, or null when the
* title is not a fold title (no prefix) or carries an empty marker.
*
* @param {string | null} title
* @returns {string | null}
*/
function foldMarkerOf(title) {
if (typeof title !== 'string') return null;
if (!title.startsWith(FOLD_PREFIX)) return null;
const marker = title.slice(FOLD_PREFIX.length).split(/\s/, 1)[0];
return marker.length > 0 ? marker : null;
}
/** @type {import('eslint').Rule.RuleModule} */
const rule = {
meta: {
type: 'problem',
docs: {
description:
'Disallow the same consolidation-epic folded suite appearing twice in one host file',
category: 'Best Practices',
},
schema: [],
messages: {
duplicateFoldMarker:
'Folded suite "{{marker}}" is already present in this file at line {{firstLine}} ' +
'(DEFECT.GENERATIVE-FIX). A second copy runs the same tests twice on every lane and ' +
'lets the two copies drift apart silently — a contributor fixing the regression edits ' +
'one copy and leaves the other asserting the old behavior, with the suite still green. ' +
'Delete this copy; keep the one at line {{firstLine}}.',
},
},
create(context) {
/**
* marker → line of its first occurrence in this file.
* Rebuilt per file: `create` runs once per linted file.
* @type {Map<string, number>}
*/
const firstSeen = new Map();
/**
* Returns the static string value of a title argument, or null when the
* title is not a plain string literal (identifier, template literal with a
* substitution, computed expression, …).
*
* A substituted template cannot be resolved statically, so it is skipped
* rather than guessed at.
*
* @param {import('eslint').Rule.Node | undefined} node
* @returns {string | null}
*/
function staticTitleOf(node) {
if (!node) return null;
if (node.type === 'Literal') {
return typeof node.value === 'string' ? node.value : null;
}
if (node.type === 'TemplateLiteral') {
// Only a substitution-free template has a knowable value.
if (node.expressions.length !== 0) return null;
if (node.quasis.length !== 1) return null;
return node.quasis[0].value.cooked ?? null;
}
return null;
}
return {
CallExpression(node) {
// Only the fold alias — a bare `describe` is a different convention.
if (node.callee.type !== 'Identifier') return;
if (node.callee.name !== FOLD_ALIAS) return;
if (node.arguments.length === 0) return;
const marker = foldMarkerOf(staticTitleOf(node.arguments[0]));
if (marker === null) return;
const firstLine = firstSeen.get(marker);
if (firstLine === undefined) {
firstSeen.set(marker, node.loc.start.line);
return;
}
context.report({
node: node.arguments[0],
messageId: 'duplicateFoldMarker',
data: { marker, firstLine: String(firstLine) },
});
},
};
},
};
module.exports = rule;

View File

@@ -25,6 +25,7 @@ import requireUserprofileWithHome from './eslint-rules/require-userprofile-with-
import normalizePathInContent from './eslint-rules/normalize-path-in-content.cjs';
import requireFsOpFallback from './eslint-rules/require-fs-op-fallback.cjs';
import noUnboundedSpawn from './eslint-rules/no-unbounded-spawn.cjs';
import noDuplicateFoldMarker from './eslint-rules/no-duplicate-fold-marker.cjs';
const localPlugin = {
rules: {
@@ -44,6 +45,7 @@ const localPlugin = {
'normalize-path-in-content': normalizePathInContent,
'require-fs-op-fallback': requireFsOpFallback,
'no-unbounded-spawn': noUnboundedSpawn,
'no-duplicate-fold-marker': noDuplicateFoldMarker,
},
};
@@ -462,6 +464,9 @@ export default tseslint.config(
// exemption surface. The only sanctioned escapes are an explicit `timeout` on
// a raw spawn or the `// allow-spawn-timeout-ceiling: <reason>` marker.
'local/no-unbounded-spawn': 'error',
// Ban a consolidation-epic folded suite appearing twice in one host file (#3271).
// A second copy runs the same tests twice on every lane and drifts silently.
'local/no-duplicate-fold-marker': 'error',
// Ban raw setTimeout sync + elapsed/duration-style assertions via no-restricted-syntax
'no-restricted-syntax': [
'error',

File diff suppressed because one or more lines are too long

View File

@@ -30,7 +30,7 @@
* 18 affected emitted paths.
*/
const test = require('node:test');
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const os = require('node:os');
@@ -66,6 +66,10 @@ const {
reconcileFamilies,
safeDirArgs,
measuredPackageVersion,
WORKTREE_TIMEOUT_MS,
BUILD_LIB_TIMEOUT_MS,
BUILD_TIMEOUT_MS,
CHUNK_TIMEOUT_CEILING_MS,
} = require('./helpers/emitted-runtime.cjs');
const { EXPECTED_MANIFEST_COUNT, loadManifests } = require('./helpers/emitted-provenance.cjs');
@@ -2345,7 +2349,7 @@ test('an unreadable baseline surfaces an error', () => {
test(
'buildBaselineAtRef resolves a baseline via the in-job build even when the generator '
+ 'script is absent at the ref (#2767 regression)',
{ timeout: 300_000 },
{ timeout: 480_000 },
(t) => {
// Mirrors "differential attribution over the real tree": install output is
// platform-specific on Windows, and this drives the same heavy worktree +
@@ -3005,7 +3009,7 @@ test('property: reported added/dropped are exactly the set differences', () => {
// the working-tree fixtures, which would be whatever this PR's author regenerated;
// comparing against those would be vacuous.
test('differential attribution over the real tree', { timeout: 900_000 }, async (t) => {
test('differential attribution over the real tree', { timeout: 480_000 }, async (t) => {
if (process.platform === 'win32') {
// Mirrors the golden harness: install output is platform-specific on Windows
// (backslash paths), so parity is asserted on macOS + Linux. An explicit t.skip,
@@ -3427,3 +3431,70 @@ test('measuredPackageVersion: resolves this checkout\'s version with no repoRoot
cleanup(unreadableRoot);
}
});
// ── #3271: the timeout ladder must escalate inward-out ──────────────────────────
//
// Three nested bounds govern this file's two heavy tests: the per-STEP bound inside
// buildBaselineAtRef, the per-TEST timeout node:test enforces, and the whole-CHUNK
// timeout in scripts/run-tests.cjs. They only produce a useful failure if they fire
// in that order. When the step bound was raised to the chunk ceiling, the chunk won
// the race and the failure arrived as an opaque "no failed step" kill — the clean
// per-step message was built and then made unreachable in the same change.
describe('#3271: emitted-runtime-bounds', () => {
const PER_TEST_TIMEOUT_MS = 480_000;
test('the step bound fires before the per-test timeout', () => {
assert.ok(
BUILD_TIMEOUT_MS < PER_TEST_TIMEOUT_MS,
`step bound ${BUILD_TIMEOUT_MS}ms must be under the per-test timeout ${PER_TEST_TIMEOUT_MS}ms, ` +
'or node:test kills the test before buildBaselineAtRef can say which step stalled',
);
});
test('the per-test timeout fires before the whole-chunk timeout', () => {
assert.ok(
PER_TEST_TIMEOUT_MS < CHUNK_TIMEOUT_CEILING_MS,
`per-test timeout ${PER_TEST_TIMEOUT_MS}ms must be under the chunk ceiling ` +
`${CHUNK_TIMEOUT_CEILING_MS}ms (scripts/run-tests.cjs:973), or the chunk is killed first ` +
'and the failure is reported with no failing step at all',
);
});
test('a realistic full build still fits inside the per-test timeout', () => {
// Steps 1 and 2 measured at 15.1s and 19.8s on the remote runner. Their own
// bounds (60s + 180s) are worst-case ceilings, not expected cost; asserting on
// the SUM of all three ceilings would demand a per-test timeout larger than the
// chunk allows and lock in an impossible ladder.
const realisticPreamble = 60_000;
assert.ok(
BUILD_TIMEOUT_MS + realisticPreamble < PER_TEST_TIMEOUT_MS,
'the generator bound plus a realistic worktree+build preamble must fit inside the per-test timeout',
);
});
test('the declared bounds are the ones this file actually uses', () => {
// Guards the drift this ladder depends on: if a call site's literal timeout is
// edited without updating PER_TEST_TIMEOUT_MS, the two tests above keep passing
// while the real ladder is inverted. Asserted behaviorally against the helper's
// exported values rather than by scanning source text.
assert.equal(WORKTREE_TIMEOUT_MS, 60_000);
assert.equal(BUILD_LIB_TIMEOUT_MS, 180_000);
assert.equal(BUILD_TIMEOUT_MS, 360_000);
assert.equal(CHUNK_TIMEOUT_CEILING_MS, 600_000);
});
test('a failing step names itself and its elapsed time', () => {
// The message is the only channel that survives into the remote runner's
// failures.json — its captured `output` field comes back empty. A bare
// "spawnSync ETIMEDOUT" cost four separate experiments to re-derive what the
// throw already had.
let thrown;
assert.throws(
() => buildBaselineAtRef('refs/heads/definitely-not-a-real-ref-3271'),
(err) => { thrown = err; return true; },
);
assert.match(thrown.message, /git-worktree-add failed after [\d.]+s/);
assert.match(thrown.message, /Step timings: git-worktree-add=FAILED@[\d.]+s/);
assert.match(thrown.message, /bounds: worktree 60000ms, build:lib 180000ms, generator 360000ms/);
});
});

View File

@@ -13,7 +13,8 @@
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const { RuleTester } = require('eslint');
const { RuleTester, ESLint } = require('eslint');
const path = require('node:path');
const fc = require('fast-check');
const noSourceGrep = require('../eslint-rules/no-source-grep.cjs');
@@ -22,6 +23,7 @@ const noElapsedAssertion = require('../eslint-rules/no-elapsed-assertion.cjs');
const noRawRmsyncInTests = require('../eslint-rules/no-raw-rmsync-in-tests.cjs');
const noTautologicalAssert = require('../eslint-rules/no-tautological-assert.cjs');
const noAdhocMarkdownParsing = require('../eslint-rules/no-adhoc-markdown-parsing.cjs');
const noDuplicateFoldMarker = require('../eslint-rules/no-duplicate-fold-marker.cjs');
const ruleTester = new RuleTester({
languageOptions: {
@@ -1589,3 +1591,374 @@ describe('no-adhoc-markdown-parsing rule', () => {
);
});
});
// ─── no-duplicate-fold-marker ────────────────────────────────────────────────
describe('no-duplicate-fold-marker rule', () => {
const REPO_ROOT = path.join(__dirname, '..');
/** Build a source string whose line numbers are the array indices + 1. */
const src = (...lines) => lines.join('\n');
const FOLD_A_B1 = '__foldDescribe("folded:a (consolidation epic #1969 B1 #1970)", () => {});';
const FOLD_A_B5 = '__foldDescribe("folded:a (consolidation epic #1969 B5 #1975)", () => {});';
const FOLD_B_B1 = '__foldDescribe("folded:b (consolidation epic #1969 B1 #1970)", () => {});';
test('rule module exports a create function', () => {
assert.strictEqual(typeof noDuplicateFoldMarker.create, 'function');
});
// ── Row 1: the #3271 regression, asserted against the real tree ────────────
//
// The unit cases below prove the rule can fire. THIS proves the tree it
// guards is actually clean — it is the assertion that was red before the 25
// duplicated regions were deleted (18 in install.test.cjs, 5 in
// install-minimal-hooks.test.cjs, 2 in install-write-confinement.test.cjs).
//
// Driven through the real ESLint API over the production glob rather than a
// hand-rolled scan of file text: a readFileSync + .match() scan of a .cjs
// path is exactly the shape `local/no-source-grep` bans in tests/**.
test('regression #3271: the real tests/ tree has no duplicate fold markers', async () => {
const eslint = new ESLint({
cwd: REPO_ROOT,
overrideConfigFile: true,
overrideConfig: {
files: ['tests/**/*.cjs'],
plugins: { local: { rules: { 'no-duplicate-fold-marker': noDuplicateFoldMarker } } },
languageOptions: { ecmaVersion: 2022, sourceType: 'commonjs' },
rules: { 'local/no-duplicate-fold-marker': 'error' },
},
});
const results = await eslint.lintFiles(['tests/**/*.cjs']);
// Filter to THIS rule: an ad-hoc config also surfaces "rule not found" for
// inline eslint-disable directives naming rules it does not register.
const violations = results.flatMap((r) =>
r.messages
.filter((m) => m.ruleId === 'local/no-duplicate-fold-marker')
.map((m) => `${path.relative(REPO_ROOT, r.filePath)}:${m.line} ${m.message}`),
);
// Non-vacuous: if the glob silently matched nothing, the empty result below
// would be meaningless.
assert.ok(results.length > 100, `expected the tests/ glob to match many files, got ${results.length}`);
assert.deepStrictEqual(violations, [], `duplicate folded suites found:\n${violations.join('\n')}`);
});
test('the rule is registered at error for tests/**/*.cjs in the real config', async () => {
const eslint = new ESLint({ cwd: REPO_ROOT });
const config = await eslint.calculateConfigForFile(
path.join(REPO_ROOT, 'tests', 'install.test.cjs'),
);
assert.deepStrictEqual(config.rules['local/no-duplicate-fold-marker'], [2]);
});
// ── Occurrence-count boundary: 1 (clean) / 2 (one report) / 3 (two) ────────
test('valid: a single folded marker in a file', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [{ code: src(FOLD_A_B1), filename: 'tests/host.test.cjs' }],
invalid: [],
});
});
test('invalid: the same folded marker twice in one file', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [],
invalid: [
{
code: src(FOLD_A_B1, FOLD_A_B1),
filename: 'tests/host.test.cjs',
errors: [
{ messageId: 'duplicateFoldMarker', data: { marker: 'a', firstLine: '1' }, line: 2 },
],
},
],
});
});
test('invalid: three occurrences report the 2nd and 3rd', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [],
invalid: [
{
code: src(FOLD_A_B1, FOLD_A_B1, FOLD_A_B1),
filename: 'tests/host.test.cjs',
errors: [
{ messageId: 'duplicateFoldMarker', data: { marker: 'a', firstLine: '1' }, line: 2 },
{ messageId: 'duplicateFoldMarker', data: { marker: 'a', firstLine: '1' }, line: 3 },
],
},
],
});
});
test('valid: two distinct folded markers', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [{ code: src(FOLD_A_B1, FOLD_B_B1), filename: 'tests/host.test.cjs' }],
invalid: [],
});
});
// ── Negative space (10-diagnosis.md) ──────────────────────────────────────
// #3271's own reproduction regex (`folded:[a-z0-9-]*`) stops at `.` and
// collides these two genuinely distinct suites, which coexist in
// tests/model-resolver.test.cjs. A guard written to that key would red the
// build on `next` forever.
test('valid: dot-suffixed marker is distinct from its prefix (model-resolver #3271 false positive)', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
'__foldDescribe("folded:feat-443-effort-fast-mode.integration (consolidation epic #1969 B8 #1977)", () => {});',
'__foldDescribe("folded:feat-443-effort-fast-mode (consolidation epic #1969 B8 #1977)", () => {});',
),
filename: 'tests/model-resolver.test.cjs',
},
],
invalid: [],
});
});
// tests/review-default-reviewers-workflow.test.cjs reuses the fold alias for
// an ordinary describe block. Those carry no uniqueness obligation.
test('valid: __foldDescribe titles without a folded: prefix are ignored', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
"__foldDescribe('#1936: OpenCode reviewer empty-output hardening', () => {});",
"__foldDescribe('#1936: OpenCode reviewer empty-output hardening', () => {});",
),
filename: 'tests/host.test.cjs',
},
],
invalid: [],
});
});
test('valid: a file with no fold markers', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [{ code: src('describe("ordinary", () => {});'), filename: 'tests/host.test.cjs' }],
invalid: [],
});
});
test('valid: plain describe with a folded: title is not the fold convention', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
'describe("folded:a (consolidation epic #1969 B1 #1970)", () => {});',
'describe("folded:a (consolidation epic #1969 B1 #1970)", () => {});',
),
filename: 'tests/host.test.cjs',
},
],
invalid: [],
});
});
// Documented non-goal, pinned so the behavior is deliberate rather than
// accidental: the rule keys on the callee identifier being literally
// __foldDescribe. Every one of the 365 fold sites calls it directly.
test('valid: a call through a further alias of the fold alias is not tracked', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
'const d = __foldDescribe;',
'd("folded:a (consolidation epic #1969 B1 #1970)", () => {});',
'd("folded:a (consolidation epic #1969 B1 #1970)", () => {});',
),
filename: 'tests/host.test.cjs',
},
],
invalid: [],
});
});
test('valid: a member-expression call named __foldDescribe is not the fold alias', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
'helpers.__foldDescribe("folded:a (consolidation epic #1969 B1 #1970)", () => {});',
'helpers.__foldDescribe("folded:a (consolidation epic #1969 B1 #1970)", () => {});',
),
filename: 'tests/host.test.cjs',
},
],
invalid: [],
});
});
// The same marker in two different HOST files is not intra-file duplication.
// RuleTester lints each entry as its own file, so this also proves the
// per-file state is rebuilt rather than shared across files.
test('valid: the same marker in two different files is not an intra-file duplicate', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{ code: src(FOLD_A_B1), filename: 'tests/host-one.test.cjs' },
{ code: src(FOLD_A_B1), filename: 'tests/host-two.test.cjs' },
],
invalid: [],
});
});
// ── Ordering / identity ───────────────────────────────────────────────────
test('invalid: interleaved duplicates each report against their own first occurrence', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [],
invalid: [
{
code: src(FOLD_A_B1, FOLD_B_B1, FOLD_A_B1, FOLD_B_B1),
filename: 'tests/host.test.cjs',
errors: [
{ messageId: 'duplicateFoldMarker', data: { marker: 'a', firstLine: '1' }, line: 3 },
{ messageId: 'duplicateFoldMarker', data: { marker: 'b', firstLine: '2' }, line: 4 },
],
},
],
});
});
// The batch label is provenance, not identity — a re-fold under a different
// batch must not evade the guard. This is the exact shape of #3271: #1975
// re-applied #1970's blocks.
test('invalid: a duplicate marker is reported even when the batch label differs', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [],
invalid: [
{
code: src(FOLD_A_B1, FOLD_A_B5),
filename: 'tests/host.test.cjs',
errors: [
{ messageId: 'duplicateFoldMarker', data: { marker: 'a', firstLine: '1' }, line: 2 },
],
},
],
});
});
// ── Title shapes that cannot be resolved statically ───────────────────────
test('invalid: substitution-free template-literal fold titles are resolved', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [],
invalid: [
{
code: src(
'__foldDescribe(`folded:a (consolidation epic #1969 B1 #1970)`, () => {});',
'__foldDescribe(`folded:a (consolidation epic #1969 B1 #1970)`, () => {});',
),
filename: 'tests/host.test.cjs',
errors: [
{ messageId: 'duplicateFoldMarker', data: { marker: 'a', firstLine: '1' }, line: 2 },
],
},
],
});
});
test('valid: non-literal fold titles are skipped without throwing', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
'const name = "folded:a";',
'const x = "a";',
'__foldDescribe(name, () => {});',
'__foldDescribe(name, () => {});',
'__foldDescribe(`folded:${x} (epic)`, () => {});',
'__foldDescribe(`folded:${x} (epic)`, () => {});',
'__foldDescribe(42, () => {});',
'__foldDescribe(42, () => {});',
),
filename: 'tests/host.test.cjs',
},
],
invalid: [],
});
});
test('valid: __foldDescribe with no arguments does not throw', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{ code: src('__foldDescribe();', '__foldDescribe();'), filename: 'tests/host.test.cjs' },
],
invalid: [],
});
});
test('valid: an empty marker after the folded: prefix is not tracked', () => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [
{
code: src(
'__foldDescribe("folded: (consolidation epic #1969 B1 #1970)", () => {});',
'__foldDescribe("folded: (consolidation epic #1969 B1 #1970)", () => {});',
),
filename: 'tests/host.test.cjs',
},
],
invalid: [],
});
});
// Property: marker identity is the whole whitespace-delimited token.
//
// This is the generative form of the #3271 correctness question. An
// implementation that keyed on the issue's `[a-z0-9-]*` slice would truncate
// at `.` and pass arm 1 while failing arm 2 on any pair like
// (`a.integration`, `a`) — which is exactly the tests/model-resolver.test.cjs
// false positive. The alphabet deliberately includes `.` and `_` so those
// pairs are generated, not hoped for.
//
// `fc` is already imported at the top of this file and used by the
// no-adhoc-markdown-parsing suite; this follows the same
// fc.property-driving-ruleTester shape.
test('property: a marker is identified by its whole token, so distinct markers never collide', () => {
const markerArb = fc
.array(fc.constantFrom('a', 'z', 'q', '0', '9', '-', '.', '_'), { minLength: 1, maxLength: 12 })
.map((chars) => chars.join(''));
const fold = (marker) =>
`__foldDescribe("folded:${marker} (consolidation epic #1969 B1 #1970)", () => {});`;
// Arm 1: the SAME marker twice is always reported exactly once, against
// the first occurrence.
fc.assert(
fc.property(markerArb, (marker) => {
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [],
invalid: [
{
code: src(fold(marker), fold(marker)),
filename: 'tests/host.test.cjs',
errors: [
{ messageId: 'duplicateFoldMarker', data: { marker, firstLine: '1' }, line: 2 },
],
},
],
});
}),
{ numRuns: 150, seed: 3271 },
);
// Arm 2: two DISTINCT markers never collide, however they differ.
fc.assert(
fc.property(markerArb, markerArb, (a, b) => {
fc.pre(a !== b);
ruleTester.run('no-duplicate-fold-marker', noDuplicateFoldMarker, {
valid: [{ code: src(fold(a), fold(b)), filename: 'tests/host.test.cjs' }],
invalid: [],
});
}),
{ numRuns: 150, seed: 3271 },
);
});
});

View File

@@ -49,7 +49,7 @@
* Cleanup is via `t.after()` (never `try/finally` in the test body).
*/
const { test } = require('node:test');
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const os = require('node:os');
@@ -58,9 +58,15 @@ const { spawnSync } = require('node:child_process');
const { runNode } = require('./helpers/process-seam.cjs');
const { gitOrThrow } = require('./helpers/git-fixture.cjs');
const { cleanup, readFileNormalized } = require('./helpers.cjs');
const { cleanup, createTempDir, readFileNormalized } = require('./helpers.cjs');
const { RUNTIME_META, installerEnv } = require('./helpers/install-shared.cjs');
const { buildOverlayRepo, REPO_ROOT } = require('./helpers/overlay-repo.cjs');
const {
buildOverlayRepo,
REPO_ROOT,
placeVanishableLeaf,
linkOrCopyFile,
isMissingPath,
} = require('./helpers/overlay-repo.cjs');
// Read each generator's own typed reason enum (never invent/regex a reason
// string) — rows 7 and 12 assert the REAL code below. gen-registry.cjs,
// gen-adr-index.cjs, gen-capability-matrix.cjs, gen-inventory-manifest.cjs
@@ -1289,3 +1295,101 @@ test('regenDerivedPropagatesSingleFragmentEditWithNoSecondSourceSurface', {
cleanup(install.root);
}
});
describe('#3271: an overlay source that vanishes mid-walk', () => {
test('a leaf whose source is GONE is skipped, not fatal', () => {
const dir = createTempDir('gsd-3271-vanish-');
try {
const missing = path.join(dir, 'never-existed.js');
let attempts = 0;
const placed = placeVanishableLeaf(missing, () => {
attempts += 1;
const err = new Error(`ENOENT: no such file or directory, link '${missing}'`);
err.code = 'ENOENT';
throw err;
});
assert.equal(placed, false, 'a source that left the tree is not part of the snapshot');
assert.equal(attempts, 1, 'no retry when the path is genuinely gone');
} finally {
cleanup(dir);
}
});
test('a leaf mid-atomic-replace is retried once and placed', () => {
// The real shape: scripts/build-hooks.js unlinks and renames, so the name is
// briefly absent and then live again. The first attempt sees ENOENT; by the
// time we re-examine, the successor is in place.
const dir = createTempDir('gsd-3271-replace-');
try {
const src = path.join(dir, 'gsd-config-reload.js');
fs.writeFileSync(src, 'module.exports = 1;\n');
let attempts = 0;
const placed = placeVanishableLeaf(src, () => {
attempts += 1;
if (attempts === 1) {
const err = new Error('ENOENT: no such file or directory, link');
err.code = 'ENOENT';
throw err;
}
});
assert.equal(placed, true);
assert.equal(attempts, 2, 'exactly one retry — no spin, no sleep');
} finally {
cleanup(dir);
}
});
test('a non-ENOENT failure still propagates', () => {
const dir = createTempDir('gsd-3271-eacces-');
try {
assert.throws(
() => placeVanishableLeaf(dir, () => {
const err = new Error('EACCES: permission denied');
err.code = 'EACCES';
throw err;
}),
/EACCES/,
'only a vanished source is tolerable; every other error is a real defect',
);
} finally {
cleanup(dir);
}
});
test('linkOrCopyFile survives a real ENOENT from linkSync when the source is live', () => {
// Monkeypatch fs.linkSync to fail ENOENT exactly once, then restore in a
// finally. Mode-bit tricks are not used on purpose: root bypasses 0o000, so
// such a test passes with zero coverage under root Docker/CI.
const dir = createTempDir('gsd-3271-link-');
const realLinkSync = fs.linkSync;
try {
const src = path.join(dir, 'src.js');
const dest = path.join(dir, 'dest.js');
fs.writeFileSync(src, 'contents\n');
let calls = 0;
fs.linkSync = (...args) => {
calls += 1;
if (calls === 1) {
const err = new Error('ENOENT: no such file or directory, link');
err.code = 'ENOENT';
throw err;
}
return realLinkSync(...args);
};
assert.equal(linkOrCopyFile(src, dest), true);
assert.equal(calls, 2);
assert.equal(fs.readFileSync(dest, 'utf8'), 'contents\n');
} finally {
fs.linkSync = realLinkSync;
cleanup(dir);
}
});
test('isMissingPath accepts only ENOENT', () => {
assert.equal(isMissingPath(Object.assign(new Error('x'), { code: 'ENOENT' })), true);
assert.equal(isMissingPath(Object.assign(new Error('x'), { code: 'EACCES' })), false);
assert.equal(isMissingPath(Object.assign(new Error('x'), { code: 'EXDEV' })), false);
assert.equal(isMissingPath(new Error('plain')), false);
assert.equal(isMissingPath(null), false);
});
});

View File

@@ -668,6 +668,35 @@ function baselineManifestsAtRef(base = 'origin/next') {
* @param {string} [o.cwd] repo to run `git worktree` from AND whose generator measures it
* @returns {object} the parsed baseline artifact ({version, sha, manifests, sizes})
*/
const WORKTREE_TIMEOUT_MS = 60_000;
const BUILD_LIB_TIMEOUT_MS = 180_000;
// 360s for the generator step. NOT the 600000ms `local/no-unbounded-spawn`
// ceiling: `scripts/run-tests.cjs:973` bounds the WHOLE chunk at 600000ms, so a
// step bound equal to it loses the race — the chunk is killed first and the
// failure arrives as an opaque "no failed step" kill instead of the per-step
// message below. The bounds must escalate inward-out, and
// `emitted-runtime-bounds` in tests/emitted-attribution.test.cjs locks that.
//
// Measured for this step: ~22s idle in a container, ~142s with 8 CPU burners on
// 8 cores, 91.6s and 115.8s in the run that passed, and 300.1s in the run that
// timed out (censored — its real need is unknown). 360s is ~3x the passing
// observation and 20% above the censored one, while leaving 240s of chunk
// headroom for every other file sharing the chunk.
//
// The old 300s sat INSIDE that variance band. Under gsd-test this slow path runs
// on every verification, because the on-disk baseline cache is restored by
// actions/cache keyed on github.event.pull_request.base.sha — a key that exists
// only inside GitHub Actions. The real remedy is making that cache reachable from
// the remote runner so the in-job build returns to being the rare fallback
// ADR-2719 §5 describes; that is a gsd-test-runner change, not one this repo can
// make.
const BUILD_TIMEOUT_MS = 360_000;
// Mirrors `scripts/run-tests.cjs:973`'s default. Duplicated deliberately and
// narrowly: the bounds here must be checkable against it, and the alternative is
// reading that script's source, which `local/no-source-grep` bans. The lock test
// names this as the drift risk.
const CHUNK_TIMEOUT_CEILING_MS = 600_000;
function buildBaselineAtRef(ref, { cwd = REPO_ROOT } = {}) {
const worktreeDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-emitted-baseline-wt-'));
// mkdtempSync already created the directory; `git worktree add` requires the
@@ -675,34 +704,59 @@ function buildBaselineAtRef(ref, { cwd = REPO_ROOT } = {}) {
fs.rmdirSync(worktreeDir);
const outFile = path.join(os.tmpdir(), `gsd-emitted-baseline-out-${crypto.randomBytes(8).toString('hex')}.json`);
const WORKTREE_TIMEOUT_MS = 60_000;
const BUILD_LIB_TIMEOUT_MS = 180_000;
const BUILD_TIMEOUT_MS = 300_000;
// Per-step timings, carried into the thrown error. A bare "spawnSync ETIMEDOUT"
// names neither the step nor its elapsed time, which is exactly the information
// needed to tell a slow machine from a hung step — and the failure message is
// the only channel that survives into the remote runner's failures.json.
const timings = [];
const timed = (step, fn) => {
const started = Date.now();
try {
const value = fn();
timings.push(`${step}=${((Date.now() - started) / 1000).toFixed(1)}s`);
return value;
} catch (err) {
const elapsed = ((Date.now() - started) / 1000).toFixed(1);
timings.push(`${step}=FAILED@${elapsed}s`);
const partial = [
err && err.stdout ? `stdout tail: ${String(err.stdout).trim().slice(-400)}` : '',
err && err.stderr ? `stderr tail: ${String(err.stderr).trim().slice(-400)}` : '',
].filter(Boolean).join('\n ');
err.message =
`${step} failed after ${elapsed}s (bounds: worktree ${WORKTREE_TIMEOUT_MS}ms, ` +
`build:lib ${BUILD_LIB_TIMEOUT_MS}ms, generator ${BUILD_TIMEOUT_MS}ms). ` +
`Step timings: ${timings.join(' ')}. ${err.message}` +
(partial ? `\n ${partial}` : '');
throw err;
}
};
try {
execFileSync('git', [...safeDirArgs(cwd), 'worktree', 'add', '--detach', worktreeDir, ref], {
cwd, encoding: 'utf8', timeout: WORKTREE_TIMEOUT_MS, stdio: ['ignore', 'pipe', 'pipe'],
});
timed('git-worktree-add', () =>
execFileSync('git', [...safeDirArgs(cwd), 'worktree', 'add', '--detach', worktreeDir, ref], {
cwd, encoding: 'utf8', timeout: WORKTREE_TIMEOUT_MS, stdio: ['ignore', 'pipe', 'pipe'],
}));
const sharedNodeModules = path.join(cwd, 'node_modules');
if (fs.existsSync(sharedNodeModules)) {
fs.symlinkSync(sharedNodeModules, path.join(worktreeDir, 'node_modules'), 'dir');
}
runNpm(['run', 'build:lib'], {
cwd: worktreeDir, timeout: BUILD_LIB_TIMEOUT_MS, stdio: ['ignore', 'pipe', 'pipe'],
});
timed('npm-run-build-lib', () =>
runNpm(['run', 'build:lib'], {
cwd: worktreeDir, timeout: BUILD_LIB_TIMEOUT_MS, stdio: ['ignore', 'pipe', 'pipe'],
}));
// Run `cwd`'s OWN generator (not the worktree's — see the function doc for why),
// pointed at the worktree as the tree to measure.
execFileSync(
process.execPath,
[path.join(cwd, 'scripts', 'gen-emitted-baseline.cjs'), '--dir', worktreeDir, '--out', outFile],
{ cwd, encoding: 'utf8', timeout: BUILD_TIMEOUT_MS, stdio: ['ignore', 'pipe', 'pipe'] },
);
timed('gen-emitted-baseline', () =>
execFileSync(
process.execPath,
[path.join(cwd, 'scripts', 'gen-emitted-baseline.cjs'), '--dir', worktreeDir, '--out', outFile],
{ cwd, encoding: 'utf8', timeout: BUILD_TIMEOUT_MS, stdio: ['ignore', 'pipe', 'pipe'] },
));
const raw = fs.readFileSync(outFile, 'utf8');
return JSON.parse(raw);
return timed('read-artifact', () => JSON.parse(fs.readFileSync(outFile, 'utf8')));
} finally {
try {
execFileSync('git', [...safeDirArgs(cwd), 'worktree', 'remove', '--force', worktreeDir], {
@@ -926,4 +980,8 @@ module.exports = {
currentManifests,
currentSizes,
readAckFile,
WORKTREE_TIMEOUT_MS,
BUILD_LIB_TIMEOUT_MS,
BUILD_TIMEOUT_MS,
CHUNK_TIMEOUT_CEILING_MS,
};

View File

@@ -58,19 +58,70 @@ const REPO_ROOT = path.join(__dirname, '..', '..');
const OVERLAY_SKIP_TOP = new Set(['node_modules', '.git']);
/**
* True when `err` reports that a path was not there.
*
* @param {unknown} err
* @returns {boolean}
*/
function isMissingPath(err) {
return Boolean(err) && typeof err === 'object' && err.code === 'ENOENT';
}
/**
* Run `attempt` against a source path that another process may be replacing
* underneath the walk, and report whether the leaf was actually placed.
*
* `buildOverlayRepo` enumerates names with `readdirSync` and then acts on them,
* which is a TOCTOU window. It is not theoretical: `hooks/dist` is regenerated
* by an ATOMIC REPLACE (`scripts/build-hooks.js` unlinks and renames), so any
* concurrently running test that rebuilds hooks makes a just-listed name vanish
* mid-walk. That took down three runs on three different branches with a bare
* `ENOENT ... link '/work/hooks/dist/...'`.
*
* On ENOENT the source is re-examined ONCE rather than slept on: an atomic
* rename is a single syscall, so by the time the failure surfaces the successor
* is either already in place (retry succeeds) or the path is genuinely gone from
* the tree (nothing to mirror, so the leaf is skipped). No sleep, no spin — a
* timing-based wait here would be the flake this is fixing, not a fix for it.
*
* Returns false only when the path left the source tree entirely; the overlay
* mirrors the tree, and a file that is no longer in it is not part of the
* snapshot. Every other error propagates untouched.
*
* @param {string} srcPath
* @param {() => void} attempt
* @returns {boolean} whether the leaf was placed
*/
function placeVanishableLeaf(srcPath, attempt) {
try {
attempt();
return true;
} catch (err) {
if (!isMissingPath(err)) throw err;
if (!fs.existsSync(srcPath)) return false;
attempt();
return true;
}
}
/** Hard-link a file, falling back to a real copy only if the two paths sit on
* different filesystems/devices (EXDEV) or linking is denied (EPERM) — both
* cross-platform-legitimate, unlike a symlink's Dirent type-detection gap. */
* cross-platform-legitimate, unlike a symlink's Dirent type-detection gap.
* Returns whether the leaf was placed; false means the source vanished
* mid-walk (see `placeVanishableLeaf`). */
function linkOrCopyFile(src, dest) {
try {
fs.linkSync(src, dest);
} catch (err) {
if (err.code === 'EXDEV' || err.code === 'EPERM') {
fs.copyFileSync(src, dest);
} else {
throw err;
return placeVanishableLeaf(src, () => {
try {
fs.linkSync(src, dest);
} catch (err) {
if (err.code === 'EXDEV' || err.code === 'EPERM') {
fs.copyFileSync(src, dest);
} else {
throw err;
}
}
}
});
}
/**
@@ -95,6 +146,7 @@ function buildOverlayRepo(fileOverrides, opts = {}) {
parts: relPath.split('/'),
content,
}));
const skipped = [];
function place(srcDir, destDir, pending, isTop) {
fs.mkdirSync(destDir, { recursive: true });
@@ -120,21 +172,48 @@ function buildOverlayRepo(fileOverrides, opts = {}) {
// fs.statSync follows symlinks (unlike Dirent.isDirectory()), so a
// symlinked source directory is still recursed as a REAL directory in
// the overlay — the property copyWithPathReplacement itself needs.
if (fs.statSync(srcPath).isDirectory()) {
//
// The stat sits in the same TOCTOU window as the copy/link below: the
// name came from readdirSync, and an atomic replace elsewhere in the tree
// can retire it before we get here.
let srcStat;
try {
srcStat = fs.statSync(srcPath);
} catch (err) {
if (isMissingPath(err)) continue;
throw err;
}
if (srcStat.isDirectory()) {
place(srcPath, destPath, overridden || [], false);
} else if (mode === 'copy') {
// Real independent inode — a write through this path in the overlay
// can never alias back to REPO_ROOT's own tracked file (see
// opts.mode doc above).
fs.copyFileSync(srcPath, destPath);
const placed = placeVanishableLeaf(srcPath, () => fs.copyFileSync(srcPath, destPath));
if (!placed) skipped.push(srcPath);
} else {
linkOrCopyFile(srcPath, destPath);
const placed = linkOrCopyFile(srcPath, destPath);
if (!placed) skipped.push(srcPath);
}
}
}
place(REPO_ROOT, tmpRepo, entries, true);
if (skipped.length > 0) {
// Not thrown: a source that left the tree mid-walk is genuinely not part of
// the snapshot, and failing here would reintroduce the crash this tolerance
// exists to remove. But it must not be SILENT either — a dropped leaf can
// surface later as a confusing "file missing" in an unrelated assertion, or
// as nothing at all for a test that never touches it.
console.warn(
`buildOverlayRepo: ${skipped.length} source file(s) vanished mid-walk and were ` +
`omitted from the overlay (likely a concurrent atomic replace, e.g. hooks/dist):\n ` +
skipped.join('\n '),
);
}
return tmpRepo;
}
module.exports = { buildOverlayRepo, linkOrCopyFile, REPO_ROOT, OVERLAY_SKIP_TOP };
module.exports = { buildOverlayRepo, linkOrCopyFile, placeVanishableLeaf, isMissingPath, REPO_ROOT, OVERLAY_SKIP_TOP };

View File

@@ -30,6 +30,30 @@ const { DEFAULT_GIT_TIMEOUT_MS } = require('./git-fixture.cjs');
*/
const PROBE_TIMEOUT_MS = 15000;
/**
* A git-hook invocation that FANS OUT to nested shell subprocesses — the hook
* itself under `bash`, plus every helper it shells to. The prepush guard is the
* worked example: it runs a mock `git` that is also a bash script, so a single
* `runHook` is roughly four Git Bash spawns.
*
* This is a heavier class than `PROBE_TIMEOUT_MS`, and the difference is
* Windows-shaped. Each spawn there is Defender-scanned, and the first hook test
* in a file pays cold start on top. CI (PR #3285, `full test (windows-latest,
* 22, shard 2/3)`) recorded `outcome=timed_out exitCode=null` at exactly the
* 15000ms probe bound while every other lane — including windows-latest node 24,
* all three shards — passed the same commit. That is a bound sized for the wrong
* class, not a slow machine.
*
* 60000ms is 4x the bound that failed and half `INSTALL_TIMEOUT_MS`, which is
* the right order: a hook fan-out is much lighter than a full installer run but
* far heavier than reading back a version string.
*
* Sites that invoke a hook doing NO subprocess fan-out should stay on
* `PROBE_TIMEOUT_MS` — this norm describes the fan-out shape, not `runHook` in
* general.
*/
const HOOK_FANOUT_TIMEOUT_MS = 60000;
/**
* Git plumbing (rev-parse, branch, log, ...) against a small mkdtemp
* fixture repo. Re-exports `tests/helpers/git-fixture.cjs`'s
@@ -57,6 +81,7 @@ const INSTALL_TIMEOUT_MS = 120000;
module.exports = {
PROBE_TIMEOUT_MS,
HOOK_FANOUT_TIMEOUT_MS,
GIT_TIMEOUT_MS,
BUILD_TIMEOUT_MS,
INSTALL_TIMEOUT_MS,

File diff suppressed because it is too large Load Diff

View File

@@ -1751,574 +1751,6 @@ describe('N3: Windows-separator confinement logic (path.win32 semantics)', () =>
});
}
// ────────────────────────────────────────────────────────────────────────
// Folded from tests/bug-2998-pristine-dir-populated.test.cjs — consolidation epic #1969 (B1 #1970)
// ────────────────────────────────────────────────────────────────────────
{
const { describe: __foldDescribe } = require('node:test');
__foldDescribe("folded:bug-2998-pristine-dir-populated (consolidation epic #1969 B1 #1970)", () => {
'use strict';
process.env.GSD_TEST_MODE = '1';
/**
* Bug #2998: gsd-pristine/ snapshot is documented but never populated by
* the installer. saveLocalPatches declared a pristineDir variable and
* promised "saves pristine copies (from manifest) to gsd-pristine/ to
* enable three-way merge during reapply-patches" -- but no code ever
* wrote to that directory. Effect: the /gsd-reapply-patches Step 5
* verifier (#2972) silently degrades to its over-broad fallback heuristic
* ("every significant backup line"), exactly the silent-success-on-lost-
* content failure mode #2969 was designed to prevent.
*
* Fix: new populatePristineDir({...}) helper runs the install transform
* pipeline (copyWithPathReplacement) into a tmp staging dir, then copies
* out the modified-file paths into gsd-pristine/. saveLocalPatches now
* accepts a pristineCtx and calls the helper when local patches are
* detected.
*/
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const os = require('node:os');
const crypto = require('node:crypto');
const ROOT = path.join(__dirname, '..');
const INSTALL = require(path.join(ROOT, 'bin', 'install.js'));
const { cleanup } = require('./helpers.cjs');
function sha256(content) {
return crypto.createHash('sha256').update(content).digest('hex');
}
describe('Bug #2998: populatePristineDir is exported and writes pristine for modified files', () => {
test('exported as a function', () => {
assert.equal(typeof INSTALL.populatePristineDir, 'function',
'expected populatePristineDir in install.js exports (#2998)');
});
test('returns 0 when no files are modified (no-op)', () => {
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-'));
try {
const written = INSTALL.populatePristineDir({
packageSrc: ROOT,
pristineDir: path.join(tmp, 'gsd-pristine'),
modified: [],
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
assert.equal(written, 0);
} finally {
cleanup(tmp);
}
});
test('writes one pristine file per modified path that exists in source', () => {
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-'));
const pristineDir = path.join(tmp, 'gsd-pristine');
try {
// Pick a real installed-side relPath from the package source. The
// install transforms map source `gsd-core/<rel>` to installed
// `gsd-core/<rel>` for skills-aware runtimes (like claude),
// so the relPath is the same on both sides.
const candidate = path.join('gsd-core', 'workflows', 'reapply-patches.md');
const sourcePath = path.join(ROOT, candidate);
assert.equal(fs.existsSync(sourcePath), true,
`precondition: source file exists at ${candidate}`);
const written = INSTALL.populatePristineDir({
packageSrc: ROOT,
pristineDir,
modified: [candidate],
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
assert.equal(written, 1, 'expected exactly one pristine file written');
const out = path.join(pristineDir, candidate);
assert.equal(fs.existsSync(out), true, `expected pristine file at ${out}`);
// The pristine content should be the transformed version (not raw source):
// copyWithPathReplacement substitutes ~/.claude/ for the runtime path prefix.
// For claude+global, the prefix is $HOME/.claude/ which equals the original,
// so the transform is effectively identity here. We assert the content is a
// non-empty markdown file rather than asserting on transform specifics.
const content = fs.readFileSync(out, 'utf-8');
assert.ok(content.length > 0, 'pristine file should be non-empty');
} finally {
cleanup(tmp);
}
});
test('skips paths not present in source (does not corrupt pristine with stale data)', () => {
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-'));
const pristineDir = path.join(tmp, 'gsd-pristine');
try {
const written = INSTALL.populatePristineDir({
packageSrc: ROOT,
pristineDir,
modified: ['gsd-core/this-path-does-not-exist.md'],
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
assert.equal(written, 0, 'expected zero pristine files for non-existent source paths');
const out = path.join(pristineDir, 'gsd-core/this-path-does-not-exist.md');
assert.equal(fs.existsSync(out), false, 'pristine should not contain ghost paths');
} finally {
cleanup(tmp);
}
});
test('pristine files have stable content (transformations are deterministic)', () => {
// Determinism is what makes the verifier's hash check meaningful:
// backup-meta.json records pristine_hashes computed at this same step,
// so re-running with the same inputs must yield byte-identical files.
const tmp1 = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-d1-'));
const tmp2 = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-d2-'));
try {
const candidate = path.join('gsd-core', 'workflows', 'reapply-patches.md');
const ctx = {
packageSrc: ROOT,
modified: [candidate],
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
};
INSTALL.populatePristineDir(Object.assign({ pristineDir: path.join(tmp1, 'gsd-pristine') }, ctx));
INSTALL.populatePristineDir(Object.assign({ pristineDir: path.join(tmp2, 'gsd-pristine') }, ctx));
const a = fs.readFileSync(path.join(tmp1, 'gsd-pristine', candidate));
const b = fs.readFileSync(path.join(tmp2, 'gsd-pristine', candidate));
assert.equal(sha256(a), sha256(b), 'two runs of the same inputs must yield identical pristine content');
} finally {
cleanup(tmp1);
cleanup(tmp2);
}
});
});
// ─── #3004 CR follow-up: multi-root pristine expansion ─────────────────────
describe('Bug #2998 (#3004 CR): pristine expansion covers every manifest install root', () => {
test('paths under agents/ are staged via copyWithPathReplacement, not silently skipped', () => {
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-multi-'));
const pristineDir = path.join(tmp, 'gsd-pristine');
try {
const candidate = path.join('agents', 'gsd-planner.md');
const sourcePath = path.join(ROOT, candidate);
assert.equal(fs.existsSync(sourcePath), true,
`precondition: source file exists at ${candidate}`);
const written = INSTALL.populatePristineDir({
packageSrc: ROOT,
pristineDir,
modified: [candidate],
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
assert.equal(written, 1, 'expected agents/ path to be staged and copied to pristine');
assert.equal(fs.existsSync(path.join(pristineDir, candidate)), true);
} finally {
cleanup(tmp);
}
});
test('a mix of gsd-core/ and agents/ paths in modified list are all staged', () => {
const tmp = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-2998-mix-'));
const pristineDir = path.join(tmp, 'gsd-pristine');
try {
const a = path.join('gsd-core', 'workflows', 'reapply-patches.md');
const b = path.join('agents', 'gsd-planner.md');
assert.equal(fs.existsSync(path.join(ROOT, a)), true);
assert.equal(fs.existsSync(path.join(ROOT, b)), true);
const written = INSTALL.populatePristineDir({
packageSrc: ROOT,
pristineDir,
modified: [a, b],
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
assert.equal(written, 2, 'expected both top-level dirs to be staged');
assert.equal(fs.existsSync(path.join(pristineDir, a)), true);
assert.equal(fs.existsSync(path.join(pristineDir, b)), true);
} finally {
cleanup(tmp);
}
});
});
describe('Bug #2998: saveLocalPatches no longer leaves the pristineDir variable unused', () => {
test('saveLocalPatches accepts a pristineCtx and exposes the helper for direct testing', () => {
// Structural assertion: the function exists with the new signature shape.
// Behavioral end-to-end is covered by the populatePristineDir tests above
// (that helper is what saveLocalPatches calls internally).
assert.equal(typeof INSTALL.populatePristineDir, 'function');
// The signature for saveLocalPatches isn't exported, but the helper IS,
// and it's the unit of behavior the bug is about. Asserting on the helper
// is the structural-IR equivalent of the no-source-grep convention.
});
});
});
}
// ────────────────────────────────────────────────────────────────────────
// Folded from tests/bug-3407-pristine-stale-content.test.cjs — consolidation epic #1969 (B1 #1970)
// ────────────────────────────────────────────────────────────────────────
{
const { describe: __foldDescribe } = require('node:test');
__foldDescribe("folded:bug-3407-pristine-stale-content (consolidation epic #1969 B1 #1970)", () => {
'use strict';
process.env.GSD_TEST_MODE = '1';
/**
* Bug #3407: Installer leaves stale content in gsd-pristine/
*
* Root cause: populatePristineDir() in saveLocalPatches() snapshots from
* pristineCtx.packageSrc — the NEWLY-downloaded release tree — and writes
* those bytes into gsd-pristine/. For files changed between the old and new
* release, this writes the NEW bytes into the pristine baseline instead of
* the OLD bytes. The three-way-diff verifier then classifies upstream-changed
* lines as user-added → Step 5a gate fails with false FAIL_USER_LINES_MISSING.
*
* The #3657 fix (OK_PRISTINE_DRIFT_DETECTED) was a symptom workaround: the
* verifier detects hash mismatch (backup-meta.json records old-release hash
* but gsd-pristine/ has new-release bytes) and skips to over-broad mode
* instead of false-failing. The root-cause stale write was never fixed.
*
* Fix: when a correctly-populated gsd-pristine/ already exists from the
* previous install (i.e., the file's sha256 matches the originalHash recorded
* in the manifest), preserve it — do NOT wipe and re-populate from the new
* release source. This ensures gsd-pristine/ holds old-release bytes even
* after an upgrade where the file content changed upstream.
*
* Regression contract (byte-comparison):
* After saveLocalPatches() is called with a user-modified file whose
* gsd-pristine/ entry was correctly set by the previous install, the
* gsd-pristine/ file MUST still contain the old-release bytes, not the
* new-release bytes supplied in pristineCtx.packageSrc.
*
* Closes: #3407
*/
const { test, describe, beforeEach } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const os = require('node:os');
const crypto = require('node:crypto');
const ROOT = path.join(__dirname, '..');
const INSTALL = require(path.join(ROOT, 'bin', 'install.js'));
const { cleanup } = require('./helpers.cjs');
const MANIFEST_NAME = 'gsd-file-manifest.json';
const PATCHES_DIR_NAME = 'gsd-local-patches';
function sha256(content) {
return crypto.createHash('sha256').update(content instanceof Buffer ? content : Buffer.from(content)).digest('hex');
}
// ─── Bug #3407: gsd-pristine/ must preserve OLD-release bytes across upgrade ──
describe('Bug #3407: saveLocalPatches preserves old-release pristine across upgrade', () => {
let tmpDir;
let configDir;
let fakeSrcDir;
beforeEach((t) => {
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-3407-'));
configDir = path.join(tmpDir, 'config');
fakeSrcDir = path.join(tmpDir, 'new-release-src');
fs.mkdirSync(configDir, { recursive: true });
fs.mkdirSync(fakeSrcDir, { recursive: true });
t.after(() => {
cleanup(tmpDir);
});
});
/**
* Core regression test.
*
* Timeline:
* Install v1: file content = OLD_RELEASE_CONTENT, gsd-pristine/ROOT_FILE
* = OLD_RELEASE_CONTENT (correctly set by previous install),
* manifest hash = sha256(OLD_RELEASE_CONTENT)
* User edits: configDir/ROOT_FILE = USER_MODIFIED_CONTENT
* Upgrade v2: pristineCtx.packageSrc has NEW_RELEASE_CONTENT for ROOT_FILE
* saveLocalPatches is called before the wipe.
*
* Expected AFTER fix: gsd-pristine/ROOT_FILE still == OLD_RELEASE_CONTENT
* Actual BEFORE fix: gsd-pristine/ROOT_FILE == NEW_RELEASE_CONTENT (stale)
*/
test('gsd-pristine/ retains old-release bytes when upgrading a user-modified file', () => {
const OLD_RELEASE_CONTENT = '# Old Release Content\nThis is v1 pristine.\n';
const NEW_RELEASE_CONTENT = '# New Release Content\nThis is v2 — upstream changed this line.\n';
const USER_MODIFIED_CONTENT = '# Old Release Content\nThis is v1 pristine.\n## User addition\nUser customization here.\n';
const oldHash = sha256(OLD_RELEASE_CONTENT);
// Simulate a root-level installed file. Root-level files in the manifest
// are denoted without a subdirectory (slash-free relPath).
const relPath = 'test-root-file.md';
// Set up configDir: user-modified installed file + manifest recording old hash
fs.writeFileSync(path.join(configDir, relPath), USER_MODIFIED_CONTENT);
fs.writeFileSync(
path.join(configDir, MANIFEST_NAME),
JSON.stringify({ version: '1.0.0', files: { [relPath]: oldHash } }, null, 2)
);
// Set up fakeSrcDir (new release): the file has NEW content
fs.writeFileSync(path.join(fakeSrcDir, relPath), NEW_RELEASE_CONTENT);
// Set up gsd-pristine/ with OLD content (as correctly populated by previous install)
const pristineDir = path.join(configDir, 'gsd-pristine');
fs.mkdirSync(pristineDir, { recursive: true });
fs.writeFileSync(path.join(pristineDir, relPath), OLD_RELEASE_CONTENT);
// Call saveLocalPatches with the new release as packageSrc (the buggy scenario)
INSTALL.saveLocalPatches(configDir, {
packageSrc: fakeSrcDir,
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
// Assert: gsd-pristine/ must still contain OLD-release bytes
const pristineFile = path.join(pristineDir, relPath);
assert.ok(
fs.existsSync(pristineFile),
`gsd-pristine/${relPath} must exist after saveLocalPatches`
);
const actualPristineContent = fs.readFileSync(pristineFile, 'utf8');
assert.equal(
sha256(actualPristineContent),
oldHash,
[
`gsd-pristine/${relPath} must contain OLD-release bytes (sha256=${oldHash.slice(0, 12)}…)`,
`but got sha256=${sha256(actualPristineContent).slice(0, 12)}…`,
`(If equal to sha256(NEW_RELEASE_CONTENT)=${sha256(NEW_RELEASE_CONTENT).slice(0, 12)}… then #3407 is NOT fixed)`,
].join(' ')
);
// Secondary: confirm backup-meta records the old hash (not new)
const backupMeta = JSON.parse(
fs.readFileSync(path.join(configDir, PATCHES_DIR_NAME, 'backup-meta.json'), 'utf8')
);
assert.ok(
Object.prototype.hasOwnProperty.call(backupMeta.pristine_hashes, relPath),
'backup-meta.json must record pristine_hash for modified file'
);
assert.equal(
backupMeta.pristine_hashes[relPath],
oldHash,
'backup-meta.json pristine_hash must equal old-release hash (not new-release hash)'
);
});
/**
* Regression test for Codex finding: when gsd-pristine/ entry is absent
* (e.g., post-buggy-run deletion or first upgrade without prior pristine)
* but the file is UNCHANGED between old and new release, the hash-validated
* regeneration path must restore the pristine entry using new-release source.
*
* When sha256(newReleaseBytesForFile) === originalHash, the file is identical
* between releases — new-release generated bytes ARE the old-release pristine
* and may be safely promoted.
*
* Previously (before the regeneration path was added): missing entries were
* left absent unconditionally, causing permanent over-broad fallback even
* when the file was unchanged upstream.
*/
test('gsd-pristine/ is regenerated for missing entries when file is unchanged between releases', () => {
const SHARED_RELEASE_CONTENT = '# Shared Content\nThis file is identical in v1 and v2.\n';
const USER_MODIFIED_CONTENT = '# Shared Content\nThis file is identical in v1 and v2.\n## User addition\nCustom.\n';
const oldHash = sha256(SHARED_RELEASE_CONTENT);
const relPath = 'test-unchanged-file.md';
// configDir has user-modified file + manifest with old-release hash
fs.writeFileSync(path.join(configDir, relPath), USER_MODIFIED_CONTENT);
fs.writeFileSync(
path.join(configDir, MANIFEST_NAME),
JSON.stringify({ version: '1.0.0', files: { [relPath]: oldHash } }, null, 2)
);
// fakeSrcDir (new release) has the SAME content — file was not changed upstream
fs.writeFileSync(path.join(fakeSrcDir, relPath), SHARED_RELEASE_CONTENT);
// NOTE: gsd-pristine/ does NOT exist (simulating post-buggy-run or first-time scenario)
INSTALL.saveLocalPatches(configDir, {
packageSrc: fakeSrcDir,
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
// The regeneration path should have detected that sha256(new-release candidate)
// === originalHash, and promoted the candidate into gsd-pristine/.
const pristineFile = path.join(configDir, 'gsd-pristine', relPath);
assert.ok(
fs.existsSync(pristineFile),
[
`gsd-pristine/${relPath} must exist after hash-validated regeneration.`,
`When new-release bytes hash to originalHash, the file was unchanged between`,
`releases and the candidate should be promoted to restore the pristine baseline.`,
].join(' ')
);
const actualContent = fs.readFileSync(pristineFile, 'utf8');
assert.equal(
sha256(actualContent),
oldHash,
[
`gsd-pristine/${relPath} must contain bytes matching originalHash after regeneration`,
`(sha256=${oldHash.slice(0, 12)}…)`,
].join(' ')
);
});
/**
* Stale-pristine recovery test (pre-fix bug artifact).
*
* Timeline:
* Buggy run: gsd-pristine/<rel> was written with NEW_RELEASE_CONTENT
* (the exact #3407 artifact — stale bytes from a buggy populatePristineDir).
* Fix run: saveLocalPatches detects the hash mismatch
* (sha256(NEW_RELEASE_CONTENT) !== originalHash recorded in manifest),
* removes the stale entry, then attempts regeneration.
*
* When the file CHANGED between releases (NEW !== OLD):
* - The stale entry is removed.
* - Regeneration discards the new-release candidate (hash mismatch).
* - gsd-pristine/<rel> must be ABSENT (over-broad fallback — correct).
*
* When the file is UNCHANGED between releases (NEW === OLD):
* - The stale entry (which happens to have correct bytes despite the bug) is
* detected as correct (hash matches originalHash) and PRESERVED.
* - gsd-pristine/<rel> must remain present with the correct bytes.
*
* This test covers the "file changed across release boundary" case.
* The "unchanged" case is already covered by the regeneration test above.
*/
test('stale gsd-pristine/ entry (new-release bytes) is removed when file changed between releases', () => {
const OLD_RELEASE_CONTENT = '# Old Release\nv1 content here.\n';
const NEW_RELEASE_CONTENT = '# New Release\nv2 content — upstream changed this.\n';
const USER_MODIFIED_CONTENT = '# Old Release\nv1 content here.\n## User section\nCustom work.\n';
const oldHash = sha256(OLD_RELEASE_CONTENT);
const relPath = 'test-stale-recovery.md';
// configDir: user-modified file + manifest recording OLD hash
fs.writeFileSync(path.join(configDir, relPath), USER_MODIFIED_CONTENT);
fs.writeFileSync(
path.join(configDir, MANIFEST_NAME),
JSON.stringify({ version: '1.0.0', files: { [relPath]: oldHash } }, null, 2)
);
// fakeSrcDir (new release): contains the NEW content
fs.writeFileSync(path.join(fakeSrcDir, relPath), NEW_RELEASE_CONTENT);
// Pre-populate gsd-pristine/ with NEW_RELEASE_CONTENT — the exact pre-fix bug artifact.
// This simulates a prior buggy run that wrote new-release bytes into the pristine baseline.
const STALE_BYTES = NEW_RELEASE_CONTENT; // named constant for clarity
const pristineDir = path.join(configDir, 'gsd-pristine');
fs.mkdirSync(pristineDir, { recursive: true });
fs.writeFileSync(path.join(pristineDir, relPath), STALE_BYTES);
// Verify the pre-condition: stale bytes do NOT match the original hash.
// If this assert fails, the test fixture is wrong (not a fix regression).
assert.notEqual(
sha256(STALE_BYTES),
oldHash,
'test fixture check: stale bytes must differ from originalHash'
);
INSTALL.saveLocalPatches(configDir, {
packageSrc: fakeSrcDir,
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
// The fix must detect the hash mismatch (stale entry) and remove it.
// The regeneration path discards the new-release candidate (its hash !== oldHash).
// Result: gsd-pristine/<rel> must be ABSENT — over-broad fallback is the safe outcome.
const pristineFile = path.join(pristineDir, relPath);
assert.strictEqual(
fs.existsSync(pristineFile),
false,
[
`expected gsd-pristine/${relPath} to be absent after stale-pristine recovery.`,
`The stale entry (new-release bytes, sha256=${sha256(STALE_BYTES).slice(0, 12)}…)`,
`must be removed; regeneration must discard the candidate because`,
`sha256(new-release)=${sha256(NEW_RELEASE_CONTENT).slice(0, 12)}… !== originalHash=${oldHash.slice(0, 12)}….`,
`Presence of the file means the stale bytes were NOT cleaned up (pre-fix behavior).`,
].join(' ')
);
});
/**
* Second scenario: gsd-pristine/ does NOT pre-exist (first upgrade with no
* prior pristine population). In this case there is no way to obtain the
* old-release pristine bytes — populatePristineDir must NOT write the new-
* release bytes either. The correct outcome is: gsd-pristine/ stays empty
* for this file, and the verifier falls back to over-broad mode (safe).
*/
test('gsd-pristine/ stays empty when no prior pristine exists (first upgrade, no stale write)', () => {
const OLD_RELEASE_CONTENT = '# Old Release Content\nThis is v1.\n';
const NEW_RELEASE_CONTENT = '# New Release Content\nThis is v2 — changed.\n';
const USER_MODIFIED_CONTENT = '# Old Release Content\nThis is v1.\n## User addition\nCustom.\n';
const oldHash = sha256(OLD_RELEASE_CONTENT);
const relPath = 'test-first-upgrade.md';
// configDir has user-modified file + manifest
fs.writeFileSync(path.join(configDir, relPath), USER_MODIFIED_CONTENT);
fs.writeFileSync(
path.join(configDir, MANIFEST_NAME),
JSON.stringify({ version: '1.0.0', files: { [relPath]: oldHash } }, null, 2)
);
// fakeSrcDir (new release) has new content
fs.writeFileSync(path.join(fakeSrcDir, relPath), NEW_RELEASE_CONTENT);
// NOTE: gsd-pristine/ does NOT exist yet (first upgrade)
INSTALL.saveLocalPatches(configDir, {
packageSrc: fakeSrcDir,
runtime: 'claude',
pathPrefix: '$HOME/.claude/',
isGlobal: true,
});
const pristineFile = path.join(configDir, 'gsd-pristine', relPath);
assert.strictEqual(
fs.existsSync(pristineFile),
false,
[
`expected gsd-pristine/${relPath} to be absent when file changed across release boundary.`,
`Writing new-release bytes as pristine for a file whose hash is unknown leads to`,
`false FAIL_USER_LINES_MISSING in the reapply-patches verifier (#3407).`,
`Over-broad fallback mode is the correct outcome here.`,
].join(' ')
);
});
});
// The former "Antipattern hunt" describe block (structural typeof checks only) was
// removed — it provided no real behavioral coverage and was a vacuous-truth pattern
// per /test-rigor skill. Behavioral tests for populatePristineDir are covered above.
});
}
// ────────────────────────────────────────────────────────────────────────
// Folded from tests/bug-2995-post-install-script-paths.test.cjs — consolidation epic #1969 (B6 #1975)
// ────────────────────────────────────────────────────────────────────────

File diff suppressed because it is too large Load Diff

View File

@@ -11,8 +11,12 @@ const { createTempDir, cleanup } = require('./helpers.cjs');
const ROOT = path.resolve(__dirname, '..');
const HOOK_PATH = path.join(ROOT, '.githooks', 'pre-push');
// #3145: class-norm timeout, not a per-suite value — see helpers/timeouts.cjs.
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
// #3271: class-norm timeout, HOOK_FANOUT_TIMEOUT_MS not a per-suite value — see
// helpers/timeouts.cjs. This file is the fan-out class: the hook runs under
// `bash` and shells to a mock `git` that is itself a bash script, so a single
// runHook call is several nested spawns, not the single short probe the base
// PROBE_TIMEOUT_MS class describes.
const { HOOK_FANOUT_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
/**
* Write a mock bash script to a .sh file in tmpDir and return its absolute path.
@@ -60,7 +64,7 @@ exit 1
GSD_BLOCKED_AUTHOR_REGEX: '@example-corp\\.com$',
},
input: 'refs/heads/pr refs-local-sha refs/heads/pr refs-remote-sha\n',
timeoutMs: PROBE_TIMEOUT_MS,
timeoutMs: HOOK_FANOUT_TIMEOUT_MS,
});
throwIfFailed(r, `bash ${HOOK_PATH}`);
}, /Push blocked: commit author email matched local blocked regex/);
@@ -93,7 +97,7 @@ exit 1
GSD_BLOCKED_AUTHOR_REGEX: '@example-corp\\.com$',
},
input: 'refs/heads/pr refs-local-sha refs/heads/pr refs-remote-sha\n',
timeoutMs: PROBE_TIMEOUT_MS,
timeoutMs: HOOK_FANOUT_TIMEOUT_MS,
});
throwIfFailed(r, `bash ${HOOK_PATH}`);
});

View File

@@ -794,3 +794,32 @@ describe('runGsdTools adapter (process-seam parity)', () => {
);
});
});
describe('#3271: hook fan-out timeout class', () => {
const {
PROBE_TIMEOUT_MS: PROBE,
HOOK_FANOUT_TIMEOUT_MS: HOOK_FANOUT,
INSTALL_TIMEOUT_MS: INSTALL,
} = require('./helpers/timeouts.cjs');
test('a hook fan-out is bounded above a bare probe and below a full install', () => {
// The ordering IS the claim: a hook that shells out several times is heavier
// than reading back a version string and lighter than running bin/install.js.
// CI recorded a Windows timeout at exactly the probe bound (PR #3285,
// windows-latest node 22 shard 2/3) while every other lane passed the same
// commit — the bound was sized for the wrong class.
assert.ok(PROBE < HOOK_FANOUT, `probe ${PROBE}ms must be under hook fan-out ${HOOK_FANOUT}ms`);
assert.ok(HOOK_FANOUT < INSTALL, `hook fan-out ${HOOK_FANOUT}ms must be under install ${INSTALL}ms`);
});
test('the fan-out bound clears the duration that actually timed out', () => {
// Observed: 15040ms, censored at the 15000ms probe bound, so the real need is
// unknown and above it. A bound that merely matched the observation would be
// the same defect again.
const OBSERVED_TIMEOUT_MS = 15040;
assert.ok(
HOOK_FANOUT >= OBSERVED_TIMEOUT_MS * 3,
`hook fan-out ${HOOK_FANOUT}ms must clear the censored ${OBSERVED_TIMEOUT_MS}ms observation with real margin`,
);
});
});