/** * Phase 4 installer migration integration tests. * * These exercise the public install() entry point so the migration runner is * pinned at the install/update seam, not just as a standalone library. */ 'use strict'; process.env.MSD_TEST_MODE = '1'; const { describe, test, beforeEach, afterEach } = require('node:test'); const assert = require('node:assert/strict'); const fs = require('node:fs'); const path = require('node:path'); const crypto = require('node:crypto'); const { runNode } = require('./helpers/process-seam.cjs'); const installModule = require('../bin/install.js'); const pkg = require('../package.json'); const { install } = installModule; const { createTempDir, cleanup } = require('./helpers.cjs'); // #3145: class-norm timeout, not a per-suite value — see helpers/timeouts.cjs. const { INSTALL_TIMEOUT_MS } = require('./helpers/timeouts.cjs'); const installScript = path.join(__dirname, '..', 'bin', 'install.js'); const SUPPORTED_RUNTIMES = installModule.allRuntimes; const RUNTIME_INSTALL_CONTRACTS = { claude: { surface: 'flat-skills', settings: true, hooksPackageJson: true }, antigravity: { surface: 'flat-skills', settings: true, hooksPackageJson: true }, // codex/cursor: #2717 stages their .js hooks via dedicated paths // (skipSharedHooksInstall / the !isCodex gate keep them out of the shared // bundle) and writes the marker beside those scripts, so hooks/package.json // is expected for both. Measured on this tree: codex stages 3 .js hooks, // cursor 6 — each with the marker. codex: { surface: 'flat-skills', settings: false, hooksPackageJson: true, codexConfig: true }, cursor: { surface: 'flat-skills', settings: false, hooksPackageJson: true }, gemini: { surface: 'commands-msd', settings: true, hooksPackageJson: true }, // #2329: OpenCode discovers commands from the PLURAL `commands/` dir. opencode: { surface: 'flat-command', settings: true, hooksPackageJson: true, commandDirName: 'commands' }, // #1821: ZCode (hooksSurface:none, no plugin surface) no longer receives the // dead hook scripts or the CommonJS package.json marker. zcode: { surface: 'flat-skills', settings: false, hooksPackageJson: false }, }; function sha256(content) { return crypto.createHash('sha256').update(content).digest('hex'); } function writeFile(root, relPath, content) { const fullPath = path.join(root, relPath); fs.mkdirSync(path.dirname(fullPath), { recursive: true }); fs.writeFileSync(fullPath, content, 'utf8'); } function writeManifest(root, files) { fs.writeFileSync( path.join(root, 'msd-file-manifest.json'), JSON.stringify({ version: '1.49.0', timestamp: '2026-05-10T00:00:00.000Z', mode: 'full', files, }, null, 2), 'utf8' ); } function withEnv(key, value, fn) { const previous = process.env[key]; process.env[key] = value; try { return fn(); } finally { if (previous == null) delete process.env[key]; else process.env[key] = previous; } } // #2088: Codex CLI skills install to `$HOME/.agents/skills` (resolved via // os.homedir()), not `$CODEX_HOME/skills`. In-process codex installs must // sandbox HOME (and USERPROFILE, for Windows os.homedir() resolution) to the // test's codexHome dir, or skills get materialized into the real developer // home directory. withEnv saves/restores a single key, so nesting is safe. function withCodexEnv(codexHome, fn) { return withEnv('CODEX_HOME', codexHome, () => withEnv('HOME', codexHome, () => withEnv('USERPROFILE', codexHome, fn) ) ); } function captureConsole(fn) { const originalLog = console.log; const originalWarn = console.warn; const lines = []; console.log = (...args) => { lines.push(args.join(' ')); }; console.warn = (...args) => { lines.push(args.join(' ')); }; try { return { value: fn(), output: lines.join('\n') }; } finally { console.log = originalLog; console.warn = originalWarn; } } function withWriteFailure(matchPath, fn) { const originalWriteFileSync = fs.writeFileSync; const resolvedMatch = path.resolve(matchPath); // Atomic writers (atomicWriteFileSync) never write the destination directly — // they write `.tmp--` and rename. Matching only the final path // would make this injection silently stop firing for any write that becomes // atomic, turning a rollback assertion into a vacuous pass. const targetsMatch = (filePath) => { const resolved = path.resolve(String(filePath)); return resolved === resolvedMatch || resolved.startsWith(`${resolvedMatch}.tmp-`); }; fs.writeFileSync = (filePath, ...args) => { if (targetsMatch(filePath)) { throw new Error(`injected write failure for ${path.basename(matchPath)}`); } return originalWriteFileSync.call(fs, filePath, ...args); }; try { return fn(); } finally { fs.writeFileSync = originalWriteFileSync; } } function withSdkDistPresent(fn) { const sdkCliPath = path.join(__dirname, '..', 'sdk', 'dist', 'cli.js'); const originalExistsSync = fs.existsSync; const originalStatSync = fs.statSync; const originalChmodSync = fs.chmodSync; fs.existsSync = (filePath) => { if (path.resolve(String(filePath)) === path.resolve(sdkCliPath)) return true; return originalExistsSync.call(fs, filePath); }; fs.statSync = (filePath, ...args) => { if (path.resolve(String(filePath)) === path.resolve(sdkCliPath)) { return { mode: 0o755 }; } return originalStatSync.call(fs, filePath, ...args); }; fs.chmodSync = (filePath, ...args) => { if (path.resolve(String(filePath)) === path.resolve(sdkCliPath)) return; return originalChmodSync.call(fs, filePath, ...args); }; try { return fn(); } finally { fs.existsSync = originalExistsSync; fs.statSync = originalStatSync; fs.chmodSync = originalChmodSync; } } function stripAnsi(value) { // eslint-disable-next-line no-control-regex -- \x1b (ESC) is the required leading byte of ANSI SGR color sequences; matching it is the purpose of stripping ANSI codes from captured CLI/console output return value.replace(/\x1b\[[0-9;]*m/g, ''); } function runInstallerCli(runtime, targetDir, options = {}) { const { minimal = true } = options; const env = { ...process.env }; delete env.MSD_TEST_MODE; env.HOME = path.join(path.dirname(targetDir), 'home'); env.USERPROFILE = env.HOME; return runNode( [ installScript, `--${runtime}`, '--global', '--config-dir', targetDir, ...(minimal ? ['--minimal'] : []), '--no-sdk', ], { env, timeoutMs: INSTALL_TIMEOUT_MS, } ); } function listDirNames(root, relPath) { const dir = path.join(root, relPath); if (!fs.existsSync(dir)) return []; return fs.readdirSync(dir, { withFileTypes: true }).map((entry) => entry.name); } function assertHasMsdDirectory(root, relPath) { assert.ok( listDirNames(root, relPath).some((name) => name.startsWith('msd-')), `${relPath} should contain generated MSD entries` ); } function assertFreshInstallContract(runtime, targetDir) { const contract = RUNTIME_INSTALL_CONTRACTS[runtime]; assert.ok(contract, `missing runtime install contract for ${runtime}`); const hooksDirName = installModule.SHARED_HOOKS_DIR; assert.equal( fs.readFileSync(path.join(targetDir, 'msd-core', 'VERSION'), 'utf8'), pkg.version, `${runtime} should install the package VERSION` ); assert.ok( fs.existsSync(path.join(targetDir, 'msd-core', 'bin', 'msd-tools.cjs')), `${runtime} should install the MSD tool payload` ); assert.ok( fs.existsSync(path.join(targetDir, 'msd-file-manifest.json')), `${runtime} should write the install manifest` ); const manifest = JSON.parse(fs.readFileSync(path.join(targetDir, 'msd-file-manifest.json'), 'utf8')); assert.equal(manifest.version, pkg.version, `${runtime} manifest should record the package version`); assert.equal(manifest.mode, 'full', `${runtime} manifest should record a full install`); assert.ok( manifest.files['msd-core/VERSION'], `${runtime} manifest should track the installed VERSION file` ); if (contract.surface === 'flat-skills') { if (runtime === 'codex') { // #2088: Codex CLI skills install to the canonical `$HOME/.agents/skills` // root (resolved via os.homedir()), NOT `/skills`. Here // runInstallerCli sandboxes HOME to /home, so assert // the skill dir under that sandboxed home instead of under targetDir. const codexSandboxHome = path.join(path.dirname(targetDir), 'home'); assertHasMsdDirectory(path.join(codexSandboxHome, '.agents'), 'skills'); } else if (runtime === 'antigravity') { // #3738: Antigravity's machine-local discovery scans ~/.gemini/config, so // global skills install under the sandboxed home's .gemini/config root // (kind `home` override), NOT `/skills`. Same sandboxed-HOME // reasoning as the codex branch above. const agySandboxHome = path.join(path.dirname(targetDir), 'home'); assertHasMsdDirectory(path.join(agySandboxHome, '.gemini', 'config'), 'skills'); assertHasMsdDirectory(path.join(agySandboxHome, '.gemini', 'config'), 'agents'); } else { // Pre-#3562: codex was special-cased to expect zero msd-* skill dirs // (assumption: Codex auto-discovers from workflows). That assumption // does not hold for Codex CLI 0.130.0 — fresh installs now materialize // the same flat-skills surface as the other runtimes. assertHasMsdDirectory(targetDir, 'skills'); } } else if (contract.surface === 'flat-command') { // #2329: dir name is per-runtime (opencode='commands'). const commandDirName = contract.commandDirName || 'command'; assert.ok( listDirNames(targetDir, commandDirName).some((name) => name.startsWith('msd-') && name.endsWith('.md')), `${runtime} should install flattened command markdown files in ${commandDirName}/` ); } else if (contract.surface === 'commands-msd') { assert.ok( listDirNames(targetDir, path.join('commands', 'msd')).length > 0, `${runtime} should install commands/msd entries` ); } if (runtime === 'antigravity') { // #3738: antigravity agents install under the sandboxed home's // .gemini/config root (see the flat-skills branch above), not targetDir. const agySandboxHomeForAgents = path.join(path.dirname(targetDir), 'home'); assert.ok( listDirNames(path.join(agySandboxHomeForAgents, '.gemini', 'config'), 'agents').some((name) => name.startsWith('msd-')), `${runtime} full install should install agents` ); } else { assert.ok( listDirNames(targetDir, 'agents').some((name) => name.startsWith('msd-')), `${runtime} full install should install agents` ); } assert.equal( fs.existsSync(path.join(targetDir, 'settings.json')), contract.settings, `${runtime} settings.json presence should match the runtime contract` ); // #2544: the CommonJS marker lives in the shared hooks dir (the dir MSD // fills with its own .js scripts — `hooks/` unless a runtime overrides it, // #3023), never at the config root — that file is user-owned // territory on OpenCode and was being clobbered on every install. assert.equal( fs.existsSync(path.join(targetDir, hooksDirName, 'package.json')), contract.hooksPackageJson, `${runtime} ${hooksDirName}/package.json presence should match the runtime contract` ); assert.equal( fs.existsSync(path.join(targetDir, 'package.json')), false, `${runtime} must not receive a MSD package.json at the config root (#2544)` ); if (contract.codexConfig) { assert.match( fs.readFileSync(path.join(targetDir, 'config.toml'), 'utf8'), /MSD Agent Configuration/, 'Codex should install config.toml with the MSD marker' ); } } describe('installer migration install integration', { concurrency: false }, () => { let tmpRoot; let codexHome; beforeEach(() => { tmpRoot = createTempDir('msd-install-migrations-'); codexHome = path.join(tmpRoot, '.codex'); fs.mkdirSync(codexHome, { recursive: true }); }); afterEach(() => { cleanup(tmpRoot); }); test('reports applied migration actions before package materialization', () => { writeFile(codexHome, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(codexHome, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); const { output } = captureConsole(() => withCodexEnv(codexHome, () => install(true, 'codex')) ); const plainOutput = stripAnsi(output); assert.match(plainOutput, /Installer migrations/); assert.match(plainOutput, /removed\s+hooks\/statusline\.js/); assert.ok( plainOutput.indexOf('Installer migrations') < plainOutput.indexOf('Installed workflow assets'), 'migration report should appear before package materialization' ); assert.equal(fs.existsSync(path.join(codexHome, 'hooks/statusline.js')), false); }); test('blocks install before materialization when baseline needs explicit user choice', () => { writeFile(codexHome, 'hooks/msd-retired-hook.txt', 'old msd hook\n'); assert.throws( () => captureConsole(() => withCodexEnv(codexHome, () => install(true, 'codex')) ), /installer migration blocked/ ); assert.equal(fs.readFileSync(path.join(codexHome, 'hooks/msd-retired-hook.txt'), 'utf8'), 'old msd hook\n'); assert.equal(fs.existsSync(path.join(codexHome, 'skills')), false); // #2088: with HOME sandboxed to codexHome via withCodexEnv, Codex's // canonical skill root ($HOME/.agents/skills) resolves under codexHome // too — assert nothing was materialized there when the install is blocked. assert.equal(fs.existsSync(path.join(codexHome, '.agents', 'skills')), false); assert.equal(fs.existsSync(path.join(codexHome, 'msd-core', 'VERSION')), false); }); test('rolls back applied migrations when package materialization fails for non-Codex installs', () => { const claudeHome = path.join(tmpRoot, '.claude'); fs.mkdirSync(claudeHome, { recursive: true }); writeFile(claudeHome, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(claudeHome, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); assert.throws( () => captureConsole(() => withEnv('CLAUDE_CONFIG_DIR', claudeHome, () => withWriteFailure(path.join(claudeHome, 'msd-core', 'VERSION'), () => install(true, 'claude')) ) ), /injected write failure for VERSION/ ); assert.equal( fs.readFileSync(path.join(claudeHome, 'hooks/statusline.js'), 'utf8'), 'legacy managed hook\n' ); assert.equal(fs.existsSync(path.join(claudeHome, 'msd-install-state.json')), false); }); test('rolls back applied migrations when multi-runtime finalization fails', () => { const claudeHome = path.join(tmpRoot, '.claude'); fs.mkdirSync(claudeHome, { recursive: true }); writeFile(claudeHome, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(claudeHome, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); assert.throws( () => captureConsole(() => withEnv('CLAUDE_CONFIG_DIR', claudeHome, () => withSdkDistPresent(() => withWriteFailure(path.join(claudeHome, 'settings.json'), () => installModule.installAllRuntimes(['claude'], true, false) ) ) ) ), /injected write failure for settings\.json/ ); assert.equal( fs.readFileSync(path.join(claudeHome, 'hooks/statusline.js'), 'utf8'), 'legacy managed hook\n' ); assert.equal(fs.existsSync(path.join(claudeHome, 'msd-install-state.json')), false); }); test('rolls back completed runtime migrations when a later runtime install fails', () => { const claudeHome = path.join(tmpRoot, '.claude'); fs.mkdirSync(claudeHome, { recursive: true }); writeFile(claudeHome, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(claudeHome, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); writeFile(codexHome, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(codexHome, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); assert.throws( () => captureConsole(() => withEnv('CLAUDE_CONFIG_DIR', claudeHome, () => withCodexEnv(codexHome, () => withWriteFailure(path.join(codexHome, 'msd-core', 'VERSION'), () => installModule.installAllRuntimes(['claude', 'codex'], true, false) ) ) ) ), /injected write failure for VERSION/ ); assert.equal( fs.readFileSync(path.join(claudeHome, 'hooks/statusline.js'), 'utf8'), 'legacy managed hook\n' ); assert.equal(fs.existsSync(path.join(claudeHome, 'msd-install-state.json')), false); assert.equal( fs.readFileSync(path.join(codexHome, 'hooks/statusline.js'), 'utf8'), 'legacy managed hook\n' ); assert.equal(fs.existsSync(path.join(codexHome, 'msd-install-state.json')), false); }); for (const runtime of SUPPORTED_RUNTIMES) { test(`runs a full end-to-end install for ${runtime}`, () => { const targetDir = path.join(tmpRoot, `.${runtime}-full-install`); fs.mkdirSync(targetDir, { recursive: true }); writeFile(targetDir, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(targetDir, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); const result = runInstallerCli(runtime, targetDir, { minimal: false }); assert.equal(result.exitCode, 0, result.stderr || result.stdout); const output = stripAnsi(`${result.stdout}\n${result.stderr}`); assert.match(output, /Installing for /); assert.match(output, /Installer migrations/); assert.match(output, /removed\s+hooks\/statusline\.js/); assert.match(output, /Installed workflow assets/); assert.match(output, /Done!/); assert.equal(fs.existsSync(path.join(targetDir, 'hooks/statusline.js')), false); const installState = JSON.parse(fs.readFileSync(path.join(targetDir, 'msd-install-state.json'), 'utf8')); assert.ok( installState.appliedMigrations.some((entry) => entry.id === '2026-05-11-legacy-orphan-files'), `${runtime} should track the applied cleanup migration in install state` ); assertFreshInstallContract(runtime, targetDir); }); test(`runs managed cleanup migrations for ${runtime}`, () => { const targetDir = path.join(tmpRoot, `.${runtime}-managed-cleanup`); fs.mkdirSync(targetDir, { recursive: true }); writeFile(targetDir, 'hooks/statusline.js', 'legacy managed hook\n'); writeManifest(targetDir, { 'hooks/statusline.js': sha256('legacy managed hook\n'), }); const result = runInstallerCli(runtime, targetDir); assert.equal(result.exitCode, 0, result.stderr || result.stdout); const output = stripAnsi(`${result.stdout}\n${result.stderr}`); assert.match(output, /Installer migrations/); assert.match(output, /removed\s+hooks\/statusline\.js/); assert.equal(fs.existsSync(path.join(targetDir, 'hooks/statusline.js')), false); const installState = JSON.parse(fs.readFileSync(path.join(targetDir, 'msd-install-state.json'), 'utf8')); assert.ok( installState.appliedMigrations.some((entry) => entry.id === '2026-05-11-legacy-orphan-files'), 'successful install should write install state for the applied cleanup migration' ); }); test(`blocks ambiguous MSD-looking user-choice artifacts for ${runtime}`, () => { const targetDir = path.join(tmpRoot, `.${runtime}-blocked`); fs.mkdirSync(targetDir, { recursive: true }); writeFile(targetDir, 'msd-core/msd-retired-tool.cjs', 'old ambiguous artifact\n'); const result = runInstallerCli(runtime, targetDir); assert.notEqual(result.exitCode, 0, 'install should fail before materialization'); const output = stripAnsi(`${result.stdout}\n${result.stderr}`); assert.match(output, /Installer migrations/); assert.match(output, /blocked\s+msd-core\/msd-retired-tool\.cjs/); assert.match(output, /installer migration blocked/); assert.equal( fs.readFileSync(path.join(targetDir, 'msd-core/msd-retired-tool.cjs'), 'utf8'), 'old ambiguous artifact\n' ); assert.equal(fs.existsSync(path.join(targetDir, 'msd-core', 'VERSION')), false); }); } });