Files
msd-core/tests/runtime-name-policy.test.cjs
Tom Boucher 69e7afd0c7 chore(#3212): bounded quantifiers over document content — prohibition with teeth — Phase 4 (#3441)
* feat(#3415): ship local/no-unbounded-quantifier, burn down ReDoS class

Phase 4 of epic #3212 (ADR-3212 §5/§7, the final phase). New rule flags
an unbounded */+/{n,} quantifier over a broad character class
([\s\S], dotAll ., or a 1-2-unit negated class like [^\n]/[^)\n] — the
exact #2128-fixed shape) applied to a regex whose match target is
data-flow-traced to readFileSync content.

eslint-rules/lib/readfilesync-trace.cjs extracts the data-flow tracer
shared with no-crlf-fragile-split (Phase 2) rather than a second copy
— no-crlf-fragile-split refactored onto it with zero behavior change,
parity-tested.

Real triage, not 798 mechanical edits: the ADR's census (2026-08-08)
screened every unbounded quantifier in the tree unscoped. Correctly
scoped to readFileSync-derived content (matching Phase 2's own G2/G3
scoping), the rule found 162 real hits across two detection waves — the
second wave (93) surfaced only after a genuine off-by-one bug in this
rule's own first draft was caught while writing its RuleTester tests
and fixed (the bug silently missed every directly-quantified [\s\S]*
with no gap before the quantifier — exactly the class this rule exists
to catch). 3 hits landed in production src/ (commands.cts, milestone.cts,
roadmap.cts) and were each empirically timed against adversarial input
(matching #2128's own measured-not-assumed precedent) — all confirmed
linear-time/benign, left unbounded with a measured-evidence comment
rather than mechanically bounded. The remaining 159 are test-file
fixture parsing (test-author-controlled, fixed-size content, not
adversarial input) — each suppressed with a specific, non-generic
reason. Zero functional behavior changed anywhere in this diff.

tests/no-pending-3212-markers.test.cjs locks the epic's own closing
invariant (ADR §7: "assert zero pending #3212 markers remain") — ground
truth confirmed trivially true today (no phase left any such marker
behind), now regression-locked going forward.

Design: .gsd/phase/chore-3415-prohibition-with-teeth/40-design.md
Test matrix: .gsd/phase/chore-3415-prohibition-with-teeth/50-test-matrix.md

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3415): correct rule category mislabel, add CI test-scope entry

An orthogonal Standards-axis review found eslint-rules/no-unbounded-quantifier.cjs
mistakenly carried meta.docs.category: 'Portability', copied from a sibling
rule without realizing what that implied: docs/contributing/cross-platform-
portability-rules.md governs an ADR-1703 rule family under a hard "zero
escape hatches" contract (tests/portability-rule-disable-ban.test.cjs's
PROTECTED_RULES bans eslint-disable for those rules entirely). This rule is
not part of that family — it's ADR-3212 (ReDoS/CWE-1333), a different epic —
and its eslint-disable-next-line suppressions (159 of them, added earlier
this same phase after empirical benign-verification) are an intentional,
correct design, not a bypass. Corrected to category: 'Best Practices',
matching the actual precedent (no-adhoc-regex-escape.cjs, Phase 1 of the
same epic, which is also correctly outside PROTECTED_RULES), and the rule's
own docstring now states this explicitly so a future reader doesn't have to
re-derive it.

Also registers a new scripts/ci-test-scope.cjs bucket so editing this rule
or the shared eslint-rules/lib/readfilesync-trace.cjs helper re-runs their
own test suites under targeted CI selection — was previously unregistered
and invisible to that fast-path (this PR's own gsd-test checkpoint runs the
full suite regardless, so this only affects future narrowly-scoped PRs).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3415): bound no-unbounded-quantifier's own scanner (CWE-1333, ironic)

Security review found the rule meant to catch algorithmic-complexity bugs
had one of its own: hasUnboundedBroadQuantifier's negated-class inner
scan walked from each `[^` occurrence to the next `]` (or EOF) with no
bound, while the outer loop only ever advanced by one character — O(n²)
total work on a pattern with many unclosed `[^` runs. Runs unconditionally
inside checkPattern on any `new RegExp('literal string')` argument in any
linted file, before the (cheap) readFileSync data-flow gate — so a single
crafted string literal, no valid regex syntax required, could make
`npm run lint` / CI hang.

Empirically confirmed both the bug and the fix: pre-fix, n=4000/8000/
16000/32000 chars took 30.8/115.6/463.8/1874.3ms (~4x work per 2x n,
quadratic); extrapolated, the 300000-char repro from the finding would
run ~165s. Post-fix (bail the inner scan once units exceeds the rule's
own 1-2-unit scope, rather than continuing to hunt for a closing `]`),
the same 300000-char input runs in 8.7ms via the real rule module,
independently reconfirmed at 18ms via a fresh Linter.verify() call.

New regression row in tests/no-unbounded-quantifier.rule.test.cjs
asserts the RuleTester run on a 50000-char adversarial pattern
completes and returns a defined result — no wall-clock assertion
(CLAUDE.md Clock Seams / local/no-elapsed-assertion).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3415): triage 3 new sites, re-raise ceiling after upstream batch

next merged 12 more PRs during this PR's review. Two consequences:

- tests/edit-phase.test.cjs (fix #3262, unrelated) added 3 new
  content.match(/<tag>([\s\S]*?)<\/tag>/) reads of this repo's own
  workflow .md content — the same Class A pattern as the ~159 sites
  already triaged elsewhere in this PR. Suppressed with the same
  established reason.
- lint-allow-test-rule-refs' ratchet ceiling needed re-raising again
  (301 -> 303) for the same reason as the two prior bumps: organic
  growth from unrelated, already-reviewed PRs landing concurrently,
  not a defect in this branch's own diff.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-14 10:02:28 -04:00

244 lines
10 KiB
JavaScript

'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const path = require('node:path');
const fs = require('node:fs');
const ROOT = path.join(__dirname, '..');
const {
canonicalizeRuntimeName,
resolveRuntimeNameFromCandidates,
getProjectInstructionFile,
} = require(path.join(ROOT, 'gsd-core', 'bin', 'lib', 'runtime-name-policy.cjs'));
describe('runtime-name-policy canonical runtime ids', () => {
test('canonicalizes Kimi without adding extra aliases', () => {
assert.strictEqual(canonicalizeRuntimeName('kimi'), 'kimi');
assert.strictEqual(canonicalizeRuntimeName(' KIMI '), 'kimi');
assert.strictEqual(resolveRuntimeNameFromCandidates('', null, 'kimi'), 'kimi');
assert.strictEqual(canonicalizeRuntimeName('kimi-cli'), null);
});
test('canonicalizes devin-desktop to windsurf (#792)', () => {
assert.strictEqual(canonicalizeRuntimeName('devin-desktop'), 'windsurf');
assert.strictEqual(canonicalizeRuntimeName('DEVIN-DESKTOP'), 'windsurf');
assert.strictEqual(resolveRuntimeNameFromCandidates('devin-desktop'), 'windsurf');
});
});
describe('runtime-name-policy windsurf alias parity — manifest vs FALLBACK_ALIASES (#792)', () => {
// DEFECT.GENERATIVE-FIX: manifest and FALLBACK_ALIASES are manually mirrored;
// this test fails if they diverge for the windsurf key.
const manifestPath = path.join(ROOT, 'gsd-core', 'bin', 'shared', 'runtime-aliases.manifest.json');
const manifest = JSON.parse(fs.readFileSync(manifestPath, 'utf8'));
test('manifest windsurf array includes devin-desktop', () => {
assert.ok(
Array.isArray(manifest.windsurf) && manifest.windsurf.includes('devin-desktop'),
`runtime-aliases.manifest.json windsurf array must include 'devin-desktop'; got: ${JSON.stringify(manifest.windsurf)}`,
);
});
test('FALLBACK_ALIASES windsurf includes devin-desktop (via canonicalization round-trip)', () => {
// The built module merges manifest over FALLBACK_ALIASES; if the manifest is present
// this verifies the combined set. The manifest test above separately guards the manifest.
// Here we verify the live canonicalizer sees devin-desktop -> windsurf.
assert.strictEqual(
canonicalizeRuntimeName('devin-desktop'),
'windsurf',
'devin-desktop must resolve to windsurf via alias lookup',
);
});
test('manifest and FALLBACK_ALIASES windsurf alias sets are identical', () => {
// Read FALLBACK_ALIASES from source to detect manual drift before a build.
const srcPath = path.join(ROOT, 'src', 'runtime-name-policy.cts');
// allow-test-rule: source-text-is-the-product
// FALLBACK_ALIASES source text IS the product contract for runtimes that can't load the manifest at runtime; verifying
// both surfaces contain the same windsurf aliases catches manual-mirror drift.
const src = fs.readFileSync(srcPath, 'utf8');
// eslint-disable-next-line local/no-unbounded-quantifier -- parses this repo's own bounded src/runtime-name-policy.cts source, not adversarial input
const match = src.match(/windsurf:\s*\[([^\]]+)\]/);
assert.ok(match, 'FALLBACK_ALIASES windsurf row must exist in src/runtime-name-policy.cts');
const srcAliases = match[1]
.split(',')
.map(s => s.trim().replace(/^['"]|['"]$/g, ''))
.filter(Boolean);
const manifestAliases = [...manifest.windsurf].sort();
assert.deepStrictEqual(
[...srcAliases].sort(),
manifestAliases,
`FALLBACK_ALIASES windsurf=${JSON.stringify(srcAliases.sort())} must match manifest windsurf=${JSON.stringify(manifestAliases)}`,
);
});
});
describe('runtime-name-policy getProjectInstructionFile (#1529)', () => {
test('claude maps to .claude/CLAUDE.md (kept-as-is boundary case)', () => {
assert.strictEqual(getProjectInstructionFile('claude'), '.claude/CLAUDE.md');
});
test('codex maps to AGENTS.md', () => {
assert.strictEqual(getProjectInstructionFile('codex'), 'AGENTS.md');
});
test('opencode maps to AGENTS.md (the #1529 bug surface)', () => {
assert.strictEqual(getProjectInstructionFile('opencode'), 'AGENTS.md');
});
test('kilo maps to AGENTS.md', () => {
assert.strictEqual(getProjectInstructionFile('kilo'), 'AGENTS.md');
});
test('kimi maps to AGENTS.md', () => {
assert.strictEqual(getProjectInstructionFile('kimi'), 'AGENTS.md');
});
test('copilot maps to .github/copilot-instructions.md (GitHub docs read path)', () => {
assert.strictEqual(getProjectInstructionFile('copilot'), '.github/copilot-instructions.md');
});
test('gemini is no longer a known runtime — falls back to AGENTS.md (#1928: Gemini CLI runtime removed)', () => {
assert.strictEqual(getProjectInstructionFile('gemini'), 'AGENTS.md');
});
test('antigravity maps to GEMINI.md', () => {
assert.strictEqual(getProjectInstructionFile('antigravity'), 'GEMINI.md');
});
test('unknown runtime maps to AGENTS.md (safe cross-agent default, boundary case)', () => {
assert.strictEqual(getProjectInstructionFile('future-runtime-xyz'), 'AGENTS.md');
assert.strictEqual(getProjectInstructionFile(''), 'AGENTS.md');
assert.strictEqual(getProjectInstructionFile(null), 'AGENTS.md');
assert.strictEqual(getProjectInstructionFile(undefined), 'AGENTS.md');
});
test('aliases normalize via canonicalizeRuntimeName before mapping', () => {
// codex-cli is an alias for codex; it must resolve to the codex mapping.
assert.strictEqual(getProjectInstructionFile('codex-cli'), 'AGENTS.md');
// opencode-cli is an alias for opencode.
assert.strictEqual(getProjectInstructionFile('opencode-cli'), 'AGENTS.md');
// gemini-cli was an alias for gemini; the gemini runtime was removed
// (#1928) so it is now an unrecognized runtime -> safe AGENTS.md default.
assert.strictEqual(getProjectInstructionFile('gemini-cli'), 'AGENTS.md');
// github-copilot is an alias for copilot.
assert.strictEqual(getProjectInstructionFile('github-copilot'), '.github/copilot-instructions.md');
});
});
// ────────────────────────────────────────────────────────────────────────
// Folded from tests/bug-783-kilo-global-skills-base.test.cjs — consolidation epic #1969 (B3 #1972)
// ────────────────────────────────────────────────────────────────────────
{
const { describe: __foldDescribe } = require('node:test');
__foldDescribe("folded:bug-783-kilo-global-skills-base (consolidation epic #1969 B3 #1972)", () => {
'use strict';
// Regression guard for bug #783.
//
// getGlobalSkillsBase('kilo') was returning ~/.config/kilo/skills (the XDG
// config dir) instead of ~/.kilo/skills — where Kilo Code actually discovers
// global skills per its docs:
// https://kilo.ai/docs/customize/skills
// "Global skills are located in the `.kilo` directory within your Home
// directory: ~/.kilo/skills/"
//
// The fix adds a special case in getGlobalSkillsBase() that resolves kilo's
// skills dir from HOME (not from the XDG config dir). The config dir at
// ~/.config/kilo is still CORRECT for commands (command/) and must stay
// unchanged — this test verifies both roles are separate.
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const path = require('node:path');
const os = require('node:os');
const ROOT = path.join(__dirname, '..');
const {
getGlobalConfigDir,
getGlobalSkillsBase,
} = require(path.join(ROOT, 'gsd-core', 'bin', 'lib', 'runtime-homes.cjs'));
// Helper: temporarily override env vars for a test, restoring them afterwards.
function withEnv(overrides, fn) {
const saved = {};
for (const [key, value] of Object.entries(overrides)) {
saved[key] = process.env[key];
if (value === undefined) delete process.env[key];
else process.env[key] = value;
}
try {
return fn();
} finally {
for (const [key] of Object.entries(overrides)) {
if (saved[key] === undefined) delete process.env[key];
else process.env[key] = saved[key];
}
}
}
// Clear all kilo-relevant env vars so tests are hermetic.
const kiloEnvClears = {
KILO_CONFIG_DIR: undefined,
XDG_CONFIG_HOME: undefined,
};
describe('bug #783: kilo global skills dir is ~/.kilo/skills, not ~/.config/kilo/skills', () => {
test('getGlobalSkillsBase("kilo") resolves to ~/.kilo/skills', () => {
withEnv(kiloEnvClears, () => {
assert.strictEqual(
getGlobalSkillsBase('kilo'),
path.join(os.homedir(), '.kilo', 'skills'),
);
});
});
test('getGlobalConfigDir("kilo") still resolves to ~/.config/kilo (config dir unchanged)', () => {
withEnv(kiloEnvClears, () => {
assert.strictEqual(
getGlobalConfigDir('kilo'),
path.join(os.homedir(), '.config', 'kilo'),
);
});
});
test('kilo skills dir and config dir are decoupled (not equal, not nested)', () => {
withEnv(kiloEnvClears, () => {
const skillsBase = getGlobalSkillsBase('kilo');
const configDir = getGlobalConfigDir('kilo');
assert.notStrictEqual(skillsBase, configDir, 'skills dir must differ from config dir');
assert.ok(
!skillsBase.startsWith(configDir + path.sep),
`skills dir (${skillsBase}) must not be nested under config dir (${configDir})`,
);
assert.ok(
!configDir.startsWith(skillsBase + path.sep),
`config dir (${configDir}) must not be nested under skills dir (${skillsBase})`,
);
});
});
test('getGlobalSkillsBase("kilo") is NOT affected by KILO_CONFIG_DIR override', () => {
// Skills always live in ~/.kilo/skills regardless of XDG/config-dir overrides.
withEnv({ KILO_CONFIG_DIR: '/tmp/custom-kilo-config', XDG_CONFIG_HOME: undefined }, () => {
assert.strictEqual(
getGlobalSkillsBase('kilo'),
path.join(os.homedir(), '.kilo', 'skills'),
);
});
});
test('getGlobalSkillsBase("kilo") is NOT affected by XDG_CONFIG_HOME override', () => {
withEnv({ KILO_CONFIG_DIR: undefined, XDG_CONFIG_HOME: '/tmp/custom-xdg' }, () => {
assert.strictEqual(
getGlobalSkillsBase('kilo'),
path.join(os.homedir(), '.kilo', 'skills'),
);
});
});
});
});
}