* test(#3148): bound the long tail and delete the allowlist Migrates the final 170 unbounded sync spawn sites across 49 files, then removes the allowlist entirely. local/no-unbounded-spawn now runs with no exemption surface across tests/**: there is no file to add a name to. drift-detection's throw-native git() helper routes to gitOrThrow -- bare runGit would have taken 16 call sites quiet on failure. commands.test.cjs has two independently-scoped runGsdTools/runCli helpers, one already bounded and one not; they are kept distinct rather than unified, the same trap as the two same-named git() helpers in Wave 1. runNpm's bound was erasable. Its options spread callerOptions after the defaults, so an explicit timeout:undefined silently dropped the 180000ms bound -- the rule flagged it and was right; it was not a false positive. Fixed by destructuring with a default, with a test that fails when the default is removed. Two sites stay on a raw spawn with an explicit timeout because the seam cannot express them: one needs shell:true for npm.cmd on Windows, one redirects stdout to a real fd. Both are the rule's own documented second option, not an escape from it. Closure verified rather than asserted: the derivation scan reports 0 unbounded spawn helpers and 0 unbounded direct git call sites, and a temporary file carrying an unbounded spawn still errors with the allowlist gone. Closes #3064. * test(#3148): close a hole in the guard's own eslint-disable ban The ban listed only the top level of tests/, so it was blind to 37 .cjs files under tests/helpers, qa, observability, fixtures and dispatch. With the allowlist deleted this test is the sole remaining way to detect someone silencing the rule inline, so the gap was load-bearing: a nested file could carry an unbounded spawn plus an eslint-disable and pass everything. Proven before and after. A probe planted under tests/helpers with both was invisible to the guard and clean under eslint; after making the listing recursive the guard fails on it. The scanned set goes from 771 files to 808. Pre-existing since the guard shipped, but this wave is what promoted it to sole defense, so it is fixed here rather than filed. Also converts the last hand-rolled throw check to throwIfFailed and the last re-derived legacy shape to compose toLegacyResult, which makes the epic's none-remain claim true rather than nearly true. toLegacyResult itself is not widened -- eight callers depend on its shape and one consumer does not justify changing a shared contract. * fix(#3148): correct seam incoherence at the bound and a slow review-lane error path Two real failures from the remote runner, both fixed at the cause. The seam could return outcome TIMED_OUT together with exitCode 0. At the exact bound spawnSync reports ETIMEDOUT while the child has already exited with a real status, and toSeamResult classified on the error code while passing status straight through -- an incoherent pair its own boundary test was written to catch, and did. A status that is not null is direct evidence the child exited on its own, so it now decides the outcome before the error-code branches run. process-seam.cjs was deliberately untouched by every earlier wave; this is a defect in the module itself, kept surgical, with a unit test that fails against the old logic. review-lane with an unknown subcommand fell through to its usage error only after loading the capability registry and building a per-lane plan, which spawns one child process per lane -- up to twelve. The error path took ~1288ms instead of ~119ms, and under bench load it outran a caller's spawn timeout and was killed before writing anything, which is the empty stdout and stderr CI saw. It now fails fast before any of that work begins. This is the epic's first production change. It is user-facing, so it carries a changeset rather than a no-changelog label. * test(#3148): replace a real-race timeout test with a deterministic one E9 raced git rev-parse against a 1ms bound and assumed git always lost. On a warm container git finishes first, spawnSync returns status 0 with no error at all, the seam correctly classifies EXITED, and gitOrThrow correctly does not throw -- so the test failed on both lanes. A probe confirms a genuine timeout always carries status null, so this was never the seam misbehaving. Raising the bound would only lengthen the odds, which is the same defect with better luck. The test now drives gitOrThrow against a stubbed runGit that returns a synthetic TIMED_OUT result, so it asserts exactly what it always meant to -- that a timeout propagates as a throw -- with no timing dependence. Five consecutive runs are identical where the old one varied. I wrote this test in Wave 0; it is a real-race test by construction and CLAUDE.md says to replace those rather than re-run them. * chore(#3148): backfill changeset PR number 3192 --------- Co-authored-by: sim <sim@local>
318 lines
13 KiB
JavaScript
318 lines
13 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* #3045 follow-up (two-review convergence: "the guard is fail-open in the
|
|
* default install") — CORE REDESIGN coverage for the sentinel WRITE side.
|
|
*
|
|
* Seam: `gsd-tools.cjs query dispatch-isolation` (routeDispatchIsolation) is
|
|
* now the SOLE, unconditional write path — it persists the resolved
|
|
* isolation decision (mode + harnessFlag + phase/plan identifiers) as a side
|
|
* effect of resolving it, so the workflow cannot learn ISOLATION without also
|
|
* recording it. `record-dispatch-isolation` (routeRecordDispatchIsolation)
|
|
* remains as an explicit fallback/testable primitive and shares the exact
|
|
* same atomic-write implementation.
|
|
*
|
|
* Every test here drives the REAL gsd-tools.cjs CLI (via runGsdTools) and
|
|
* asserts on the sentinel file it actually wrote, parsed as JSON — no
|
|
* fixture-text/source-string assertions.
|
|
*/
|
|
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
const os = require('node:os');
|
|
const { runGsdTools, createTempProject, cleanup } = require('./helpers.cjs');
|
|
const { gitOrThrow } = require('./helpers/git-fixture.cjs');
|
|
const { SENTINEL_RELATIVE_PATH, readSentinel } = require('../hooks/lib/isolation-sentinel.js');
|
|
const { runtimes } = require('../gsd-core/bin/lib/capability-registry.cjs');
|
|
|
|
function sentinelFile(dir) {
|
|
return path.join(dir, SENTINEL_RELATIVE_PATH);
|
|
}
|
|
|
|
function readSentinelRaw(dir) {
|
|
return JSON.parse(fs.readFileSync(sentinelFile(dir), 'utf-8'));
|
|
}
|
|
|
|
describe('#3045 CORE REDESIGN — dispatch-isolation records as an unconditional side effect', () => {
|
|
test('a plain --raw query with no explicit isolation-record verb still writes the sentinel', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
assert.equal(fs.existsSync(sentinelFile(dir)), false, 'precondition: no sentinel yet');
|
|
const result = runGsdTools(
|
|
['query', 'dispatch-isolation', '--raw', '--phase', '7'],
|
|
dir,
|
|
{ GSD_RUNTIME: 'claude', HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
assert.equal(result.output.trim(), 'harness-worktree');
|
|
|
|
const sentinel = readSentinelRaw(dir);
|
|
assert.equal(sentinel.isolation, 'harness-worktree');
|
|
assert.equal(sentinel.harness_flag, 'isolation="worktree"');
|
|
assert.equal(sentinel.phase, '7');
|
|
assert.equal(sentinel.plan, null);
|
|
assert.equal(typeof sentinel.written_at, 'number');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('--json output and the recorded sentinel agree on isolation + harnessFlag', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'dispatch-isolation', '--json', '--phase', '3', '--plan', 'plan-b'],
|
|
dir,
|
|
{ GSD_RUNTIME: 'claude', HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
const parsed = JSON.parse(result.output);
|
|
const sentinel = readSentinelRaw(dir);
|
|
assert.equal(sentinel.isolation, parsed.isolation);
|
|
assert.equal(sentinel.harness_flag, parsed.harnessFlag);
|
|
assert.equal(sentinel.phase, '3');
|
|
assert.equal(sentinel.plan, 'plan-b');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('--force-isolation none overrides a naturally-resolved harness-worktree host and clears harnessFlag', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'dispatch-isolation', '--raw', '--phase', '4', '--force-isolation', 'none'],
|
|
dir,
|
|
{ GSD_RUNTIME: 'claude', HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
// routeDispatchIsolation's own stdout still reflects the FORCED value.
|
|
assert.equal(result.output.trim(), 'none');
|
|
|
|
const sentinel = readSentinelRaw(dir);
|
|
assert.equal(sentinel.isolation, 'none');
|
|
assert.equal(sentinel.harness_flag, null);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('an invalid --force-isolation value is ignored, not applied', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'dispatch-isolation', '--raw', '--force-isolation', 'bogus-mode'],
|
|
dir,
|
|
{ GSD_RUNTIME: 'claude', HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
assert.equal(result.output.trim(), 'harness-worktree');
|
|
assert.equal(readSentinelRaw(dir).isolation, 'harness-worktree');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('#3045 BLOCKER 1 — a later, plan-scoped call overwrites an earlier phase-only sentinel atomically', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
// Phase-level resolve (as the "Resolve ISOLATION" step performs it).
|
|
runGsdTools(['query', 'dispatch-isolation', '--raw', '--phase', '9'], dir, { GSD_RUNTIME: 'claude', HOME: dir });
|
|
assert.equal(readSentinelRaw(dir).plan, null);
|
|
|
|
// Per-plan gate degrades THIS plan to sequential (submodule intersection).
|
|
const r = runGsdTools(
|
|
['query', 'dispatch-isolation', '--raw', '--phase', '9', '--plan', 'plan-sub', '--force-isolation', 'none'],
|
|
dir,
|
|
{ GSD_RUNTIME: 'claude', HOME: dir },
|
|
);
|
|
assert.equal(r.success, true, r.error);
|
|
|
|
const sentinel = readSentinelRaw(dir);
|
|
assert.equal(sentinel.isolation, 'none', 'the plan-scoped degrade must win over the stale phase-level record');
|
|
assert.equal(sentinel.plan, 'plan-sub');
|
|
assert.equal(sentinel.phase, '9');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('the sentinel round-trips through the real reader (hooks/lib/isolation-sentinel.js)', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
runGsdTools(
|
|
['query', 'dispatch-isolation', '--raw', '--phase', '2', '--plan', 'p1'],
|
|
dir,
|
|
{ GSD_RUNTIME: 'claude', HOME: dir },
|
|
);
|
|
const read = readSentinel(dir);
|
|
assert.equal(read.present, true);
|
|
assert.equal(read.stale, false);
|
|
assert.equal(read.malformed, false);
|
|
assert.equal(read.isolation, 'harness-worktree');
|
|
assert.equal(read.harnessFlag, 'isolation="worktree"');
|
|
assert.equal(read.phase, '2');
|
|
assert.equal(read.plan, 'p1');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
});
|
|
|
|
describe('#3045 MAJOR — --harness-flag can now accept a bare CLI-flag value (Cursor real registry value + generalized parsing)', () => {
|
|
test('record-dispatch-isolation --harness-flag=--worktree persists the REAL cursor registry value verbatim', () => {
|
|
const cursorFlag = runtimes.cursor.runtime.harnessIsolationFlag;
|
|
assert.equal(cursorFlag, '--worktree', 'precondition: registry shape assumed by this test');
|
|
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'record-dispatch-isolation', '--isolation', 'harness-worktree', `--harness-flag=${cursorFlag}`, '--phase', '1'],
|
|
dir,
|
|
{ HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
const sentinel = readSentinelRaw(dir);
|
|
assert.equal(sentinel.harness_flag, cursorFlag);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('record-dispatch-isolation --harness-flag=<bare-flag> persists ANY bare-CLI-flag-shaped value verbatim (parser is not Cursor-specific)', () => {
|
|
// A prior draft of this test asserted `runtimes.windsurf.runtime.harnessIsolationFlag
|
|
// === '--worktree'`, assuming Windsurf's registry entry mirrors Cursor's.
|
|
// It does not: Windsurf's `hostIntegration.dispatch.isolation` is 'none'
|
|
// and it declares NO `harnessIsolationFlag` at all — per ADR-1239
|
|
// (docs/adr/1239-gsd-embeddable-orchestration-engine.md:247,250),
|
|
// `pi`/`zcode`/`windsurf` "genuinely cannot benefit and correctly stay
|
|
// none" because they lack named/concurrent subagent dispatch, so there is
|
|
// no per-dispatch isolation flag for Windsurf to record. That was a wrong
|
|
// test expectation (a fabricated registry precondition), not a production
|
|
// defect — corrected here to prove the `--harness-flag=<value>` parser
|
|
// generalizes to any bare-CLI-flag-shaped value, not merely Cursor's
|
|
// specific '--worktree' string (which the sub-test above already pins).
|
|
assert.equal(
|
|
runtimes.windsurf.runtime.harnessIsolationFlag,
|
|
undefined,
|
|
'precondition: windsurf declares no harnessIsolationFlag (isolation: "none", ADR-1239)',
|
|
);
|
|
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'record-dispatch-isolation', '--isolation', 'harness-worktree', '--harness-flag=--isolated', '--phase', '1'],
|
|
dir,
|
|
{ HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
assert.equal(readSentinelRaw(dir).harness_flag, '--isolated');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('the legacy space-separated form still rejects a value that looks like another flag (unchanged, regression pin)', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'record-dispatch-isolation', '--isolation', 'harness-worktree', '--harness-flag', '--worktree', '--phase', '1'],
|
|
dir,
|
|
{ HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
assert.equal(readSentinelRaw(dir).harness_flag, null, 'space form must not swallow a value shaped like a flag');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('record-dispatch-isolation still errors with usage text when --isolation is missing', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(['query', 'record-dispatch-isolation'], dir, { HOME: dir });
|
|
assert.equal(result.success, false);
|
|
assert.match(result.error, /Usage: record-dispatch-isolation/);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('record-dispatch-isolation accepts --plan and records it', () => {
|
|
const dir = createTempProject('gsd-3045-resolver-');
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'record-dispatch-isolation', '--isolation', 'none', '--phase', '5', '--plan', 'plan-x'],
|
|
dir,
|
|
{ HOME: dir },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
const sentinel = readSentinelRaw(dir);
|
|
assert.equal(sentinel.isolation, 'none');
|
|
assert.equal(sentinel.phase, '5');
|
|
assert.equal(sentinel.plan, 'plan-x');
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
});
|
|
|
|
describe('#3045 MINOR — writer/reader sentinel path derivation now agrees for a linked worktree without its own .planning/', () => {
|
|
function git(args, cwd) {
|
|
gitOrThrow(args, { cwd });
|
|
}
|
|
|
|
test('a sentinel written from a linked worktree (via --cwd) is found by readSentinel() called with that SAME worktree path', () => {
|
|
const mainRepo = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-3045-minor-main-'));
|
|
const wtParent = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-3045-minor-wtparent-'));
|
|
try {
|
|
git(['init'], mainRepo);
|
|
git(['config', 'user.email', 'test@test.com'], mainRepo);
|
|
git(['config', 'user.name', 'Test'], mainRepo);
|
|
git(['config', 'commit.gpgsign', 'false'], mainRepo);
|
|
fs.writeFileSync(path.join(mainRepo, 'README.md'), 'placeholder\n');
|
|
git(['add', '-A'], mainRepo);
|
|
git(['commit', '-m', 'initial commit'], mainRepo);
|
|
|
|
// .planning/ is created AFTER the commit — uncommitted/untracked, the
|
|
// documented shape where a linked worktree does NOT get its own copy
|
|
// (git worktree only checks out tracked files).
|
|
fs.mkdirSync(path.join(mainRepo, '.planning'));
|
|
fs.writeFileSync(path.join(mainRepo, '.planning', 'config.json'), JSON.stringify({}));
|
|
|
|
const linked = path.join(wtParent, 'linked');
|
|
git(['worktree', 'add', linked, '-b', 'gsd-3045-minor-branch'], mainRepo);
|
|
assert.equal(fs.existsSync(path.join(linked, '.planning')), false, 'precondition: linked worktree has no own .planning/');
|
|
|
|
// Write FROM the linked worktree path — mirrors an orchestrator
|
|
// running in a linked worktree calling `dispatch-isolation`.
|
|
const result = runGsdTools(
|
|
['query', 'dispatch-isolation', '--raw', '--cwd', linked, '--phase', '1'],
|
|
mainRepo,
|
|
{ GSD_RUNTIME: 'claude', HOME: mainRepo },
|
|
);
|
|
assert.equal(result.success, true, result.error);
|
|
|
|
// The writer resolved up to the MAIN worktree (findProjectRoot(resolveMainWorktreeCwd(...))) —
|
|
// the sentinel must NOT exist at the linked worktree's own (nonexistent) .gsd/.
|
|
assert.equal(fs.existsSync(sentinelFile(linked)), false, 'writer must not have written under the linked worktree itself');
|
|
assert.equal(fs.existsSync(sentinelFile(mainRepo)), true, 'writer must have resolved up to the main worktree');
|
|
|
|
// The READER, given the raw linked-worktree cwd (exactly what a guard
|
|
// hook receives as data.cwd / workspace_roots[i]), must derive the SAME
|
|
// root the writer did and find the sentinel — this is the MINOR fix.
|
|
const read = readSentinel(linked);
|
|
assert.equal(read.present, true, 'reader must resolve the linked worktree up to the main worktree, same as the writer');
|
|
assert.equal(read.stale, false);
|
|
assert.equal(read.isolation, 'harness-worktree');
|
|
} finally {
|
|
cleanup(mainRepo);
|
|
cleanup(wtParent);
|
|
}
|
|
});
|
|
});
|