* test(#2724): delete golden-install-parity fixtures, test, and generator Removes the 19 committed path->hash manifests, the two per-file size baselines, tests/golden-install-parity.test.cjs, and scripts/gen-golden-install-parity-zcode.cjs. These were pure functions of the source tree (ADR-2719); the differential attribution check (tests/emitted-attribution.test.cjs + tests/emitted-provenance.test.cjs) is now the sole gate for emitted-artifact propagation. tests/fixtures/install-tree/*.json and tests/golden-install-tree.test.cjs are unchanged (ADR-2719 section 7 exception). Follow-up commits fix the resulting bookkeeping: scripts/ci-test-scope.cjs's existence guard, .gitattributes, package.json scripts, the emitted-provenance totality guard's IO, the differential check's baseline acquisition, CI wiring to publish/restore the baseline artifact, and docs. * refactor(#2724): make the differential attribution check self-sufficient Three fixes required to delete the golden fixtures without breaking CI: - scripts/ci-test-scope.cjs: remove tests/golden-install-parity.test.cjs from the three rules that named it. #2759's missingRuleTestFiles guard hard-throws at module load if a rule names a test file absent from disk, which would break the changes job on every PR the moment the fixture-deletion commit landed. - tests/helpers/emitted-provenance.cjs: loadManifests() read the committed golden fixture directory. With that directory deleted at every future ref, this would throw at module load forever, taking the Phase 2 totality guard down with it. Rebuilt from real installer spawns (MANIFEST_FAMILIES + runMinimalInstall + buildParityManifest), the same shape emitted-runtime.cjs's currentManifests() already uses. - tests/emitted-attribution.test.cjs / tests/helpers/emitted-runtime.cjs: the real-tree test's baseline acquisition swaps from baselineManifestsAtRef(base) (git show at a ref that no longer carries fixtures) to resolveBaseline()'s documented precedence: env, then the on-disk cache, then an in-job build. The build fallback (buildBaselineAtRef, new) checks out base into a throwaway git worktree and runs the new scripts/gen-emitted-baseline.cjs there -- no npm ci needed, since bin/install.js and the test helper shells are Node-builtins-only. That script also publishes the baseline artifact from CI's push-to-next job (wired in a follow-up commit). * refactor(#2724): retire the merge-driver bridge and per-file size baselines The Phase 1 bridge (#2721) is retired now that the artifacts it guarded are deleted: scripts/git-merge-regen-driver.cjs, its test, and the 'setup:merge-driver' npm script are removed, and the .gitattributes merge=gsd-regen/linguist-generated block for the three deleted-path globs is dropped. tests/fixtures/install-tree/*.json keeps its normal merge behavior, unchanged (ADR-2719 section 7). scripts/update-size-baseline.cjs and its test are removed: their sole purpose was regenerating tests/workflow-size-baseline.json and tests/agent-size-baseline.json, both deleted. The 'size:baseline' npm script and its step in 'regen:derived' go with it. The per-file baseline describe blocks in tests/workflow-size-budget.test.cjs and tests/agent-size-budget.test.cjs are removed for the same reason; the independent loose-tier hard caps are untouched. The differential attribution check's size ratchet (tests/emitted-diff.cjs, already shipped in #2723) is the replacement anti-creep mechanism. 'npm run gen:golden' is replaced by 'npm run gen:install-tree', which keeps regenerating tests/fixtures/install-tree/*.json (the one artifact family ADR-2719 section 7 keeps committed); tests/golden-install-tree.test.cjs's error messages point at the new command name. tests/golden-parity-single-source.test.cjs's anti-divergence guard (#2266) is retargeted from the two deleted golden-parity consumers to their two replacements (tests/helpers/emitted-runtime.cjs and tests/helpers/emitted-provenance.cjs), which import buildParityManifest the same way — the divergence risk the guard exists for is unchanged. Also wires CI: a new publish-emitted-baseline job runs scripts/gen-emitted-baseline.cjs after a push to next and caches the result keyed on the sha; the test and test-full jobs restore that cache on pull_request events, keyed on the PR's base sha, and export GSD_EMITTED_BASELINE for tests/emitted-attribution.test.cjs's real-tree test to pick up. * docs(#2724): flip ADR-2719 to Accepted and update contributor docs Status: Proposed -> Accepted. Regenerated docs/adr/README.md index. CONTRIBUTING.md, docs/TESTING-SUITES.md, and CONTEXT.md (RULESET. EMITTED_ATTRIBUTION, RULESET.WORKFLOW_SIZE_BUDGET, RULESET. AGENT_SIZE_BUDGET, and the Emitted Artifact Provenance glossary entry) no longer point at the deleted golden-install-parity fixtures, size baselines, gen:golden, UPDATE_GOLDEN, or the setup:merge-driver / git-merge-regen-driver.cjs bridge. Editing shipped content now requires zero manual fixture regeneration, documented against the differential attribution check instead of the deleted commands. * docs(#2724): add changeset for removed golden-parity commands * fix(#2724): drop stale scripts/update-size-baseline.cjs glossary ref check-glossary-refs.cjs verifies every backtick-wrapped scripts/*.cjs token in CONTEXT.md resolves to a real file. The RULESET. EMITTED_ATTRIBUTION rewrite named the deleted script inside backticks, which the checker reads as a live reference, not historical prose. * test(#2724): retarget ci-test-scope tests off the deleted golden test tests/ci-test-scope.test.cjs asserted specific RULES entries select tests/golden-install-parity.test.cjs, and that every rule selecting it also selects both emitted gates. Both premises broke when the golden test was deleted (#2724): the deleted filename never re-appears in targeted_tests, and there was no longer a third file for the gates to travel alongside. Retargeted the two selection describe blocks to assert tests/emitted-provenance.test.cjs directly (the drift guard the golden gate's rules were retargeted to), and simplified the third block to assert the two emitted gates always travel together, without reference to the golden filename. * docs(#2724): repoint two contributor how-to guides at the differential check Both guides told contributors to regenerate a baseline against tests/golden-install-parity.test.cjs, which #2724 deletes. Repointed at the differential attribution check (tests/emitted-attribution.test.cjs, ADR-2719), which needs no manual regeneration step. * fix(#2724): repair phase6-capstone-conformance's deleted-baseline read An independent orthogonal review caught a real regression this branch introduced into a test file the branch's diff never touched: tests/phase6-capstone-conformance.test.cjs read tests/workflow-size-baseline.json (deleted earlier in this branch) with no fallback, so the whole suite would throw ENOENT the moment this branch landed. The test's actual intent — prove the host-loop workflow files are real, tracked, non-empty docs — is preserved by asserting the live byte count via the same shared counter (scripts/workflow-size.cjs) the size guards already use, instead of a committed snapshot. Also, from the same review: a stale doc comment in scripts/workflow-size.cjs still named the deleted scripts/update-size-baseline.cjs as a consumer, and buildBaselineAtRef's cleanup in tests/helpers/emitted-runtime.cjs left two fs.rmSync calls unguarded against masking the primary result/error, inconsistent with the try/catch already wrapping the git cleanup beside them. Both fixed. A doc comment was added to baselineFamilyNamesAtRef explaining why it (and its siblings) are kept despite having no production caller post-cutover — they still answer real questions about refs that predate the cutover. * fix(#2724): repair three real regressions found by remote verification 1. tests/emitted-provenance.test.cjs's two hostile-input tests (non-object manifest, unreadable fixture) drove loadManifests(tmp) and monkeypatched fs.readFileSync, both premised on the deleted fixture-directory read this branch already replaced with real installer spawns -- the negative assertions silently stopped firing. loadManifests() now accepts injected {families, install, build, clean} (defaulting to production values), giving the tests a real seam to drive a bad build result and a build failure through the ACTUAL loader instead of a reimplementation, and added coverage that clean() still runs on both paths. 2. .github/workflows/test.yml's two 'Export GSD_EMITTED_BASELINE' steps hardcoded shell: bash, which is wrong on windows-latest (native pwsh) and on test-full's macos-latest legs (native zsh per that job's own matrix) -- the repo's H1 shell policy (tests/policy-shell-pinning .test.cjs) caught it. Replaced the inline bash script with scripts/ci-export-emitted-baseline-env.cjs, a plain Node script: a bare 'node <path>' command line has no shell-specific syntax, so it runs correctly under bash, zsh, and pwsh without a shell override. tests/phase6-capstone-conformance.test.cjs's deleted-baseline read (caught by the same remote run, at a commit prior to this one) was already fixed in d0c3b1242 and is not touched here; verified still passing after these changes. * fix(#2724): revive ADR-1610's new-file size cap inside the differential An isolated review caught a real regression: deleting tests/workflow-size-baseline.json silently dropped NEW_FILE_CAP (ADR-1610 Decision point 3, the Codex project_doc_max_bytes anchor) with no successor. tests/helpers/emitted-diff.cjs's size ratchet already 'continue's past any file absent from sizeBaseline -- exactly the files this cap exists to bound -- so a brand-new workflow file sized 32,769-40,960 bytes passed CI clean and shipped, then risked silent truncation at the Codex anchor at runtime. ADR-1610 is Accepted and never referenced anywhere in this branch. Fix: NEW_FILE_CAP=32768 revived inside emitted-diff.cjs's own size-ratchet loop, keyed off the SAME hasOwnProperty(sizeBaseline, name) signal the growth check already computes -- 'new' is exactly 'present in sizeCurrent, absent from sizeBaseline'. Not ack-able, matching the tier hard caps it sits beside: the fix is extraction, not an acknowledgment entry. Documented, disclosed narrowing: the pure differential module cannot see XL_WORKFLOWS/LARGE_WORKFLOWS tiering (tests/workflow-size-budget.test.cjs's classification), so a legitimately large new file must extract rather than tier in, one release earlier than an existing file would need to. ADR-1610 itself is left unamended -- this restores its decision rather than re-litigating it. Also fixes a stale comment plus a redundant real 19-installer-spawn assertion left over from the pre-injection-seam version of tests/emitted-provenance.test.cjs's build-failure test, and annotates 3 of 4 stale golden-fixture citations in docs/reference/host-integration-capability-matrix.md as superseded (the 4th is an accurate historical PR narrative, left alone). * fix(#2724): repair three red CI defects on the golden-fixture cutover Windows-only provenance false attribution (defect A): the `hooks-built` provenance rule attributed `hooks/<name>.cmd` to itself. Those shims are Windows-only installer output (ensureCodexHooksJsonSessionStart / ensureCodexHooksJsonEvent, both in src/runtime-hooks-surface.cts) wrapping the same-named `.js` hook — no `.cmd` file is ever tracked in the repo, so the self-attribution resolved to a path that exists on no platform. Only windows-latest ever emits the key, so this only failed there. Fixed by special-casing `.cmd` inside the SAME `hooks-built` rule (not a dedicated rule) — a dedicated rule would match zero paths, and therefore report as a dead rule, on every non-Windows lane of the same totality guard. `sources` already supported per-match functions; `transforms` is extended to support the same shape so the attribution can vary by match within one rule. Baseline bootstrap was structurally impossible (defect B): `buildBaselineAtRef` ran `scripts/gen-emitted-baseline.cjs` from INSIDE the base-ref worktree, but that script is new in this PR and therefore absent at any base ref that predates it — every call failed closed with "Cannot find module". Fixed by running the PR checkout's own generator against the worktree via a new `--dir` parameter, decoupling "which copy of the script runs" from "which tree it measures" (`currentManifests`/`currentSizes` gained a `repoRoot` override, threaded down to `runMinimalInstall`'s new `installScript` override). This is not just a bootstrap fix: a differential needs ONE measurement schema applied to both sides, or the two stop being comparable the moment that schema evolves — running each side's own copy would silently reintroduce that risk. Verified locally end-to-end against real origin/next: resolves a valid {version, sha, manifests, sizes} artifact with the correct sha and no leaked worktree. Changeset placeholder (defect C): `pr: 0` -> `pr: 2767`, which is what let docs-lint evaluate the fragment for the first time; it already passes (docs/TESTING-SUITES.md and friends already document the removed scripts). Also fixed while in this file: an eslint no-unused-vars warning surfaced by the changed lint run (unused `cleanup` import in tests/emitted-provenance.test.cjs). Added regression coverage for both A and B: a cross-platform spot-check that drives the real hooks-built rule against `.cmd` keys directly (not through a real Windows install), and a real-tree test that drives buildBaselineAtRef against a base ref verified (via git cat-file) to lack the generator, both skipping honestly rather than false-passing when their precondition does not hold. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W5kQs6ZufZDySC6zDJfYP6 * fix(#2724): repair false .cmd byte-provenance and a permanently-skipping regression test Two isolated-review findings on PR #2767: - `hooks-built`'s `.cmd` branch attributed the Windows shim's bytes to the wrapped `hooks/<name>.js` script, asserting a byte-provenance link that does not exist — traced against buildCodexHookWindowsShimIR (src/runtime-hooks-surface.cts), only the script's NAME (a literal in that same file) flows into the .cmd bytes, never its content. Point `sources` at HOOKS_WINDOWS_SHIM_SRC instead, matching the code-derived convention used elsewhere in the table. Since `sources` is checked before `transforms` in the differential, the wrong mapping silently excused any .cmd byte movement caused by editing the wrapped .js file. - The `buildBaselineAtRef` regression test skipped unless a resolvable base ref still lacked scripts/gen-emitted-baseline.cjs — true only until this PR merges, after which every base ref carries the file and the test skips forever with zero ongoing coverage. Rebuilt hermetically: synthesize the missing-generator condition in-place via git plumbing (a throwaway commit, child of HEAD, with just that one file removed from a scratch index), never touching the real working tree, HEAD, or index, and never depending on ambient history or remotes. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W5kQs6ZufZDySC6zDJfYP6 * fix(#2724): tolerate the remote runner's dubious-ownership git mount in the emitted baseline path The runner container mounts the repo at a path owned by a different uid than the process running the suite, so git's dubious-ownership protection refuses every git operation there. GitHub Actions never hits this because actions/checkout registers the workspace as safe automatically; this runner's container does not. buildBaselineAtRef is the production build-fallback the sole remaining emitted gate depends on (resolveBaseline's in-job-build leg), not just a test helper, so the fix is in the shared git() wrapper (emitted-runtime.cjs) that every caller — resolveChangedPaths, resolveBase, buildBaselineAtRef's worktree add/remove/prune, and the hermetic regression test added in the prior commit — funnels through, plus gen-emitted-baseline.cjs's own rev-parse (now reusing that same wrapper instead of a second execFileSync, so the fix has one source of truth). Each call declares -c safe.directory=<the exact directory it already operates on>, never the * wildcard. Audited every other helper on this surface (emitted-diff.cjs, emitted-baseline.cjs, install-shared.cjs) for the same gap: none of them shell out to git at all. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01W5kQs6ZufZDySC6zDJfYP6 --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
392 lines
16 KiB
JavaScript
392 lines
16 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Differential emitted-artifact attribution — the conservation law (ADR-2719 §1,
|
|
* issue #2723, epic #2719 Phase 3).
|
|
*
|
|
* Given the emitted manifests at `next` HEAD and at PR HEAD, plus the repo paths the
|
|
* PR actually changed, decide which moved emitted paths are EXPLAINED by the diff and
|
|
* which are not. Unattributable deltas are a hard failure that names them; the only
|
|
* way through is a committed acknowledgment (`tests/emitted-drift-ack.json`).
|
|
*
|
|
* ── Why this module is pure ──────────────────────────────────────────────────
|
|
* No fs, no git, no installer, no clock. The naive shape — one integration test that
|
|
* builds 19 manifests at each end and asserts — cannot practically exercise the four
|
|
* failing-first criteria #2723 requires, so in practice they would not get written,
|
|
* which is precisely how a phase ships promised-but-not-built. Keeping the law pure
|
|
* makes every criterion a millisecond-scale table test, and makes the Stryker gate
|
|
* able to bite (a 20-branch pure function is mutation-testable; a 40-minute
|
|
* integration test is not).
|
|
*
|
|
* The expensive part — obtaining the manifests — lives in emitted-baseline.cjs.
|
|
*
|
|
* ── What this does NOT do ────────────────────────────────────────────────────
|
|
* It never re-derives a byte (ADR-2719 §1 is explicit that asserting
|
|
* `emitted == transform(source)` is the tautology ADR-2264's Amendment rejected).
|
|
* It constrains which keys may move. It also never mutates repo state: no
|
|
* regeneration, no auto-ack. `UPDATE_GOLDEN=1` is exactly the escape hatch this
|
|
* design removes.
|
|
*/
|
|
|
|
const { attributeEmittedPath } = require('./emitted-provenance.cjs');
|
|
|
|
/** Ack schema version. Pinned from day one: contributors hand-write this file, so its
|
|
* shape is public the moment it ships (Hyrum). Loosening later is easy; tightening is not. */
|
|
const ACK_VERSION = 1;
|
|
|
|
/**
|
|
* A brand-new workflow/agent file — absent from the baseline, present now — must
|
|
* still stay under the Codex `project_doc_max_bytes` anchor (ADR-1610 Decision
|
|
* point 3, `NEW_FILE_CAP` in the pre-#2724 tests/workflow-size-budget.test.cjs).
|
|
*
|
|
* #2724 (ADR-2719 Phase 4) deleted the committed per-file baseline that cap used to
|
|
* key "not yet baselined" off of. The size ratchet below (ADR-2719 §4) already
|
|
* computes the exact same signal for a different reason — a name present in
|
|
* `sizeCurrent` but absent from `sizeBaseline` IS "new" by construction, the same
|
|
* definition ADR-1610 used — so no new baseline, git diff, or CI wiring is needed to
|
|
* revive the cap; it only needed a home once the old one was deleted.
|
|
*
|
|
* This is a HARD cap, not ack-able, matching the tier hard caps it sits beside
|
|
* (XL/LARGE/DEFAULT in tests/workflow-size-budget.test.cjs): the fix for exceeding it
|
|
* is extraction, never an acknowledgment entry. Not exempted by explicit XL/LARGE
|
|
* tiering the way the original test-file version was — this module is intentionally
|
|
* pure and has no access to that classification (tests/workflow-size-budget.test.cjs's
|
|
* XL_WORKFLOWS/LARGE_WORKFLOWS sets) — so a legitimately large NEW file must be split
|
|
* via the same lazy-extraction pattern the tier caps already require, one release
|
|
* earlier than an existing file would need to. Documented narrowing, not a silent one.
|
|
*/
|
|
const NEW_FILE_CAP = 32768;
|
|
|
|
/**
|
|
* Does a changed repo path satisfy a provenance `sources` entry?
|
|
*
|
|
* A trailing `/` marks a PREFIX (Phase 2's SOURCE_PREFIX_SUFFIX contract) — e.g. Kimi's
|
|
* root agent aggregates all of `agents/`. Prefix matching is SEGMENT-AWARE on purpose:
|
|
* a bare `startsWith('agents/')` would also accept `agentsfoo/x.md` under a source of
|
|
* `agents`, and silently over-attribute. Exact entries compare exactly.
|
|
*/
|
|
function sourceSatisfiedBy(source, changedSet) {
|
|
if (source.endsWith('/')) {
|
|
for (const changed of changedSet) {
|
|
if (changed.startsWith(source)) return changed;
|
|
}
|
|
return null;
|
|
}
|
|
return changedSet.has(source) ? source : null;
|
|
}
|
|
|
|
/**
|
|
* Normalize + validate the acknowledgment document.
|
|
*
|
|
* Rejects a document that parses but is not a plain object. Treating `0` / `"s"` / `[]` /
|
|
* `null` / `true` as "no acks" would SILENTLY DISARM the gate — the single worst failure
|
|
* available here, because it looks identical to a healthy run.
|
|
*
|
|
* @returns {{ entries: Map<string, {reason: string, runtime?: string}>, errors: string[] }}
|
|
*/
|
|
function parseAck(doc, { source = 'emitted-drift-ack.json' } = {}) {
|
|
const errors = [];
|
|
const entries = new Map();
|
|
|
|
if (doc === null || doc === undefined) return { entries, errors }; // absent == no acks (legal)
|
|
|
|
if (typeof doc !== 'object' || Array.isArray(doc)) {
|
|
errors.push(
|
|
`${source}: must be a JSON object, got ${Array.isArray(doc) ? 'array' : typeof doc}`,
|
|
);
|
|
return { entries, errors };
|
|
}
|
|
|
|
if (doc.version !== undefined && doc.version !== ACK_VERSION) {
|
|
errors.push(`${source}: unsupported version ${JSON.stringify(doc.version)} (expected ${ACK_VERSION})`);
|
|
}
|
|
|
|
const paths = doc.paths;
|
|
if (paths === undefined) return { entries, errors }; // `{}` or `{version:1}` == no acks
|
|
if (paths === null || typeof paths !== 'object' || Array.isArray(paths)) {
|
|
errors.push(`${source}: "paths" must be an object of <emitted path> -> { reason }`);
|
|
return { entries, errors };
|
|
}
|
|
|
|
for (const [rel, value] of Object.entries(paths)) {
|
|
const reason = value && typeof value === 'object' ? value.reason : value;
|
|
if (typeof reason !== 'string' || reason.trim() === '') {
|
|
// "name them AND say why" is the contract (ADR-2719 §3). An ack with no reason
|
|
// is a silent regeneration wearing a declaration's clothes.
|
|
errors.push(`${source}: ack for "${rel}" has no non-empty "reason"`);
|
|
continue;
|
|
}
|
|
entries.set(rel, {
|
|
reason: reason.trim(),
|
|
runtime: value && typeof value === 'object' ? value.runtime : undefined,
|
|
});
|
|
}
|
|
|
|
return { entries, errors };
|
|
}
|
|
|
|
/**
|
|
* The conservation law.
|
|
*
|
|
* @param {object} opts
|
|
* @param {object} opts.baseline { [runtime]: { [rel]: hash } } at `next` HEAD
|
|
* @param {object} opts.current { [runtime]: { [rel]: hash } } at PR HEAD
|
|
* @param {string[]} opts.changedPaths repo paths the PR changed (git diff --name-only)
|
|
* @param {object} [opts.ack] parsed emitted-drift-ack.json document (or null)
|
|
* @param {object} [opts.sizeBaseline] { [name]: bytes } workflow/agent sizes at next
|
|
* @param {object} [opts.sizeCurrent] { [name]: bytes } workflow/agent sizes at PR HEAD
|
|
*
|
|
* @returns {{
|
|
* moved: number, attributed: Array, unattributable: Array, acked: Array,
|
|
* removed: Array, grown: Array, shrunk: Array, newFileCapExceeded: Array,
|
|
* staleAcks: string[], errors: string[], ok: boolean
|
|
* }}
|
|
*/
|
|
function diffEmitted({
|
|
baseline,
|
|
current,
|
|
changedPaths,
|
|
ack = null,
|
|
sizeBaseline = null,
|
|
sizeCurrent = null,
|
|
} = {}) {
|
|
const errors = [];
|
|
|
|
if (!baseline || typeof baseline !== 'object' || Array.isArray(baseline)) {
|
|
errors.push('baseline manifest set must be an object keyed by runtime');
|
|
}
|
|
if (!current || typeof current !== 'object' || Array.isArray(current)) {
|
|
errors.push('current manifest set must be an object keyed by runtime');
|
|
}
|
|
if (!Array.isArray(changedPaths)) {
|
|
// NOT the same as an empty array. A failed `git diff` must never be read as
|
|
// "nothing changed" — that would make every moved hash unattributable and produce
|
|
// a failure storm that reads like a real finding.
|
|
errors.push('changedPaths must be an array (a failed git diff is an error, not an empty set)');
|
|
}
|
|
if (errors.length) {
|
|
return {
|
|
moved: 0, attributed: [], unattributable: [], acked: [], removed: [],
|
|
grown: [], shrunk: [], staleAcks: [], errors, ok: false,
|
|
};
|
|
}
|
|
|
|
const changedSet = new Set(changedPaths);
|
|
const { entries: ackEntries, errors: ackErrors } = parseAck(ack);
|
|
errors.push(...ackErrors);
|
|
|
|
const attributed = [];
|
|
const unattributable = [];
|
|
const acked = [];
|
|
const removed = [];
|
|
const usedAcks = new Set();
|
|
let moved = 0;
|
|
|
|
const runtimes = new Set([...Object.keys(baseline), ...Object.keys(current)]);
|
|
|
|
for (const runtime of [...runtimes].sort()) {
|
|
const before = baseline[runtime] || {};
|
|
const after = current[runtime] || {};
|
|
const keys = new Set([...Object.keys(before), ...Object.keys(after)]);
|
|
|
|
for (const rel of [...keys].sort()) {
|
|
const had = Object.prototype.hasOwnProperty.call(before, rel);
|
|
const has = Object.prototype.hasOwnProperty.call(after, rel);
|
|
|
|
if (had && has && before[rel] === after[rel]) continue; // unchanged — ignored
|
|
|
|
const change = !had ? 'added' : (!has ? 'removed' : 'modified');
|
|
moved++;
|
|
|
|
let attribution;
|
|
try {
|
|
attribution = attributeEmittedPath(rel, runtime);
|
|
} catch (err) {
|
|
// A path the Phase 2 table cannot resolve is surfaced, never silently skipped —
|
|
// otherwise a table hole becomes a blind spot in the differential too.
|
|
errors.push(`${runtime}: ${rel}: ${err.message}`);
|
|
continue;
|
|
}
|
|
|
|
const record = { runtime, rel, change, ruleId: attribution.ruleId, kind: attribution.kind };
|
|
|
|
if (change === 'removed') removed.push(record);
|
|
|
|
// Synthesized paths carry no repo source by definition, so a delta in them can
|
|
// never be "unexplained by the diff" — exempt, but still counted and reported.
|
|
if (attribution.kind === 'synthesized') {
|
|
attributed.push({ ...record, via: '<synthesized: exempt>' });
|
|
continue;
|
|
}
|
|
|
|
// Sources are checked before transforms so `via` is deterministic when a moved
|
|
// path is explained by both at once — the SOURCE is the more specific, more
|
|
// legible story ("the agent file changed") and is what a reviewer expects to
|
|
// see first, not an accident of iteration order.
|
|
let via = null;
|
|
for (const source of attribution.sources) {
|
|
const hit = sourceSatisfiedBy(source, changedSet);
|
|
// `!== null`, not truthiness: an exact match returns the source string, and an
|
|
// empty-string source would return '' — falsy, so a real match would be
|
|
// silently discarded. Unreachable with today's rules (every source is a
|
|
// non-empty template) but it is a footgun for the next rule author.
|
|
if (hit !== null) { via = hit; break; }
|
|
}
|
|
// #2757: a `derived`/`code-derived` artifact's bytes can also move because the
|
|
// TRANSFORM code that generates them changed, not the source it derives from —
|
|
// `sources` alone cannot express that. Reuses `sourceSatisfiedBy` unchanged so
|
|
// exact/prefix semantics stay identical for both lists.
|
|
if (via === null) {
|
|
for (const transform of attribution.transforms) {
|
|
const hit = sourceSatisfiedBy(transform, changedSet);
|
|
if (hit !== null) { via = hit; break; }
|
|
}
|
|
}
|
|
|
|
if (via !== null) {
|
|
attributed.push({ ...record, via });
|
|
} else if (ackEntries.has(rel)) {
|
|
usedAcks.add(rel);
|
|
acked.push({ ...record, reason: ackEntries.get(rel).reason });
|
|
} else {
|
|
unattributable.push({
|
|
...record,
|
|
expectedSources: attribution.sources,
|
|
expectedTransforms: attribution.transforms,
|
|
});
|
|
}
|
|
}
|
|
}
|
|
|
|
// ── Size ratchet, folded into the same machine (ADR-2719 §4, must-have 6) ──
|
|
// NOTE: stale-ack detection is computed AFTER this block, not before. An ack may be
|
|
// consumed by either a hash move or a size growth, so computing it earlier would
|
|
// report a size-growth ack as stale.
|
|
const grown = [];
|
|
const shrunk = [];
|
|
const newFileCapExceeded = [];
|
|
if (sizeBaseline && sizeCurrent) {
|
|
for (const name of Object.keys(sizeCurrent).sort()) {
|
|
if (!Object.prototype.hasOwnProperty.call(sizeBaseline, name)) {
|
|
// No baseline entry: this file is NEW. No `from` to diff against, so the
|
|
// growth ratchet does not apply — but the absolute new-file cap does
|
|
// (ADR-1610 Decision point 3). Never ack-able; see NEW_FILE_CAP's doc comment.
|
|
const bytes = sizeCurrent[name];
|
|
if (bytes > NEW_FILE_CAP) newFileCapExceeded.push({ name, bytes, cap: NEW_FILE_CAP });
|
|
continue;
|
|
}
|
|
const from = sizeBaseline[name];
|
|
const to = sizeCurrent[name];
|
|
if (to > from) {
|
|
// Growth needs the SAME acknowledgment. Anti-creep survives without pinning a
|
|
// number: "verify-work.md grew 1,247 bytes" beats a number moving in a 93-line map.
|
|
const isAcked = ackEntries.has(name);
|
|
if (isAcked) usedAcks.add(name);
|
|
grown.push({ name, from, to, delta: to - from, acked: isAcked });
|
|
} else if (to < from) {
|
|
// Shrinkage is not creep — reported, never gated.
|
|
shrunk.push({ name, from, to, delta: from - to });
|
|
}
|
|
}
|
|
}
|
|
|
|
const unackedGrowth = grown.filter((g) => !g.acked);
|
|
|
|
// An ack that outlives the ripple it explained is future blindness: it would silently
|
|
// pre-clear a NEW ripple on the same path. It must be deleted when the ripple is.
|
|
// Computed here, once, after BOTH the hash pass and the size pass have consumed acks.
|
|
const staleAcks = [...ackEntries.keys()].filter((rel) => !usedAcks.has(rel)).sort();
|
|
|
|
const ok = errors.length === 0
|
|
&& unattributable.length === 0
|
|
&& unackedGrowth.length === 0
|
|
&& staleAcks.length === 0
|
|
&& newFileCapExceeded.length === 0;
|
|
|
|
return {
|
|
moved,
|
|
attributed,
|
|
unattributable,
|
|
acked,
|
|
removed,
|
|
grown,
|
|
shrunk,
|
|
newFileCapExceeded,
|
|
staleAcks,
|
|
errors,
|
|
ok,
|
|
};
|
|
}
|
|
|
|
/**
|
|
* Render a report as the failure message ADR-2719 §1 specifies — it sells the whole
|
|
* design on this text, so it is a deliverable, not a detail.
|
|
*/
|
|
function formatReport(result, { sampleLimit = 20 } = {}) {
|
|
const parts = [];
|
|
|
|
if (result.errors.length) {
|
|
parts.push(`${result.errors.length} error(s):\n ${result.errors.slice(0, sampleLimit).join('\n ')}`);
|
|
}
|
|
|
|
if (result.unattributable.length) {
|
|
const list = result.unattributable.slice(0, sampleLimit)
|
|
.map((u) => {
|
|
// #2757: a rule may explain a moved path via its source OR its transform
|
|
// code; name whichever possibilities exist so the message tells the whole
|
|
// story, not just half of it.
|
|
const expected = [
|
|
u.expectedSources.length ? `a change under ${u.expectedSources.join(' or ')}` : null,
|
|
(u.expectedTransforms && u.expectedTransforms.length)
|
|
? `a transform change under ${u.expectedTransforms.join(' or ')}`
|
|
: null,
|
|
].filter(Boolean).join(', or ');
|
|
return ` ${u.runtime}: ${u.rel}\n rule ${u.ruleId}; expected ${expected}`;
|
|
});
|
|
parts.push(
|
|
`${result.unattributable.length} emitted path(s) changed that nothing in this diff explains:\n${list.join('\n')}` +
|
|
(result.unattributable.length > sampleLimit
|
|
? `\n …and ${result.unattributable.length - sampleLimit} more`
|
|
: '') +
|
|
'\n\nIf this ripple is intended, record it in tests/emitted-drift-ack.json naming each\n' +
|
|
'path and why. Do NOT regenerate anything to silence this.',
|
|
);
|
|
}
|
|
|
|
const unackedGrowth = result.grown.filter((g) => !g.acked);
|
|
if (unackedGrowth.length) {
|
|
const list = unackedGrowth.slice(0, sampleLimit)
|
|
.map((g) => ` ${g.name} grew ${g.delta} bytes (${g.from} -> ${g.to})`);
|
|
parts.push(
|
|
`${unackedGrowth.length} file(s) grew without an acknowledgment:\n${list.join('\n')}`,
|
|
);
|
|
}
|
|
|
|
if (result.newFileCapExceeded.length) {
|
|
const list = result.newFileCapExceeded.slice(0, sampleLimit)
|
|
.map((f) => ` ${f.name} is ${f.bytes} bytes — exceeds the ${f.cap}-byte new-file cap (ADR-1610)`);
|
|
parts.push(
|
|
`${result.newFileCapExceeded.length} new file(s) exceed the new-file cap (extract, not ack):\n${list.join('\n')}`,
|
|
);
|
|
}
|
|
|
|
if (result.staleAcks.length) {
|
|
parts.push(
|
|
`${result.staleAcks.length} stale acknowledgment(s) — the ripple they explained is gone, ` +
|
|
'so they must be deleted (an ack that outlives its ripple pre-clears the next one):\n ' +
|
|
result.staleAcks.slice(0, sampleLimit).join('\n '),
|
|
);
|
|
}
|
|
|
|
return parts.join('\n\n');
|
|
}
|
|
|
|
module.exports = {
|
|
ACK_VERSION,
|
|
NEW_FILE_CAP,
|
|
sourceSatisfiedBy,
|
|
parseAck,
|
|
diffEmitted,
|
|
formatReport,
|
|
};
|