Files
msd-core/tests/research-provider.property.test.cjs
Tom Boucher 5fa4dcd78c fix: recover silently-excluded test dirs + test-architecture audit hardening (#1195)
* fix: recurse test discovery so subdir test suites actually run

scripts/run-tests.cjs discovered tests with a flat readdirSync(testDir),
silently excluding tests/observability/ (4 files), tests/dispatch/ (1) and
tests/installer-migrations/ (1) — 94 passing tests — from `npm test` and all
CI lanes. Walk the tree recursively (relative subpaths preserved), classify
suites by basename, and add a fail-on-zero-executed guard for suite/default
runs (escape hatch GSD_ALLOW_EMPTY_SUITE=1) while preserving the empty
--files/--files-from path the CI inert lane relies on.

Unit suite 735 -> 741 files; surfaces ADR-227's observability/dispatch seam.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: retire 5 verified-worthless tests

Adversarial verification confirmed these 5 prove nothing — their coverage is
provided more strictly elsewhere:
- enh-2790 'has a name: field' spot-checks (command-contract enforces /^gsd[:-]/)
- command-routing-hub duplicate construct + duplicate ERROR_KINDS assertions
- no-cjs-sdk-handsync-tooling (guarded files that never existed on main; bug-190
  covers the real retired SDK artifacts)
- runtime-artifact-layout cline edge case (subsumed by the explicit-global test
  and bug-782-cline-skills-emission)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: add ADR-218 release version-validation coverage

ADR-218 (reject leading-zero versions like 1.01.0; npm duplicate pre-check) had
zero tests — the logic lived only in release.yml bash. Add a test that extracts
the actual rejection regexes from the workflow and exercises them against a
boundary table (leading-zero/malformed rejected, valid accepted) plus structural
wiring assertions. Goes red if the regex is reverted to [0-9]+.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: redesign weak tests into behavioral, deterministic assertions

Per the ADR test audit, rewrite 27 weak test files (test-only, no source
changes) so each can go red for the defect it guards:
- kill pass-always assert.ok(true) placeholders (research-cli, worktree-baseref,
  bug-260 security guard, eslint-rules x24, clusters '|| true')
- replace source-text grep with behavioral calls (install Kilo, sh-hook-paths,
  plan-review-convergence) and add a repo-layout governance test
- de-flake real-clock/Math.random coupling (phase last_updated, bug-3707 mtime,
  context-utilization property, feat-3594)
- fix independence/shared-state violations (bug-492 singleton, issue-844 tmpRoot,
  core reapStaleTempFiles, active-workstream TTY, feat-488 GSD_HOME)
- strengthen property/shape-only tests (research-provider/store classification +
  collision) and unconditional plugin.json schema validation (issue-766)

Verified: all 28 files run together 1220 pass / 0 fail / 1 skip.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: add no-tautological-assert lint rule, error in test suite

New custom ESLint rule (eslint-rules/no-tautological-assert.cjs) bans asserts
that can never fail: assert(true)/assert.ok(<always-truthy literal>),
'cond || true' inside an assert, and equality asserts comparing two identical
literals. Wired as error on tests/**; full sweep confirmed zero existing
violations so the suite stays green. Prevents the placeholder-assert regressions
the audit redesigns just removed. RuleTester coverage added (6 valid, 8 invalid).

Note: no-only-tests was already enforced via eslint-plugin-no-only-tests, so no
duplicate rule was added.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: gate new allow-test-rule exemptions to require an issue ref

ADR-456 requires any allow-test-rule exemption added after the ADR to carry a
tracking issue number, but nothing enforced it. New ratchet gate
(scripts/lint-allow-test-rule-refs.cjs, wired into lint:ci) fails when a NEW
allow-test-rule comment lacks a #NNN/URL reference; the 323 existing untracked
exemptions are grandfathered in an allowlist that ratchets down as they gain
refs. Red-green verified (novel untracked offender fails; compliant passes).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* docs: add ADR test-audit evidence report (#1192)

Full risk-first qa-test-architect audit of the ADR portfolio (37 ADRs + 4
platform lenses, adversarial verification of retire verdicts) that drove the
P0 discovery fix, ADR-218 coverage, 5 retires, 27 redesigns, and the two new
lint gates. Filed as point-in-time evidence under docs/issueevidence/, named
for tracking issue #1192.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: replace pre-existing raw NUL byte with escape in feat-3594 fixture

feat-3594's null-byte parser fixture contained a literal NUL byte (pre-existing
on next at b10e5681 — confirmed: base blob has 1 NUL, this fix has 0), which
made git treat the file as binary and would break grep/editors. Switch to the
\x00 escape; the runtime string value (a real NUL in the parser input) is
unchanged.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: address adversarial-review findings

Codex adversarial pass over the branch:
- capability-registry drift test no longer mutates the committed generated
  capability-registry.cjs in place (concurrency hazard) — uses in-memory
  checkPipeline comparison instead.
- allow-test-rule ratchet now detects exemptions in ALL comment forms (block
  /* */ too, matching no-source-grep) so a block comment can't bypass it;
  one newly-surfaced pre-existing offender grandfathered (323->324).
- install.test Kilo case asserts on what install(false,'kilo') actually writes
  rather than manually calling configureKiloPermissions (masked the call site).
- issue-766 drops the undeclared transitive ajv dep for explicit structural
  assertions from the schema fixture.
- adr-218 test notes the hotfix leading-zero gap is tracked in #1186.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix: address code-review findings (subdir discovery, rule + test gaps)

xhigh code review surfaced 15 confirmed issues, all fixed:
- run-tests.cjs --files now resolves subdir tests by bare basename + handles
  Windows backslash paths (ambiguous basenames error clearly).
- affected-tests-lib.cjs listTestFiles made recursive — the targeted CI lane was
  silently dropping changed subdir tests (same false-green class the audit fixed).
- no-tautological-assert now catches 'true || cond' and empty []/{}  equality.
- verify-test-quality: restore provenance-classification coverage, tighten the
  writeFile circular-detection check, guard the module-level file read.
- sh-hook-paths: cover the global-install .sh delegation branch (#2045 guard).
- active-workstream null-guard runs deterministically (no longer skipped on TTY).
- adr-218 structural guards tightened (major/minor leading-zero; needs: membership).
- repo-layout AGENTS.md guard no longer false-alarms on equivalent refactors.
- cross-ai ordering guard fails red when the step is missing.
- issue-766 parses required fields from the schema fixture (auto-enforced).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test: stub USERPROFILE alongside HOME in feat-488 (Windows parity)

The feat-488 redesign stubbed process.env.HOME but not USERPROFILE; os.homedir()
resolves from USERPROFILE on Windows, so the home stub was not hermetic there —
caught by windows-test-parity-guard (stubsHomeNoUserProfile). Save/set/restore
USERPROFILE symmetrically with HOME (delete-if-originally-undefined).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore: reconcile allow-test-rule allowlist after rebase onto next

Rebasing onto current next pulled in merged PR #1170, which added
inventory-headings-countfree.test.cjs (a baseline allow-test-rule exemption) and
deleted inventory-counts.test.cjs. Grandfather the former and prune the latter so
the ratchet matches the merged tree. No new debt from this PR.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 23:35:08 -04:00

261 lines
8.1 KiB
JavaScript

'use strict';
/**
* Property-based and boundary tests for research-provider.cjs classifyConfidence.
*
* Two layers of coverage:
* (a) Robustness property — classifyConfidence never throws on arbitrary inputs
* and always returns a valid confidence level.
* (b) Classification boundary examples — specific inputs assert HIGH vs MEDIUM vs LOW
* so that inverting the classification rules makes at least one test go red.
*
* RULESET.TESTS.property-based-testing
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fc = require('./helpers/fast-check-setup.cjs');
const { classifyConfidence } = require('../gsd-core/bin/lib/research-provider.cjs');
// ---------------------------------------------------------------------------
// (a) Robustness property: classifyConfidence never throws + always valid type
// ---------------------------------------------------------------------------
describe('research-provider property: classifyConfidence never throws', () => {
test('classifyConfidence({provider: any, verifiedAgainstOfficial: any, legitimacyVerdict: any}) never throws', () => {
// Sample legitimacyVerdict from values an agent might supply or that arrive via checkPackages
const legitimacyVerdictArb = fc.oneof(
fc.constant('OK'),
fc.constant('SUS'),
fc.constant('SLOP'),
fc.constant(undefined),
fc.constant(null),
fc.integer(),
fc.anything(),
);
fc.assert(
fc.property(
fc.anything(),
fc.anything(),
legitimacyVerdictArb,
(provider, verifiedAgainstOfficial, legitimacyVerdict) => {
let result;
assert.doesNotThrow(() => {
result = classifyConfidence({ provider, verifiedAgainstOfficial, legitimacyVerdict });
});
// Must return one of the three valid confidence levels
assert.ok(
result === 'HIGH' || result === 'MEDIUM' || result === 'LOW',
`Expected HIGH|MEDIUM|LOW but got: ${String(result)}`
);
}
)
);
});
});
// ---------------------------------------------------------------------------
// (b) Classification boundary examples
//
// Classification rules (in priority order):
// 1. legitimacyVerdict 'SLOP' → LOW (cap, checked first — overrides authority)
// 2. legitimacyVerdict 'OK' + known authority (!== 'none') → HIGH
// 3. authority === 'official' (context7, ref) → MEDIUM (no legitimacyVerdict)
// 4. authority === 'scrape' (jina, firecrawl) → MEDIUM (no legitimacyVerdict)
// 5. legitimacyVerdict 'OK' + unknown provider → MEDIUM (groundTruth but no authority)
// 6. authority === 'web' (exa/tavily/brave/perplexity/websearch)
// + verifiedAgainstOfficial === true → MEDIUM
// 7. everything else (web without verification, unknown provider) → LOW
// ---------------------------------------------------------------------------
describe('research-provider boundary: HIGH classification', () => {
// Rule 2: groundTruth + any known authority → HIGH
test('context7 (official) + OK verdict → HIGH', () => {
assert.equal(
classifyConfidence({ provider: 'context7', legitimacyVerdict: 'OK' }),
'HIGH'
);
});
test('ref (official) + OK verdict → HIGH', () => {
assert.equal(
classifyConfidence({ provider: 'ref', legitimacyVerdict: 'OK' }),
'HIGH'
);
});
test('jina (scrape) + OK verdict → HIGH', () => {
assert.equal(
classifyConfidence({ provider: 'jina', legitimacyVerdict: 'OK' }),
'HIGH'
);
});
test('exa (web) + OK verdict → HIGH', () => {
assert.equal(
classifyConfidence({ provider: 'exa', legitimacyVerdict: 'OK' }),
'HIGH'
);
});
test('tavily (web) + OK verdict → HIGH', () => {
assert.equal(
classifyConfidence({ provider: 'tavily', legitimacyVerdict: 'OK' }),
'HIGH'
);
});
});
describe('research-provider boundary: MEDIUM classification', () => {
// Rule 3: official authority alone (no verdict)
test('context7, no verdict → MEDIUM (official authority alone)', () => {
assert.equal(
classifyConfidence({ provider: 'context7' }),
'MEDIUM'
);
});
test('ref, no verdict → MEDIUM (official authority alone)', () => {
assert.equal(
classifyConfidence({ provider: 'ref' }),
'MEDIUM'
);
});
// Rule 4: scrape authority alone (no verdict)
test('jina, no verdict → MEDIUM (scrape authority alone)', () => {
assert.equal(
classifyConfidence({ provider: 'jina' }),
'MEDIUM'
);
});
test('firecrawl, no verdict → MEDIUM (scrape authority alone)', () => {
assert.equal(
classifyConfidence({ provider: 'firecrawl' }),
'MEDIUM'
);
});
// Rule 5: OK verdict + unknown provider → MEDIUM (groundTruth but no authority)
test('unknown provider + OK verdict → MEDIUM (groundTruth, no authority)', () => {
assert.equal(
classifyConfidence({ provider: 'unknown-provider', legitimacyVerdict: 'OK' }),
'MEDIUM'
);
});
test('undefined provider + OK verdict → MEDIUM (groundTruth, no authority)', () => {
assert.equal(
classifyConfidence({ provider: undefined, legitimacyVerdict: 'OK' }),
'MEDIUM'
);
});
// Rule 6: web authority + verifiedAgainstOfficial === true → MEDIUM
test('exa + verifiedAgainstOfficial:true (no verdict) → MEDIUM', () => {
assert.equal(
classifyConfidence({ provider: 'exa', verifiedAgainstOfficial: true }),
'MEDIUM'
);
});
test('tavily + verifiedAgainstOfficial:true (no verdict) → MEDIUM', () => {
assert.equal(
classifyConfidence({ provider: 'tavily', verifiedAgainstOfficial: true }),
'MEDIUM'
);
});
test('websearch + verifiedAgainstOfficial:true (no verdict) → MEDIUM', () => {
assert.equal(
classifyConfidence({ provider: 'websearch', verifiedAgainstOfficial: true }),
'MEDIUM'
);
});
// SUS verdict: not OK → does not reach rule 2; official authority → MEDIUM via rule 3
test('context7 + SUS verdict → MEDIUM (SUS is not OK; official authority applies)', () => {
assert.equal(
classifyConfidence({ provider: 'context7', legitimacyVerdict: 'SUS' }),
'MEDIUM'
);
});
});
describe('research-provider boundary: LOW classification', () => {
// Rule 1: SLOP caps everything — even trusted official providers
test('context7 + SLOP verdict → LOW (SLOP cap overrides official authority)', () => {
assert.equal(
classifyConfidence({ provider: 'context7', legitimacyVerdict: 'SLOP' }),
'LOW'
);
});
test('ref + SLOP verdict → LOW (SLOP cap overrides official authority)', () => {
assert.equal(
classifyConfidence({ provider: 'ref', legitimacyVerdict: 'SLOP' }),
'LOW'
);
});
test('exa + SLOP verdict → LOW (SLOP cap overrides web authority)', () => {
assert.equal(
classifyConfidence({ provider: 'exa', legitimacyVerdict: 'SLOP' }),
'LOW'
);
});
// Rule 7: web authority without verification and no OK verdict → LOW
test('exa, no verdict, verifiedAgainstOfficial:false → LOW', () => {
assert.equal(
classifyConfidence({ provider: 'exa', verifiedAgainstOfficial: false }),
'LOW'
);
});
test('websearch, no verdict → LOW', () => {
assert.equal(
classifyConfidence({ provider: 'websearch' }),
'LOW'
);
});
test('perplexity, no verdict → LOW', () => {
assert.equal(
classifyConfidence({ provider: 'perplexity' }),
'LOW'
);
});
test('brave, no verdict → LOW', () => {
assert.equal(
classifyConfidence({ provider: 'brave' }),
'LOW'
);
});
// Rule 7: completely unknown provider, no other signals → LOW
test('unknown provider, no verdict → LOW', () => {
assert.equal(
classifyConfidence({ provider: 'unknown-provider' }),
'LOW'
);
});
test('undefined provider, no verdict → LOW', () => {
assert.equal(
classifyConfidence({ provider: undefined }),
'LOW'
);
});
test('null provider, no verdict → LOW', () => {
assert.equal(
classifyConfidence({ provider: null }),
'LOW'
);
});
});