Files
msd-core/tests/require-issue-link-policy.test.cjs
Tom Boucher dced41f536 chore(#3211): accept a non-closing issue reference for docs/test-only PRs (#3289)
* test(#3211): failing-first coverage for the issue-link follow-up exemption

Adds the regression suite before the policy module exists, so the RED state
is recorded against a real verdict rather than asserted. Covers the reported
gap (a fork test-only follow-up PR cannot satisfy the gate without an inert
closing keyword) and the file-list truncation vector that any diff-shape
exemption must fail closed on.

Refs #3211

* chore(#3211): accept a non-closing issue reference for docs/test-only PRs

The `Issue link required` gate modelled exactly one PR->issue relationship —
"this PR closes that issue" — and its sole exemption additionally required
same-repo identity (#1389), so a fork PR had no exemption path of any kind. A
test-only or docs-only follow-up therefore had to ship a knowingly-inert
`Closes #<already-closed-issue>` to get a green check.

The verdict now lives in scripts/require-issue-link-policy.cjs as a pure,
unit-tested function returning a typed reason. It additionally accepts a
non-closing reference (`Refs #N`, `Follow-up to #N`, ...) but only when every
changed file is under tests/, under docs/, or is a root-level *.md — the same
doc-only shape pre-pr-gate.sh:111 recognizes, minus CHANGELOG.md, which
changeset/lint.cjs classes as user-facing. Source-touching PRs still require a
closing keyword and a PR with no reference at all still hard-fails, so gate
strength is unchanged.

Both constraints the issue names as hard requirements are preserved: the
backmerge exemption keeps its same-repo conjunct, and the failing step's `if:`
stays step-level so the required check reports SUCCESS rather than a
branch-protection-blocking `skipped`.

Also closes a forgery vector found while building this. `gh pr view --json
files` returns at most 100 paths and does not paginate, while the payload's
`changed_files` reports the true total (verified live: PR #3202 returns 100 of
118). A >100-file PR could therefore present a falsely tests-only list. The new
shared helper scripts/lib/pr-changed-files.cjs fails closed when the list
cannot be confirmed complete, and the pre-existing tooling-paths carve-out in
scripts/pr-template-policy.cjs — which relaxed template enforcement on the same
untrustworthy list — now uses it too.

Closes #3211

* fix(#3211): treat the authoritative file count as authority at every list size

Both orthogonal review passes independently found the same blocker.
`fileListIsComplete` only compared the list length against the PR's true
`changed_files` count once the list reached the 100-entry page cap, so any
mechanism that shortened the list BELOW the cap went undetected:

  evaluateIssueLink({prBody:"Refs #1", sameRepo:false,
                     changedFiles:["CONTRIBUTING.md"], changedFilesTotal:3})
  -> {ok:true, reason:"ok_followup_reference"}

The concrete exploit was a $GITHUB_OUTPUT heredoc collision. Both this
workflow and pr-template-format.yml wrote the file list with a fixed
terminator (`GSD_EOF` / the even weaker `EOF`), and every path in that value
is attacker-controlled on a fork PR. A file named after the delimiter closes
the value early and drops every path after it, so a fork PR touching src/
could present a list of only its exempt-looking files and take the follow-up
exemption. That is exactly the #1389 property this change is required to
preserve.

Fixed in two independent layers:

  1. The total is now the authority at every size, not only at/above the cap.
     One rule catches truncation, delimiter collision, and a path containing
     a newline, without having to enumerate the mechanisms.
  2. Both workflows now use an unguessable random delimiter, per GitHub's
     documented guidance for untrusted multiline output.

Also from review: pr-template-format.yml never passed CHANGED_FILES_TOTAL, so
the parameter threaded through evaluatePrTemplate was always undefined in
production and would have permanently blocked the tooling carve-out for any
100+-file PR; its env is now wired. Root-doc exclusion is case-insensitive.
Dropped a no-op `tr '\n' '\n'`.

Refs #3211

* chore(#3211): regenerate install-tree fixtures for the new shared helper

scripts/lib/** ships in the install tree, so adding
scripts/lib/pr-changed-files.cjs drifts all 19 golden fixtures by exactly one
path each. Caught by tests/golden-install-tree.test.cjs (25 failures on the
remote runner), which is the drift detector doing its job — not a defect.

Placement is deliberate: every existing occupant of scripts/lib/ is a CI/dev
helper that already ships (alias-drift-families, allowlist-ratchet, cli-exit,
drift-scan), so a shared helper used by two policy scripts belongs there. The
two policy modules themselves live at the top level of scripts/ and do not
ship.

Regenerated with `npm run gen:install-tree`; the delta is one added path per
fixture and nothing else.

Refs #3211

* fix(#3211): keep the shared CI helper out of the shipped install tree

The remote runner reported 6 failures on the previous head. Two causes.

`scripts/lib/**` is enumerated in `bin/install.js` (GSD_SCRIPTS_LIB_FILES) and
ships to users, and the install suite asserts that enumeration is complete.
Putting the new shared helper there broke four install tests and drifted all 19
golden install-tree fixtures. The right answer is not to add it to the manifest
— it is CI-only tooling used by two scripts that do not ship, so it has no
business in a user's config directory. Moved to `scripts/pr-changed-files.cjs`;
top-level `scripts/` ships only what the installer names explicitly, so nothing
is enumerated and nothing ships. The fixture regeneration from the previous
commit is reverted: the install-tree fixtures are byte-identical to `next`
again, and `bin/` is untouched. That also keeps the diff free of any
user-facing path, so no changeset fragment is required.

The other failure was a stale test, not a regression. The workflow carve-out
suite asserted the backmerge exemption by grepping require-issue-link.yml for
`startsWith(github.head_ref, ...)` and `steps.check.outputs.found`. This change
moved the whole verdict — carve-out included — into the policy module and
renamed the step, so those assertions measured a location the logic no longer
occupies.

Rewritten to lock the property at its new home, and made stronger in the
process: the step-level placement is now verified by PARSING the YAML and
asserting the job carries no `if:` of its own (a job-level `if:` would make the
required check report `skipped` and block branch protection), and the #1389
anti-forgery conjunct is asserted BEHAVIORALLY against evaluateIssueLink for
both sameRepo branches rather than by matching text. The bootstrap fallback
grep is locked too, so the introducing-PR path cannot be silently dropped.

Refs #3211

* fix(#3211): correct the contributor guidance and pin it against the rule

The sticky comment the gate posts still described the qualifying diff shape as
"nothing outside tests/ and docs/". The predicate had since been widened to
also accept root-level *.md, so the guidance was narrower than the rule it
describes — and narrower in the worst direction: a contributor whose PR is
CONTRIBUTING.md plus a test, which is exactly the shape #3211 was filed about,
would have been told they do not qualify while the gate was in fact passing
them. The two failure explanations now name all three accepted shapes and the
CHANGELOG.md exclusion.

This is a shared-rule-across-parallel-surfaces drift: the guidance restates a
rule whose definition lives in EXEMPT_PATH_PREFIXES / isRootLevelDoc /
EXCLUDED_ROOT_DOCS. It was caught by eye, which is not a control. Added the
parity assertion CLAUDE.md prescribes for exactly this: the test parses the
workflow, pulls the github-script body out of the failing step, and asserts it
names every entry of EXEMPT_PATH_PREFIXES and every entry of
EXCLUDED_ROOT_DOCS — derived from the module's exports, never from a second
hardcoded copy — plus the root-level shape and an actionable `Refs #` example.

The test is non-vacuous by construction and by demonstration: it guards against
zero-length iteration and an empty script body, and removing any single
expected token from the real text makes it fail (verified per token, plus the
empty-string case which reports all five missing).

Refs #3211

---------

Co-authored-by: sim <sim@local>
2026-08-09 21:38:53 -04:00

431 lines
19 KiB
JavaScript

'use strict';
/**
* Tests for scripts/require-issue-link-policy.cjs (#3211, preserving #1389).
*
* All assertions are on the typed ISSUE_LINK_REASON enum, never on free
* text — see CLAUDE.md "Mutation Score" / test conventions.
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const yaml = require('js-yaml');
const {
ISSUE_LINK_REASON,
hasClosingKeyword,
hasFollowUpReference,
allPathsAreTestsOrDocs,
evaluateIssueLink,
EXEMPT_PATH_PREFIXES,
EXCLUDED_ROOT_DOCS,
} = require('../scripts/require-issue-link-policy.cjs');
const { fileListIsComplete } = require('../scripts/pr-changed-files.cjs');
function forkPr(overrides = {}) {
return {
prBody: '',
headRef: 'fix/123-something',
sameRepo: false,
changedFiles: ['src/init.cts'],
changedFilesTotal: 1,
...overrides,
};
}
function testPaths(n) {
return Array.from({ length: n }, (_, i) => `tests/generated-${i}.test.cjs`);
}
describe('evaluateIssueLink', () => {
// 1. Real-world vector: a fork PR that adds regression coverage for an
// issue without closing it.
test('fork PR referencing an issue with a tests-only diff is OK_FOLLOWUP_REFERENCE', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269 — regression coverage.',
changedFiles: ['tests/commit-files-pathspec.test.cjs'],
changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
assert.strictEqual(result.ok, true);
});
// 2. Every accepted reference form, including a lowercase variant.
test('every accepted follow-up reference form passes with a tests-only diff', () => {
const forms = [
'Refs #1', 'Ref #1', 'References #1', 'Relates to #1',
'Related to #1', 'Follow-up to #1', 'Follow up to #1', 'refs #1',
];
for (const body of forms) {
const result = evaluateIssueLink(forkPr({ prBody: body, changedFiles: ['tests/a.test.cjs'], changedFilesTotal: 1 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE, `form: ${body}`);
}
});
// 3. Docs-only and mixed tests+docs diffs are both allowed.
test('docs-only and mixed tests+docs diffs pass', () => {
const docsOnly = evaluateIssueLink(forkPr({
prBody: 'Refs #1', changedFiles: ['docs/CONFIGURATION.md'], changedFilesTotal: 1,
}));
assert.strictEqual(docsOnly.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
const mixed = evaluateIssueLink(forkPr({
prBody: 'Refs #1', changedFiles: ['tests/a.test.cjs', 'docs/guide.md'], changedFilesTotal: 2,
}));
assert.strictEqual(mixed.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
// 4. Windows-style backslash path is normalized before the prefix check.
test('backslash path is normalized and recognized as tests/', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #1', changedFiles: ['tests\\windows\\a.test.cjs'], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
// 5. CRLF vs LF bodies must produce the same reason.
test('CRLF and LF bodies with the same reference produce the same reason', () => {
const lf = evaluateIssueLink(forkPr({ prBody: 'Refs #1\n\nMore prose.', changedFiles: ['tests/a.test.cjs'], changedFilesTotal: 1 }));
const crlf = evaluateIssueLink(forkPr({ prBody: 'Refs #1\r\n\r\nMore prose.', changedFiles: ['tests/a.test.cjs'], changedFilesTotal: 1 }));
assert.strictEqual(lf.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
assert.strictEqual(crlf.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
// 6. No reference at all, even with a docs-only diff, fails.
test('no reference at all fails even with a docs-only diff', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Just a description, no issue mentioned.', changedFiles: ['docs/guide.md'], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_NO_ISSUE_REFERENCE);
});
// 7 & 8. A reference (not a closing keyword) touching source files needs
// an actual closing keyword instead.
test('reference-only PR touching a source file fails needs-closing', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269', changedFiles: ['src/init.cts'], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING);
});
test('reference-only PR with a mixed tests+source diff fails needs-closing', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269',
changedFiles: ['tests/a.test.cjs', 'tests/b.test.cjs', 'src/b.cts'],
changedFilesTotal: 3,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING);
});
// 9. Bodies that must NOT be recognized as any kind of issue reference.
test('non-reference bodies fail with FAIL_NO_ISSUE_REFERENCE', () => {
const bodies = ['see #123', '#123', 'unlike #123', 'issue 123', 'a #123 b'];
for (const body of bodies) {
const result = evaluateIssueLink(forkPr({ prBody: body, changedFiles: ['tests/a.test.cjs'], changedFilesTotal: 1 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_NO_ISSUE_REFERENCE, `body: ${JSON.stringify(body)}`);
}
});
// 10. Lookalike words that embed "ref"/"reference" inside a longer word
// must not be treated as a reference.
test('lookalike embedded-word bodies fail with FAIL_NO_ISSUE_REFERENCE', () => {
const bodies = ['prefs #1', 'unreferenced #1', 'xref#1', 'preferences #1'];
for (const body of bodies) {
const result = evaluateIssueLink(forkPr({ prBody: body, changedFiles: ['tests/a.test.cjs'], changedFilesTotal: 1 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_NO_ISSUE_REFERENCE, `body: ${JSON.stringify(body)}`);
}
});
// 11. Directory-lookalike paths (tests-e2e/, src/tests/, testsuite/,
// docsite/) must NOT be treated as tests/ or docs/.
test('directory-lookalike paths are rejected, forcing needs-closing', () => {
const paths = ['tests-e2e/src/a.ts', 'src/tests/x.ts', 'testsuite/y.cjs', 'docsite/z.md'];
for (const p of paths) {
const result = evaluateIssueLink(forkPr({ prBody: 'Refs #1', changedFiles: [p], changedFilesTotal: 1 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING, `path: ${p}`);
}
});
// 12. A closing keyword on a source diff passes outright.
test('Closes #123 with a source diff is OK_CLOSING_KEYWORD', () => {
const result = evaluateIssueLink(forkPr({ prBody: 'Closes #123', changedFiles: ['src/init.cts'], changedFilesTotal: 1 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_CLOSING_KEYWORD);
});
// 13. Closing keyword case/whitespace variants.
test('closing keyword variants (case, whitespace) all pass', () => {
const bodies = ['closes #1', 'FIXES #1', 'Resolves #1', 'resolves\t#1'];
for (const body of bodies) {
const result = evaluateIssueLink(forkPr({ prBody: body, changedFiles: ['src/init.cts'], changedFilesTotal: 1 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_CLOSING_KEYWORD, `body: ${JSON.stringify(body)}`);
}
});
// 14 & 15. #1389 anti-forgery property: the backmerge exemption requires
// BOTH the branch prefix AND sameRepo === true.
test('backmerge branch + sameRepo true is exempt with no reference at all', () => {
const result = evaluateIssueLink(forkPr({
prBody: '', headRef: 'chore/backmerge-main-to-next-20260101', sameRepo: true,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_BACKMERGE_EXEMPT);
});
test('#1389 anti-forgery: backmerge branch name from a FORK (sameRepo false) is NOT exempt', () => {
const result = evaluateIssueLink(forkPr({
prBody: '', headRef: 'chore/backmerge-main-to-next-20260101', sameRepo: false,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_NO_ISSUE_REFERENCE);
});
// 16. hasClosingKeyword corpus parity — expected values come from the
// shipped shell grep this regex replaces:
// grep -qiE '(closes|fixes|resolves)\s+#[0-9]+'
test('hasClosingKeyword corpus parity with the replaced shell grep', () => {
const cases = [
['Closes #2269', true],
['closes #1', true],
['Fixes #12', true],
['Resolves #3', true],
['fixes #4', true],
['Closes #123 and more prose', true],
['Refs #2269', false],
['Follow-up to #2269', false],
['no reference at all', false],
['Closes #', false],
['Closes123', false],
['closes issue 5', false],
];
for (const [body, expected] of cases) {
assert.strictEqual(hasClosingKeyword(body), expected, `body: ${JSON.stringify(body)}`);
}
});
// 17-18. BOUNDARY: exactly at and just below the page cap, with a total
// that matches, must pass.
test('BOUNDARY 99 tests-only paths, total 99 passes', () => {
const paths = testPaths(99);
const result = evaluateIssueLink(forkPr({ prBody: 'Refs #1', changedFiles: paths, changedFilesTotal: 99 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
test('BOUNDARY 100 tests-only paths, total 100 passes', () => {
const paths = testPaths(100);
const result = evaluateIssueLink(forkPr({ prBody: 'Refs #1', changedFiles: paths, changedFilesTotal: 100 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
// 19. Real vector: PR #3202 — gh returns 100 of 118 changed files.
test('BOUNDARY 100 tests-only paths, total 118 fails FAIL_FILE_LIST_INCOMPLETE (PR #3202 vector)', () => {
const paths = testPaths(100);
const result = evaluateIssueLink(forkPr({ prBody: 'Refs #1', changedFiles: paths, changedFilesTotal: 118 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_FILE_LIST_INCOMPLETE);
});
test('100 tests-only paths, total undefined fails FAIL_FILE_LIST_INCOMPLETE', () => {
const paths = testPaths(100);
const result = evaluateIssueLink(forkPr({ prBody: 'Refs #1', changedFiles: paths, changedFilesTotal: undefined }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_FILE_LIST_INCOMPLETE);
});
// Reviewed BLOCKER: the old fileListIsComplete only consulted the total
// when length >= FILE_LIST_PAGE_LIMIT, so ANY mechanism that shortens the
// list below 100 went undetected. A $GITHUB_OUTPUT heredoc terminated
// early by a file named after the delimiter is exactly such a mechanism —
// it truncates the list well below the page cap, with the true total
// still available from the separate, non-paginated `changedFiles` field.
test('a list shorter than its authoritative total fails closed', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #1', changedFiles: ['CONTRIBUTING.md'], changedFilesTotal: 3,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_FILE_LIST_INCOMPLETE);
});
// A path containing a literal newline can inflate the parsed list past the
// true total (e.g. a filename that itself looks like another path once
// split on newlines) — the total is the authority in both directions.
test('a list longer than its authoritative total fails closed', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #1',
changedFiles: ['tests/a.test.cjs', 'tests/b.test.cjs', 'tests/c.test.cjs'],
changedFilesTotal: 2,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_FILE_LIST_INCOMPLETE);
});
// 21. An empty changedFiles list cannot confirm anything.
test('empty changedFiles fails FAIL_FILE_LIST_INCOMPLETE', () => {
const result = evaluateIssueLink(forkPr({ prBody: 'Refs #1', changedFiles: [], changedFilesTotal: 0 }));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_FILE_LIST_INCOMPLETE);
});
});
describe('fileListIsComplete', () => {
// 22. Direct table of (changedFiles, changedFilesTotal) -> expected.
test('boundary table', () => {
const cases = [
[['a', 'b', 'c'], 3, true],
[['a', 'b', 'c'], undefined, true],
[testPaths(100), 100, true],
[testPaths(100), 101, false],
[testPaths(100), undefined, false],
[[], 0, false],
[undefined, 0, false],
[testPaths(3), 5, false],
[testPaths(5), 3, false],
[testPaths(3), 3, true],
[testPaths(3), undefined, true],
];
for (const [changedFiles, changedFilesTotal, expected] of cases) {
assert.strictEqual(
fileListIsComplete(changedFiles, changedFilesTotal),
expected,
`changedFiles.length=${Array.isArray(changedFiles) ? changedFiles.length : changedFiles}, total=${changedFilesTotal}`,
);
}
});
});
describe('hasFollowUpReference', () => {
// 23. Direct spot checks on the raw predicate.
test('rejects a closing keyword, accepts a reference', () => {
assert.strictEqual(hasFollowUpReference('Closes #1'), false);
assert.strictEqual(hasFollowUpReference('Refs #1'), true);
});
});
describe('allPathsAreTestsOrDocs', () => {
// 24. Direct spot checks on the raw predicate.
test('true for tests/docs mix, false for a non-exempt path, false for empty', () => {
assert.strictEqual(allPathsAreTestsOrDocs(['tests/a.cjs', 'docs/b.md']), true);
assert.strictEqual(allPathsAreTestsOrDocs(['tests/a.cjs', '.github/workflows/x.yml']), false);
assert.strictEqual(allPathsAreTestsOrDocs([]), false);
});
// 25. Root-level markdown is a third accepted shape; CHANGELOG.md is
// excluded from it even though it is root-level markdown.
test('root-level markdown is accepted, CHANGELOG.md and subdirectory markdown are not', () => {
assert.strictEqual(allPathsAreTestsOrDocs(['CONTRIBUTING.md']), true);
assert.strictEqual(allPathsAreTestsOrDocs(['CHANGELOG.md']), false);
assert.strictEqual(allPathsAreTestsOrDocs(['agents/x.md']), false);
assert.strictEqual(allPathsAreTestsOrDocs(['package.json']), false);
});
// The exclusion of CHANGELOG.md must not be defeatable by casing — the
// extension test (`/\.md$/i`) is already case-insensitive, so the
// exclusion lookup must match it rather than silently letting a
// differently-cased CHANGELOG.md ride in on the docs carve-out.
test('CHANGELOG.md exclusion is case-insensitive', () => {
assert.strictEqual(allPathsAreTestsOrDocs(['changelog.md']), false);
assert.strictEqual(allPathsAreTestsOrDocs(['CHANGELOG.MD']), false);
});
});
describe('require-issue-link policy — root-level documentation (#2290 shape)', () => {
// #2290 is the motivating PR the follow-up-reference exemption failed to
// cover: its diff is CONTRIBUTING.md (root-level markdown) plus a tests/
// file, and the old EXEMPT_PATH_PREFIXES-only predicate rejected it because
// CONTRIBUTING.md is neither tests/ nor docs/-prefixed.
test('the motivating PR #2290 shape qualifies', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269',
changedFiles: ['CONTRIBUTING.md', 'tests/commit-files-pathspec.test.cjs'],
changedFilesTotal: 2,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
test('a root-level README change qualifies', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269', changedFiles: ['README.md'], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.OK_FOLLOWUP_REFERENCE);
});
// scripts/changeset/lint.cjs classes a direct CHANGELOG.md edit as
// user-facing specifically to close a bypass — the docs carve-out here
// must not undo that by treating CHANGELOG.md as ordinary documentation.
test('a direct CHANGELOG.md edit does NOT qualify', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269', changedFiles: ['CHANGELOG.md'], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING);
});
test('CHANGELOG.md alongside real docs still disqualifies', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269', changedFiles: ['docs/a.md', 'CHANGELOG.md'], changedFilesTotal: 2,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING);
});
// These are runtime-loaded text, deliberately gated by the same root-only
// anchor pre-pr-gate.sh uses — a subdirectory .md file is not root-level.
test('subdirectory markdown is not root-level documentation', () => {
const paths = ['gsd-core/workflows/next.md', 'agents/reviewer.md', 'commands/gsd/plan.md', 'src/notes.md'];
for (const p of paths) {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269', changedFiles: [p], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING, `path: ${p}`);
}
});
test('a root-level non-markdown file does not qualify', () => {
const result = evaluateIssueLink(forkPr({
prBody: 'Refs #2269', changedFiles: ['package.json'], changedFilesTotal: 1,
}));
assert.strictEqual(result.reason, ISSUE_LINK_REASON.FAIL_REFERENCE_NEEDS_CLOSING);
});
});
describe('require-issue-link policy — the workflow guidance matches the rule', () => {
// Parity assertion (CLAUDE.md "Generative Fix Divergence"): the sticky
// comment's guidance text is generated separately from the predicate it
// describes, and the two have already drifted once (the predicate widened
// to accept root-level markdown while the guidance kept saying "nothing
// outside tests/ and docs/"). Every expectation below is derived from the
// module's actual exports, never hardcoded, so a future widening of the
// predicate without a guidance update fails this test.
const workflowPath = path.join(__dirname, '..', '.github', 'workflows', 'require-issue-link.yml');
const workflowDoc = yaml.load(fs.readFileSync(workflowPath, 'utf8'));
const job = workflowDoc.jobs['check-issue-link'];
const steps = job.steps;
const lastStep = steps[steps.length - 1];
const script = lastStep.with.script;
// Non-vacuous guards: if these fail, the assertions below would otherwise
// silently pass against zero-length input.
test('the resolved script text and export lists are non-empty (guard)', () => {
assert.strictEqual(typeof script, 'string');
assert.ok(script.length > 200, `expected script.length > 200, got ${script.length}`);
assert.ok(EXEMPT_PATH_PREFIXES.length > 0, 'EXEMPT_PATH_PREFIXES must be non-empty');
assert.ok(EXCLUDED_ROOT_DOCS instanceof Set, 'EXCLUDED_ROOT_DOCS must be a Set');
assert.ok(EXCLUDED_ROOT_DOCS.size > 0, 'EXCLUDED_ROOT_DOCS must be non-empty');
});
test('guidance names every EXEMPT_PATH_PREFIXES entry verbatim', () => {
for (const prefix of EXEMPT_PATH_PREFIXES) {
assert.ok(script.includes(prefix), `guidance script missing prefix: ${prefix}`);
}
});
// isRootLevelDoc accepts root-level *.md — the guidance must say so; this
// is the exact shape that drifted before.
test('guidance mentions root-level markdown', () => {
assert.ok(script.includes('root-level'), 'guidance script missing "root-level"');
});
test('guidance names every EXCLUDED_ROOT_DOCS entry verbatim', () => {
for (const doc of EXCLUDED_ROOT_DOCS) {
assert.ok(script.includes(doc), `guidance script missing excluded doc: ${doc}`);
}
});
test('guidance mentions an accepted non-closing reference marker', () => {
assert.ok(script.includes('Refs #'), 'guidance script missing "Refs #"');
});
});