Files
msd-core/tests/ci-rebase-check.test.cjs
Tom Boucher 48b1e35187 fix(#431): enforce H1 shell policy (linux=bash, macOS=zsh, windows=pwsh) across PR + release gates (#434)
* test(#431): policy-shell-pinning linter — RED baseline (37 violations on origin/next)

Adds scripts/workflow-policy.cjs: H1 shell-policy linter with POLICY map,
VIOLATION enum, matrix expansion, effective-shell resolution order, and
runPolicyLint({ workflowsDir }) entry point.

Adds tests/policy-shell-pinning.test.cjs: 8 tests (baseline + 6 synthetic
counter-tests). Synthetic tests 2–7 pass; baseline test is intentionally RED
(37 violations: 28 in test.yml, 9 in install-smoke.yml — all macos/windows
lanes using shell: bash instead of native zsh/pwsh).

Adds js-yaml@4.1.1 as devDependency for YAML parsing.

* fix(#431): switch ubuntu/windows lanes to native shells; extract bash-isms to Node

Remove all explicit shell: bash pins from ubuntu-only jobs (changes, lint-tests,
coverage, required-tests, smoke-unpacked) — ubuntu runner default is bash, which
is both H1-compliant and the runner default, making the pin redundant.

For the test and test-full mixed-OS jobs (ubuntu+windows, windows+macos):
- Move bash-ism steps to shell-agnostic Node scripts:
    scripts/ci-guard-runner.cjs       — RUNNER_ENVIRONMENT check
    scripts/ci-rebase-check.cjs       — git fetch+merge PR base branch
    scripts/check-npm-integrity.cjs   — Node port of check-npm-integrity.sh
    scripts/ci-prepare-test-scope.cjs — write .ci-selected-tests.txt
    scripts/ci-smoke-skip.cjs         — set skip= output for full-only matrix entries
- Remove shell: bash from simple npm/node command steps (runner default applies)

This brings Windows violations from 19 to 0. Remaining 17 violations are all
MACOS_MISSING_EXPLICIT_ZSH in mixed-OS matrix jobs (test-full: windows+macos,
install-smoke smoke: ubuntu+macos) — these require job splitting to fix; see
BLOCKER in PR description.

* fix(#431): update workflow-shell-pinning test for H1 policy

The old test required all Windows-targeting npm steps to pin shell: bash
(to prevent pwsh stderr-swallow). Under H1, Windows runners must use
pwsh (native, no pin needed) — shell: bash on Windows is now the
violation, not the fix.

Update findViolations() to flag npm steps with effectiveShell === 'bash'
(rather than effectiveShell === null). Update synthetic tests to verify
the H1-inverted semantics: defaults.run.shell: bash on Windows is now 2
violations, not 0. Update test name and assertion messages to describe
the H1 constraint rather than the old missing-pin constraint.

* fix(#431): extend policy linter to resolve matrix.shell expressions

- expandRunsOn now captures all matrix.include row keys as realization
  context (os, node-version, shell, full_only, etc.) instead of only os
- effectiveShell now accepts a realizationContext and resolves
  ${{ matrix.<key> }} expressions against it before checking policy
- Unresolvable matrix key in shell expression emits UNRESOLVABLE_MATRIX
- Add 3 new tests: positive (zsh+pwsh per row → 0 violations),
  counter (bash in macOS row → WRONG_SHELL_FOR_OS), counter (missing
  shell key → UNRESOLVABLE_MATRIX)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(#431): apply matrix.shell pattern to test-full and smoke jobs (clears BLOCKER)

test-full job (test.yml):
- Add shell: pwsh/zsh per matrix.include row (windows-latest→pwsh,
  macos-latest→zsh)
- Add job-level defaults.run.shell: ${{ matrix.shell }}
- No step-level shell pins existed to remove

smoke job (install-smoke.yml):
- Add shell: bash/zsh per matrix.include row (ubuntu→bash, macos→zsh)
- Add job-level defaults.run.shell: ${{ matrix.shell }}
- No step-level shell pins existed to remove

Policy linter now reports 0 violations across all workflow files.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor(#431): migrate .sh check scripts to .cjs; remove .sh originals

- Add scripts/check-env.cjs: Node.js port of check-env.sh with
  identical exit codes (0/1/2), human-readable and --json output,
  --help flag, and all 5 checks (node-version, npm-version,
  lockfile-present, lockfile-sync, version-manager-pin)
- Migrate all callers:
  - package.json check:env → node scripts/check-env.cjs
  - package.json check:integrity → node scripts/check-npm-integrity.cjs
  - scripts/ci-test-scope.cjs path strings → .cjs equivalents
  - .github/workflows/release.yml rc+finalize jobs → node .cjs (drop chmod+x)
  - .github/workflows/security-scan.yml → node .cjs (drop chmod+x)
  - tests/check-env.test.cjs → spawn node process.execPath [.cjs]
  - tests/npm-integrity-gate.test.cjs → spawn node process.execPath [.cjs]
- Delete scripts/check-env.sh and scripts/check-npm-integrity.sh

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* refactor(#431): update doc references from .sh to .cjs

Update SECURITY.md and docs/contributing/bootstrap.md to reference the
canonical Node invocation instead of the removed bash scripts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(#431): use per-step shell:matrix.shell instead of defaults.run.shell (GHA compat)

GHA does not reliably resolve matrix expressions inside defaults.run.shell.
Per-step shell: always resolves correctly. Removed the defaults.run.shell block
from the test-full job (test.yml) and the smoke job (install-smoke.yml), and
added shell: \${{ matrix.shell }} directly on every run: step in both jobs.

Codex finding: defaults.run.shell with matrix expressions is not a
GHA-supported pattern; per-step shell: is the safe form.

* fix(#431): policy linter validates every matrix.include row independently

Removed runner-label-only dedup from expandRunsOn() in workflow-policy.cjs.
The prior guard (if !realizations.find(r => r.runner === runner)) collapsed
two macos-latest rows with different node-version/shell contexts into one,
hiding the second row's policy violation.

Each matrix.include row is a distinct CI realization with its own context;
validating it twice is harmless but skipping it causes false negatives.

Added counter-test (Test 8) in tests/policy-shell-pinning.test.cjs:
two macos-latest rows (shell:zsh compliant + shell:bash violation) must
produce exactly one WRONG_SHELL_FOR_OS violation on the second row.

* fix(#431): remove dedup-by-runner in Cartesian matrix.<key> expansion (Codex round 3)

The base-list path in expandRunsOn (matrix.<key> arrays, e.g. matrix.os)
previously guarded each push with `if (!realizations.find(r => r.runner === runner))`,
collapsing duplicate runner values into a single realization and hiding policy
violations on later rows of a Cartesian matrix.

Remove the guard unconditionally; each entry in the base-list array now produces
its own realization, matching the same fix already applied to the matrix.include path.

Add counter-test "Cartesian matrix os × shell — dedup must not collapse rows by
runner alone": matrix.os: [macos-latest, macos-latest] + shell: ${{ matrix.shell }}
now yields 2 realizations (not 1). Documents that Cartesian cross-product expansion
(carrying all keys into realization context) is a separate follow-up; current violations
are UNRESOLVABLE_MATRIX pending that work.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(#431): remove 60s timeout regression on npm ci --dry-run (parity with check-env.sh)

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(#431): ci-rebase-check.cjs — return truthy sentinel on success (Codex round 4)

run() used execFileSync with stdio:'inherit', which returns null on success.
Caller checked `result !== null`, always false → every successful fetch fell
through to "failed after 3 attempts" exit-1 path.

Fix: run() now returns true on success, false on failure.
Update caller from `result !== null` to `if (result)`.

Adds tests/ci-rebase-check.test.cjs (5 tests) covering the sentinel contract
and a local-bare-remote integration smoke that verifies the full fetch+merge
path exits 0 when fetch succeeds.

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
Co-authored-by: CI Rebase Check <ci@gsd-redux>
2026-05-28 09:23:59 -04:00

175 lines
7.9 KiB
JavaScript

'use strict';
/**
* Tests for scripts/ci-rebase-check.cjs — Codex round 4 P1 regression.
*
* The root bug: run() used execFileSync with stdio:'inherit', which returns null
* on success. The caller checked `result !== null` to detect success, so the
* condition was ALWAYS false (null !== null === false) and every successful fetch
* fell through to the "failed after 3 attempts" exit-1 path.
*
* Fix: run() now returns true on success, false on failure, making the boolean
* check unambiguous regardless of the stdio mode.
*
* These tests exercise the run() logic in isolation via subprocess execution,
* verifying the sentinel behaviour rather than internal module state.
*/
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const { spawnSync } = require('node:child_process');
const path = require('node:path');
const fs = require('node:fs');
const os = require('node:os');
const ROOT = path.resolve(__dirname, '..');
const SCRIPT = path.join(ROOT, 'scripts', 'ci-rebase-check.cjs');
const NODE = process.execPath;
// ---------------------------------------------------------------------------
// Helper: run a small inline Node snippet that requires the run() helper
// directly from the source (extracted via a thin wrapper).
//
// Because the script has top-level side-effects (git config calls), we cannot
// require() it. Instead we test the run() sentinel by embedding the function
// body verbatim in a one-shot subprocess.
// ---------------------------------------------------------------------------
function evalRunHelper(stmts) {
// Inline the exact fixed run() body so the test is tightly coupled to the
// contract, not some mock.
const code = `
'use strict';
const { execFileSync } = require('child_process');
function run(cmd, args, opts) {
try {
execFileSync(cmd, args, { stdio: 'inherit', ...opts });
return true;
} catch (e) {
return false;
}
}
${stmts}
`;
const r = spawnSync(NODE, ['-e', code], { encoding: 'utf8', timeout: 10_000 });
return { status: r.status ?? 1, stdout: r.stdout ?? '', stderr: r.stderr ?? '' };
}
// ---------------------------------------------------------------------------
// Test group 1 — run() sentinel correctness
// ---------------------------------------------------------------------------
describe('ci-rebase-check: run() helper — success sentinel (Codex round 4 P1)', () => {
test('run() returns true when the command succeeds', () => {
// Use `node -e ""` (no-op) as a guaranteed-success command that produces no output,
// avoiding stdout contamination when stdio:'inherit' writes to the same stream.
const { status, stdout, stderr } = evalRunHelper(`
const result = run(process.execPath, ['-e', '']);
process.stdout.write(String(result));
`);
assert.strictEqual(status, 0, `subprocess should exit 0; stderr: ${stderr}`);
assert.strictEqual(stdout, 'true', `run() must return true on success; got: ${stdout}`);
});
test('run() returns false when the command fails', () => {
// An invalid binary name causes execFileSync to throw ENOENT.
const { status, stdout, stderr } = evalRunHelper(`
const result = run('__nonexistent_binary_that_cannot_exist__', []);
process.stdout.write(String(result));
`);
assert.strictEqual(status, 0, `subprocess should exit 0; stderr: ${stderr}`);
assert.strictEqual(stdout, 'false', `run() must return false on failure; got: ${stdout}`);
});
test('run() returns true (not null) — counter-test for pre-fix null behaviour', () => {
// Pre-fix: execFileSync with stdio:'inherit' returns null on success.
// The old check was `result !== null`, which would be `null !== null === false`.
// Post-fix: result must be strictly true, making `if (result)` correct.
// Use `node -e ""` (no-op) so stdio:'inherit' does not pollute our stdout capture.
const { status, stdout } = evalRunHelper(`
const result = run(process.execPath, ['-e', '']);
process.stdout.write(JSON.stringify({ isTrue: result === true, isNull: result === null }));
`);
assert.strictEqual(status, 0);
const { isTrue, isNull } = JSON.parse(stdout);
assert.strictEqual(isNull, false, 'run() must NOT return null on success (pre-fix bug)');
assert.strictEqual(isTrue, true, 'run() must return exactly true on success');
});
test('run() returns false (not null) — failure path also returns boolean', () => {
const { status, stdout } = evalRunHelper(`
const result = run('__nonexistent__', []);
process.stdout.write(JSON.stringify({ isFalse: result === false, isNull: result === null }));
`);
assert.strictEqual(status, 0);
const { isFalse, isNull } = JSON.parse(stdout);
assert.strictEqual(isNull, false, 'run() must NOT return null on failure');
assert.strictEqual(isFalse, true, 'run() must return exactly false on failure');
});
});
// ---------------------------------------------------------------------------
// Test group 2 — fetch-retry loop uses the boolean correctly
//
// We cannot run the actual git fetch against GitHub in unit tests, but we can
// verify the fetch-loop logic by running the full script against a local git
// repo where GITHUB_TOKEN and GITHUB_REPOSITORY are absent (so remote set-url
// is skipped) and GITHUB_BASE_REF points to a branch that exists locally.
// ---------------------------------------------------------------------------
describe('ci-rebase-check: fetch-retry loop resolves when git fetch succeeds', () => {
test('script exits 0 when fetch succeeds (local bare remote, clean merge)', () => {
// Set up: create a temp dir with a local git repo that has a `main` branch.
// The script will fetch `origin main` from this local "remote".
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-431-ci-rebase-'));
const remoteDir = path.join(tmpDir, 'remote.git');
const workDir = path.join(tmpDir, 'work');
try {
// Build a bare remote with a `main` branch containing one commit.
fs.mkdirSync(remoteDir, { recursive: true });
spawnSync('git', ['init', '--bare', remoteDir], { encoding: 'utf8' });
// Create a working clone to push an initial commit.
spawnSync('git', ['clone', remoteDir, workDir], { encoding: 'utf8' });
fs.writeFileSync(path.join(workDir, 'seed.txt'), 'init\n');
spawnSync('git', ['-C', workDir, 'config', 'user.email', 'ci@test'], { encoding: 'utf8' });
spawnSync('git', ['-C', workDir, 'config', 'user.name', 'CI Test'], { encoding: 'utf8' });
spawnSync('git', ['-C', workDir, 'checkout', '-b', 'main'], { encoding: 'utf8' });
spawnSync('git', ['-C', workDir, 'add', 'seed.txt'], { encoding: 'utf8' });
spawnSync('git', ['-C', workDir, 'commit', '-m', 'init'], { encoding: 'utf8' });
spawnSync('git', ['-C', workDir, 'push', 'origin', 'main'], { encoding: 'utf8' });
// Run the script from `workDir` with origin pointing at our bare remote.
// GITHUB_BASE_REF=main so it fetches `origin main`.
// No GITHUB_TOKEN so remote set-url is skipped.
const r = spawnSync(NODE, [SCRIPT], {
cwd: workDir,
encoding: 'utf8',
timeout: 20_000,
env: {
...process.env,
GITHUB_BASE_REF: 'main',
GITHUB_TOKEN: '',
GITHUB_REPOSITORY: '',
},
});
assert.strictEqual(
r.status, 0,
`Script should exit 0 when fetch+merge succeed.\nstdout: ${r.stdout}\nstderr: ${r.stderr}`
);
// Must NOT emit the "failed after 3 attempts" error message.
assert.ok(
!(r.stderr || '').includes('failed after 3 attempts'),
`Script must not emit "failed after 3 attempts" when fetch succeeded.\nstderr: ${r.stderr}`
);
} finally {
fs.rmSync(tmpDir, { recursive: true, force: true });
}
});
});