Files
msd-core/.changeset/3595-fs-fault-injection-atomic-write.md
Tom Boucher 418b361a99 test(3595): filesystem fault-injection for platformWriteSync atomic-write seam (#3634)
* test(3595): filesystem fault-injection for platformWriteSync atomic-write seam

Per CONTRIBUTING.md §"QA Matrix Requirements / Filesystem writes and
installers", adds adversarial coverage against the canonical write
seam every CJS config/state/generated-artifact writer routes through —
`platformWriteSync` in get-shit-done/bin/lib/shell-command-projection.cjs.

Fault matrix exercised via node:test mock.method() on real fs seams,
with t.after() restoring mocks so failures don't leak between tests:

  - happy path baseline (atomicity + no orphan tmp file)
  - renameSync EXDEV → fallback path writes directly, tmp cleaned up
  - tmp writeFileSync ENOSPC → fallback writes directly
  - both tmp and fallback fail → fallback error propagates (PINNED:
    original cause is swallowed; open follow-up for .cause chaining)
  - mkdirSync EACCES → escapes unhandled (PINNED current behavior)
  - target path is an existing directory → typed errno code surfaces
    AND the directory is preserved
  - paths with spaces / Unicode / tabs / newlines (POSIX only for \n)
  - 25 sequential writes leave 0 tmp orphans (cleanup invariant)
  - platformEnsureDir is idempotent (no EEXIST throw)
  - platformEnsureDir EACCES propagates

Symlink-safety invariants (security-critical):

  - REPLACES a symlink with a regular file rather than following it —
    a planted symlink in .planning/ pointing at ~/.ssh/authorized_keys
    is NOT clobbered. Test pins this so a future refactor to
    fs.writeFileSync (which follows symlinks) is a visible regression.
  - Broken symlinks are replaced with the intended regular file.

Concurrent-write collision: a renameSync EBUSY on the in-flight write
must still produce a parseable, complete final file via the fallback —
never a half-written corruption.

13 new tests; total 192/192 pass when bundled with the pre-existing
state/config/worktree-safety suites (179 of theirs). Zero production
code changes — test-only PR.

Two known-open gaps deliberately NOT fixed in this PR (warrant separate
focused issues):
  - platformWriteSync fallback path swallows the original tmp-write
    error. Operator only sees the fallback's error when both fail.
  - platformWriteSync mkdirSync(dirname, recursive:true) error
    escapes without context — no message-wrapping or typed reason.

Closes #3595

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* test(3595): use t.skip() for Win32 symlink gates + fix rename mock delegation

Two Codex review findings addressed:

1. Symlink tests previously used `if (process.platform === 'win32') return`
   which CI reports as PASS even though the test ran zero assertions.
   Replaced with `t.skip('symlinks on Win32 need admin'); return;` so
   CI correctly reports SKIPPED on Windows lanes. Applied to both the
   symlink-replace and broken-symlink tests.

2. The concurrent-collision test's rename mock referenced a
   non-existent `fs.renameSync.wrapped` property in its fallback
   branch — that path would silently no-op instead of delegating to
   the real renameSync. Capture the real `fs.renameSync` BEFORE
   installing the mock and call `originalRename.call(fs, src, dest)`
   in the fallback branch, matching the ENOSPC test's pattern.

Codex review on PR #3634.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-16 00:40:34 -04:00

826 B

get-shit-done-cc
get-shit-done-cc
patch

Added: filesystem fault-injection coverage for platformWriteSync. New tests in tests/feat-3595-fs-fault-injection-atomic-write.test.cjs use node:test's mock.method() to inject ENOSPC, EACCES, EXDEV, EBUSY, and EISDIR against the shared atomic-write seam in get-shit-done/bin/lib/shell-command-projection.cjs. Covers rename-failure fallback, double-failure error propagation, mkdir failure, target-is-directory collision, paths with spaces/Unicode/newlines, symlink-replacement safety (writer does NOT follow symlinks), broken-symlink handling, and concurrent-write collision. Documents two pre-existing behavior gaps (fallback error swallows original cause; mkdir failure escapes unhandled) as pinned current behavior, ready for the future fix to flip the assertion.