Files
msd-core/tests/bug-2647-outer-tarball-sdk-dist.test.cjs
Tom Boucher 334a64168e chore(npm): rebrand packages to @opengsd scope (#127)
* chore(npm): rebrand packages to @opengsd scope

Rename:
- get-shit-done-redux → @opengsd/get-shit-done-redux
- @gsd-redux/sdk → @opengsd/gsd-sdk

Add publishConfig.access=public for first-time scoped publish.
CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged.

Sweeps install commands, npx invocations, CI publish/version-check
workflows, tests, docs, READMEs (all translations), and the
PACKAGE_NAME constant in check-latest-version.

Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by
the audit-clean test (GHSA-q8mj-m7cp-5q26).

Closes #126

* chore: pin 2.0.0 release + remove canary workflow

- Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish
- Remove .github/workflows/canary.yml and canary dist-tag handling in
  release.yml / release-sdk.yml
- Drop canary section from VERSIONING.md

Refs #126

* chore: address review findings + harden tarball-smoke timeout

- .changeset/opengsd-org-rename.md: match project's custom
  parse.cjs frontmatter (type: Changed / pr: 127); the scoped
  @changesets/cli keys were silently rejected.
- CONTEXT.md: drop two canary-stream policy lines and a dangling
  DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone.
- tests/release-tarball-smoke.install.test.cjs: pass
  timeout: 600_000 for npm pack + global install; the 3-minute
  runNpm default was timing out on slower Docker hosts (cartographer).

Refs #126

* fix(sdk): add missing type/runtime devDependencies for build

prepublishOnly invokes tsc which couldn't resolve @types/node,
@types/ws, or synckit. They had been hoisted from root but were
not declared in sdk/'s own package.json — first publish from a
clean SDK tree failed.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(ci): use npm pack stdout instead of glob to find tarball

`npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux)
produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`.
Capture the filename from stdout instead of a hardcoded glob so the step
works regardless of package name format.

Fixes smoke (ubuntu-latest, 22, false) CI failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci: treat workflow-file changes as test-skip eligible

`.github/workflows/install-smoke.yml` (and other workflow files)
were in neither `test.yml` paths nor `test-skip.yml` paths-ignore,
so neither workflow ran on a workflow-only commit — leaving the
required test-skip check perpetually missing.

Refs #126

* chore: reset version to 1.0.0 for first @opengsd publish

Nothing has been published yet under the @opengsd scope, so the
inaugural release uses 1.0.0 rather than 2.0.0. The "major bump"
in the changeset reflects the breaking install-command change for
users migrating from the prior unscoped `get-shit-done-redux`, not
a numeric continuation from a 1.x line under the new identity.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 16:22:41 -04:00

156 lines
6.5 KiB
JavaScript

/**
* Regression test for bug #2647 (also partial fix for #2649).
*
* v1.38.3 of get-shit-done-redux shipped with:
* - `files` array missing `sdk/dist`
* - `prepublishOnly` only running `build:hooks`, not `build:sdk`
*
* Result: the published tarball had no `sdk/dist/cli.js`. The `gsd-sdk`
* bin shim in `bin/gsd-sdk.js` resolves `<pkg>/sdk/dist/cli.js`, which
* didn't exist, so PATH fell through to the separately installed
* `@opengsd/gsd-sdk@0.1.0` (predates the `query` subcommand).
*
* Every `gsd-sdk query <noun>` call in workflow docs thus failed on
* fresh installs of 1.38.3.
*
* This test guards the OUTER package.json (get-shit-done-redux) so future
* edits cannot silently drop either safeguard. A sibling test at
* tests/bug-2519-sdk-tarball-dist.test.cjs guards the inner sdk package.
*
* The `npm pack` dry-run assertion makes the guard concrete: if the
* files whitelist, the prepublishOnly chain, or the shim target ever
* drift out of alignment, this fails.
*/
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const os = require('os');
const { execFileSync } = require('child_process');
const REPO_ROOT = path.join(__dirname, '..');
const PKG_PATH = path.join(REPO_ROOT, 'package.json');
const SHIM_PATH = path.join(REPO_ROOT, 'bin', 'gsd-sdk.js');
describe('bug #2647: outer tarball ships sdk/dist so gsd-sdk query works', () => {
const pkg = JSON.parse(fs.readFileSync(PKG_PATH, 'utf-8'));
const filesField = Array.isArray(pkg.files) ? pkg.files : [];
const scripts = pkg.scripts || {};
test('package.json `files` includes sdk/dist', () => {
const hasDist = filesField.some((entry) => {
if (typeof entry !== 'string') return false;
const norm = entry.replace(/\\/g, '/').replace(/^\.\//, '');
return /^sdk\/dist(?:$|\/|\/\*\*|\/\*\*\/\*)/.test(norm);
});
assert.ok(
hasDist,
`package.json "files" must include "sdk/dist" so the compiled CLI ships in the tarball. Found: ${JSON.stringify(filesField)}`,
);
});
test('package.json declares a build:sdk script', () => {
assert.ok(
typeof scripts['build:sdk'] === 'string' && scripts['build:sdk'].length > 0,
'package.json must define scripts["build:sdk"] to compile sdk/dist before publish',
);
assert.ok(
/\bbuild\b|\btsc\b/.test(scripts['build:sdk']),
`scripts["build:sdk"] must run a build. Got: ${JSON.stringify(scripts['build:sdk'])}`,
);
});
test('package.json `prepublishOnly` invokes build:sdk', () => {
const prepub = scripts.prepublishOnly;
assert.ok(
typeof prepub === 'string' && prepub.length > 0,
'package.json must define scripts.prepublishOnly',
);
assert.ok(
/build:sdk\b/.test(prepub),
`scripts.prepublishOnly must invoke "build:sdk" so sdk/dist exists at pack time. Got: ${JSON.stringify(prepub)}`,
);
});
test('gsd-sdk bin shim resolves sdk/dist/cli.js', () => {
assert.ok(
pkg.bin && pkg.bin['gsd-sdk'] === 'bin/gsd-sdk.js',
`package.json bin["gsd-sdk"] must point at bin/gsd-sdk.js. Got: ${JSON.stringify(pkg.bin)}`,
);
const shim = fs.readFileSync(SHIM_PATH, 'utf-8');
assert.ok(
/sdk['"],\s*['"]dist['"],\s*['"]cli\.js/.test(shim) ||
/sdk\/dist\/cli\.js/.test(shim),
'bin/gsd-sdk.js must resolve ../sdk/dist/cli.js — otherwise shipping sdk/dist does not help',
);
});
test('npm pack dry-run includes sdk/dist/cli.js after build:sdk', { timeout: 180_000 }, () => {
const npmCache = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-npm-cache-'));
const npmEnv = { ...process.env, npm_config_cache: npmCache };
// Ensure the sdk is built so the pack reflects what publish would ship.
// The outer prepublishOnly chains through build:sdk, which does `npm ci && npm run build`
// inside sdk/. We emulate that here without full ci to keep the test fast:
// if sdk/dist/cli.js already exists, use it; otherwise build.
const sdkDir = path.join(REPO_ROOT, 'sdk');
const cliJs = path.join(sdkDir, 'dist', 'cli.js');
// On Windows `npm` is the shell script `npm.cmd`; without {shell:true}
// execFileSync only finds literal-name binaries and errors with ENOENT.
const isWindows = process.platform === 'win32';
const npmCmd = isWindows ? 'npm.cmd' : 'npm';
if (!fs.existsSync(cliJs)) {
// Build requires node_modules; install if missing, then build.
const sdkNodeModules = path.join(sdkDir, 'node_modules');
if (!fs.existsSync(sdkNodeModules)) {
execFileSync(npmCmd, ['ci', '--silent'], { cwd: sdkDir, stdio: 'pipe', env: npmEnv, shell: isWindows });
}
execFileSync(npmCmd, ['run', 'build'], { cwd: sdkDir, stdio: 'pipe', env: npmEnv, shell: isWindows });
}
assert.ok(fs.existsSync(cliJs), 'sdk build must produce sdk/dist/cli.js');
try {
const out = execFileSync(
npmCmd,
['pack', '--dry-run', '--json', '--ignore-scripts'],
{ cwd: REPO_ROOT, stdio: ['ignore', 'pipe', 'pipe'], env: npmEnv, shell: isWindows },
).toString('utf-8');
const manifest = JSON.parse(out);
const files = manifest[0].files.map((f) => f.path);
const cliPresent = files.includes('sdk/dist/cli.js');
assert.ok(
cliPresent,
`npm pack must include sdk/dist/cli.js in the tarball (so "gsd-sdk query" resolves after install). sdk/dist entries found: ${files.filter((p) => p.startsWith('sdk/dist')).length}`,
);
} finally {
fs.rmSync(npmCache, { recursive: true, force: true });
}
});
test('built sdk CLI exposes the `query` subcommand', { timeout: 60_000 }, () => {
const cliJs = path.join(REPO_ROOT, 'sdk', 'dist', 'cli.js');
if (!fs.existsSync(cliJs)) {
assert.fail('sdk/dist/cli.js missing — the previous test should have built it');
}
let stdout = '';
let stderr = '';
let status = 0;
try {
stdout = execFileSync(process.execPath, [cliJs, 'query', '--help'], {
stdio: ['ignore', 'pipe', 'pipe'],
}).toString('utf-8');
} catch (err) {
stdout = err.stdout ? err.stdout.toString('utf-8') : '';
stderr = err.stderr ? err.stderr.toString('utf-8') : '';
status = err.status ?? 1;
}
const combined = `${stdout}\n${stderr}`;
assert.ok(
/query/i.test(combined) && !/unknown command|unrecognized/i.test(combined),
`sdk/dist/cli.js must expose a "query" subcommand. status=${status} output=${combined.slice(0, 500)}`,
);
});
});