Files
msd-core/tests/bug-3610-installer-migration-bundled-hooks-classification.test.cjs
Tom Boucher 334a64168e chore(npm): rebrand packages to @opengsd scope (#127)
* chore(npm): rebrand packages to @opengsd scope

Rename:
- get-shit-done-redux → @opengsd/get-shit-done-redux
- @gsd-redux/sdk → @opengsd/gsd-sdk

Add publishConfig.access=public for first-time scoped publish.
CLI binary names (get-shit-done-redux, gsd-sdk, gsd-tools) unchanged.

Sweeps install commands, npx invocations, CI publish/version-check
workflows, tests, docs, READMEs (all translations), and the
PACKAGE_NAME constant in check-latest-version.

Bumps qs 6.15.1 → 6.15.2 to clear a moderate advisory surfaced by
the audit-clean test (GHSA-q8mj-m7cp-5q26).

Closes #126

* chore: pin 2.0.0 release + remove canary workflow

- Bump both packages 1.50.0-canary.0 → 2.0.0 for first @opengsd publish
- Remove .github/workflows/canary.yml and canary dist-tag handling in
  release.yml / release-sdk.yml
- Drop canary section from VERSIONING.md

Refs #126

* chore: address review findings + harden tarball-smoke timeout

- .changeset/opengsd-org-rename.md: match project's custom
  parse.cjs frontmatter (type: Changed / pr: 127); the scoped
  @changesets/cli keys were silently rejected.
- CONTEXT.md: drop two canary-stream policy lines and a dangling
  DEFECT.CANARY-VERSION-LEAK.cross-ref now that canary.yml is gone.
- tests/release-tarball-smoke.install.test.cjs: pass
  timeout: 600_000 for npm pack + global install; the 3-minute
  runNpm default was timing out on slower Docker hosts (cartographer).

Refs #126

* fix(sdk): add missing type/runtime devDependencies for build

prepublishOnly invokes tsc which couldn't resolve @types/node,
@types/ws, or synckit. They had been hoisted from root but were
not declared in sdk/'s own package.json — first publish from a
clean SDK tree failed.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* fix(ci): use npm pack stdout instead of glob to find tarball

`npm pack --silent` for a scoped package (@opengsd/get-shit-done-redux)
produces `opengsd-get-shit-done-redux-*.tgz`, not `get-shit-done-redux-*.tgz`.
Capture the filename from stdout instead of a hardcoded glob so the step
works regardless of package name format.

Fixes smoke (ubuntu-latest, 22, false) CI failure.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* ci: treat workflow-file changes as test-skip eligible

`.github/workflows/install-smoke.yml` (and other workflow files)
were in neither `test.yml` paths nor `test-skip.yml` paths-ignore,
so neither workflow ran on a workflow-only commit — leaving the
required test-skip check perpetually missing.

Refs #126

* chore: reset version to 1.0.0 for first @opengsd publish

Nothing has been published yet under the @opengsd scope, so the
inaugural release uses 1.0.0 rather than 2.0.0. The "major bump"
in the changeset reflects the breaking install-command change for
users migrating from the prior unscoped `get-shit-done-redux`, not
a numeric continuation from a 1.x line under the new identity.

Refs #126

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-22 16:22:41 -04:00

191 lines
6.7 KiB
JavaScript

/**
* Regression test for #3610: fresh `npx @opengsd/get-shit-done-redux@latest --codex`
* hard-aborts when the target ~/.codex/hooks/ contains the bundled GSD
* hook files (`gsd-check-update-worker.js`, `gsd-prompt-guard.js`, …)
* left over from a previous version. The installer-migration report
* classifies them as "GSD-looking file is not proven manifest-managed
* and needs explicit user choice" and `assertInstallerMigrationsUnblocked`
* throws.
*
* The files in question are NOT user-owned — they are the GSD bundled
* hooks shipped under `hooks/gsd-*` in the npm package. The fix adds a
* `bundled-gsd-hook` classification to `classifyPromptUserAction` so the
* resolver removes them (the installer then writes the fresh bundled
* versions in their place).
*
* Because this classification is unambiguous (these are not user files),
* it must apply regardless of whether stdin is a TTY — the reporter's
* `npx ... --codex` run was interactive and the existing non-TTY
* resolver gate at install.js:8069 skipped the safe-default pass.
*/
'use strict';
process.env.GSD_TEST_MODE = '1';
const { describe, test, beforeEach, afterEach } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const crypto = require('node:crypto');
const {
runInstallerMigrations,
} = require('../get-shit-done/bin/lib/installer-migrations.cjs');
const {
assertInstallerMigrationsUnblocked,
resolveInstallerMigrationPromptsForNonTty,
classifyPromptUserAction,
} = require('../get-shit-done/bin/lib/installer-migration-report.cjs');
const { createTempDir, cleanup } = require('./helpers.cjs');
function writeFile(root, relPath, content) {
const fullPath = path.join(root, relPath);
fs.mkdirSync(path.dirname(fullPath), { recursive: true });
fs.writeFileSync(fullPath, content, 'utf8');
}
function writeManifest(root, files) {
fs.writeFileSync(
path.join(root, 'gsd-file-manifest.json'),
JSON.stringify(
{
version: '1.41.2',
timestamp: '2026-05-10T00:00:00.000Z',
mode: 'full',
files,
},
null,
2,
),
'utf8',
);
}
// Reporter's exact list of blocked files from the v1.42.2 → v1.42.0 upgrade
// abort. Each is a real `hooks/gsd-*` file shipped under hooks/ in the npm
// package (verified by `ls hooks/`).
const BUNDLED_HOOK_RELPATHS = [
'hooks/gsd-check-update-worker.js',
'hooks/gsd-check-update.js',
'hooks/gsd-context-monitor.js',
'hooks/gsd-phase-boundary.sh',
'hooks/gsd-prompt-guard.js',
'hooks/gsd-read-guard.js',
'hooks/gsd-read-injection-scanner.js',
'hooks/gsd-session-state.sh',
'hooks/gsd-statusline.js',
'hooks/gsd-update-banner.js',
'hooks/gsd-validate-commit.sh',
'hooks/gsd-workflow-guard.js',
];
describe('bug #3610: classifyPromptUserAction recognizes bundled GSD hooks', () => {
test('classifies hooks/gsd-*.js as bundled-gsd-hook → remove', () => {
const result = classifyPromptUserAction({
relPath: 'hooks/gsd-prompt-guard.js',
});
assert.ok(result, 'classifier returned null for a bundled GSD hook (.js)');
assert.strictEqual(result.category, 'bundled-gsd-hook');
assert.strictEqual(
result.choice,
'remove',
'bundled hook must default to remove so the installer can write the fresh bundled version',
);
});
test('classifies hooks/gsd-*.sh as bundled-gsd-hook → remove', () => {
const result = classifyPromptUserAction({
relPath: 'hooks/gsd-validate-commit.sh',
});
assert.ok(result);
assert.strictEqual(result.category, 'bundled-gsd-hook');
assert.strictEqual(result.choice, 'remove');
});
test('does NOT classify non-gsd hooks (preserves user-owned hook files)', () => {
// A user's custom hook that happens to live under hooks/ must NOT be
// auto-classified as bundled — the existing block-then-choose flow
// continues to apply, preserving the user's control over their files.
const result = classifyPromptUserAction({
relPath: 'hooks/my-custom-hook.js',
});
assert.strictEqual(
result,
null,
'non-gsd-prefixed hook must NOT auto-classify (would clobber user files)',
);
});
test('does NOT classify deeper paths under hooks/gsd-* (e.g. hooks/lib/) as bundled-gsd-hook', () => {
// The bundled GSD distribution has hooks/lib/ (helper modules). Those
// are managed differently — verify the classifier limits itself to
// top-level hooks/gsd-<name>.<ext> files, not nested directories.
const result = classifyPromptUserAction({
relPath: 'hooks/gsd-helpers/index.js',
});
assert.strictEqual(result, null);
});
});
describe('bug #3610: fresh upgrade with leftover bundled hooks does not throw', () => {
let configDir;
beforeEach(() => {
configDir = createTempDir('gsd-3610-');
});
afterEach(() => {
cleanup(configDir);
});
test('end-to-end: 12 leftover bundled hooks + empty manifest → resolver clears all blockers', () => {
// Recreate the reporter's environment: 12 bundled `gsd-*` hook files
// present at target, but the manifest has not yet seeded their baseline
// entries (first-time-baseline scan).
for (const rel of BUNDLED_HOOK_RELPATHS) {
writeFile(configDir, rel, '#!/usr/bin/env node\n// stale 1.42.0 hook\n');
}
writeManifest(configDir, {});
const result = runInstallerMigrations({
configDir,
runtime: 'codex',
scope: 'global',
baselineScan: true,
});
// Precondition: all 12 leftover hooks classify as prompt-user blockers.
const blockedPaths = (result.blocked || []).map((a) => a.relPath).sort();
assert.deepStrictEqual(
blockedPaths,
[...BUNDLED_HOOK_RELPATHS].sort(),
'precondition: every leftover hooks/gsd-* should be a prompt-user blocker',
);
// Resolve through the safe-default classifier (passing isTty=false to
// exercise the same code path the bundled-hook classification will hit
// regardless of TTY once the fix removes the gate).
const resolved = resolveInstallerMigrationPromptsForNonTty(result, { isTty: false });
assert.strictEqual(
resolved.resolutions.length,
BUNDLED_HOOK_RELPATHS.length,
'every bundled hook should produce a safe-default resolution entry',
);
for (const entry of resolved.resolutions) {
assert.strictEqual(entry.category, 'bundled-gsd-hook');
assert.strictEqual(entry.choice, 'remove');
assert.strictEqual(entry.resolvedActionType, 'backup-and-remove');
}
assert.strictEqual(
(resolved.result.blocked || []).length,
0,
'no blockers should remain after bundled-hook classification fires',
);
assert.doesNotThrow(() => assertInstallerMigrationsUnblocked(resolved.result));
});
});