* feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes() The base lint (scripts/lint-no-source-grep.cjs) only catches readFileSync(...).<text-method>() chained directly. The much more common var-binding form escapes it: const src = fs.readFileSync(p, 'utf8'); // 50 lines later if (src.includes('foo')) {} // ← still grep, lint missed it Scan of the test suite found ~141 files using this pattern. Implementation built TDD per #2982 with structured-IR assertions: scripts/lint-no-source-grep-extras.cjs - detectVarBindingViolations(src) — pure detector, two passes: pass 1 collects vars bound from readFileSync, pass 2 finds any <var>.<includes|startsWith|endsWith|match|search>( on those vars. - detectWrappedAssertOkMatch(src) — flags assert.ok(<expr>.match(...)) which escapes the assert.match rule. - VIOLATION enum exposes stable codes for tests to assert on. scripts/lint-no-source-grep.cjs - Wires the new detectors into the existing per-file check; one additional violation row per file with the first 3 sample tokens. tests/bug-2982-lint-var-binding.test.cjs - 13 tests, all assertions on typed VIOLATION enum / structured records. Covers all 5 text-match methods, multi-var, no-bind, string literal (must NOT trigger), wrapped assert.ok(.match), and assert.match (must NOT double-flag). Migration backlog (#2974 expanded scope): - 42 files annotated `// allow-test-rule: source-text-is-the-product` (legitimate — they read .md/.json/.yml files whose deployed text IS the product) - 3 files annotated `// allow-test-rule: pending-migration-to-typed-ir [#2974]` (read .cjs/.js source — clear migration debt) - 95 files annotated `pending-migration-to-typed-ir [#2974]` with `Per-file review may reclassify as source-text-is-the-product during migration` (mixed — manual review under #2974) After this lands the lint reports 0 violations on main; new violations in PRs surface immediately. Closes #2982 Refs #2974 * test(#2982): fix truncated test name per CR The label ended with a bare '(' from a copy-paste mishap. Now reads 'does NOT flag .matchAll(...) — matchAll is not match, so assert.ok(.matchAll(...)) is not flagged'. * chore(#2982): add changeset fragment for PR #2985 * chore(#2982): add changeset fragment for PR #2985
89 lines
3.4 KiB
JavaScript
89 lines
3.4 KiB
JavaScript
'use strict';
|
|
|
|
// allow-test-rule: pending-migration-to-typed-ir [#2974]
|
|
// Tracked in #2974 for migration to typed-IR assertions per CONTRIBUTING.md
|
|
// "Prohibited: Raw Text Matching on Test Outputs". Per-file review may
|
|
// reclassify some entries as source-text-is-the-product during migration.
|
|
|
|
/**
|
|
* verify-work auto-transition tests (#2018)
|
|
*
|
|
* Validates that verify-work.md calls the transition workflow to mark the
|
|
* phase complete in ROADMAP.md and STATE.md when UAT passes with 0 issues.
|
|
*/
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
|
|
const VERIFY_WORK = path.join(__dirname, '..', 'get-shit-done', 'workflows', 'verify-work.md');
|
|
|
|
describe('verify-work.md — auto-transition after UAT passes with 0 issues', () => {
|
|
test('workflow reads transition.md when issues == 0 and security gate cleared', () => {
|
|
const content = fs.readFileSync(VERIFY_WORK, 'utf-8');
|
|
assert.ok(
|
|
content.includes('transition.md'),
|
|
'verify-work.md must reference transition.md for phase completion when issues == 0'
|
|
);
|
|
});
|
|
|
|
test('transition call appears after complete_session section', () => {
|
|
const content = fs.readFileSync(VERIFY_WORK, 'utf-8');
|
|
const completeSessionIdx = content.indexOf('complete_session');
|
|
const transitionIdx = content.indexOf('transition.md');
|
|
assert.ok(
|
|
completeSessionIdx !== -1,
|
|
'verify-work.md must contain a complete_session section'
|
|
);
|
|
assert.ok(
|
|
transitionIdx !== -1,
|
|
'verify-work.md must reference transition.md'
|
|
);
|
|
assert.ok(
|
|
transitionIdx > completeSessionIdx,
|
|
'transition.md reference must appear after the complete_session section'
|
|
);
|
|
});
|
|
|
|
test('security gate check gates the transition (no auto-transition when security pending)', () => {
|
|
const content = fs.readFileSync(VERIFY_WORK, 'utf-8');
|
|
// The security check must appear before the transition reference
|
|
const securityCfgIdx = content.indexOf('SECURITY_CFG');
|
|
const transitionIdx = content.indexOf('transition.md');
|
|
assert.ok(
|
|
securityCfgIdx !== -1,
|
|
'verify-work.md must check SECURITY_CFG before transitioning'
|
|
);
|
|
assert.ok(
|
|
securityCfgIdx < transitionIdx,
|
|
'SECURITY_CFG check must appear before transition.md reference'
|
|
);
|
|
});
|
|
|
|
test('transition is only invoked when security gate is cleared or disabled', () => {
|
|
const content = fs.readFileSync(VERIFY_WORK, 'utf-8');
|
|
// Transition must be guarded by security check:
|
|
// Either SECURITY_CFG is false, or security file exists with 0 open threats
|
|
const hasGuardedTransition =
|
|
content.includes('transition.md') &&
|
|
(
|
|
content.includes("SECURITY_CFG") &&
|
|
(content.includes('threats_open') || content.includes('SECURITY_FILE'))
|
|
);
|
|
assert.ok(
|
|
hasGuardedTransition,
|
|
'transition.md invocation must be guarded by security gate checks'
|
|
);
|
|
});
|
|
|
|
test('transition is NOT suggested when security enforcement is enabled and no SECURITY.md exists', () => {
|
|
const content = fs.readFileSync(VERIFY_WORK, 'utf-8');
|
|
// The workflow should suggest /gsd-secure-phase when security is enabled but no file exists
|
|
assert.ok(
|
|
content.includes('gsd-secure-phase') || content.includes('gsd:secure-phase'),
|
|
'verify-work.md must suggest /gsd:secure-phase when security gate blocks transition'
|
|
);
|
|
});
|
|
});
|