Phase 1 of #3464. Removes the `// allow-test-rule:` marker from 22 test files where it is provably vestigial, and tightens the ratchet ceiling in scripts/lint-allow-test-rule-refs.ceiling.json from 305 to 285. Eligibility is decided by two independent AST discriminators, both conservative (any doubt => keep): (a) Read-target type. Every readFileSync/readFile call in the file resolves statically to a prose/config extension (.md/.json/.yml/.yaml/.toml/.txt), or the file performs no reads at all. Any read of a source extension (.cjs/.js/.mjs/.ts/.cts/.mts/.jsx/.tsx), any dynamic/unresolvable path, and any other extension all disqualify the file. (b) Marker context. Every `allow-test-rule:` occurrence is a genuine comment node, never string- or template-literal payload. A marker that lives inside a RuleTester `code:` fixture is test DATA, not a suppression directive; stripping it corrupts the test. tests/eslint-rules.test.cjs is the one such fixture host and is deliberately untouched. An earlier attempt at this phase classified markers by "strip it and see if local/no-source-grep still passes" and was reverted in full before commit. That oracle is unsound: the rule only fires on a literal .cjs/.js/.ts path containing a quoted bin/lib/gsd-core/src segment, tracked one hop from the binding, so files that genuinely source-grep real JavaScript pass it silently -- tests/no-unbounded-spawn-allowlist.test.cjs (reads test sources through a listTestFiles() walk) and tests/claude-imperative-reference.test.cjs (matches bin/install.js through an intermediate variable) both cleared it while being real source-greps. The rule's implementation is narrower than its intent, so it cannot adjudicate whether an exemption is load-bearing. Scope is limited to comment deletions: the diff over the test tree is 100% line removals with zero insertions, and no executable line is altered. On the ceiling value. The measured count at this HEAD is 283, so 285 leaves 2 slack -- deliberate, and well inside the documented grace band of 3. Pinning the ceiling to the exact count makes this change effectively unmergeable: any concurrent PR that lands one marker-bearing test file re-reds it. That race fired twice while preparing this branch (once mid-rebase taking the count 304->305 on next, once between rebase and the verification run taking it 282->283), and it is the same race that broke next in #3461. A ceiling of actual+2 preserves a merge window while still ratcheting 305 -> 285. Known limit, disclosed rather than papered over: this clears 22 of 303 markers and does not reach #3464's trend-to-zero goal. Most of the remaining markers sit on dynamic-path reads, commonly a hoisted `const p = path.join(tmpDir, 'STATE.md')` whose target is prose but is unresolvable to this classifier. A stricter one-hop const resolution would flip an estimated 95 more; that is deliberately left to a follow-up so it can be reviewed on its own evidence. Marker discovery reads bytes rather than shelling out to grep: tests/security-prompt-injection.security.test.cjs carries a literal NUL byte (an intentional injection fixture) that makes grep treat it as binary and skip it, which is why the true marked-file count is 303 and not the 302 a shell scan reports. Closes #3465 Co-authored-by: sim <sim@local> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
95 lines
3.5 KiB
JavaScript
95 lines
3.5 KiB
JavaScript
// Phase 5 kimi-variant disambiguation is verified via install.js subprocess
|
|
// output capture (regex on printed notices), since disambiguateKimiVariant
|
|
// is inline in bin/install.js (not exported) and emits no structured/JSON
|
|
// output. Exporting the function and/or adding a --json notice mode is a
|
|
// production change out of scope here. Tracked under #3090.
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
const { test, describe, before, after } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const { spawnSync } = require('node:child_process');
|
|
const fs = require('node:fs');
|
|
const os = require('node:os');
|
|
const path = require('node:path');
|
|
const { cleanup } = require('./helpers.cjs');
|
|
|
|
const INSTALL_JS = path.join(__dirname, '..', 'bin', 'install.js');
|
|
|
|
function makeDisposableHome() {
|
|
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-kimi-disambig-'));
|
|
return {
|
|
dir,
|
|
cleanup() { cleanup(dir); },
|
|
};
|
|
}
|
|
|
|
function runInstall(args, home) {
|
|
// spawnSync captures stdout AND stderr separately regardless of exit code
|
|
// (execFileSync drops stderr on success, which hid the console.error warnings).
|
|
const r = spawnSync('node', [INSTALL_JS, ...args], {
|
|
env: { ...process.env, HOME: home, USERPROFILE: home, GSD_TEST_MODE: '1' },
|
|
encoding: 'utf8',
|
|
timeout: 15000,
|
|
});
|
|
return { stdout: r.stdout || '', stderr: r.stderr || '', exit: r.status };
|
|
}
|
|
|
|
describe('Kimi variant disambiguation (#2505 Phase 5 / #2513)', () => {
|
|
let home;
|
|
before(() => { home = makeDisposableHome(); });
|
|
after(() => home.cleanup());
|
|
|
|
test('--kimi prints the Kimi CLI (Python) description', () => {
|
|
const r = runInstall(['--kimi', '--help'], home.dir);
|
|
const combined = r.stdout + r.stderr;
|
|
assert.match(combined, /Kimi CLI \(Python kimi-cli\).*named subagents.*~\/\.kimi\//);
|
|
});
|
|
|
|
test('--kimi-code prints the Kimi Code (Node CLI) description', () => {
|
|
const r = runInstall(['--kimi-code', '--help'], home.dir);
|
|
const combined = r.stdout + r.stderr;
|
|
assert.match(combined, /Kimi Code \(Node CLI\).*coder\/explore\/plan.*~\/\.kimi-code\//);
|
|
});
|
|
|
|
test('--kimi warns when only ~/.kimi-code/config.toml exists', () => {
|
|
const h = makeDisposableHome();
|
|
try {
|
|
fs.mkdirSync(path.join(h.dir, '.kimi-code'), { recursive: true });
|
|
fs.writeFileSync(path.join(h.dir, '.kimi-code', 'config.toml'), '# kimi-code');
|
|
const r = runInstall(['--kimi', '--help'], h.dir);
|
|
const combined = r.stdout + r.stderr;
|
|
assert.match(combined, /variant mismatch/i);
|
|
assert.match(combined, /Detected ~\/\.kimi-code\/config\.toml/);
|
|
assert.match(combined, /Re-run with --kimi-code/);
|
|
} finally {
|
|
h.cleanup();
|
|
}
|
|
});
|
|
|
|
test('--kimi-code warns when only ~/.kimi/config.toml exists', () => {
|
|
const h = makeDisposableHome();
|
|
try {
|
|
fs.mkdirSync(path.join(h.dir, '.kimi'), { recursive: true });
|
|
fs.writeFileSync(path.join(h.dir, '.kimi', 'config.toml'), '# kimi-cli');
|
|
const r = runInstall(['--kimi-code', '--help'], h.dir);
|
|
const combined = r.stdout + r.stderr;
|
|
assert.match(combined, /variant mismatch/i);
|
|
assert.match(combined, /Detected ~\/\.kimi\/config\.toml/);
|
|
assert.match(combined, /Re-run with --kimi/);
|
|
} finally {
|
|
h.cleanup();
|
|
}
|
|
});
|
|
|
|
test('no warning when neither config exists (fresh install)', () => {
|
|
const h = makeDisposableHome();
|
|
try {
|
|
const r = runInstall(['--kimi', '--help'], h.dir);
|
|
const combined = r.stdout + r.stderr;
|
|
assert.doesNotMatch(combined, /variant mismatch/i);
|
|
} finally {
|
|
h.cleanup();
|
|
}
|
|
});
|
|
});
|