* fix: recurse test discovery so subdir test suites actually run
scripts/run-tests.cjs discovered tests with a flat readdirSync(testDir),
silently excluding tests/observability/ (4 files), tests/dispatch/ (1) and
tests/installer-migrations/ (1) — 94 passing tests — from `npm test` and all
CI lanes. Walk the tree recursively (relative subpaths preserved), classify
suites by basename, and add a fail-on-zero-executed guard for suite/default
runs (escape hatch GSD_ALLOW_EMPTY_SUITE=1) while preserving the empty
--files/--files-from path the CI inert lane relies on.
Unit suite 735 -> 741 files; surfaces ADR-227's observability/dispatch seam.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test: retire 5 verified-worthless tests
Adversarial verification confirmed these 5 prove nothing — their coverage is
provided more strictly elsewhere:
- enh-2790 'has a name: field' spot-checks (command-contract enforces /^gsd[:-]/)
- command-routing-hub duplicate construct + duplicate ERROR_KINDS assertions
- no-cjs-sdk-handsync-tooling (guarded files that never existed on main; bug-190
covers the real retired SDK artifacts)
- runtime-artifact-layout cline edge case (subsumed by the explicit-global test
and bug-782-cline-skills-emission)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test: add ADR-218 release version-validation coverage
ADR-218 (reject leading-zero versions like 1.01.0; npm duplicate pre-check) had
zero tests — the logic lived only in release.yml bash. Add a test that extracts
the actual rejection regexes from the workflow and exercises them against a
boundary table (leading-zero/malformed rejected, valid accepted) plus structural
wiring assertions. Goes red if the regex is reverted to [0-9]+.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test: redesign weak tests into behavioral, deterministic assertions
Per the ADR test audit, rewrite 27 weak test files (test-only, no source
changes) so each can go red for the defect it guards:
- kill pass-always assert.ok(true) placeholders (research-cli, worktree-baseref,
bug-260 security guard, eslint-rules x24, clusters '|| true')
- replace source-text grep with behavioral calls (install Kilo, sh-hook-paths,
plan-review-convergence) and add a repo-layout governance test
- de-flake real-clock/Math.random coupling (phase last_updated, bug-3707 mtime,
context-utilization property, feat-3594)
- fix independence/shared-state violations (bug-492 singleton, issue-844 tmpRoot,
core reapStaleTempFiles, active-workstream TTY, feat-488 GSD_HOME)
- strengthen property/shape-only tests (research-provider/store classification +
collision) and unconditional plugin.json schema validation (issue-766)
Verified: all 28 files run together 1220 pass / 0 fail / 1 skip.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore: add no-tautological-assert lint rule, error in test suite
New custom ESLint rule (eslint-rules/no-tautological-assert.cjs) bans asserts
that can never fail: assert(true)/assert.ok(<always-truthy literal>),
'cond || true' inside an assert, and equality asserts comparing two identical
literals. Wired as error on tests/**; full sweep confirmed zero existing
violations so the suite stays green. Prevents the placeholder-assert regressions
the audit redesigns just removed. RuleTester coverage added (6 valid, 8 invalid).
Note: no-only-tests was already enforced via eslint-plugin-no-only-tests, so no
duplicate rule was added.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore: gate new allow-test-rule exemptions to require an issue ref
ADR-456 requires any allow-test-rule exemption added after the ADR to carry a
tracking issue number, but nothing enforced it. New ratchet gate
(scripts/lint-allow-test-rule-refs.cjs, wired into lint:ci) fails when a NEW
allow-test-rule comment lacks a #NNN/URL reference; the 323 existing untracked
exemptions are grandfathered in an allowlist that ratchets down as they gain
refs. Red-green verified (novel untracked offender fails; compliant passes).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* docs: add ADR test-audit evidence report (#1192)
Full risk-first qa-test-architect audit of the ADR portfolio (37 ADRs + 4
platform lenses, adversarial verification of retire verdicts) that drove the
P0 discovery fix, ADR-218 coverage, 5 retires, 27 redesigns, and the two new
lint gates. Filed as point-in-time evidence under docs/issueevidence/, named
for tracking issue #1192.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test: replace pre-existing raw NUL byte with escape in feat-3594 fixture
feat-3594's null-byte parser fixture contained a literal NUL byte (pre-existing
on next at b10e5681 — confirmed: base blob has 1 NUL, this fix has 0), which
made git treat the file as binary and would break grep/editors. Switch to the
\x00 escape; the runtime string value (a real NUL in the parser input) is
unchanged.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test: address adversarial-review findings
Codex adversarial pass over the branch:
- capability-registry drift test no longer mutates the committed generated
capability-registry.cjs in place (concurrency hazard) — uses in-memory
checkPipeline comparison instead.
- allow-test-rule ratchet now detects exemptions in ALL comment forms (block
/* */ too, matching no-source-grep) so a block comment can't bypass it;
one newly-surfaced pre-existing offender grandfathered (323->324).
- install.test Kilo case asserts on what install(false,'kilo') actually writes
rather than manually calling configureKiloPermissions (masked the call site).
- issue-766 drops the undeclared transitive ajv dep for explicit structural
assertions from the schema fixture.
- adr-218 test notes the hotfix leading-zero gap is tracked in #1186.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* fix: address code-review findings (subdir discovery, rule + test gaps)
xhigh code review surfaced 15 confirmed issues, all fixed:
- run-tests.cjs --files now resolves subdir tests by bare basename + handles
Windows backslash paths (ambiguous basenames error clearly).
- affected-tests-lib.cjs listTestFiles made recursive — the targeted CI lane was
silently dropping changed subdir tests (same false-green class the audit fixed).
- no-tautological-assert now catches 'true || cond' and empty []/{} equality.
- verify-test-quality: restore provenance-classification coverage, tighten the
writeFile circular-detection check, guard the module-level file read.
- sh-hook-paths: cover the global-install .sh delegation branch (#2045 guard).
- active-workstream null-guard runs deterministically (no longer skipped on TTY).
- adr-218 structural guards tightened (major/minor leading-zero; needs: membership).
- repo-layout AGENTS.md guard no longer false-alarms on equivalent refactors.
- cross-ai ordering guard fails red when the step is missing.
- issue-766 parses required fields from the schema fixture (auto-enforced).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* test: stub USERPROFILE alongside HOME in feat-488 (Windows parity)
The feat-488 redesign stubbed process.env.HOME but not USERPROFILE; os.homedir()
resolves from USERPROFILE on Windows, so the home stub was not hermetic there —
caught by windows-test-parity-guard (stubsHomeNoUserProfile). Save/set/restore
USERPROFILE symmetrically with HOME (delete-if-originally-undefined).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
* chore: reconcile allow-test-rule allowlist after rebase onto next
Rebasing onto current next pulled in merged PR #1170, which added
inventory-headings-countfree.test.cjs (a baseline allow-test-rule exemption) and
deleted inventory-counts.test.cjs. Grandfather the former and prune the latter so
the ratchet matches the merged tree. No new debt from this PR.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
557 lines
22 KiB
JavaScript
557 lines
22 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Behavioral tests for research-store, research-plan, and package-legitimacy
|
|
* CLI commands (gsd-tools dispatch layer).
|
|
*
|
|
* Conventions:
|
|
* - Uses runGsdTools from tests/helpers.cjs (no source-grep)
|
|
* - No wall-clock assertions (RULESET.TESTS.no-timing-assertion)
|
|
* - No network calls (package-legitimacy tests are arg-validation only)
|
|
* - Each test gets a fresh temp dir via fs.mkdtempSync
|
|
* - HOME is overridden via runGsdTools env param to sandbox ~/.gsd/ writes
|
|
*/
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
const os = require('node:os');
|
|
|
|
const { runGsdTools, cleanup } = require('./helpers.cjs');
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// Helper: make a temp dir and return it (caller is responsible for cleanup)
|
|
// ---------------------------------------------------------------------------
|
|
function makeTempDir() {
|
|
return fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-research-test-'));
|
|
}
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (a) research-store put then get round-trip
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('research-store: put then get round-trip', () => {
|
|
test('put stores entry; get returns hit:true, stale:false, correct content', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
// Must be a valid 64-char sha256 hex string (as produced by researchKey).
|
|
// Using a pre-computed key for 'test-round-trip' to satisfy isValidResearchKey.
|
|
const key = '4642afa8420709e0902413b46e2f26806499a5df710b602c22a5344f0eb298d0';
|
|
|
|
// PUT
|
|
const putResult = runGsdTools(
|
|
[
|
|
'research-store', 'put', key,
|
|
'--content', 'hello docs',
|
|
'--source', 'curated',
|
|
'--provider', 'context7',
|
|
'--confidence', 'HIGH',
|
|
'--kind', 'docs',
|
|
],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(putResult.success, `put failed: ${putResult.error}`);
|
|
const entry = JSON.parse(putResult.output);
|
|
assert.equal(entry.content, 'hello docs', 'put: entry.content mismatch');
|
|
assert.equal(entry.kind, 'docs', 'put: entry.kind mismatch');
|
|
|
|
// GET
|
|
const getResult = runGsdTools(
|
|
['research-store', 'get', key, '--kind', 'docs'],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(getResult.success, `get failed: ${getResult.error}`);
|
|
const got = JSON.parse(getResult.output);
|
|
assert.ok(got.hit === true, `get: expected hit:true, got hit:${got.hit}`);
|
|
assert.ok(got.stale === false, `get: expected stale:false, got stale:${got.stale}`);
|
|
assert.ok(got.entry !== null, 'get: entry should not be null');
|
|
assert.equal(got.entry.content, 'hello docs', 'get: entry.content mismatch');
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (b) research-store get on unknown key -> hit:false, entry:null, exit 0
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('research-store: get on unknown key', () => {
|
|
test('returns hit:false, entry:null with exit 0', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
// Must be a valid 64-char sha256 hex string — but nothing seeded under this key.
|
|
const noSuchKey = '5620aa17b85cb82f1d82633c8cfb4799d3e947f58a1775248c96bbeeeb8f8537';
|
|
const result = runGsdTools(
|
|
['research-store', 'get', noSuchKey, '--kind', 'docs'],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(result.success, `expected exit 0 for unknown key; got: ${result.error}`);
|
|
const got = JSON.parse(result.output);
|
|
assert.ok(got.hit === false, `expected hit:false, got hit:${got.hit}`);
|
|
assert.ok(got.entry === null, `expected entry:null, got: ${JSON.stringify(got.entry)}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (c) research-plan: cache hit — seeded via research-store module directly
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('research-plan: cache hit via pre-seeded store', () => {
|
|
test('returns cache.hit:true for pre-seeded question; no fetch property', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
// Compute the key the CLI will use for this question
|
|
const researchStore = require('../gsd-core/bin/lib/research-store.cjs');
|
|
const key = researchStore.researchKey({
|
|
ecosystem: 'npm',
|
|
library: '',
|
|
version: '',
|
|
query: 'use zod',
|
|
kind: 'docs',
|
|
});
|
|
|
|
// Seed the cache directly, passing homeDir so it writes into tmpDir/.gsd/
|
|
researchStore.putResearch(
|
|
tmpDir,
|
|
key,
|
|
{
|
|
content: 'zod usage documentation',
|
|
source: 'curated',
|
|
provider: 'context7',
|
|
confidence: 'HIGH',
|
|
kind: 'docs',
|
|
},
|
|
{ homeDir: tmpDir },
|
|
);
|
|
|
|
// Write the --input file
|
|
const inputFile = path.join(tmpDir, 'research-plan-input.json');
|
|
fs.writeFileSync(
|
|
inputFile,
|
|
JSON.stringify({
|
|
ecosystem: 'npm',
|
|
config: {},
|
|
questions: [{ text: 'use zod', kind: 'docs' }],
|
|
}),
|
|
);
|
|
|
|
// Run research-plan with HOME overridden so the CLI reads from the same cache
|
|
const result = runGsdTools(
|
|
['research-plan', '--input', inputFile],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(result.success, `research-plan failed: ${result.error}`);
|
|
const plan = JSON.parse(result.output);
|
|
assert.ok(Array.isArray(plan.items), `expected plan.items array; got: ${JSON.stringify(plan)}`);
|
|
assert.equal(plan.items.length, 1, 'expected exactly one item');
|
|
const item = plan.items[0];
|
|
assert.ok(item.cache && item.cache.hit === true, `expected cache.hit:true, got: ${JSON.stringify(item.cache)}`);
|
|
assert.ok(item.cache.stale === false, `expected stale:false, got: ${JSON.stringify(item.cache)}`);
|
|
assert.ok(!item.fetch, `expected no fetch property for cache hit, got: ${JSON.stringify(item.fetch)}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (d) research-plan: fetch plan — unseeded question -> item.fetch.provider is string
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('research-plan: fetch plan for unseeded question', () => {
|
|
test('returns item with fetch.provider string and no cache hit', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const inputFile = path.join(tmpDir, 'research-plan-input.json');
|
|
fs.writeFileSync(
|
|
inputFile,
|
|
JSON.stringify({
|
|
ecosystem: 'npm',
|
|
config: {},
|
|
questions: [{ text: 'completely unseeded question zxcvbnmasdf', kind: 'docs' }],
|
|
}),
|
|
);
|
|
|
|
const result = runGsdTools(
|
|
['research-plan', '--input', inputFile],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(result.success, `research-plan failed: ${result.error}`);
|
|
const plan = JSON.parse(result.output);
|
|
assert.ok(Array.isArray(plan.items), 'expected plan.items array');
|
|
assert.equal(plan.items.length, 1, 'expected exactly one item');
|
|
const item = plan.items[0];
|
|
assert.ok(item.fetch, 'expected fetch property for unseeded question');
|
|
assert.equal(typeof item.fetch.provider, 'string', `expected fetch.provider to be string, got: ${typeof item.fetch.provider}`);
|
|
assert.ok(item.fetch.provider.length > 0, 'expected non-empty fetch.provider');
|
|
// No cache hit
|
|
assert.ok(!item.cache || item.cache.hit !== true, 'expected no cache hit for unseeded question');
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (e) classify-confidence: context7 provider, no --verified -> MEDIUM, verified:false
|
|
// (context7 has authority=official; without a code-computed legitimacyVerdict of OK,
|
|
// the HIGH branch is never reached — correctly yields MEDIUM)
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('classify-confidence: context7 without --verified', () => {
|
|
test('returns confidence MEDIUM and verified false', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'classify-confidence', '--provider', 'context7'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(result.success, `expected exit 0; got: ${result.error}`);
|
|
const out = JSON.parse(result.output);
|
|
assert.equal(out.confidence, 'MEDIUM', `expected MEDIUM, got ${out.confidence}`);
|
|
assert.equal(out.verified, false, `expected verified:false, got ${out.verified}`);
|
|
assert.equal(out.provider, 'context7', `expected provider:context7, got ${out.provider}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (f) classify-confidence: exa provider, no --verified -> LOW
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('classify-confidence: exa without --verified', () => {
|
|
test('returns confidence LOW', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'classify-confidence', '--provider', 'exa'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(result.success, `expected exit 0; got: ${result.error}`);
|
|
const out = JSON.parse(result.output);
|
|
assert.equal(out.confidence, 'LOW', `expected LOW, got ${out.confidence}`);
|
|
assert.equal(out.verified, false, `expected verified:false, got ${out.verified}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (g) classify-confidence: exa with --verified -> MEDIUM
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('classify-confidence: exa with --verified', () => {
|
|
test('returns confidence MEDIUM and verified true', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'classify-confidence', '--provider', 'exa', '--verified'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(result.success, `expected exit 0; got: ${result.error}`);
|
|
const out = JSON.parse(result.output);
|
|
assert.equal(out.confidence, 'MEDIUM', `expected MEDIUM, got ${out.confidence}`);
|
|
assert.equal(out.verified, true, `expected verified:true, got ${out.verified}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (h) classify-confidence: missing --provider -> usage error, non-zero exit
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('classify-confidence: missing --provider -> usage error', () => {
|
|
test('exits non-zero and reports usage error when --provider is absent', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
['query', 'classify-confidence'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(!result.success, 'expected non-zero exit when --provider is missing');
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// (e) package-legitimacy check with NO --ecosystem -> usage error, non-zero exit
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('package-legitimacy: missing --ecosystem -> usage error', () => {
|
|
test('exits non-zero and reports usage error when --ecosystem is absent', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
['package-legitimacy', 'check', 'somepackage'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(!result.success, 'expected non-zero exit when --ecosystem is missing');
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// FINDING 1 REGRESSION (CLI): research-store put/get must reject non-64-hex keys
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('research-store CLI: traversal/invalid key rejected with usage error', () => {
|
|
test('put ../../x --content ... → non-zero exit (usage error)', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
[
|
|
'research-store', 'put', '../../x',
|
|
'--content', 'evil',
|
|
'--source', 'web',
|
|
'--provider', 'p',
|
|
'--confidence', 'HIGH',
|
|
'--kind', 'docs',
|
|
],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit for traversal key; got: ${result.output}`);
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
test('get ../../etc/passwd → non-zero exit (usage error)', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const result = runGsdTools(
|
|
['research-store', 'get', '../../etc/passwd'],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit for traversal key; got: ${result.output}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
test('put with valid 64-hex key → success', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const researchStore = require('../gsd-core/bin/lib/research-store.cjs');
|
|
const validKey = researchStore.researchKey({ ecosystem: 'npm', library: 'lodash', version: '4.0.0', query: 'chunk', kind: 'docs' });
|
|
const result = runGsdTools(
|
|
[
|
|
'research-store', 'put', validKey,
|
|
'--content', 'test content',
|
|
'--source', 'web',
|
|
'--provider', 'p',
|
|
'--confidence', 'HIGH',
|
|
'--kind', 'docs',
|
|
],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(result.success, `put with valid 64-hex key should succeed; got: ${result.error}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// FINDING 1 REGRESSION: package-legitimacy flag parser must not swallow packages
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('FINDING-1: package-legitimacy check flag parser correctness', () => {
|
|
test('unknown flag → usage error (not silently dropped)', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
// --unknown-flag is not a valid flag; should produce a usage error, not silently skip
|
|
const result = runGsdTools(
|
|
['package-legitimacy', 'check', '--ecosystem', 'npm', '--unknown-flag', 'somevalue', 'mypkg'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit for unknown flag; got success with output: ${result.output}`);
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
test('--bad-flag pkgA pkgB → unknown-flag error on stderr, non-zero exit, pkgA and pkgB not consumed as flag values', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
// The 2-package arg-parse regression:
|
|
// A buggy parser that treats unknown flags as taking a value would silently
|
|
// consume pkgA as the value of --bad-flag, leaving only pkgB in the package
|
|
// list — proceeding without a usage error (exit 0).
|
|
// The correct parser must reject --bad-flag with a usage error (non-zero exit)
|
|
// so that neither pkgA nor pkgB is silently swallowed.
|
|
//
|
|
// Red proof: if the unknown-flag check is removed so --bad-flag consumes pkgA,
|
|
// the CLI would exit 0 (pkgB remains as the sole package) and result.success
|
|
// would be true — the assertions below would both FAIL.
|
|
//
|
|
// Green proof: the current parser (gsd-tools.cjs lines 1951-1952) hits
|
|
// if (a.startsWith('--')) { error(`package-legitimacy: unknown flag ${a}`, ...) }
|
|
// which writes to stderr and exits 1.
|
|
const result = runGsdTools(
|
|
['package-legitimacy', 'check', '--ecosystem', 'npm', '--bad-flag', 'pkgA', 'pkgB'],
|
|
tmpDir,
|
|
);
|
|
assert.ok(
|
|
!result.success,
|
|
`expected non-zero exit for --bad-flag; got success with output: ${result.output}`,
|
|
);
|
|
assert.ok(
|
|
result.exitCode !== 0,
|
|
`expected non-zero exit code, got ${result.exitCode}`,
|
|
);
|
|
// The error text must mention the offending flag so the caller can diagnose it,
|
|
// not a generic "0 packages" usage error (which would indicate pkgA was silently
|
|
// consumed as the flag value, leaving pkgB as the sole package without triggering
|
|
// the unknown-flag guard at all).
|
|
assert.ok(
|
|
result.error.includes('--bad-flag'),
|
|
`expected stderr to mention '--bad-flag', got: ${result.error}`,
|
|
);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// FINDING 3 REGRESSION: research-plan --input with null/bad input → clean usage error
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('FINDING-3: research-plan --input null/invalid → clean usage error, no crash', () => {
|
|
test('input file contains JSON null → clean usage error (non-zero, no stack trace crash)', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const inputFile = path.join(tmpDir, 'null-input.json');
|
|
fs.writeFileSync(inputFile, 'null');
|
|
const result = runGsdTools(
|
|
['research-plan', '--input', inputFile],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit for null JSON input; got success: ${result.output}`);
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
// Must not crash with an unhandled TypeError stack trace — should be a usage error message
|
|
const combinedOutput = (result.output || '') + (result.error || '');
|
|
assert.ok(
|
|
!combinedOutput.includes('TypeError') || combinedOutput.toLowerCase().includes('usage'),
|
|
`expected clean usage error (not raw TypeError), got: ${combinedOutput.slice(0, 500)}`,
|
|
);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
test('input file contains {"questions": null} → clean usage error', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const inputFile = path.join(tmpDir, 'questions-null.json');
|
|
fs.writeFileSync(inputFile, JSON.stringify({ questions: null }));
|
|
const result = runGsdTools(
|
|
['research-plan', '--input', inputFile],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit for questions:null; got success: ${result.output}`);
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
test('input file contains {"questions": "x"} (string, not array) → clean usage error', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const inputFile = path.join(tmpDir, 'questions-string.json');
|
|
fs.writeFileSync(inputFile, JSON.stringify({ questions: 'x' }));
|
|
const result = runGsdTools(
|
|
['research-plan', '--input', inputFile],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit for questions:"x"; got success: ${result.output}`);
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// FINDING 4 REGRESSION: research-store put must reject flag-as-value
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('FINDING-4: research-store put rejects flag-as-value', () => {
|
|
test('--content --source curated → usage error (--source is consumed as content value)', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const researchStore = require('../gsd-core/bin/lib/research-store.cjs');
|
|
const validKey = researchStore.researchKey({ ecosystem: 'npm', library: 'z', version: '1', query: 'q', kind: 'docs' });
|
|
const result = runGsdTools(
|
|
[
|
|
'research-store', 'put', validKey,
|
|
'--content', '--source', // --source starts with --, should be rejected as value for --content
|
|
'--source', 'curated',
|
|
'--provider', 'context7',
|
|
'--confidence', 'HIGH',
|
|
'--kind', 'docs',
|
|
],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(!result.success, `expected non-zero exit when --content value is a flag; got success: ${result.output}`);
|
|
assert.ok(result.exitCode !== 0, `expected non-zero exit code, got ${result.exitCode}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
|
|
test('well-formed put still succeeds (positive regression guard)', () => {
|
|
const tmpDir = makeTempDir();
|
|
try {
|
|
const researchStore = require('../gsd-core/bin/lib/research-store.cjs');
|
|
const validKey = researchStore.researchKey({ ecosystem: 'npm', library: 'lodash', version: '4', query: 'merge', kind: 'docs' });
|
|
const result = runGsdTools(
|
|
[
|
|
'research-store', 'put', validKey,
|
|
'--content', 'real content',
|
|
'--source', 'curated',
|
|
'--provider', 'context7',
|
|
'--confidence', 'HIGH',
|
|
'--kind', 'docs',
|
|
],
|
|
tmpDir,
|
|
{ HOME: tmpDir },
|
|
);
|
|
assert.ok(result.success, `well-formed put should succeed; got: ${result.error}`);
|
|
} finally {
|
|
cleanup(tmpDir);
|
|
}
|
|
});
|
|
});
|