Two more diagnostic passes (clusters J: residuals in already-touched files,
K: 12 untouched files) plus a production-code path fix and a new
ratchet-style lint guard.
## Test-only fixes (14 files)
bug-1736, bug-2248, bug-2698 — replace inline 1s-budget rmSync with the
shared cleanup() helper (5s budget, 20×250ms retries). The earlier
inline maxRetries:10 / retryDelay:100 wasn't enough to absorb Windows
Defender's deferred-scan handle hold on cold runners.
bug-2256, skill-manifest — also override USERPROFILE alongside HOME in
beforeEach/runGsdTools calls. os.homedir() reads USERPROFILE on win32,
so HOME-only stubs leak the runner's real home into the SUT.
bug-2784, bug-3608, enh-2500, enh-2790, few-shot-calibration,
gsd-settings-advanced — CRLF tolerance: literal \n in regexes against
file content (frontmatter anchors, bash-fence regex, multi-line
numbered-list captures, awk-block extractors) becomes \r?\n; split('\n')
becomes split(/\r?\n/). Windows checkout with autocrlf=true puts \r
before every \n; .+ doesn't match \r in JS regex by default.
bug-2966 — three-part fix to extractStepRun (CRLF split), awk regex
(\r?\n), and conflict-marker parser (rawLine + \r$ strip).
bug-2969, config — normalize separators on test assertions where the
SUT correctly emits \ on win32 but the test compares against /.
prompt-injection-scan — normalize relPath via replace(/\\/g, '/') before
ALLOWLIST.has() lookup. ALLOWLIST keys are POSIX; path.relative returns
backslashes on win32 → falsely scans allowlisted security module → trips
the boundary-tag detector on its own legitimate detection code.
prune-orphaned-worktrees — use the existing canonicalPath +
listedWorktreePaths(repoDir).has(...) helpers instead of substring
matching the raw path. git stores long-form canonical paths
(runneradmin), but mkdtempSync returns 8.3 short-form (RUNNER~1) on
Windows runners; plain string compare misses every entry.
## Production-code fix (1 file)
get-shit-done/bin/lib/init.cjs — bug-3491 in_nested_subdir computation
canonicalizes both worktreeRoot and cwd via fs.realpathSync.native +
path.relative before declaring "nested." Windows runner cwd (8.3 short
name) vs git's --show-toplevel (long form, forward slashes) made the
raw string compare always say true even at the worktree root, breaking
the "init new-project at worktree root" subtest.
## New ratchet lint guard
tests/windows-test-parity-guard.test.cjs — scans tests/ for 7
anti-patterns that drove the Windows failure clusters. Each rule has a
baseline count snapshot from this PR; the test fails when a new
occurrence appears (count grows above baseline), ratcheting down as
existing offenders are fixed. Patterns covered:
G1 split('\n') after readFileSync (use /\r?\n/)
G2 ```bash\n fence regex (use ```bash\r?\n)
G3 ^---\n frontmatter anchor (use ^---\r?\n)
G4 hardcoded "/tmp/..." literal passed to fs.* (use os.tmpdir())
G5 bare 'npm' to execFileSync without {shell:true} on win32
G6 process.env.HOME stub with no USERPROFILE
G7 fs.rmSync({recursive,force}) without maxRetries
Future Windows-parity regressions get caught at PR time rather than
five iterations into a CI loop.
Validated: holodeck (ubuntu docker) 11232/0 pass (count +8 = the 7
new ratchet tests + parent describe).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
184 lines
7.7 KiB
JavaScript
184 lines
7.7 KiB
JavaScript
'use strict';
|
|
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
/**
|
|
* Ratchet-style lint guard against Windows-test-parity regressions.
|
|
*
|
|
* PR #3649 cleared ~270 Windows-only test failures from the chunking fix
|
|
* in #3597 surfaced. Each cluster reduced to a handful of repeating
|
|
* patterns. This guard prevents the patterns from being re-introduced.
|
|
*
|
|
* Strategy: per-pattern offender list is snapshotted at the count present
|
|
* at the time of PR #3649. The test fails if a NEW file is added that
|
|
* matches the anti-pattern (count grows above the baseline). Existing
|
|
* offenders are acknowledged as technical debt that can be cleared
|
|
* incrementally without blocking this PR.
|
|
*
|
|
* When you fix an existing offender, lower the corresponding BASELINE
|
|
* count by 1. When CI breaks because BASELINE is set higher than the
|
|
* actual offender count, lower BASELINE to match (one-way ratchet down).
|
|
*
|
|
* Scope: tests/ only. Production-code Windows-compat is enforced via
|
|
* behavioural tests (see no-unconditional-win32-skip.test.cjs).
|
|
*/
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
|
|
const TESTS_DIR = path.join(__dirname);
|
|
const SELF = path.basename(__filename);
|
|
|
|
// ── Baseline counts after PR #3649 batch ─────────────────────────────────
|
|
// Set these to the exact number of offending files at the time of merge.
|
|
// Each rule must not exceed its baseline; CI fails when a new offender appears.
|
|
// Decrement when an existing offender is fixed.
|
|
const BASELINE = {
|
|
splitNewlineOnFileContent: 3,
|
|
fenceRegexLiteralNewline: 2,
|
|
frontmatterAnchorLiteralNewline: 5,
|
|
hardcodedTmpToFsCall: 0,
|
|
bareNpmExecWithoutShell: 0,
|
|
stubsHomeNoUserProfile: 8,
|
|
rmSyncNoMaxRetries: 95,
|
|
};
|
|
|
|
function listTestFiles() {
|
|
return fs.readdirSync(TESTS_DIR)
|
|
.filter((f) => /\.(test|spec)\.cjs$/.test(f))
|
|
.filter((f) => f !== SELF)
|
|
.map((f) => path.join(TESTS_DIR, f));
|
|
}
|
|
|
|
function readFileText(filePath) {
|
|
return fs.readFileSync(filePath, 'utf8');
|
|
}
|
|
|
|
// Strip line comments and block comments before pattern matching to avoid
|
|
// false-positives in commentary describing the very pattern we forbid.
|
|
function stripComments(text) {
|
|
return text
|
|
.replace(/\/\*[\s\S]*?\*\//g, '')
|
|
.replace(/(^|[^:])\/\/[^\n]*/g, '$1');
|
|
}
|
|
|
|
function countMatchingFiles(predicate) {
|
|
let count = 0;
|
|
const offenders = [];
|
|
for (const file of listTestFiles()) {
|
|
const text = stripComments(readFileText(file));
|
|
if (predicate(text, file)) {
|
|
count += 1;
|
|
offenders.push(path.basename(file));
|
|
}
|
|
}
|
|
return { count, offenders };
|
|
}
|
|
|
|
function ratchetAssert(rule, actualCount, baselineCount, offenders, guidance) {
|
|
if (actualCount > baselineCount) {
|
|
const newCount = actualCount - baselineCount;
|
|
assert.fail(
|
|
`Windows-parity guard "${rule}": ${actualCount} offenders, baseline is ${baselineCount} ` +
|
|
`(+${newCount} new). New occurrences of this anti-pattern were added. ` +
|
|
`${guidance}\n\nFull offender list (${actualCount}):\n ` +
|
|
offenders.join('\n '),
|
|
);
|
|
}
|
|
}
|
|
|
|
describe('Windows test-parity lint guards (ratchet baseline: PR #3649)', () => {
|
|
// ── G1 — CRLF: file-content split on literal '\n' ─────────────────────
|
|
test('split-on-newline after readFileSync (use /\\r?\\n/)', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
return /\.readFileSync\s*\([^)]*\)[^;]*\.split\(\s*['"]\\n['"]\s*\)/.test(text);
|
|
});
|
|
ratchetAssert(
|
|
'splitNewlineOnFileContent', count, BASELINE.splitNewlineOnFileContent, offenders,
|
|
"Replace .split('\\n') with .split(/\\r?\\n/) so the test tolerates CRLF " +
|
|
"checkout (autocrlf=true on Windows leaves trailing \\r on every line).",
|
|
);
|
|
});
|
|
|
|
// ── G2 — CRLF: ```bash|sh\n fence regex on file content ──────────────
|
|
test('markdown-fence regex with literal \\n after ```bash/sh', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
return /\/[^/]*```(?:bash|sh)\\n[^/]*\//.test(text);
|
|
});
|
|
ratchetAssert(
|
|
'fenceRegexLiteralNewline', count, BASELINE.fenceRegexLiteralNewline, offenders,
|
|
"Use /```(?:bash|sh)\\r?\\n([\\s\\S]*?)```/g — Windows CRLF makes the byte after " +
|
|
"`bash` be \\r, the regex never matches, and bash-block extraction returns empty.",
|
|
);
|
|
});
|
|
|
|
// ── G3 — CRLF: frontmatter regex with literal '\n' ────────────────────
|
|
test('frontmatter regex anchors on /^---\\n/', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
return /\/\^---\\n/.test(text);
|
|
});
|
|
ratchetAssert(
|
|
'frontmatterAnchorLiteralNewline', count, BASELINE.frontmatterAnchorLiteralNewline, offenders,
|
|
"Use /^---\\r?\\n/ — on Windows the byte after --- is \\r, not \\n, so the " +
|
|
"anchor fails to match and parseFrontmatter returns null/{}.",
|
|
);
|
|
});
|
|
|
|
// ── G4 — POSIX-tmp: hardcoded '/tmp/' literal passed to fs.* ─────────
|
|
test('fs.* call receives a hardcoded "/tmp/..." literal', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
return /\bfs\.[A-Za-z]+\s*\([^)]*['"]\/tmp\/[^'"]+['"][^)]*\)/.test(text);
|
|
});
|
|
ratchetAssert(
|
|
'hardcodedTmpToFsCall', count, BASELINE.hardcodedTmpToFsCall, offenders,
|
|
"Use os.tmpdir() — on Windows '/tmp/foo' becomes 'D:\\tmp\\foo' where D:\\tmp " +
|
|
"doesn't exist by default → ENOENT.",
|
|
);
|
|
});
|
|
|
|
// ── G5 — npm.cmd: bare 'npm' to exec*Sync without shell:true ─────────
|
|
test('bare npm exec without shell-true Windows fallback', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
const re = /\b(?:execFileSync|spawnSync)\s*\(\s*['"]npm['"]\s*,[^)]*\)/g;
|
|
const matches = text.match(re) || [];
|
|
return matches.some((m) =>
|
|
!/shell\s*:\s*true/.test(m) && !/shell\s*:\s*isWindows/.test(m),
|
|
);
|
|
});
|
|
ratchetAssert(
|
|
'bareNpmExecWithoutShell', count, BASELINE.bareNpmExecWithoutShell, offenders,
|
|
"On Windows npm is npm.cmd — pass {shell: process.platform === 'win32'} or " +
|
|
"use npm.cmd directly, otherwise execFileSync errors ENOENT.",
|
|
);
|
|
});
|
|
|
|
// ── G6 — Test stubs HOME without USERPROFILE ─────────────────────────
|
|
test('test stubs process.env.HOME but never references USERPROFILE', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
return /process\.env\.HOME\s*=\s*/.test(text) && !/USERPROFILE/.test(text);
|
|
});
|
|
ratchetAssert(
|
|
'stubsHomeNoUserProfile', count, BASELINE.stubsHomeNoUserProfile, offenders,
|
|
"On Windows os.homedir() reads USERPROFILE (not HOME). Tests redirecting ~ " +
|
|
"must override both, or the SUT sees the real user's home.",
|
|
);
|
|
});
|
|
|
|
// ── G7 — rmSync cleanup without retry budget ─────────────────────────
|
|
test('test teardown rmSync without maxRetries', () => {
|
|
const { count, offenders } = countMatchingFiles((text) => {
|
|
const re = /fs\.rmSync\s*\([^)]*recursive\s*:\s*true[^)]*force\s*:\s*true[^)]*\)/g;
|
|
const matches = text.match(re) || [];
|
|
return matches.some((m) => !/maxRetries/.test(m));
|
|
});
|
|
ratchetAssert(
|
|
'rmSyncNoMaxRetries', count, BASELINE.rmSyncNoMaxRetries, offenders,
|
|
"Use helpers.cleanup() (shared 5s retry budget) or pass " +
|
|
"{maxRetries: 10, retryDelay: 100} — Windows AV scanners can hold handles for " +
|
|
"seconds after a process exits, surfacing as flaky EBUSY teardown failures.",
|
|
);
|
|
});
|
|
});
|