Files
msd-core/tests/no-unbounded-dirname-walk.rule.test.cjs
Tom Boucher 1fe85cd43e chore(#4244): ESLint rules for the #4220 Windows dirname-walk / TMPDIR-triad bug class (#4246)
* fix(#4244): repoint TEMP/TMP alongside TMPDIR and fix the sweepProtectSet fixed-point walk

Repo-wide sweep (ahead of adding lint rules for these exact bug classes)
found both incident patterns still live and unfixed on `next`:

- scripts/run-tests.cjs's sweepProtectSet walk stopped on
  `cur !== runTempRoot && cur.length > 1` — a POSIX-only sentinel.
  win32 dirname('D:\') is a fixed point (length 3, never satisfies
  `> 1`... wait, it does satisfy length>1), so a selected file living
  outside runTempRoot (the common case) spins the walk forever on
  Windows. Extracted a pure, exported computeSweepProtectSet helper
  that terminates on dirname(cur) === cur instead, with in-process
  RuleTester-style coverage for both win32 and posix paths.

- tests/run-tests-temp-root.test.cjs's own #4020 regression test set
  only TMPDIR on its runNode(...) child env. Node's os.tmpdir() never
  reads TMPDIR on Windows (only TEMP, then TMP), so the redirect
  silently no-oped there — masked because Windows CI died in the
  dirname-walk hang above before ever reaching this test.

- tests/config-schema.property.test.cjs's fallow config-set test had
  the same TMPDIR-only pattern, direct process.env assignment this
  time, restored in its own finally block.

Origin: #4220 and its shared root cause #4020.

* feat(#4244): require-full-tmpdir-triad and no-unbounded-dirname-walk ESLint rules

Two custom local ESLint rules catch the #4220 / #4020 Windows CI hang bug
class at author time, joining the ADR-1703 DEFECT.WINDOWS-TEST-PORTABILITY
catalog. Neither eslint-plugin-unicorn nor eslint-plugin-n has a rule for
either shape.

- local/require-full-tmpdir-triad: flags a TMPDIR environment override
  (direct process.env.TMPDIR assignment, or a TMPDIR property in a
  spawn-like call's env: object literal) not accompanied by TEMP and TMP
  in the same scope. Node's os.tmpdir() never reads TMPDIR on Windows.
  Registered on tests/**/*.cjs, matching the require-userprofile-with-home
  precedent.

- local/no-unbounded-dirname-walk: flags a while/do-while loop reassigning
  from dirname() with no fixed-point termination guard
  (dirname(cur) !== cur, or path.parse(cur).root). path.dirname() is a
  no-op at the platform root, but the value differs by platform
  (win32 'D:\' is length 3, posix '/' is length 1), so a POSIX-shaped
  length/equality bound never fires on Windows. Registered on BOTH
  tests/**/*.cjs and scripts/**/*.cjs — the real #4020 bug lived in
  scripts/run-tests.cjs, not tests/.

Both rules join the zero-escape-hatch discipline already established for
this catalog (no bespoke comment marker; PROTECTED_RULES in
tests/portability-rule-disable-ban.test.cjs independently bans
eslint-disable of either). ADR-1703 and its two companion contributing
docs get an amendment documenting the mechanism, code examples, and the
repo-wide sweep (three live instances found and fixed in the prior
commit; no others found). CI test-scope selection updated so an edit to
either rule or to scripts/run-tests.cjs re-runs the right suites.

* fix(#4244): no-unbounded-dirname-walk must analyze a single-condition loop test too

checkWhile bailed out early unless node.test was a LogicalExpression,
so a single-condition loop -- while (cur !== root) { cur = dirname(cur); } --
was silently skipped and never reported. That is the EXACT minimal
shape of the original #4020/#4220 bug, and it is literally the shape
used by this rule's own shipped RuleTester fixtures (the "equality-only
bound" invalid cases), which were failing (0 errors reported, 1
expected) until this fix -- confirmed by running RuleTester directly
against both fixtures, not just via a passing test-runner exit code.

The conjunct-collection helper already handled a non-LogicalExpression
test correctly (it pushes a single node as the sole conjunct); only the
early-return gate needed to stop requiring a compound && / || test.

Verified: RuleTester run directly against both previously-broken
fixtures plus two new sanity cases (a guarded single-condition loop
stays valid; an unrelated single-condition loop stays silent), and a
fresh `npx eslint .` across the whole repo remains clean (no other
single-condition dirname-walk shape exists in the tree).

* fix(#4244): require-full-tmpdir-triad must recognize a destructured child_process call

isSpawnLikeCallee only recognized a MemberExpression callee
(child_process.spawnSync(...)) or a bare identifier in
ENV_LOCAL_HELPER_NAMES (runNode). A destructured import called bare --
const { spawnSync } = require('child_process'); spawnSync(...) -- has an
Identifier callee named "spawnSync", which matched neither branch, so
the whole env-literal check was skipped. gsd-test caught this: both
"invalid: child_process.spawnSync with TMPDIR-only env" cases in
tests/require-full-tmpdir-triad.rule.test.cjs were failing (0 errors
reported, 1 expected).

Widened the bare-identifier branch to also match any of the known
ENV_CHILD_PROCESS_METHODS names, matched by name only -- the same
lightweight convention this repo's other eslint-rules/*.cjs use (e.g.
no-hardcoded-tmp.cjs's isFsMethodCall), not full import data-flow
tracing.

Verified: RuleTester run directly against all 11 cases in
tests/require-full-tmpdir-triad.rule.test.cjs (not just the two that
were failing), all pass; a fresh npx eslint . and npm run lint:ci
across the whole repo remain clean.

* fix(#4244): correct a stale escape-hatch reference in a test comment

The comment on the "length comparison against another expression's
length" case referenced a "// allow-dirname-walk marker" that doesn't
exist -- the rule has zero comment-based escape hatches by design
(ADR-1703), and an earlier draft's marker mechanism was removed before
this branch's first commit. Spec-axis review caught the stale
reference. No behavior change; comment-only.

* chore(#4244): backfill changeset PR number (pr:0 -> pr:4246)

---------

Co-authored-by: sim <sim@local>
2026-09-03 14:14:09 -04:00

208 lines
6.2 KiB
JavaScript

'use strict';
/**
* no-unbounded-dirname-walk.rule.test.cjs
*
* RuleTester unit tests for the local/no-unbounded-dirname-walk ESLint rule.
*
* Rule: flag a while/do-while loop that reassigns its condition variable
* from path.dirname() without a fixed-point termination guard
* (DEFECT.WINDOWS-TEST-PORTABILITY, the #4020 / #4220 Windows CI hang:
* path.win32.dirname() is a no-op at the drive root, so a length- or
* equality-only bound spins forever there).
*/
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const { RuleTester } = require('eslint');
const rule = require('../eslint-rules/no-unbounded-dirname-walk.cjs');
const ruleTester = new RuleTester({
languageOptions: {
ecmaVersion: 2022,
sourceType: 'commonjs',
},
});
describe('no-unbounded-dirname-walk rule module', () => {
test('exports a create function and the unboundedWalk message', () => {
assert.strictEqual(typeof rule.create, 'function');
assert.strictEqual(rule.meta.type, 'problem');
assert.ok(rule.meta.messages.unboundedWalk, 'unboundedWalk message must exist');
});
});
describe('no-unbounded-dirname-walk: invalid — no fixed-point guard', () => {
test('invalid: the real #4020/#4220 shape — length-bounded walk against a POSIX-only sentinel', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [],
invalid: [
{
// The exact shipped shape: on Windows the repo is on D:\, the target
// root on C:\ — `cur !== runTempRoot` holds forever and win32
// dirname('D:\\') is a fixed point, so this spins at 100% CPU.
code: `
const { dirname } = require('path');
const protectSet = new Set();
let cur = f;
while (cur && cur !== runTempRoot && cur.length > 1) {
protectSet.add(cur);
cur = dirname(cur);
}
`,
errors: [{ messageId: 'unboundedWalk' }],
},
],
});
});
test('invalid: destructured dirname with equality-only bound', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [],
invalid: [
{
code: `
const { dirname } = require('path');
let cur = file;
while (cur !== root) {
cur = dirname(cur);
}
`,
errors: [{ messageId: 'unboundedWalk' }],
},
],
});
});
test('invalid: path.dirname member form with equality-only bound', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [],
invalid: [
{
code: `
const path = require('path');
let cur = file;
while (cur !== root) {
cur = path.dirname(cur);
}
`,
errors: [{ messageId: 'unboundedWalk' }],
},
],
});
});
test('invalid: do-while form with no fixed-point guard', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [],
invalid: [
{
code: `
const path = require('path');
let cur = file;
do {
cur = path.dirname(cur);
} while (cur !== root && cur.length > 1);
`,
errors: [{ messageId: 'unboundedWalk' }],
},
],
});
});
});
describe('no-unbounded-dirname-walk: valid — fixed-point guard present', () => {
test('valid: the real fixed shape — dirname(cur) !== cur added to the condition', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [
{
code: `
const { dirname } = require('path');
const protectSet = new Set();
let cur = f;
while (cur && cur !== runTempRoot && dirname(cur) !== cur) {
protectSet.add(cur);
cur = dirname(cur);
}
`,
},
],
invalid: [],
});
});
test('valid: walk bounded via path.parse(cur).root', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [
{
code: `
const path = require('path');
let cur = file;
while (cur && cur !== path.parse(cur).root) {
cur = path.dirname(cur);
}
`,
},
],
invalid: [],
});
});
test('valid: a length-only bound is still unsafe in principle, but the fixed-point conjunct present here silences it', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [
{
code: `
const { dirname } = require('path');
let cur = file;
while (cur && cur.length > 1 && dirname(cur) !== cur) {
cur = dirname(cur);
}
`,
},
],
invalid: [],
});
});
test('valid: not a dirname walk at all — a linked-list traversal must stay silent', () => {
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [
{
code: `
let cur = list.head;
while (cur && cur.length > 1) { cur = cur.next; }
`,
},
],
invalid: [],
});
});
test('invalid: a length comparison against another expression\'s length is still unguarded — no fixed-point conjunct present', () => {
// Confirms the rule does not special-case a dynamic (non-literal) length
// bound as an implicit guard: only an explicit fixed-point conjunct
// silences it. This rule has NO comment-marker escape hatch (ADR-1703
// zero-escape-hatch) — a loop shaped like this needs an added
// `dirname(cur) !== cur` (or `path.parse(cur).root`) conjunct; there is
// no annotation-based way to silence it instead.
ruleTester.run('no-unbounded-dirname-walk', rule, {
valid: [],
invalid: [
{
code: `
let cursor = path.dirname(path.resolve(target));
const stop = path.resolve(root);
while (cursor.length >= stop.length && cursor.startsWith(stop)) {
if (check(cursor)) return true;
cursor = path.dirname(cursor);
}
`,
errors: [{ messageId: 'unboundedWalk' }],
},
],
});
});
});