* fix(#4250): distinguish a timed-out npm audit from a JSON parse failure npm-audit-baseline.cjs's runPackageLockAudit, and the near-identical auditProductionVulns helper in npm-integrity-gate.test.cjs, both grabbed e.stdout whenever an npm audit child process exited non-zero -- without checking whether the process was actually killed by its 180s timeout. A timeout-killed process's stdout is truncated mid-write, not complete JSON, so JSON.parse threw a misleading "Unexpected end of JSON input" instead of naming npm's registry timeout as the real cause. Root-caused live during a CI investigation: npm's own status page reported degraded service, and the registry's bulk-advisories endpoint was returning 503/hanging, causing npm audit to sit until the timeout fired. Adds a shared isTimeoutKill(error) predicate (checks execFileSync's documented killed/signal fields) and checks it first in both catch blocks, throwing a clear, actionable error before ever reaching JSON.parse. The pre-existing "non-zero exit with complete JSON" recovery path is unchanged and still covered by regression tests. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore(#4250): add changeset for npm-audit timeout fix Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#4250): share the timeout-kill error message and cover auditProductionVulns Two independent review passes (standards + spec) on the first commit found real gaps: the timeout-kill error message was duplicated verbatim between runPackageLockAudit and the near-identical auditProductionVulns helper in tests/npm-integrity-gate.test.cjs (this repo's own Generative Fix Divergence anti-pattern -- shared logic across parallel surfaces with no parity check), and auditProductionVulns picked up the same production fix with zero test coverage of its own. Extracts buildTimeoutKillError(cwd), used by both callers so the message cannot independently drift. Gives auditProductionVulns the same injectable execFileSyncImpl seam runPackageLockAudit already had, and adds the matching regression tests (timeout-kill throws the clear error; the pre-existing non-zero-exit-with-complete-JSON path still recovers correctly). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore(#4250): backfill changeset PR number to #4251 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * diag(#4250): surface captured stderr in the timeout-kill error The killed child process's stderr is buffered in-memory by execFileSync and attached to the thrown error, but nothing surfaced it -- the timeout message named the timeout but discarded the one piece of data that could show WHY npm was still running when it fired (DNS stall, TLS handshake stall, a registry-side retry loop, all look identical without it). buildTimeoutKillError now takes the killed error and includes its stderr (or an explicit 'no stderr was captured' note) in the message. This is a diagnostic improvement for the next CI occurrence, not a behavior fix -- local reproduction has directly ruled out npm version (installed the exact CI-bundled 11.17.0 and ran it against this repo: 0.49s, clean), general npm registry reachability (0.4-1.4s locally, repeatedly), and npm ci speed (2m, succeeded) as explanations for the 180s CI hangs. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#4260): bounded retry with backoff for npm audit calls, finish the extraction The audit backend has real, independent latency variance from the rest of the npm registry -- measured (see #4260): a bulk-advisories POST took 43.41s vs 0.20s for a plain registry fetch on the same host, and the same endpoint returned no response at all (000) twice in the same window, while status.npmjs.org reported fully operational throughout. Against that, runPackageLockAudit and its near-duplicate auditProductionVulns each made exactly one attempt with no retry -- any single bad moment failed a REQUIRED CI gate on a transport hiccup, not a real advisory. Replaces the single 180s attempt with runNpmAuditWithRetry: up to 3 attempts at 60s each (comfortably above the worst measured working latency) with exponential backoff between them. Only a confirmed timeout-kill is retried; a genuine non-timeout failure still fails immediately, and exhausting all attempts still fails the gate -- per #4260's own caveat, silently disarming a required security check on a transport error is worse than occasionally re-running CI. Also finishes the extraction #4260 flagged as stopped halfway: auditProductionVulns (tests/npm-integrity-gate.test.cjs) duplicated runPackageLockAudit's entire candidate loop, recovery branch, and timeout classification, differing only in npm args and precondition check. It is now a thin wrapper delegating to the newly-exported runInstalledTreeAudit, which shares runNpmAuditWithRetry with runPackageLockAudit -- one implementation instead of two that could independently drift. buildTimeoutKillError now reports attempt count and still surfaces captured stderr from the last kill. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore(#4260): update changeset for retry/backoff scope Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * test(#4260): budget for two sequential retry-audit calls, close coverage gaps Two review passes on the retry/backoff commit found real gaps: - TEST_TIMEOUT_MS budgeted only one retry-audit call's worst case (210s), but checkTreeAgainstBaseline makes two sequential calls (HEAD tree via auditProductionVulns, baseline tree via runPackageLockAudit) -- combined worst case is ~372s. If both genuinely exhausted retries, node:test's own timeout would fire first and mask buildTimeoutKillError's clear message, undercutting #4250's own fix in that edge case. Recomputed using the same backoff formula the production code uses, so it can't independently drift. - buildTimeoutKillError's default-attempts(1) singular-phrasing branch had zero direct test coverage (nothing calls it with a single attempt anymore) -- a real mutation-testing risk. Added direct tests for both phrasing branches plus the no-error-object case. - runInstalledTreeAudit's null-guard skip paths (missing package.json, missing node_modules) had no tests, unlike runPackageLockAudit's matching paths. Added for parity. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: sim <sim@local> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
503 lines
20 KiB
JavaScript
503 lines
20 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Unit tests for scripts/npm-audit-baseline.cjs (#4196).
|
|
*
|
|
* Covers the pure diff/verdict functions directly, plus the git-object-level
|
|
* extraction and env-driven ref resolution using real throwaway git fixture
|
|
* repos (no network, no real npm registry round-trip -- runPackageLockAudit
|
|
* is only exercised here for its filesystem-only skip conditions).
|
|
*/
|
|
|
|
const { test, describe, beforeEach, afterEach } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const path = require('node:path');
|
|
const { execFileSync } = require('node:child_process');
|
|
|
|
const {
|
|
AUDIT_DIFF_REASON,
|
|
diffNewVulnerablePackages,
|
|
evaluateAuditDiff,
|
|
runPackageLockAudit,
|
|
runInstalledTreeAudit,
|
|
runNpmAuditWithRetry,
|
|
extractBaselineTree,
|
|
resolveBaselineRef,
|
|
isTimeoutKill,
|
|
buildTimeoutKillError,
|
|
AUDIT_BACKOFF_BASE_MS,
|
|
NULL_SHA,
|
|
} = require('../scripts/npm-audit-baseline.cjs');
|
|
|
|
const { createTempDir, cleanup } = require('./helpers.cjs');
|
|
|
|
const GIT_TIMEOUT_MS = 30_000;
|
|
|
|
function git(args, cwd) {
|
|
return execFileSync('git', args, {
|
|
cwd,
|
|
encoding: 'utf-8',
|
|
stdio: ['ignore', 'pipe', 'pipe'],
|
|
timeout: GIT_TIMEOUT_MS,
|
|
}).trim();
|
|
}
|
|
|
|
/**
|
|
* Builds a throwaway git repo with one commit containing package.json +
|
|
* package-lock.json (and optionally under a subdir), returning
|
|
* { dir, commitSha }.
|
|
*/
|
|
function makeCommittedFixtureRepo(t, { subdir = '', pkgContent = '{"name":"fixture"}', lockContent = '{"lockfileVersion":3}' } = {}) {
|
|
const dir = createTempDir('gsd-audit-baseline-fixture-');
|
|
t.after(() => cleanup(dir));
|
|
git(['init', '-q'], dir);
|
|
git(['config', 'user.email', 'test@example.com'], dir);
|
|
git(['config', 'user.name', 'Test'], dir);
|
|
const targetDir = subdir ? path.join(dir, subdir) : dir;
|
|
fs.mkdirSync(targetDir, { recursive: true });
|
|
fs.writeFileSync(path.join(targetDir, 'package.json'), pkgContent);
|
|
fs.writeFileSync(path.join(targetDir, 'package-lock.json'), lockContent);
|
|
git(['add', '-A'], dir);
|
|
git(['commit', '-q', '-m', 'fixture commit'], dir);
|
|
const commitSha = git(['rev-parse', 'HEAD'], dir);
|
|
return { dir, commitSha };
|
|
}
|
|
|
|
// ─── diffNewVulnerablePackages ────────────────────────────────────────────
|
|
|
|
describe('diffNewVulnerablePackages', () => {
|
|
test('empty baseline + empty head -> []', () => {
|
|
assert.deepStrictEqual(diffNewVulnerablePackages({}, {}), []);
|
|
});
|
|
|
|
test('baseline and head share the same packages -> [] (nothing new)', () => {
|
|
const baseline = { a: {}, b: {} };
|
|
const head = { a: {}, b: {} };
|
|
assert.deepStrictEqual(diffNewVulnerablePackages(baseline, head), []);
|
|
});
|
|
|
|
test('head adds a package not in baseline -> only the addition', () => {
|
|
const baseline = { a: {} };
|
|
const head = { a: {}, b: {} };
|
|
assert.deepStrictEqual(diffNewVulnerablePackages(baseline, head), ['b']);
|
|
});
|
|
|
|
test('empty baseline, head has one package -> that package', () => {
|
|
assert.deepStrictEqual(diffNewVulnerablePackages({}, { a: {} }), ['a']);
|
|
});
|
|
|
|
test('packages removed from head (present in baseline only) are not "new"', () => {
|
|
const baseline = { a: {}, b: {}, c: {} };
|
|
const head = { a: {} };
|
|
assert.deepStrictEqual(diffNewVulnerablePackages(baseline, head), []);
|
|
});
|
|
|
|
test('baseline and head both undefined -> [] (must not throw)', () => {
|
|
assert.deepStrictEqual(diffNewVulnerablePackages(undefined, undefined), []);
|
|
});
|
|
});
|
|
|
|
// ─── evaluateAuditDiff ─────────────────────────────────────────────────────
|
|
|
|
describe('evaluateAuditDiff', () => {
|
|
test('no new packages -> ok:true with OK_NO_NEW_VULNERABILITIES and preExisting list', () => {
|
|
const baselineVulnerabilities = { a: {} };
|
|
const headVulnerabilities = { a: {} };
|
|
const result = evaluateAuditDiff({ baselineVulnerabilities, headVulnerabilities });
|
|
assert.deepStrictEqual(result, {
|
|
ok: true,
|
|
reason: AUDIT_DIFF_REASON.OK_NO_NEW_VULNERABILITIES,
|
|
preExisting: ['a'],
|
|
});
|
|
});
|
|
|
|
test('one new package -> ok:false with FAIL_NEW_VULNERABLE_PACKAGE and exact newlyIntroduced', () => {
|
|
const baselineVulnerabilities = { a: {} };
|
|
const headVulnerabilities = { a: {}, b: {} };
|
|
const result = evaluateAuditDiff({ baselineVulnerabilities, headVulnerabilities });
|
|
assert.strictEqual(result.ok, false);
|
|
assert.strictEqual(result.reason, AUDIT_DIFF_REASON.FAIL_NEW_VULNERABLE_PACKAGE);
|
|
assert.deepStrictEqual(result.newlyIntroduced, ['b']);
|
|
});
|
|
|
|
test('multiple new packages -> all listed', () => {
|
|
const baselineVulnerabilities = {};
|
|
const headVulnerabilities = { a: {}, b: {}, c: {} };
|
|
const result = evaluateAuditDiff({ baselineVulnerabilities, headVulnerabilities });
|
|
assert.strictEqual(result.ok, false);
|
|
assert.deepStrictEqual(result.newlyIntroduced.sort(), ['a', 'b', 'c']);
|
|
});
|
|
});
|
|
|
|
// ─── resolveBaselineRef ─────────────────────────────────────────────────────
|
|
|
|
describe('resolveBaselineRef', () => {
|
|
const envKeys = ['AUDIT_BASELINE_REF', 'GITHUB_BASE_REF', 'GITHUB_EVENT_NAME'];
|
|
let originalEnv;
|
|
|
|
beforeEach(() => {
|
|
originalEnv = Object.fromEntries(envKeys.map((key) => [key, process.env[key]]));
|
|
for (const key of envKeys) delete process.env[key];
|
|
});
|
|
|
|
afterEach(() => {
|
|
for (const key of envKeys) {
|
|
if (originalEnv[key] === undefined) delete process.env[key];
|
|
else process.env[key] = originalEnv[key];
|
|
}
|
|
});
|
|
|
|
test('AUDIT_BASELINE_REF set -> returned verbatim, highest priority even with others set', (t) => {
|
|
const { dir } = makeCommittedFixtureRepo(t);
|
|
process.env.AUDIT_BASELINE_REF = 'some/explicit-ref';
|
|
process.env.GITHUB_BASE_REF = 'next';
|
|
process.env.GITHUB_EVENT_NAME = 'push';
|
|
assert.strictEqual(resolveBaselineRef(dir), 'some/explicit-ref');
|
|
});
|
|
|
|
test('AUDIT_BASELINE_REF unset, GITHUB_BASE_REF=next -> origin/next', (t) => {
|
|
const { dir } = makeCommittedFixtureRepo(t);
|
|
process.env.GITHUB_BASE_REF = 'next';
|
|
assert.strictEqual(resolveBaselineRef(dir), 'origin/next');
|
|
});
|
|
|
|
test('neither set, push event, HEAD~1 resolves -> returns that parent sha', (t) => {
|
|
const dir = createTempDir('gsd-audit-baseline-fixture-');
|
|
t.after(() => cleanup(dir));
|
|
git(['init', '-q'], dir);
|
|
git(['config', 'user.email', 'test@example.com'], dir);
|
|
git(['config', 'user.name', 'Test'], dir);
|
|
fs.writeFileSync(path.join(dir, 'a.txt'), 'first');
|
|
git(['add', '-A'], dir);
|
|
git(['commit', '-q', '-m', 'first commit'], dir);
|
|
fs.writeFileSync(path.join(dir, 'a.txt'), 'second');
|
|
git(['add', '-A'], dir);
|
|
git(['commit', '-q', '-m', 'second commit'], dir);
|
|
|
|
// Compute expected parent sha independently, not via resolveBaselineRef.
|
|
const expectedParentSha = git(['rev-parse', 'HEAD~1'], dir);
|
|
|
|
process.env.GITHUB_EVENT_NAME = 'push';
|
|
assert.strictEqual(resolveBaselineRef(dir), expectedParentSha);
|
|
});
|
|
|
|
test('NULL_SHA is the documented all-zeros 40-char sentinel', () => {
|
|
assert.strictEqual(NULL_SHA, '0'.repeat(40));
|
|
assert.strictEqual(NULL_SHA.length, 40);
|
|
});
|
|
|
|
test('push event but only one commit (HEAD~1 does not exist) falls through without choking', (t) => {
|
|
const dir = createTempDir('gsd-audit-baseline-fixture-');
|
|
t.after(() => cleanup(dir));
|
|
git(['init', '-q'], dir);
|
|
git(['config', 'user.email', 'test@example.com'], dir);
|
|
git(['config', 'user.name', 'Test'], dir);
|
|
fs.writeFileSync(path.join(dir, 'a.txt'), 'only');
|
|
git(['add', '-A'], dir);
|
|
git(['commit', '-q', '-m', 'only commit'], dir);
|
|
|
|
process.env.GITHUB_EVENT_NAME = 'push';
|
|
// No origin/next remote-tracking ref exists in this throwaway repo, so
|
|
// this must fall all the way through to ''.
|
|
assert.strictEqual(resolveBaselineRef(dir), '');
|
|
});
|
|
|
|
test('no origin/next, but a plain local branch named next exists -> returns "next"', (t) => {
|
|
const dir = createTempDir('gsd-audit-baseline-fixture-');
|
|
t.after(() => cleanup(dir));
|
|
git(['init', '-q'], dir);
|
|
git(['config', 'user.email', 'test@example.com'], dir);
|
|
git(['config', 'user.name', 'Test'], dir);
|
|
fs.writeFileSync(path.join(dir, 'a.txt'), 'first');
|
|
git(['add', '-A'], dir);
|
|
git(['commit', '-q', '-m', 'first commit'], dir);
|
|
// rename the default branch to "next" so it's a plain LOCAL branch, not
|
|
// a remote-tracking origin/next ref -- mirrors gsd-test's sandbox shape.
|
|
git(['branch', '-M', 'next'], dir);
|
|
|
|
process.env.GITHUB_EVENT_NAME = 'push';
|
|
assert.strictEqual(resolveBaselineRef(dir), 'next');
|
|
});
|
|
|
|
test('nothing resolves at all (no env vars, not a git repo) -> returns ""', (t) => {
|
|
const dir = createTempDir('gsd-audit-baseline-nongit-');
|
|
t.after(() => cleanup(dir));
|
|
assert.strictEqual(resolveBaselineRef(dir), '');
|
|
});
|
|
});
|
|
|
|
// ─── extractBaselineTree ─────────────────────────────────────────────────────
|
|
|
|
describe('extractBaselineTree', () => {
|
|
test('extracts package.json + package-lock.json at root from a real commit', (t) => {
|
|
const pkgContent = JSON.stringify({ name: 'root-fixture' });
|
|
const lockContent = JSON.stringify({ lockfileVersion: 3, name: 'root-fixture' });
|
|
const { dir, commitSha } = makeCommittedFixtureRepo(t, { pkgContent, lockContent });
|
|
|
|
const extracted = extractBaselineTree(commitSha, dir);
|
|
assert.notStrictEqual(extracted, null);
|
|
t.after(() => cleanup(extracted));
|
|
|
|
assert.strictEqual(fs.readFileSync(path.join(extracted, 'package.json'), 'utf-8'), pkgContent);
|
|
assert.strictEqual(fs.readFileSync(path.join(extracted, 'package-lock.json'), 'utf-8'), lockContent);
|
|
});
|
|
|
|
test('extracts package.json + package-lock.json from a subdir', (t) => {
|
|
const pkgContent = JSON.stringify({ name: 'sdk-fixture' });
|
|
const lockContent = JSON.stringify({ lockfileVersion: 3, name: 'sdk-fixture' });
|
|
const { dir, commitSha } = makeCommittedFixtureRepo(t, { subdir: 'sdk', pkgContent, lockContent });
|
|
|
|
const extracted = extractBaselineTree(commitSha, dir, 'sdk');
|
|
assert.notStrictEqual(extracted, null);
|
|
t.after(() => cleanup(extracted));
|
|
|
|
assert.strictEqual(fs.readFileSync(path.join(extracted, 'package.json'), 'utf-8'), pkgContent);
|
|
assert.strictEqual(fs.readFileSync(path.join(extracted, 'package-lock.json'), 'utf-8'), lockContent);
|
|
});
|
|
|
|
test('a ref that does not exist -> null', (t) => {
|
|
const { dir } = makeCommittedFixtureRepo(t);
|
|
const bogusSha = 'f'.repeat(40);
|
|
assert.strictEqual(extractBaselineTree(bogusSha, dir), null);
|
|
});
|
|
|
|
test('ref exists but package-lock.json was never committed at that ref -> null', (t) => {
|
|
const dir = createTempDir('gsd-audit-baseline-nolock-');
|
|
t.after(() => cleanup(dir));
|
|
git(['init', '-q'], dir);
|
|
git(['config', 'user.email', 'test@example.com'], dir);
|
|
git(['config', 'user.name', 'Test'], dir);
|
|
fs.writeFileSync(path.join(dir, 'package.json'), '{"name":"nolock"}');
|
|
git(['add', '-A'], dir);
|
|
git(['commit', '-q', '-m', 'no lockfile'], dir);
|
|
const sha = git(['rev-parse', 'HEAD'], dir);
|
|
|
|
assert.strictEqual(extractBaselineTree(sha, dir), null);
|
|
});
|
|
});
|
|
|
|
// ─── runPackageLockAudit (filesystem-only skip conditions, no registry) ────
|
|
|
|
describe('runPackageLockAudit', () => {
|
|
test('missing package.json -> null', () => {
|
|
const dir = createTempDir('gsd-audit-baseline-empty-');
|
|
try {
|
|
assert.strictEqual(runPackageLockAudit(dir), null);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('package.json present but no package-lock.json -> null', () => {
|
|
const dir = createTempDir('gsd-audit-baseline-nolock2-');
|
|
try {
|
|
fs.writeFileSync(path.join(dir, 'package.json'), '{"name":"nolock2"}');
|
|
assert.strictEqual(runPackageLockAudit(dir), null);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ─── runInstalledTreeAudit (filesystem-only skip conditions, no registry) ──
|
|
|
|
describe('runInstalledTreeAudit', () => {
|
|
test('missing package.json -> null', () => {
|
|
const dir = createTempDir('gsd-audit-installed-empty-');
|
|
try {
|
|
assert.strictEqual(runInstalledTreeAudit(dir), null);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
|
|
test('package.json present but no node_modules -> null', () => {
|
|
const dir = createTempDir('gsd-audit-installed-nomodules-');
|
|
try {
|
|
fs.writeFileSync(path.join(dir, 'package.json'), '{"name":"nomodules"}');
|
|
assert.strictEqual(runInstalledTreeAudit(dir), null);
|
|
} finally {
|
|
cleanup(dir);
|
|
}
|
|
});
|
|
});
|
|
|
|
// ─── isTimeoutKill ───────────────────────────────────────────────────────────
|
|
|
|
describe('isTimeoutKill', () => {
|
|
test('killed: true -> true', () => {
|
|
assert.strictEqual(isTimeoutKill({ killed: true }), true);
|
|
});
|
|
|
|
test('signal set (e.g. SIGTERM) -> true', () => {
|
|
assert.strictEqual(isTimeoutKill({ signal: 'SIGTERM' }), true);
|
|
});
|
|
|
|
test('both killed and signal set -> true', () => {
|
|
assert.strictEqual(isTimeoutKill({ killed: true, signal: 'SIGTERM' }), true);
|
|
});
|
|
|
|
test('neither killed nor signal set (normal non-zero exit) -> false', () => {
|
|
assert.strictEqual(isTimeoutKill({ killed: false, signal: null, status: 1, stdout: '{}' }), false);
|
|
});
|
|
|
|
test('killed: false explicitly -> false', () => {
|
|
assert.strictEqual(isTimeoutKill({ killed: false }), false);
|
|
});
|
|
|
|
test('null/undefined error -> false, does not throw', () => {
|
|
assert.strictEqual(isTimeoutKill(null), false);
|
|
assert.strictEqual(isTimeoutKill(undefined), false);
|
|
});
|
|
|
|
test('plain object with no killed/signal keys at all -> false', () => {
|
|
assert.strictEqual(isTimeoutKill({}), false);
|
|
});
|
|
});
|
|
|
|
// ─── buildTimeoutKillError ───────────────────────────────────────────────────
|
|
|
|
describe('buildTimeoutKillError', () => {
|
|
test('default attempts (1) uses singular ms-based phrasing, not "N attempts"', () => {
|
|
const err = buildTimeoutKillError('/some/dir', { stderr: 'some stderr text' });
|
|
assert.match(err.message, /npm audit timed out after \d+ms/);
|
|
assert.doesNotMatch(err.message, /attempts/);
|
|
assert.match(err.message, /some stderr text/);
|
|
});
|
|
|
|
test('attempts > 1 uses plural "N attempts" phrasing with backoff mention', () => {
|
|
const err = buildTimeoutKillError('/some/dir', { stderr: '' }, 3);
|
|
assert.match(err.message, /npm audit timed out after 3 attempts/);
|
|
assert.match(err.message, /exponential backoff/);
|
|
});
|
|
|
|
test('no error object at all still produces a message, no crash', () => {
|
|
const err = buildTimeoutKillError('/some/dir', undefined);
|
|
assert.match(err.message, /npm audit timed out after \d+ms/);
|
|
assert.match(err.message, /no stderr was captured/);
|
|
});
|
|
});
|
|
|
|
// ─── runPackageLockAudit -- timeout-kill classification (#4250) ─────────────
|
|
|
|
describe('runPackageLockAudit — timeout-kill retry classification (#4250, #4260)', () => {
|
|
function makeFixtureDir(t) {
|
|
const dir = createTempDir('gsd-audit-baseline-timeout-');
|
|
t.after(() => cleanup(dir));
|
|
fs.writeFileSync(path.join(dir, 'package.json'), '{"name":"fixture"}');
|
|
fs.writeFileSync(path.join(dir, 'package-lock.json'), '{"lockfileVersion":3}');
|
|
return dir;
|
|
}
|
|
|
|
function makeKilledError() {
|
|
return Object.assign(new Error('command timed out'), {
|
|
killed: true,
|
|
signal: 'SIGTERM',
|
|
stdout: '{"auditReportVersion":2,"vulnerabi', // deliberately truncated, non-empty
|
|
stderr: 'npm http fetch GET 200 https://registry.npmjs.org/-/npm/v1/security/advisories/bulk (attempt 1) 178234ms',
|
|
});
|
|
}
|
|
|
|
test('a timeout-killed execFileSync call on every attempt throws a clear timeout error after exhausting retries, not a JSON parse error', (t) => {
|
|
const dir = makeFixtureDir(t);
|
|
const execFileSyncImpl = () => { throw makeKilledError(); };
|
|
const sleepImpl = () => {};
|
|
|
|
assert.throws(
|
|
() => runPackageLockAudit(dir, { execFileSyncImpl, sleepImpl }),
|
|
(err) => {
|
|
assert.match(err.message, /npm audit timed out after \d+ attempts/);
|
|
assert.match(err.message, /status\.npmjs\.org/);
|
|
assert.doesNotMatch(err.message, /Unexpected end of JSON input/);
|
|
assert.match(err.message, /Captured stderr before the last kill/);
|
|
assert.match(err.message, /npm http fetch GET/);
|
|
return true;
|
|
},
|
|
);
|
|
});
|
|
|
|
test('a timeout-killed call with no captured stderr still produces a clear message (no crash on missing stderr)', (t) => {
|
|
const dir = makeFixtureDir(t);
|
|
const killedError = Object.assign(new Error('command timed out'), {
|
|
killed: true,
|
|
signal: 'SIGTERM',
|
|
// no stdout, no stderr at all
|
|
});
|
|
const execFileSyncImpl = () => { throw killedError; };
|
|
const sleepImpl = () => {};
|
|
|
|
assert.throws(
|
|
() => runPackageLockAudit(dir, { execFileSyncImpl, sleepImpl }),
|
|
(err) => {
|
|
assert.match(err.message, /npm audit timed out after \d+ attempts/);
|
|
assert.match(err.message, /no stderr was captured/);
|
|
return true;
|
|
},
|
|
);
|
|
});
|
|
|
|
test('retry recovers: timeouts on the first attempts followed by a successful final attempt succeeds', (t) => {
|
|
const dir = makeFixtureDir(t);
|
|
const completeJson = JSON.stringify({ metadata: { vulnerabilities: { high: 0 } }, vulnerabilities: {} });
|
|
let calls = 0;
|
|
const execFileSyncImpl = () => {
|
|
calls += 1;
|
|
if (calls < 3) throw makeKilledError();
|
|
return completeJson;
|
|
};
|
|
const sleepImpl = () => {};
|
|
|
|
const result = runPackageLockAudit(dir, { execFileSyncImpl, sleepImpl });
|
|
assert.deepStrictEqual(result.metadata.vulnerabilities, { high: 0 });
|
|
assert.strictEqual(calls, 3);
|
|
});
|
|
|
|
test('a normal non-zero exit with complete stdout JSON still recovers correctly (no regression)', (t) => {
|
|
const dir = makeFixtureDir(t);
|
|
const completeJson = JSON.stringify({ metadata: { vulnerabilities: { high: 1 } }, vulnerabilities: { foo: {} } });
|
|
const nonZeroExitError = Object.assign(new Error('npm audit found vulnerabilities'), {
|
|
status: 1,
|
|
stdout: completeJson,
|
|
});
|
|
const execFileSyncImpl = () => { throw nonZeroExitError; };
|
|
|
|
const result = runPackageLockAudit(dir, { execFileSyncImpl });
|
|
assert.deepStrictEqual(result.metadata.vulnerabilities, { high: 1 });
|
|
});
|
|
|
|
test('a real successful call (no throw) still works via the injected impl', (t) => {
|
|
const dir = makeFixtureDir(t);
|
|
const completeJson = JSON.stringify({ metadata: { vulnerabilities: {} }, vulnerabilities: {} });
|
|
const execFileSyncImpl = () => completeJson;
|
|
|
|
const result = runPackageLockAudit(dir, { execFileSyncImpl });
|
|
assert.deepStrictEqual(result.metadata.vulnerabilities, {});
|
|
});
|
|
});
|
|
|
|
// ─── runNpmAuditWithRetry — backoff timing (#4260) ──────────────────────────
|
|
|
|
describe('runNpmAuditWithRetry — backoff timing (#4260)', () => {
|
|
test('a timeout-then-recover attempt sequence sleeps once with the base backoff value', (t) => {
|
|
const dir = createTempDir('gsd-audit-baseline-backoff-');
|
|
t.after(() => cleanup(dir));
|
|
const completeJson = JSON.stringify({ metadata: { vulnerabilities: {} }, vulnerabilities: {} });
|
|
let calls = 0;
|
|
const execFileSyncImpl = () => {
|
|
calls += 1;
|
|
if (calls === 1) {
|
|
throw Object.assign(new Error('command timed out'), { killed: true, signal: 'SIGTERM' });
|
|
}
|
|
return completeJson;
|
|
};
|
|
const sleepCalls = [];
|
|
const sleepImpl = (ms) => sleepCalls.push(ms);
|
|
|
|
const parsed = runNpmAuditWithRetry(dir, ['audit', '--json'], { execFileSyncImpl, sleepImpl });
|
|
|
|
assert.deepStrictEqual(parsed.metadata.vulnerabilities, {});
|
|
assert.deepStrictEqual(sleepCalls, [AUDIT_BACKOFF_BASE_MS * 1]);
|
|
});
|
|
});
|