* test(#3148): bound the long tail and delete the allowlist Migrates the final 170 unbounded sync spawn sites across 49 files, then removes the allowlist entirely. local/no-unbounded-spawn now runs with no exemption surface across tests/**: there is no file to add a name to. drift-detection's throw-native git() helper routes to gitOrThrow -- bare runGit would have taken 16 call sites quiet on failure. commands.test.cjs has two independently-scoped runGsdTools/runCli helpers, one already bounded and one not; they are kept distinct rather than unified, the same trap as the two same-named git() helpers in Wave 1. runNpm's bound was erasable. Its options spread callerOptions after the defaults, so an explicit timeout:undefined silently dropped the 180000ms bound -- the rule flagged it and was right; it was not a false positive. Fixed by destructuring with a default, with a test that fails when the default is removed. Two sites stay on a raw spawn with an explicit timeout because the seam cannot express them: one needs shell:true for npm.cmd on Windows, one redirects stdout to a real fd. Both are the rule's own documented second option, not an escape from it. Closure verified rather than asserted: the derivation scan reports 0 unbounded spawn helpers and 0 unbounded direct git call sites, and a temporary file carrying an unbounded spawn still errors with the allowlist gone. Closes #3064. * test(#3148): close a hole in the guard's own eslint-disable ban The ban listed only the top level of tests/, so it was blind to 37 .cjs files under tests/helpers, qa, observability, fixtures and dispatch. With the allowlist deleted this test is the sole remaining way to detect someone silencing the rule inline, so the gap was load-bearing: a nested file could carry an unbounded spawn plus an eslint-disable and pass everything. Proven before and after. A probe planted under tests/helpers with both was invisible to the guard and clean under eslint; after making the listing recursive the guard fails on it. The scanned set goes from 771 files to 808. Pre-existing since the guard shipped, but this wave is what promoted it to sole defense, so it is fixed here rather than filed. Also converts the last hand-rolled throw check to throwIfFailed and the last re-derived legacy shape to compose toLegacyResult, which makes the epic's none-remain claim true rather than nearly true. toLegacyResult itself is not widened -- eight callers depend on its shape and one consumer does not justify changing a shared contract. * fix(#3148): correct seam incoherence at the bound and a slow review-lane error path Two real failures from the remote runner, both fixed at the cause. The seam could return outcome TIMED_OUT together with exitCode 0. At the exact bound spawnSync reports ETIMEDOUT while the child has already exited with a real status, and toSeamResult classified on the error code while passing status straight through -- an incoherent pair its own boundary test was written to catch, and did. A status that is not null is direct evidence the child exited on its own, so it now decides the outcome before the error-code branches run. process-seam.cjs was deliberately untouched by every earlier wave; this is a defect in the module itself, kept surgical, with a unit test that fails against the old logic. review-lane with an unknown subcommand fell through to its usage error only after loading the capability registry and building a per-lane plan, which spawns one child process per lane -- up to twelve. The error path took ~1288ms instead of ~119ms, and under bench load it outran a caller's spawn timeout and was killed before writing anything, which is the empty stdout and stderr CI saw. It now fails fast before any of that work begins. This is the epic's first production change. It is user-facing, so it carries a changeset rather than a no-changelog label. * test(#3148): replace a real-race timeout test with a deterministic one E9 raced git rev-parse against a 1ms bound and assumed git always lost. On a warm container git finishes first, spawnSync returns status 0 with no error at all, the seam correctly classifies EXITED, and gitOrThrow correctly does not throw -- so the test failed on both lanes. A probe confirms a genuine timeout always carries status null, so this was never the seam misbehaving. Raising the bound would only lengthen the odds, which is the same defect with better luck. The test now drives gitOrThrow against a stubbed runGit that returns a synthetic TIMED_OUT result, so it asserts exactly what it always meant to -- that a timeout propagates as a throw -- with no timing dependence. Five consecutive runs are identical where the old one varied. I wrote this test in Wave 0; it is a real-race test by construction and CLAUDE.md says to replace those rather than re-run them. * chore(#3148): backfill changeset PR number 3192 --------- Co-authored-by: sim <sim@local>
191 lines
8.8 KiB
JavaScript
191 lines
8.8 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* Regression test for #2657.
|
|
*
|
|
* Nine compiled `.cjs` artifacts under gsd-core/bin/lib/ were tracked in git
|
|
* despite each having a matching src/*.cts source, violating ADR-457's
|
|
* build-at-publish contract ("bin/lib/*.cjs" must be a gitignored build
|
|
* artifact, never checked-in source of truth). A tracked compiled artifact
|
|
* can silently drift from its source without anyone noticing — #2653
|
|
* demonstrated exactly this for api-coverage.cjs, which shipped four days
|
|
* behind its .cts with CI green throughout.
|
|
*
|
|
* This asserts the ADR-457 end state for all nine: none tracked, all
|
|
* gitignored, and the regime-agnostic sync guard (added in #2656,
|
|
* scripts/lint-compiled-artifact-sync.cjs) reports the empty tracked set.
|
|
*
|
|
* Two of the nine (markdown-table.cjs, write-set.cjs) already had a
|
|
* .gitignore pattern before this fix (added by #2248) but were never
|
|
* `git rm --cached`; the other seven had no .gitignore pattern at all. Both
|
|
* gaps produce the same `git ls-files` symptom, so both are covered by the
|
|
* same assertions here.
|
|
*
|
|
* ── Diagnostics discipline ────────────────────────────────────────────────
|
|
* Every git invocation below uses `spawnSync` (never throws) and every
|
|
* assertion explicitly checks the exit status BEFORE interpreting output.
|
|
* A git command that errors (bad cwd, dubious-ownership refusal, missing
|
|
* binary, anything) must never be silently read as a legitimate "not
|
|
* ignored" / "still tracked" answer — that conflates "the property does not
|
|
* hold" with "I could not determine whether the property holds", which is a
|
|
* distinct defect from the bug this file guards against. On any failure,
|
|
* the assertion message includes the resolved cwd, exit status, and stderr,
|
|
* so a red run is self-diagnosing without a second round-trip.
|
|
*/
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const path = require('node:path');
|
|
const { runGit, runNode, OUTCOME } = require('./helpers/process-seam.cjs');
|
|
const { toLegacyResult } = require('./helpers/git-fixture.cjs');
|
|
const { PROBE_TIMEOUT_MS } = require('./helpers/timeouts.cjs');
|
|
|
|
const { trackedCompiledArtifacts } = require('../scripts/lint-compiled-artifact-sync.cjs');
|
|
|
|
const REPO_ROOT = path.join(__dirname, '..');
|
|
const LIB_DIR = 'gsd-core/bin/lib';
|
|
|
|
const NINE_ARTIFACTS = [
|
|
'api-coverage.cjs',
|
|
'assumption-delta.cjs',
|
|
'claude-orchestration-command-router.cjs',
|
|
'claude-orchestration.cjs',
|
|
'external-job.cjs',
|
|
'markdown-table.cjs',
|
|
'runtime-artifact-install-plan.cjs',
|
|
'state-transition.cjs',
|
|
'write-set.cjs',
|
|
].map((name) => `${LIB_DIR}/${name}`);
|
|
|
|
/**
|
|
* Run a command via the process seam (never throws) and return a legacy
|
|
* `{status, stdout, stderr, signal}` shape. `cmd` is either `'git'` (routed
|
|
* through `runGit`) or `process.execPath` (routed through `runNode`) — the
|
|
* only two callers below. Throws immediately, with full context, only on a
|
|
* genuine spawn failure (binary not found, etc.) — a condition no caller
|
|
* here can meaningfully interpret as a match/no-match answer.
|
|
*/
|
|
function run(cmd, args, opts) {
|
|
const options = { cwd: REPO_ROOT, timeoutMs: PROBE_TIMEOUT_MS, ...opts };
|
|
const result = cmd === 'git' ? runGit(args, options) : runNode(args, options);
|
|
if (result.outcome === OUTCOME.SPAWN_FAILED) {
|
|
throw new Error(
|
|
`${cmd} ${args.join(' ')} failed to spawn (cwd=${REPO_ROOT}): ${result.stderr || result.code}`,
|
|
);
|
|
}
|
|
return { ...toLegacyResult(result), signal: result.signal };
|
|
}
|
|
|
|
/** Render a failed command's full context for an assertion message. */
|
|
function describeFailure(cmd, args, result) {
|
|
return (
|
|
`${cmd} ${args.join(' ')} (cwd=${REPO_ROOT}) exited ${result.status}` +
|
|
(result.signal ? ` (signal ${result.signal})` : '') +
|
|
`\n stderr: ${(result.stderr || '(empty)').trim()}` +
|
|
`\n stdout: ${(result.stdout || '(empty)').trim()}`
|
|
);
|
|
}
|
|
|
|
function git(args) {
|
|
// -c safe.directory=REPO_ROOT: containerized CI checkouts are frequently
|
|
// owned by a different uid than the one running node --test, and git
|
|
// refuses to operate at all on such a repo ("detected dubious ownership")
|
|
// unless explicitly trusted. Scoped per-invocation (not written to any
|
|
// config file), matching the same fix applied to
|
|
// scripts/lint-compiled-artifact-sync.cjs's own git() helper, which has
|
|
// the identical defect (#2657 diagnostic run: `git ls-files` there failed
|
|
// with the same "dubious ownership" fatal in the runner).
|
|
return run('git', ['-c', `safe.directory=${REPO_ROOT}`, ...args]);
|
|
}
|
|
|
|
/** `git ls-files <LIB_DIR>`, asserting success before trusting the output. */
|
|
function trackedLibFiles() {
|
|
const args = ['ls-files', LIB_DIR];
|
|
const result = git(args);
|
|
assert.equal(
|
|
result.status,
|
|
0,
|
|
`git ls-files must exit 0 before its output can be trusted as "nothing tracked":\n${describeFailure('git', args, result)}`,
|
|
);
|
|
return new Set(result.stdout.split('\n').filter(Boolean));
|
|
}
|
|
|
|
/**
|
|
* `git check-ignore -q <path>` has exactly two legitimate outcomes: exit 0
|
|
* (ignored) and exit 1 (not ignored) — check-ignore(1). Any other exit code
|
|
* or a signal is an infrastructure failure, not a "not ignored" answer, and
|
|
* must not be conflated with one.
|
|
*/
|
|
function isIgnored(artifactPath) {
|
|
const args = ['check-ignore', '-q', artifactPath];
|
|
const result = git(args);
|
|
if (result.status === 0) return true;
|
|
if (result.status === 1) return false;
|
|
throw new Error(
|
|
`git check-ignore for ${artifactPath} returned neither a match (0) nor a legitimate ` +
|
|
`no-match (1) exit code — this is an infrastructure failure, not evidence the path ` +
|
|
`is unignored:\n${describeFailure('git', args, result)}`,
|
|
);
|
|
}
|
|
|
|
// Shared shape for both "none of the nine should still be in state X" checks
|
|
// below: derive the still-bad subset via `isBad`, then assert it's empty.
|
|
function assertNoneStillBad(isBad, failureLabel) {
|
|
const stillBad = NINE_ARTIFACTS.filter(isBad);
|
|
assert.deepEqual(
|
|
stillBad,
|
|
[],
|
|
`expected none of the nine ${failureLabel}; still: ${stillBad.join(', ') || '(none)'}`,
|
|
);
|
|
}
|
|
|
|
describe('fix-2657: compiled .cjs artifacts are gitignored, not tracked (ADR-457)', () => {
|
|
test('none of the nine ADR-457 migration-gap artifacts are tracked by git', () => {
|
|
const tracked = trackedLibFiles();
|
|
assertNoneStillBad((p) => tracked.has(p), 'to be tracked');
|
|
});
|
|
|
|
test('every one of the nine paths is ignored per git', () => {
|
|
// Deliberately WITHOUT --no-index: git-check-ignore(1) operates on the
|
|
// pathname alone and does not require the file to exist on disk (true
|
|
// both with and without --no-index — this repo's gsd-test runner checks
|
|
// out a fresh shallow clone per sha, where an untracked, gitignored path
|
|
// exists as a pattern match only, never as a file on disk). Plain
|
|
// check-ignore is preferred here over --no-index specifically because it
|
|
// also honors git's "a still-TRACKED path is never reported ignored"
|
|
// rule (check-ignore(1)) — which is exactly the property under test: a
|
|
// path that still matches a .gitignore pattern while ALSO remaining
|
|
// tracked (the pre-fix state for two of the nine, whose pattern
|
|
// predates this fix per #2248) must still read as "not ignored," the
|
|
// same as the seven with no pattern at all. --no-index would blur that
|
|
// distinction by reporting the two as ignored regardless of tracking.
|
|
assertNoneStillBad((p) => !isIgnored(p), 'to be reported not-ignored by git');
|
|
});
|
|
|
|
test('trackedCompiledArtifacts() reports the ADR-457 empty-set end state for the nine', () => {
|
|
let pairs;
|
|
try {
|
|
pairs = trackedCompiledArtifacts();
|
|
} catch (err) {
|
|
// trackedCompiledArtifacts() (scripts/lint-compiled-artifact-sync.cjs)
|
|
// wraps its OWN internal `git ls-files gsd-core/bin/lib` call, with cwd
|
|
// resolved from that script's own __dirname (should equal REPO_ROOT
|
|
// here regardless of caller). A throw means THAT invocation failed —
|
|
// not that any artifact is still tracked. Surface it, don't mask it.
|
|
assert.fail(
|
|
`trackedCompiledArtifacts() threw instead of returning a result — this indicates its ` +
|
|
`internal git invocation failed, not that any of the nine is still tracked:\n` +
|
|
`${err && err.stack ? err.stack : err}`,
|
|
);
|
|
}
|
|
const stillPresentArtifacts = new Set(pairs.map((p) => p.artifact));
|
|
assertNoneStillBad((p) => stillPresentArtifacts.has(p), 'to appear in trackedCompiledArtifacts()');
|
|
});
|
|
|
|
test('lint-compiled-artifact-sync exits 0 with nothing left to check', () => {
|
|
const args = [path.join(REPO_ROOT, 'scripts', 'lint-compiled-artifact-sync.cjs')];
|
|
const result = run(process.execPath, args);
|
|
assert.equal(result.status, 0, describeFailure(process.execPath, args, result));
|
|
});
|
|
});
|