Files
msd-core/tests/lockfile-cve-audit.test.cjs
Tom Boucher 5b5d473e13 chore(#3465): remove 22 verified-vestigial allow-test-rule markers (#3494)
Phase 1 of #3464. Removes the `// allow-test-rule:` marker from 22 test files
where it is provably vestigial, and tightens the ratchet ceiling in
scripts/lint-allow-test-rule-refs.ceiling.json from 305 to 285.

Eligibility is decided by two independent AST discriminators, both
conservative (any doubt => keep):

(a) Read-target type. Every readFileSync/readFile call in the file resolves
    statically to a prose/config extension (.md/.json/.yml/.yaml/.toml/.txt),
    or the file performs no reads at all. Any read of a source extension
    (.cjs/.js/.mjs/.ts/.cts/.mts/.jsx/.tsx), any dynamic/unresolvable path,
    and any other extension all disqualify the file.

(b) Marker context. Every `allow-test-rule:` occurrence is a genuine comment
    node, never string- or template-literal payload. A marker that lives
    inside a RuleTester `code:` fixture is test DATA, not a suppression
    directive; stripping it corrupts the test. tests/eslint-rules.test.cjs is
    the one such fixture host and is deliberately untouched.

An earlier attempt at this phase classified markers by "strip it and see if
local/no-source-grep still passes" and was reverted in full before commit.
That oracle is unsound: the rule only fires on a literal .cjs/.js/.ts path
containing a quoted bin/lib/gsd-core/src segment, tracked one hop from the
binding, so files that genuinely source-grep real JavaScript pass it
silently -- tests/no-unbounded-spawn-allowlist.test.cjs (reads test sources
through a listTestFiles() walk) and tests/claude-imperative-reference.test.cjs
(matches bin/install.js through an intermediate variable) both cleared it
while being real source-greps. The rule's implementation is narrower than its
intent, so it cannot adjudicate whether an exemption is load-bearing.

Scope is limited to comment deletions: the diff over the test tree is 100%
line removals with zero insertions, and no executable line is altered.

On the ceiling value. The measured count at this HEAD is 283, so 285 leaves 2
slack -- deliberate, and well inside the documented grace band of 3. Pinning
the ceiling to the exact count makes this change effectively unmergeable: any
concurrent PR that lands one marker-bearing test file re-reds it. That race
fired twice while preparing this branch (once mid-rebase taking the count
304->305 on next, once between rebase and the verification run taking it
282->283), and it is the same race that broke next in #3461. A ceiling of
actual+2 preserves a merge window while still ratcheting 305 -> 285.

Known limit, disclosed rather than papered over: this clears 22 of 303
markers and does not reach #3464's trend-to-zero goal. Most of the remaining
markers sit on dynamic-path reads, commonly a hoisted `const p =
path.join(tmpDir, 'STATE.md')` whose target is prose but is unresolvable to
this classifier. A stricter one-hop const resolution would flip an estimated
95 more; that is deliberately left to a follow-up so it can be reviewed on
its own evidence.

Marker discovery reads bytes rather than shelling out to grep:
tests/security-prompt-injection.security.test.cjs carries a literal NUL byte
(an intentional injection fixture) that makes grep treat it as binary and skip
it, which is why the true marked-file count is 303 and not the 302 a shell
scan reports.

Closes #3465

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-14 13:10:49 -04:00

99 lines
5.3 KiB
JavaScript

'use strict';
// Regression guard for #2765: the lockfile must pin the patched brace-expansion
// versions (>=1.1.18 for the 1.x line, >=5.0.9 for the 5.x line) published 2026-07-30
// to resolve the high-severity DoS/OOM advisories (GHSA-3jxr-9vmj-r5cp /
// GHSA-mh99-v99m-4gvg, range <=5.0.7). This is a lockfile-only devDependency bump
// (eslint/stryker → minimatch → brace-expansion); production (npm audit --omit=dev) is
// unaffected. The test pins the installed versions so the bump can't silently regress.
//
// Regression guard for #3238: the lockfile must also pin a patched js-yaml (>=4.3.1 on
// the 4.x line, >=3.15.1 on the 3.x line) to resolve GHSA-5p4m-2wfm-xmqj — a
// high-severity (CVSS 7.5, CWE-407) quadratic-CPU DoS in `!!omap` resolution,
// vulnerable range `>=4.0.0 <4.3.1`. `!!omap` is in the DEFAULT schema, so a plain
// yaml.load() is affected. This is a lockfile-only devDependency bump (direct, plus
// an @eslint/eslintrc dedupe); production (npm audit --omit=dev) was already clean.
// The test pins every installed copy so the bump can't silently regress. Folded into
// this file (originally tests/issue-3238-js-yaml-lockfile.test.cjs) because it is the
// same shape of lockfile CVE-pin regression test for a different package/CVE; it
// shares the ROOT/npmLs/NPM_LS_TIMEOUT_MS helpers below rather than duplicating them.
const { test } = require('node:test');
const assert = require('node:assert/strict');
const { execFileSync } = require('node:child_process');
const path = require('node:path');
const ROOT = path.join(__dirname, '..');
// `npm` is not process.execPath, git, or a bash script/hook, so this does not
// route through tests/helpers/process-seam.cjs (whose runNode/runGit/runHook
// primitives cover exactly those three shapes and forward no `shell` option)
// — `npm` needs `shell: true` on Windows (npm.cmd), which the seam has no
// surface for. Bounding this directly with an explicit `timeout` is the
// documented alternative in eslint-rules/no-unbounded-spawn.cjs.
const NPM_LS_TIMEOUT_MS = 30000;
function npmLs(pkg) {
// `npm ls <pkg> --json --all` lists every installed copy with its version. Collect
// the version of every node whose key is `pkg` (not the parent packages).
const out = execFileSync('npm', ['ls', pkg, '--json', '--all'], {
cwd: ROOT, encoding: 'utf8', shell: true, stdio: ['ignore', 'pipe', 'ignore'],
timeout: NPM_LS_TIMEOUT_MS,
});
const versions = [];
const walk = (node) => {
if (!node || !node.dependencies) return;
for (const [k, v] of Object.entries(node.dependencies)) {
if (k === pkg && v && v.version) versions.push(v.version);
walk(v);
}
};
walk(JSON.parse(out));
return versions;
}
test('all installed brace-expansion copies are patched (>=1.1.18 / >=5.0.9) — #2765', () => {
const versions = npmLs('brace-expansion');
assert.ok(versions.length > 0, 'brace-expansion must be installed (devDependency) to guard');
for (const v of versions) {
const [maj, min, pat] = v.split('.').map(Number);
const ok = (maj === 1 && (min > 1 || (min === 1 && pat >= 18))) // 1.x >= 1.1.18
|| (maj === 5 && (min > 0 || pat >= 9)) // 5.x >= 5.0.9
|| (maj > 5); // >5.x
assert.ok(ok,
`brace-expansion@${v} is within the vulnerable range (<=5.0.7) — lockfile regressed the #2765 patch bump. ` +
'Re-apply: npm audit fix (non-breaking) to bump to 1.1.18 / 5.0.9.');
}
});
// GHSA-5p4m-2wfm-xmqj names only the 3.x (<3.15.1) and 4.x (<4.3.1) lines. The SAME
// weakness in the 5.x line is CVE-2026-59870 / GHSA-724g-mxrg-4qvm, fixed in 5.2.1 —
// so a guard against this bug CLASS must require 5.2.1 there too rather than waving
// every 5.x through, or an accidental major bump to 5.0.0 would reintroduce the exact
// quadratic `!!omap` resolution this test exists to prevent.
function isPatchedJsYaml(version) {
const core = String(version).split('+')[0]; // drop build metadata
// A prerelease of the patched version (e.g. 4.3.1-beta.1) sorts BELOW it in semver
// and may predate the fix — fail closed rather than guess.
if (core.includes('-')) return false;
const [maj, min, pat] = core.split('.').map(Number);
if (![maj, min, pat].every(Number.isInteger)) return false; // unparseable — fail closed
if (maj < 3) return true; // predates the affected lines
if (maj === 3) return min > 15 || (min === 15 && pat >= 1); // 3.x >= 3.15.1
if (maj === 4) return min > 3 || (min === 3 && pat >= 1); // 4.x >= 4.3.1
if (maj === 5) return min > 2 || (min === 2 && pat >= 1); // 5.x >= 5.2.1 (CVE-2026-59870)
return true; // >5.x
}
test('all installed js-yaml copies are patched (>=4.3.1 / >=3.15.1 / >=5.2.1) — #3238', () => {
const versions = npmLs('js-yaml');
// Vacuity guard: an empty list would make every assertion below trivially true.
assert.ok(versions.length > 0, 'js-yaml must be installed (devDependency) to guard');
for (const v of versions) {
assert.ok(isPatchedJsYaml(v),
`js-yaml@${v} is not a patched version — the quadratic \`!!omap\` resolution bug is ` +
'present in 3.x <3.15.1 (GHSA-5p4m-2wfm-xmqj), 4.x <4.3.1 (same), and 5.x <5.2.1 ' +
'(CVE-2026-59870). Re-apply: npm install js-yaml@^4.3.1');
}
});