* test(#4641): failing-first tests for the tier ceiling and a single Windows selector Tests only, committed ahead of the implementation so the RED run is real. - tests/platform-conformance-tier.test.cjs: tier-size ceiling asserted as a ratio against a live denominator (Windows 33%, macOS 25%); per-helper negative cases proving seam calls and path-call-plus-slash-literal are not platform signals; positive pins that genuine platform content, seam-bypassing spawns, chmod and symlink still classify in; macOS signal set and generated list unchanged. - tests/ci-full-lane-sharding.test.cjs: the test job has zero windows-latest rows and test-conformance still has 3 windows + 1 macOS. - tests/ci-test-scope.test.cjs: windows_tests is absent rather than empty, a non-tier test file no longer forces full_matrix, a RULE-pulled windows-hint test does, and resolveSelection rejects the retired windows scope. Refs #4589, #4591, #4592, #4593, #4603 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#4641): delete the second Windows selector and narrow the conformance tier Epic #4589's goal — the OS-agnostic bulk on Linux, a small explicitly-scoped conformance tier on real Windows/macOS — was not met. Measured on PR #4640 (run 34618834118): 7 non-Linux jobs, a 546/930 (58.7%) "tier", and 5 of 7 changed test files running on a real Windows runner twice. Two selectors, only one in the epic's scope. The test job's three scope:windows shards predate the epic (#494, sharded #3057) and gate on product_changed, not full_matrix, so they fire on every product PR whatever Phase 3's classifier decides. They are deleted; test-conformance becomes the sole Windows selector, as it already was for macOS. Non-Linux jobs 7 -> 4. Gating the lane instead was rejected as provably redundant: for a test file reachesConformanceTierOrSeam is literally CONFORMANCE_TIER_FILES.includes(file), and that same predicate sets full_matrix, which turns test-conformance on. Every file a gated lane would run is already covered in the same run. The lane's one non-redundant residue -- RULE-pulled tests matched by the isWindowsHint filename heuristic -- is ported into reachesConformanceTierOrSeam so it sets full_matrix instead of feeding a parallel lane. Two detectors matched the repo's own test idiom rather than any platform signal and carried 226 of the tier's sole-signal membership against 41 for the other eight: process-seam-subprocess (335 files, 118 unique) matches the tests/helpers.cjs entry points nearly every CLI test uses, and going through the seam is the opposite of a platform signal since shell-command-projection takes platform as an injected parameter; hardcoded-path-vs-path-call (328, 108) needs only a path call anywhere plus a slash literal anywhere, and that class is already enforced by ADR-1703's Linux-runnable ESLint rules. Both are removed. Tier 546 -> 254 (27.3%). src/ reachability is unchanged at 28 files, measured. Adds the size gate Phase 2 never had, as a ratio against a live denominator so it cannot stop binding as the suite grows. 292 files leave real-OS Windows execution. The drop-out set was audited: 14 have a platform-suggestive filename and all 14 are static source-text analyses or seam-mediated CLI tests. raw-child-process was investigated as a suspected false negative and left unchanged -- relaxing it adds 13 files, all false positives. macOS is untouched: MACOS_CATEGORIES is a separate array and the regenerated macos-conformance-tier.generated.cjs is byte-identical at 196 files. Fixes #4641 Refs #4589, #4591, #4592, #4593, #4603 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#4641): register the new ADR path in the docs-guard exempt baseline tests/ci-test-scope.test.cjs references docs/adr/4641-windows-selector-consolidation.md in a comment justifying the retired windows scope; lint-docs-guard-registration tracks that reference set, so the baseline needs the new path. Verified the exemption still holds: the path is prose, not a filesystem read. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#4641): make the escalation tier-backed and drop every hardcoded count Three follow-ups from measuring the first pass rather than trusting it. The windows-hint escalation now requires tier membership as well as the filename hint. Setting full_matrix runs test-conformance, which runs only the tier; escalating on a test that is NOT in the tier costs four jobs and still never runs that test on Windows. Measured over the 16 RULES entries the narrowed predicate fires on exactly the same rules today, so this is correct-by-construction rather than a behavior change. The broader variant -- escalate on any tier member a rule pulls in, ignoring the hint -- was measured at 14/16 rules and rejected as over-broad. Removes the hardcoded counts. A hardcoded macOS tier length of 196 broke as soon as the rebase pulled in one new test file from #4253, which is the whole argument against them: the ceilings are ratios against a live denominator, the committed lists are pinned by comparison against a fresh classification of the live tree, and the three named probe files now assert on their SIGNAL rather than on membership in a literal list -- asserting by filename is the exact error this PR fixes in the classifier. Regenerates both lists against the rebased tree. Same-tree figures are now 547 -> 255 of 931 eligible (58.8% -> 27.4%), 292 entries removed and none added; macOS is unchanged at 197 with a zero-line diff. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#4641): restore real-shell-spawn coverage and repair assertions the narrowing broke An isolated adversarial review found a real false negative. Removing the blanket process-seam-subprocess detector also removed the only coverage for tests that spawn a REAL shell: tests/helpers/process-seam.cjs's runHook spawns options.interpreter via real spawnSync, so runHook('-c', [script], { interpreter: 'bash' }) runs a real bash binary executing a shell script extracted from workflow markdown. The seam argument holds for src/shell-command-projection.cts, which takes platform as an injected parameter; it does NOT hold for the test helpers, which spawn real binaries. Conflating the two is what made the blanket detector look purely noisy -- it was 99% noise wrapping a real signal. Adds a narrow shell-interpreter-spawn category keyed on a real interpreter option. Measured 2026-09-11: 33 files match, 9 were outside the tier and are added back, taking it 255 -> 264 of 931 (27.4% -> 28.4%), still under the 33% ceiling. All 9 confirmed by reading the matching source line, zero comment or fixture matches. runGit-alone and non-node-spawnSeam alternatives were measured and rejected -- each adds 9 files but misses the counterexample entirely. Fixes a real bug the suite caught: jobs.test is ubuntu-only now that its scope:windows rows are gone, so it must wire GSD_STRICT_LIVE_CONFIG_GUARD strictly rather than carrying the Windows report-only carve-out. The carve-out now lives solely on test-conformance, whose matrix does include windows. Repairs seven pre-existing assertions the category removal invalidated, preserving each case's purpose rather than deleting coverage, and converts the last hardcoded tier bounds to live-derived ratios -- including the macOS sanity range that was still a magic [100, 350]. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#4641): keep the confinement test on a real OS via a documented allowlist A security review found tests/external-descriptor-confinement.test.cjs had dropped out of the Windows tier. It must stay in, and no content signal can express why: it exercises isPathConfined (src/external-descriptor-trust.cts), which uses the AMBIENT path module -- path.resolve(root, target) and path.sep -- with no injection. Its win32 semantics (drive letters, UNC, separator) are only reachable by actually running on Windows, and it is a security-relevant write-confinement gate. A content classifier cannot see 'this module reads the ambient path module', so no regex belongs here. Adds ALWAYS_REAL_OS, a Map of path -> recorded reason, unioned into the Windows tier only. A Map rather than a list so an entry without a reason is impossible by construction, and tests assert every entry names a file that exists on disk so a stale entry fails loudly instead of rotting. This is the centrally- enumerated single source of truth epic #4589 Phase 2 asked for and ADR-1703's portability-vocab.cjs already models -- deliberately not a heuristic. Windows tier 264 -> 265 of 931 (28.5%), still under the 33% ceiling. macOS is untouched and byte-identical: the win32 concern does not apply to a POSIX runner, and a test asserts the allowlist does not leak into that tier. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#4641): inject the path impl into isPathConfined and correct the ADR count Two review findings, both fixed rather than dispositioned. A security review found tests/external-descriptor-confinement.test.cjs had left real-OS execution. The allowlist pinned it back, but that only restored INCIDENTAL coverage: isPathConfined used the ambient path module, and its test carried POSIX-only literals, so a win32 confinement escape was unverified on every platform including Windows. isPathConfined now takes an optional third parameter carrying the path implementation, defaulting to the ambient module. Blast radius is CRITICAL -- 53 affected symbols across 19 files -- so the change is purely additive and every existing two-argument caller is byte-identical. Tests now inject path.win32 and path.posix, covering a different drive letter, a cross-drive absolute, backslash and forward-slash traversal, UNC, and the startsWith prefix-boundary bug (.gsdEVIL against root .gsd) on both separators. Proved load-bearing: dropping the + p.sep from the prefix check fails exactly the two boundary cases and nothing else. Callers' suites 149/149. The spec review caught an off-by-one: the ADR narrated a 264-file tier while the committed list holds 265. The ADR now records the full chain 547 -> 255 -> 264 -> 265 (28.5%). Also corrects a stale comment in scripts/docs-guard-registry.cjs that narrated classify() as zeroing windows_tests, a key this change removes -- kept as historical narration but labelled as such. Refs #4641 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(#131): make the unwritable-HOME test actually test something Found by sweeping for the root-bypass class after fixing commit-files-deletion. This one is the silent variant, and it was broken twice over. First, the condition: the test made a fake HOME unwritable with chmod 0o500. The gsd-test Docker bench runs as root, root bypasses mode bits, so HOME stayed writable and the hostile condition never existed. Replaced with a HOME whose PARENT is a regular file, so every write under it fails ENOTDIR at the VFS layer for every uid -- no permission check is involved at all. Second, and more fundamental: the probe was npm --version, which on npm 11.19.0 performs zero filesystem I/O against HOME. Proven rather than assumed -- neutralizing runNpm()'s isolation turned the sibling test red while this one stayed green, so its assertion could never detect the regression it guards, on any uid, with or without the condition fix. npm config get cache was tried next and proved vacuous the same way (it only string-resolves the path). The probe is now npm cache verify, which really does mkdir _cacache under HOME. Re-proved load-bearing after the change: with isolation neutralized the test now fails with ENOTDIR on <blocker>/home/.npm/_cacache. tests/helpers.cjs was restored and verified diff-clean; suite 13/13. Refs #4641 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): correct the net drop-out figure in ADR-4641 The Consequences section still said 292 files leave real-OS Windows execution. That was the count before the narrow shell-interpreter-spawn replacement restored 9 and ALWAYS_REAL_OS pinned 1. Net is 282. Also names both real-binary categories rather than only raw-child-process, and clarifies that the 14-file filename audit was against the 292 initially dropped. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): record the rejected concentration ceiling and its measurement Applying Goodhart's own question to the new ceiling -- how would you make this metric look good without improving what it represents -- surfaces a real weakness: a ratio can be satisfied by inflating the denominator, so adding OS-agnostic tests loosens it without narrowing the tier. The obvious companion gate was a sole-signal concentration ceiling, since the original defect was one detector carrying half the tier. Measured and rejected: peak concentration post-fix is raw-child-process at 53/265 = 20.0%, against the historic offenders at 21.6% and 19.8%. Any threshold above 20% misses the original defect; any threshold below it fails on a legitimate category. The discriminator is whether a signal is platform-meaningful, which no threshold encodes. Weakness disclosed rather than covered by a gate that does not bind. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * chore(#4641): add the changeset fragment for the confinement-check change changeset-lint failed on PR #4643: the PR touches user-facing paths and carried no fragment. The earlier no-changeset call matched #4604's CI-only precedent and was correct then; it was not revisited once the PR grew a src/ change, which is my miss. The fragment describes the real user-visible improvement: the external-descriptor write-confinement check's Windows semantics are now verified deterministically rather than only when the suite happened to run on Windows. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): correct the tier count in TESTING-SUITES.md Said the tier narrowed from 546 to 254. The final committed list is 265 of 931 eligible (58.8% -> 28.5%) after the shell-interpreter-spawn replacement restored 9 files and ALWAYS_REAL_OS pinned 1. Same error class the spec review caught in the ADR, in a live reference page rather than a dated record, so it states the current truth rather than carrying an amendment note. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): record the measured aggregate from real CI job lists Epic #4589's closeout asserted its reduction from a static count; #4641's acceptance criterion asks for a figure read off a real run. Recorded here: test.yml job count 21 -> 15 and non-Linux 7 -> 4, comparing PR #4640's run against this PR's own. Against the true pre-epic baseline of 9, that is 9 -> 4. Also states the caveat that a PR's total CHECK count is not a clean before/after comparison, since many gates are path-scoped and this change touches a broader path set -- the like-for-like figure is the test.yml job count. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): compare job totals the same way on both sides The measured-aggregate table put #4640's COMPLETED run total (21) against this run's count at matrix-expansion time (15). Those are not the same measurement: the completed total includes the post-test Coverage gate and baseline-publisher jobs. Counted identically, it is 21 -> 17. The load-bearing figure, non-Linux jobs 7 -> 4, was correct and is unchanged. Called out in the table rather than silently corrected -- comparing two differently-derived numbers is exactly the error class this ADR is about. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): record measured conformance wall-clock and date the stale counterfactual Adds the per-job durations from both runs. The honest read is that this is a correctness win more than a speed one: file count fell 52% but wall-clock only 9-29%, because what was removed were the cheap static tests and what remains is concentrated in expensive spawn-heavy work. Stated explicitly so nobody expects a future narrowing to buy time proportional to file count. The load-bearing figure is windows shard 3/3: 40m24s against a 45-minute cap on the 547-file tier -- 90% of the cliff #869 and #3057 were both filed about -- pulled back to 31m27s. macOS moved the wrong way (17m48s -> 21m02s) while its tier was UNCHANGED at 197 files, which fixes that as runner variance and is noted as a caution against reading a single duration as signal. Also dates the symlink-keyword counterfactual, which cited a 254-file tier from before the replacement category and allowlist took it to its final 265. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * docs(#4641): re-measure against the rebased tree and disclose the allowlist's zero next gained #4644 mid-flight, so every absolute count shifted. Re-measured on the tree this actually ships against (932 eligible): 548 -> 257 by detector removal, 257 -> 266 once shell-interpreter-spawn restores 9. Net 282 removed, 9 restored. macOS 198, unchanged by this PR. The percentages did not move across three rebases (58.8% -> 28.5%), which is the whole argument for expressing the ceilings as ratios rather than counts -- noted in the ADR since it is now evidence rather than assertion. Also discloses that ALWAYS_REAL_OS now contributes ZERO files: this PR's own win32 test cases introduced the literal win32 into the pinned file, so it classifies in on content via win32-darwin-literal. The entry stays and the reason is written down, because the file's real-OS need is a property of the code under test (isPathConfined reads the ambient path module), not of the test's text -- the text that currently saves it is incidental and could be refactored away silently. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> --------- Co-authored-by: sim <sim@local> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
740 lines
32 KiB
JavaScript
740 lines
32 KiB
JavaScript
#!/usr/bin/env node
|
||
'use strict';
|
||
|
||
const path = require('path');
|
||
const { execFileSync } = require('child_process');
|
||
const { existsSync, readdirSync, appendFileSync, readFileSync } = require('fs');
|
||
|
||
const { ExitError, runMain } = require('./lib/cli-exit.cjs');
|
||
const { classifyContent, NOISY_FOR_SOURCE_REACHABILITY } = require('./gen-platform-conformance-tier.cjs');
|
||
|
||
// Workflow files that are purely administrative / policy bots. Changes to these
|
||
// files do NOT require the cross-platform test matrix — only a lightweight
|
||
// ubuntu lane running workflow-lint tests is needed.
|
||
// FAIL-SAFE: any .github/workflows/*.yml NOT listed here is treated as a
|
||
// pipeline workflow and gets the full matrix. New workflow files default to full.
|
||
const INERT_WORKFLOWS = new Set([
|
||
'stale.yml',
|
||
'branch-cleanup.yml',
|
||
'branch-naming.yml',
|
||
'auto-label-issues.yml',
|
||
'auto-branch.yml',
|
||
'auto-backmerge.yml',
|
||
'close-draft-prs.yml',
|
||
'dismiss-unauthorized-pr-approvals.yml',
|
||
'pr-target-validator.yml',
|
||
'pr-template-format.yml',
|
||
'require-issue-link.yml',
|
||
'changeset-required.yml',
|
||
'docs-required.yml',
|
||
'discord-changelog.yml',
|
||
]);
|
||
|
||
// Workflows that gate merges, ship the product, or run security/cross-platform
|
||
// suites — these must ALWAYS get the full pipeline treatment and can never be
|
||
// added to INERT_WORKFLOWS. A module-load assertion enforces this so a mistaken
|
||
// or malicious addition fails CI loudly in the `changes` job on every PR.
|
||
const PROTECTED_WORKFLOWS = new Set([
|
||
'test.yml',
|
||
'install-smoke.yml',
|
||
'mutation.yml',
|
||
'security-scan.yml',
|
||
'release.yml',
|
||
// #3833: the reusable gate every `pull_request` compute lane depends on —
|
||
// marking it inert would let a change to the gate itself ship without ever
|
||
// running the full matrix it is responsible for enforcing.
|
||
'pr-mergeable-preflight.yml',
|
||
]);
|
||
for (const wf of PROTECTED_WORKFLOWS) {
|
||
if (INERT_WORKFLOWS.has(wf)) {
|
||
throw new Error(`ci-test-scope: protected workflow "${wf}" must not be in INERT_WORKFLOWS (it requires the full test matrix).`);
|
||
}
|
||
}
|
||
|
||
/**
|
||
* Returns true if the path is an inert (non-pipeline) workflow file.
|
||
* Only `.github/workflows/<name>` where <name> is in INERT_WORKFLOWS qualifies.
|
||
*/
|
||
function isInertCi(filePath) {
|
||
if (!filePath.startsWith('.github/workflows/')) return false;
|
||
const name = filePath.slice('.github/workflows/'.length);
|
||
// Must be a direct child (no further slashes) and in the allowlist.
|
||
return !name.includes('/') && INERT_WORKFLOWS.has(name);
|
||
}
|
||
|
||
// Tests shared by both the 'workflow automation' and 'inert CI' rules.
|
||
const WORKFLOW_LINT_TESTS = [
|
||
'tests/workflow-shell-pinning.test.cjs',
|
||
'tests/pr-template-policy.test.cjs',
|
||
'tests/lint-pr-check-project-dir.test.cjs',
|
||
];
|
||
|
||
const RULES = [
|
||
{
|
||
name: 'workflow automation',
|
||
// Only NON-inert .github/workflows/* and all .github/rulesets/* trigger full matrix.
|
||
// FAIL-SAFE: any .github/workflows/*.yml not in INERT_WORKFLOWS is treated as pipeline.
|
||
match: filePath => (filePath.startsWith('.github/workflows/') && !isInertCi(filePath)) ||
|
||
filePath.startsWith('.github/rulesets/'),
|
||
fullMatrix: true,
|
||
tests: [
|
||
...WORKFLOW_LINT_TESTS,
|
||
'tests/release-tarball-smoke-workflow.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'inert CI',
|
||
match: filePath => isInertCi(filePath),
|
||
fullMatrix: false,
|
||
tests: [
|
||
...WORKFLOW_LINT_TESTS,
|
||
'tests/policy-lint-shallow-checkout.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'test harness',
|
||
match: path => path === 'scripts/run-tests.cjs',
|
||
fullMatrix: true,
|
||
tests: [
|
||
'tests/run-tests-harness.test.cjs',
|
||
'tests/workflow-shell-pinning.test.cjs',
|
||
// #4220: the run-scoped temp root + computeSweepProtectSet ancestor-walk
|
||
// termination coverage — was previously not re-selected by an edit to
|
||
// scripts/run-tests.cjs, the exact file that shipped the #4020 hang.
|
||
'tests/run-tests-temp-root.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'environment and dependency gates',
|
||
match: path => [
|
||
'scripts/check-env.cjs',
|
||
'scripts/check-npm-integrity.cjs',
|
||
'package.json',
|
||
'package-lock.json',
|
||
].includes(path),
|
||
fullMatrix: true,
|
||
tests: [
|
||
'tests/check-env.test.cjs',
|
||
'tests/npm-integrity-gate.test.cjs', // #2758: absorbs the former tests/bug-3588-npm-audit-clean.test.cjs (folded into it by consolidation epic #1969 B6 #1975; the stale filename here was a silent coverage hole this rule never actually re-selected)
|
||
'tests/package-manifest.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'TS runtime sources (ADR-457 build-at-publish)',
|
||
// src/*.cts compiles into gsd-core/bin/lib/*.cjs; a source-only edit must
|
||
// still trigger the migrated module's tests (otherwise CI silently skips them).
|
||
match: path => path.startsWith('src/') || path === 'tsconfig.build.json',
|
||
tests: [
|
||
'tests/semver-compare.test.cjs', // #2758: absorbs the former tests/bug-10-semver-policy-consolidation.test.cjs (folded into it by consolidation epic #1969 B3 #1972; the stale filename here was a silent coverage hole this rule never actually re-selected)
|
||
'tests/emitted-provenance.test.cjs', // any src/installer change can alter emitted install artifacts → re-verify provenance totality (#2724: golden-install-parity retired, this is the sole gate)
|
||
'tests/emitted-attribution.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'installer and package layout',
|
||
match: path => path.startsWith('bin/') ||
|
||
path.startsWith('gsd-core/bin/') ||
|
||
path.includes('install') ||
|
||
path.includes('release-tarball-smoke'),
|
||
fullMatrix: true,
|
||
tests: [
|
||
'tests/install.test.cjs',
|
||
'tests/install-regressions.test.cjs',
|
||
'tests/install-runtime-artifacts.test.cjs',
|
||
'tests/install-path-detection.test.cjs',
|
||
// NOTE: release-tarball-smoke.install.test.cjs is intentionally NOT here.
|
||
// It is a 3–6 min `npm pack` + `npm install -g` integration test with its
|
||
// OWN dedicated workflow (.github/workflows/install-smoke.yml, triggered on
|
||
// the production install paths). Running it in the scoped/targeted lane too
|
||
// is redundant and blows the per-chunk Windows timeout when a broad PR
|
||
// bundles it with many other changed test files (epic #1969). See the
|
||
// SCOPED_LANE_EXCLUDE guard below, which also drops it when it is itself a
|
||
// changed test file.
|
||
'tests/runtime-artifact-layout.test.cjs',
|
||
'tests/emitted-provenance.test.cjs', // any src/installer change can alter emitted install artifacts → re-verify provenance totality (#2724: golden-install-parity retired, this is the sole gate)
|
||
'tests/emitted-attribution.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'shipped install content (emitted-attribution drift guard, #2267/#2724)',
|
||
// Every source file the installer EMITS into a runtime layout is captured by
|
||
// the emitted-attribution differential + the install-tree snapshot. A source
|
||
// edit here that changes emitted output MUST re-verify (#2266: a
|
||
// hooks/gsd-statusline.js edit changed installed output but no rule selected
|
||
// the drift guard, so a stale emitted state shipped to next undetected).
|
||
// Union semantics: this ADDS the drift guard on top of each path's existing
|
||
// content-specific tests. Targeted lane only (the real-tree test skips win32
|
||
// by design), no fullMatrix.
|
||
// #2724: golden-install-parity.test.cjs is retired (ADR-2719 Phase 4); the
|
||
// emitted differential (ADR-2719 Phase 2/3) is now the sole gate for a PR
|
||
// editing only shipped content, the archetypal emitted-ripple case.
|
||
// NOTE: intentionally NOT a blanket 'gsd-core/' prefix, for two reasons:
|
||
// (1) gsd-core/bin/** is tsc-compiled runtime output — EXCLUDED_PREFIXES-
|
||
// excluded from both manifests, and already covered by the 'installer and
|
||
// package layout' rule (path.startsWith('gsd-core/bin/')) — so matching it
|
||
// here would be pure noise; and
|
||
// (2) enumerating only the installer-shipped content subtrees preserves the
|
||
// bug-408 unit-fallback contract: a gsd-core/ path that is NOT shipped
|
||
// verbatim (the bug-408 test uses gsd-core/src/some-util.js) must still
|
||
// fall back to ['unit'] when no rule matches.
|
||
// Listed: the four gsd-core content subtrees the installer ships verbatim
|
||
// (contexts, references, templates, workflows) + bin/shared/*.json data files.
|
||
// Verify against Object.keys(golden fixture) grouped by gsd-core/<subdir>.
|
||
match: path =>
|
||
['hooks/', 'commands/', 'agents/', 'skills/', 'gsd-core/workflows/', 'gsd-core/templates/', 'gsd-core/references/', 'gsd-core/contexts/', 'scripts/changeset/', 'scripts/lib/'].some(p => path.startsWith(p)) ||
|
||
(path.startsWith('gsd-core/bin/shared/') && path.endsWith('.json')) ||
|
||
['scripts/fix-slash-commands.cjs', 'scripts/gen-capability-registry.cjs', 'scripts/gen-loop-host-contract.cjs'].includes(path),
|
||
tests: [
|
||
'tests/golden-install-tree.test.cjs',
|
||
'tests/emitted-provenance.test.cjs',
|
||
'tests/emitted-attribution.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'hooks',
|
||
match: path => path.startsWith('hooks/'),
|
||
fullMatrix: true,
|
||
tests: [
|
||
'tests/hook-validation.test.cjs',
|
||
'tests/managed-hooks.test.cjs',
|
||
'tests/hooks-opt-in.test.cjs',
|
||
'tests/sh-hook-paths.test.cjs',
|
||
'tests/precommit-alias-drift-hook.test.cjs',
|
||
'tests/prepush-enterprise-email-hook.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'changeset tooling',
|
||
match: path => path.startsWith('scripts/changeset/') || path.startsWith('.changeset/'),
|
||
tests: [
|
||
'tests/changeset-cli.test.cjs',
|
||
'tests/changeset-lint.test.cjs',
|
||
'tests/changeset-new.test.cjs',
|
||
'tests/changeset-parse.test.cjs',
|
||
'tests/changeset-render.test.cjs',
|
||
'tests/changeset-serialize.test.cjs',
|
||
'tests/changeset-github-release-notes.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'security scanners',
|
||
match: path => path.includes('secret-scan') ||
|
||
path.includes('base64-scan') ||
|
||
path.includes('prompt-injection-scan') ||
|
||
path.startsWith('tests/fixtures/adversarial/security/'),
|
||
tests: [
|
||
'tests/secret-scan-lint.security.test.cjs',
|
||
'tests/prompt-injection-scan.security.test.cjs',
|
||
'tests/security-prompt-injection.security.test.cjs',
|
||
'tests/read-injection-scanner.security.test.cjs',
|
||
'tests/security-scan.security.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'command definitions',
|
||
match: path => path.startsWith('commands/'),
|
||
tests: [
|
||
'tests/command-contract.test.cjs',
|
||
'tests/command-routing-hub.test.cjs',
|
||
'tests/commands.test.cjs',
|
||
'tests/docs-parity-live-registry.test.cjs',
|
||
'tests/phase-command-router.test.cjs',
|
||
'tests/roadmap-command-router.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'workflow prompts',
|
||
match: path => path.startsWith('gsd-core/workflows/'),
|
||
tests: [
|
||
'tests/workflow-compat.test.cjs',
|
||
'tests/workflow-size-budget.test.cjs',
|
||
'tests/workflow-guard-registration.test.cjs',
|
||
'tests/commands.test.cjs',
|
||
// #2758: was 'tests/bug-3683-workflow-colon-namespace-leak.test.cjs', deleted by
|
||
// consolidation epic #1969 (B6 #1975) and folded into slash-command-namespace.test.cjs
|
||
// ("folded:bug-3683-workflow-colon-namespace-leak" describe block). The stale filename
|
||
// here was itself an instance of this issue's defect class — silently dropped by
|
||
// existingTests() below, so gsd-core/workflows/ changes stopped re-running this
|
||
// regression's coverage with nothing signaling it.
|
||
'tests/slash-command-namespace.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'agent prompts',
|
||
match: path => path.startsWith('agents/'),
|
||
tests: [
|
||
'tests/agent-frontmatter.test.cjs',
|
||
'tests/agent-size-budget.test.cjs',
|
||
'tests/agent-skills.test.cjs',
|
||
'tests/agent-skills-awareness.test.cjs',
|
||
'tests/agent-required-reading-consistency.test.cjs',
|
||
'tests/docs-parity-live-registry.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
name: 'configuration',
|
||
match: path => ['config', 'configuration', 'model-catalog', 'model-profile'].some(k => path.includes(k)),
|
||
tests: [
|
||
'tests/config.test.cjs',
|
||
'tests/config-get-default.test.cjs',
|
||
'tests/configuration-migrate-config.test.cjs',
|
||
'tests/model-catalog-runtime-defaults.test.cjs',
|
||
'tests/model-profiles.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
// ADR-1703 portability lint surface. Editing a rule, the shared vocab/guard
|
||
// helpers, or the eslint config that wires them must re-run the rule suites
|
||
// + the disable-ban. The disable-ban also scans bin/install.js and
|
||
// scripts/build-hooks.js (the Phase 6 glob-expansion surface), so changes
|
||
// to those files re-run it too.
|
||
name: 'portability lint rules (ADR-1703)',
|
||
match: path => path.startsWith('eslint-rules/') ||
|
||
path === 'eslint.config.mjs' ||
|
||
path === 'bin/install.js' ||
|
||
path === 'scripts/build-hooks.js',
|
||
tests: [
|
||
'tests/portability-rule-disable-ban.test.cjs',
|
||
'tests/portability-vocab-drift.test.cjs',
|
||
// All nine RuleTester suites (P1–P6) — editing any rule / the shared
|
||
// vocab+guard helpers / the eslint config re-runs the full rule family.
|
||
'tests/no-path-literal-in-assert.rule.test.cjs',
|
||
'tests/no-posix-mode-bit-assert.rule.test.cjs',
|
||
'tests/no-unguarded-nonportable-exec.rule.test.cjs',
|
||
'tests/no-crlf-fragile-split.rule.test.cjs',
|
||
'tests/no-hardcoded-tmp.rule.test.cjs',
|
||
'tests/no-bare-npm-exec.rule.test.cjs',
|
||
'tests/require-userprofile-with-home.rule.test.cjs',
|
||
'tests/normalize-path-in-content.rule.test.cjs',
|
||
'tests/require-fs-op-fallback.rule.test.cjs',
|
||
// #4244 (origin #4020/#4220 Windows CI hang) — see ADR-1703 amendment.
|
||
'tests/require-full-tmpdir-triad.rule.test.cjs',
|
||
'tests/no-unbounded-dirname-walk.rule.test.cjs',
|
||
],
|
||
},
|
||
{
|
||
// ADR-3212 Phase 4 (#3415): no-unbounded-quantifier and the shared
|
||
// readfilesync-trace helper it uses (also now imported by
|
||
// no-crlf-fragile-split). NOT part of the ADR-1703 portability family above
|
||
// — kept as its own bucket so this rule's tests re-run without pulling in
|
||
// the ADR-1703 disable-ban / vocab-drift suites it is not governed by.
|
||
name: 'no-unbounded-quantifier + readfilesync-trace (ADR-3212 Phase 4)',
|
||
match: path => [
|
||
'eslint-rules/no-unbounded-quantifier.cjs',
|
||
'eslint-rules/lib/readfilesync-trace.cjs',
|
||
'eslint-rules/no-crlf-fragile-split.cjs',
|
||
].includes(path),
|
||
tests: [
|
||
'tests/no-unbounded-quantifier.rule.test.cjs',
|
||
'tests/readfilesync-trace-parity.test.cjs',
|
||
],
|
||
},
|
||
];
|
||
|
||
/**
|
||
* Every RULES[].tests entry (deduped, across every rule) that does NOT exist on
|
||
* disk. #2758: a rule naming a test file that no longer exists is not merely
|
||
* inert — existingTests() below silently drops it out of targeted_tests, with
|
||
* nothing in the CI output signaling why. Phase 4 (#2724) deletes
|
||
* tests/golden-install-parity.test.cjs; without this check, any rule still
|
||
* naming it would stop selecting the guard entirely and CI would stay green
|
||
* throughout. Pure and independent of which rule / which file: it catches ANY
|
||
* phantom entry, not only the two names this issue is about.
|
||
* Paths resolve relative to the repo root (this file's parent directory), not
|
||
* the caller's cwd, so the check behaves identically whether invoked as the CLI
|
||
* (`node scripts/ci-test-scope.cjs ...`, cwd == repo root by convention) or
|
||
* required directly by a test.
|
||
*/
|
||
function missingRuleTestFiles(rules) {
|
||
const referenced = new Set();
|
||
for (const rule of rules) {
|
||
for (const f of rule.tests) referenced.add(f);
|
||
}
|
||
return [...referenced].filter(f => !existsSync(path.join(__dirname, '..', f))).sort();
|
||
}
|
||
|
||
/**
|
||
* Every PROTECTED_WORKFLOWS member that does not exist on disk.
|
||
* The name list and the real filenames are two surfaces over one fact
|
||
* (#3833): without this, renaming or deleting a gating workflow silently
|
||
* un-protects it and CI stays green while the protection is gone. Same
|
||
* shape and rationale as missingRuleTestFiles() above.
|
||
*/
|
||
function missingProtectedWorkflows(names = PROTECTED_WORKFLOWS) {
|
||
return [...names]
|
||
.filter(name => !existsSync(path.join(__dirname, '..', '.github', 'workflows', name)))
|
||
.sort();
|
||
}
|
||
|
||
/**
|
||
* Shared module-load assertion for the two "this list names something that
|
||
* does not exist on disk" guards above. Both are silent-coverage-hole guards:
|
||
* a name that no longer resolves stops selecting/protecting anything while CI
|
||
* stays green, so both must fail loudly at load rather than at test time.
|
||
*/
|
||
function assertNoneMissing(missing, summary, issueRef) {
|
||
if (missing.length === 0) return;
|
||
throw new Error(`ci-test-scope: ${summary} (${issueRef}):\n ${missing.join('\n ')}`);
|
||
}
|
||
|
||
// Fail loudly at module load — this fires on EVERY invocation of the CLI
|
||
// (including the real `changes` job in .github/workflows/test.yml), not only
|
||
// when a test suite happens to run.
|
||
assertNoneMissing(
|
||
missingRuleTestFiles(RULES),
|
||
'RULES reference test file(s) that do not exist on disk (silent coverage hole)',
|
||
'see #2758',
|
||
);
|
||
|
||
// A PROTECTED_WORKFLOWS entry naming a file that does not exist means the
|
||
// workflow was renamed or deleted without updating this list, silently
|
||
// un-protecting it while CI stays green.
|
||
assertNoneMissing(
|
||
missingProtectedWorkflows(PROTECTED_WORKFLOWS),
|
||
'PROTECTED_WORKFLOWS reference workflow file(s) that do not exist on disk (silent protection hole)',
|
||
'see #3833',
|
||
);
|
||
|
||
function usage() {
|
||
return [
|
||
'Usage:',
|
||
' node scripts/ci-test-scope.cjs --base <sha> --head <sha>',
|
||
' node scripts/ci-test-scope.cjs --files <path-list>',
|
||
'',
|
||
'Prints JSON by default. With GITHUB_OUTPUT set, also writes workflow outputs.',
|
||
].join('\n');
|
||
}
|
||
|
||
function parseArgs(argv) {
|
||
const out = { base: null, head: null, files: null };
|
||
for (let i = 0; i < argv.length; i++) {
|
||
const arg = argv[i];
|
||
if (arg === '--base') {
|
||
out.base = argv[++i];
|
||
if (!out.base || out.base.startsWith('--')) throw new Error('--base requires a value');
|
||
} else if (arg.startsWith('--base=')) {
|
||
out.base = arg.slice('--base='.length);
|
||
if (!out.base) throw new Error('--base requires a value');
|
||
} else if (arg === '--head') {
|
||
out.head = argv[++i];
|
||
if (!out.head || out.head.startsWith('--')) throw new Error('--head requires a value');
|
||
} else if (arg.startsWith('--head=')) {
|
||
out.head = arg.slice('--head='.length);
|
||
if (!out.head) throw new Error('--head requires a value');
|
||
} else if (arg === '--files') {
|
||
out.files = argv[++i];
|
||
if (!out.files || out.files.startsWith('--')) throw new Error('--files requires a value');
|
||
} else if (arg.startsWith('--files=')) {
|
||
out.files = arg.slice('--files='.length);
|
||
if (!out.files) throw new Error('--files requires a value');
|
||
} else if (arg === '--help' || arg === '-h') {
|
||
console.log(usage());
|
||
throw new ExitError(0);
|
||
} else {
|
||
throw new Error(`unknown argument: ${arg}`);
|
||
}
|
||
}
|
||
return out;
|
||
}
|
||
|
||
function splitFiles(value) {
|
||
if (!value) return [];
|
||
const SEPARATORS = new Set([',', ' ', '\t', '\n', '\r', '\f', '\v']);
|
||
const tokens = [];
|
||
let current = '';
|
||
for (const ch of value) {
|
||
if (SEPARATORS.has(ch)) {
|
||
if (current) tokens.push(current);
|
||
current = '';
|
||
} else {
|
||
current += ch;
|
||
}
|
||
}
|
||
if (current) tokens.push(current);
|
||
return tokens.map(v => v.trim()).filter(Boolean);
|
||
}
|
||
|
||
function changedFiles(args) {
|
||
if (args.files) return splitFiles(args.files);
|
||
if (!args.base || !args.head) {
|
||
throw new Error('--base/--head or --files is required');
|
||
}
|
||
// Three-dot diff (merge-base...head) matches GitHub's PR "Files changed" semantics.
|
||
// A two-dot `git diff base head` would surface every file `next` gained after this
|
||
// branch's merge-base, mis-flagging product_changed/full_matrix on docs-only PRs cut
|
||
// from a slightly stale base (#837). The `changes` job checks out with fetch-depth: 0,
|
||
// so the merge-base is always available.
|
||
const stdout = execFileSync('git', ['diff', '--name-only', `${args.base}...${args.head}`], {
|
||
encoding: 'utf8',
|
||
});
|
||
return splitFiles(stdout);
|
||
}
|
||
|
||
function existingTests(files) {
|
||
const all = new Set(readdirSync('tests').filter(f => f.endsWith('.test.cjs')).map(f => `tests/${f}`));
|
||
return files.filter(file => all.has(file) && existsSync(file));
|
||
}
|
||
|
||
function addAll(set, values) {
|
||
for (const value of values) set.add(value);
|
||
}
|
||
|
||
// Windows-sensitive filename hints — deliberately narrow. 'workflow',
|
||
// 'install', and 'hook' were dropped from this list: workflow-lint tests are
|
||
// platform-independent YAML/policy checks, and the installer/hooks RULES set
|
||
// fullMatrix=true, so the full Windows lane already runs when those paths
|
||
// change. The old six-hint list pulled 102 of ~633 test files into the scoped
|
||
// windows lane, turning it into a ~10-minute job on every PR.
|
||
// #4641: the scoped windows lane itself is gone. These hints now drive
|
||
// full_matrix instead — a matched RULE whose tests[] includes a
|
||
// windows-hint filename AND that hinted file is itself in the conformance
|
||
// tier (per reachesConformanceTierOrSeam) escalates straight to full_matrix
|
||
// (routed to test-conformance, the sole Windows selector) rather than
|
||
// feeding a side lane. Tier-backed on purpose: full_matrix only ever runs
|
||
// CONFORMANCE_TIER_FILES, so a hint on a non-tier file would cost 4 CI jobs
|
||
// with zero Windows coverage of that file. See
|
||
// docs/adr/4641-windows-selector-consolidation.md.
|
||
const WINDOWS_HINTS = ['windows', 'win32', 'shell', 'path'];
|
||
const isWindowsHint = s => WINDOWS_HINTS.some(k => s.toLowerCase().includes(k));
|
||
|
||
// A change to the classification mechanism itself cannot be presumed safe by
|
||
// the very mechanism being changed (#4592).
|
||
const CLASSIFIER_DEFINITION_FILES = new Set([
|
||
'scripts/gen-platform-conformance-tier.cjs',
|
||
'scripts/lib/platform-conformance-tier.generated.cjs',
|
||
'scripts/lib/suite-detection.cjs',
|
||
]);
|
||
|
||
/**
|
||
* Does `file`'s blast radius reach (a) Phase 2's conformance-tier test-file
|
||
* list or (b) a live platform-conditional signal in src/? Fail-safe: any
|
||
* thrown error (a require failure, a readFileSync failure, a malformed
|
||
* generated module, etc.) is treated as uncertainty and returns true — per
|
||
* #4592's explicit "fail-safe to full_matrix=true on any reachability-
|
||
* computation error or uncertainty" requirement.
|
||
* `loadConformanceTier` is injectable (defaults to the real generated module)
|
||
* solely so tests can simulate a load failure without touching the real,
|
||
* committed generated file.
|
||
* @param {string} file
|
||
* @param {{loadConformanceTier?: () => {CONFORMANCE_TIER_FILES: string[]}}} [deps]
|
||
* @returns {boolean}
|
||
*/
|
||
function reachesConformanceTierOrSeam(file, deps = {}) {
|
||
const loadConformanceTier =
|
||
deps.loadConformanceTier || (() => require('./lib/platform-conformance-tier.generated.cjs'));
|
||
try {
|
||
if (file.startsWith('tests/') && file.endsWith('.test.cjs')) {
|
||
const { CONFORMANCE_TIER_FILES } = loadConformanceTier();
|
||
return CONFORMANCE_TIER_FILES.includes(file);
|
||
}
|
||
|
||
if (file.startsWith('src/')) {
|
||
const content = readFileSync(file, 'utf8');
|
||
const { signals } = classifyContent(content);
|
||
const narrowSignals = signals.filter(signal => !NOISY_FOR_SOURCE_REACHABILITY.has(signal));
|
||
return narrowSignals.length > 0;
|
||
}
|
||
|
||
return false;
|
||
} catch {
|
||
return true;
|
||
}
|
||
}
|
||
|
||
// `reachabilityDeps` is injectable (defaults to {}, which makes
|
||
// reachesConformanceTierOrSeam use the real generated module) solely so
|
||
// tests can simulate a reachability-computation failure without touching
|
||
// the real, committed generated file.
|
||
function classify(files, reachabilityDeps = {}) {
|
||
const targeted = new Set();
|
||
const reasons = [];
|
||
let productOrPipelineChanged = false; // product/pipeline code (excludes docs)
|
||
let inertCiChanged = false; // inert workflow files
|
||
let fullMatrix = false;
|
||
|
||
for (const file of files) {
|
||
// Determine if this file is product/pipeline code.
|
||
// docs/ and root-level .md files are intentionally excluded.
|
||
// 'skills/' is shipped agent-skill content installed into every runtime by
|
||
// the installer (see the 'shipped install content' RULES entry below) — it
|
||
// must be product code, or a skills/-only change silently gets
|
||
// code_changed=false and skips the ENTIRE CI matrix, not merely golden-parity
|
||
// (found while verifying the #2267 golden-parity rule against skills/**: the
|
||
// rule fired in `reasons` but classify()'s codeChanged gate zeroed out every
|
||
// targeted test because 'skills/' was absent from this list).
|
||
if (
|
||
['bin/', 'src/', 'gsd-core/', 'agents/', 'commands/', 'hooks/', 'skills/', 'tests/', 'scripts/', 'eslint-rules/'].some(p => file.startsWith(p)) ||
|
||
file === 'package.json' || file === 'package-lock.json' ||
|
||
(file.startsWith('tsconfig') && file.endsWith('.json')) ||
|
||
file.startsWith('.github/rulesets/')
|
||
) {
|
||
productOrPipelineChanged = true;
|
||
}
|
||
|
||
// Non-inert .github/workflows/* are pipeline code → full matrix.
|
||
if (file.startsWith('.github/workflows/') && !isInertCi(file)) {
|
||
productOrPipelineChanged = true;
|
||
}
|
||
|
||
// Inert workflow files set a lightweight signal.
|
||
if (isInertCi(file)) {
|
||
inertCiChanged = true;
|
||
}
|
||
|
||
if (file.startsWith('tests/') && file.endsWith('.test.cjs')) {
|
||
targeted.add(file);
|
||
// #494 originally narrowed this to skip full_matrix for changed test
|
||
// files, on the theory that ubuntu targeted_tests + the scoped windows
|
||
// lane already covered them. Rescinded per #4421: PR #4384 landed a
|
||
// macOS-only regression on 2026-09-06 that stayed invisible pre-merge
|
||
// precisely because this carve-out suppressed the only macOS signal.
|
||
// #4592: the blanket rule is replaced with a reachability check — only
|
||
// a changed test file that actually reaches Phase 2's conformance-tier
|
||
// list (or is the classification mechanism itself) forces full_matrix.
|
||
if (reachesConformanceTierOrSeam(file, reachabilityDeps)) {
|
||
fullMatrix = true;
|
||
reasons.push(`${file}: conformance-tier reachability`);
|
||
}
|
||
}
|
||
|
||
// #4592: a src/-only diff (no test file touched) must still be able to
|
||
// set full_matrix=true when it carries a live platform-conditional
|
||
// signal — this is independent of the tests/ branch above.
|
||
if (file.startsWith('src/') && reachesConformanceTierOrSeam(file, reachabilityDeps)) {
|
||
fullMatrix = true;
|
||
reasons.push(`${file}: platform seam reachability`);
|
||
}
|
||
|
||
// #4592: a changed file that IS the classification mechanism itself
|
||
// (neither under tests/ nor src/, so neither branch above reaches it)
|
||
// must also force full_matrix — a change to the mechanism cannot be
|
||
// presumed safe by the very mechanism being changed.
|
||
if (CLASSIFIER_DEFINITION_FILES.has(file)) {
|
||
fullMatrix = true;
|
||
reasons.push(`${file}: reachability classifier definition changed`);
|
||
}
|
||
|
||
for (const rule of RULES) {
|
||
if (rule.match(file)) {
|
||
addAll(targeted, rule.tests);
|
||
reasons.push(`${file}: ${rule.name}`);
|
||
if (rule.fullMatrix) fullMatrix = true;
|
||
// #4641: a rule that pulls in a test file matching a Windows-sensitive
|
||
// filename hint is the one non-redundant residue of the deleted
|
||
// scoped windows lane — escalate to full_matrix (test-conformance)
|
||
// instead of feeding a side lane. TIER-BACKED (measured): full_matrix
|
||
// routes to test-conformance, which runs ONLY CONFORMANCE_TIER_FILES —
|
||
// escalating on the filename hint alone can fire on a hinted test that
|
||
// isn't in that tier, costing 4 CI jobs while never actually running it
|
||
// on Windows. The predicate below requires BOTH the hint AND tier
|
||
// membership (via reachesConformanceTierOrSeam, the same fail-safe
|
||
// reachability helper used elsewhere in this file, so error/uncertainty
|
||
// behavior stays identical). Measured: over the 16 RULES entries this
|
||
// narrowed form fires on the same rules as the un-narrowed form today
|
||
// (no behavior change now, correct-by-construction going forward). The
|
||
// broader alternative — escalate on ANY tier member a rule pulls in,
|
||
// ignoring the filename hint — was measured and rejected: it fires on
|
||
// 14 of 16 rules, newly escalating most ordinary product-code PRs
|
||
// (src/, agents/, commands/, hooks/, skills/, config paths). Only one
|
||
// rule's escalation is live today: 'portability lint rules (ADR-1703)'.
|
||
// Four others already had fullMatrix: true (no-op here), and 'inert
|
||
// CI''s escalation is overridden downstream by the inert-CI reset.
|
||
// Distinct, greppable reason so the conformance-lane coverage for it
|
||
// is traceable per rule.
|
||
if (rule.tests.some(t => isWindowsHint(t) && reachesConformanceTierOrSeam(t, reachabilityDeps))) {
|
||
fullMatrix = true;
|
||
reasons.push(`${file}: ${rule.name} (windows-hint rule test, #4641)`);
|
||
}
|
||
}
|
||
}
|
||
}
|
||
|
||
// Heavy integration tests that own a dedicated workflow must never run in the
|
||
// scoped/targeted lane — they carry a multi-minute cost that overruns the
|
||
// per-chunk timeout (worst on Windows) when a broad PR bundles them with many
|
||
// other changed test files, and their production paths already trigger their
|
||
// own workflow. Drop them however they entered (matched rule OR changed-file).
|
||
const SCOPED_LANE_EXCLUDE = new Set([
|
||
// covered by .github/workflows/install-smoke.yml
|
||
'tests/release-tarball-smoke.install.test.cjs',
|
||
]);
|
||
for (const f of SCOPED_LANE_EXCLUDE) { targeted.delete(f); }
|
||
|
||
// code_changed: true when product/pipeline OR inert CI changed.
|
||
// Docs-only PRs (neither flag set) get code_changed=false → full matrix skip.
|
||
const codeChanged = productOrPipelineChanged || inertCiChanged;
|
||
|
||
const targetedTests = existingTests([...targeted].sort());
|
||
|
||
// When code changed but no rule matched any changed file, fall back to the
|
||
// unit suite so the targeted lane always runs something meaningful (#408).
|
||
if (codeChanged && targetedTests.length === 0) {
|
||
targetedTests.push('unit');
|
||
}
|
||
|
||
// Inert-CI-only: full_matrix must be false (override any RULES that fired).
|
||
if (inertCiChanged && !productOrPipelineChanged) {
|
||
fullMatrix = false;
|
||
}
|
||
|
||
// Normalize: when code_changed is false, the output must be self-consistent.
|
||
// A docs file can coincidentally match a coarse content RULE (e.g. docs/installer-migrations.md
|
||
// matches the installer rule via path.includes('install')), leaving full_matrix=true and
|
||
// non-empty targeted_tests. The workflow skips correctly (gated on code_changed)
|
||
// but the output object would be self-contradictory. Force a clean "nothing to run" result.
|
||
if (!codeChanged) {
|
||
fullMatrix = false;
|
||
targetedTests.length = 0;
|
||
}
|
||
|
||
return {
|
||
code_changed: codeChanged,
|
||
product_changed: productOrPipelineChanged,
|
||
full_matrix: fullMatrix,
|
||
targeted_tests: targetedTests,
|
||
reasons: [...new Set(reasons)].sort(),
|
||
};
|
||
}
|
||
|
||
function writeOutputs(result) {
|
||
if (!process.env.GITHUB_OUTPUT) return;
|
||
const lines = [
|
||
`code_changed=${result.code_changed}`,
|
||
`product_changed=${result.product_changed}`,
|
||
`full_matrix=${result.full_matrix}`,
|
||
`targeted_tests=${result.targeted_tests.join(' ')}`,
|
||
];
|
||
appendFileSync(process.env.GITHUB_OUTPUT, `${lines.join('\n')}\n`);
|
||
}
|
||
|
||
function main() {
|
||
try {
|
||
const args = parseArgs(process.argv.slice(2));
|
||
|
||
const files = changedFiles(args);
|
||
const result = classify(files);
|
||
result.changed_files = files;
|
||
writeOutputs(result);
|
||
console.log(JSON.stringify(result, null, 2));
|
||
} catch (error) {
|
||
if (error instanceof ExitError) throw error;
|
||
console.error(`ci-test-scope: ${error.message}`);
|
||
console.error(usage());
|
||
throw new ExitError(2);
|
||
}
|
||
}
|
||
|
||
if (require.main === module) {
|
||
runMain(main);
|
||
}
|
||
|
||
module.exports = {
|
||
RULES,
|
||
missingRuleTestFiles,
|
||
PROTECTED_WORKFLOWS,
|
||
INERT_WORKFLOWS,
|
||
missingProtectedWorkflows,
|
||
classify,
|
||
reachesConformanceTierOrSeam,
|
||
};
|