Files
msd-core/tests/context-index-sync.test.cjs
Tom Boucher 5a0a9f0972 fix(#2944): remove the catastrophic-backtracking regex from the ADR-1671 example (#2950)
* fix(#2944): remove the catastrophic-backtracking regex from the example

The non-shipping Option-E reference example carried its own copy of the
predicate-id regex, which nested a dot-containing character class inside a
dot-prefixed repeat. A run of N consecutive dots therefore had exponentially
many partitions. Measured on next before this change: 30 dots 54ms, 35 66ms,
40 807ms — so roughly 55-60 dots hangs for hours.

Not exploitable where it sits: the example is outside tsconfig.build.json,
outside the npm package files list, outside the installer and outside tests,
so no build step or CI job parses anything with it. Fixed because the entire
point of a reference example is that people copy it forward, and ADR-1671
presents this one as the pattern for the platform.

Ports the linear per-segment validation that #2928 gave the production module,
so the two copies agree: both parse the real CONTEXT.md to 415 predicates
across 20 classes with 0 duplicates. Doubled-dot ids are now rejected here
too, matching production, and the grammar comment records it.

Also refreshes the example's committed index, which #2928 made stale when it
removed the duplicate predicate from CONTEXT.md.

Closes #2944

* test(#2944): guard predicate-index sync and example/production parity

Two regression tests for the two defects in this PR.

Index sync: asserts the committed docs/CONTEXT-INDEX.json equals a fresh parse
of CONTEXT.md, naming any diverging predicate ids. The merge race that reddened
next was invisible to both PRs involved and only surfaced on the next PR to run
lint:ci; this puts the same check inside the suite, which runs on every PR, and
a mutation test proves the assertion is not vacuous.

Example/production parity: asserts both copies of the parser report the same
count, classes and duplicates for the real CONTEXT.md, and agree verdict-for-
verdict over a table of id shapes. The divergence WAS the bug — production went
linear-time while the example kept the backtracking regex, with nothing
asserting they agreed. Also pins the example rejecting a 60-dot id, with the
clean rejection as the binding assertion and wall-clock only as a smoke check.

Notes a real tension rather than hiding it: ADR-1671 says the example sits
outside tests/, and this imports it. The ADR's intent is that the example is
not compiled, packaged or installed — not that it may silently rot. A parity
guard does not ship it. The file states this so a reviewer can object.

* fix(#2944): address both isolated review passes

Two independent reviewers (correctness and security axes, neither the author).
Security found nothing — it measured linearity to 100k chars across dots,
hyphens, underscores and mixed classes, and showed prototype pollution is
structurally unreachable because the first-segment pattern forbids
lowercase and underscore-leading ids. The correctness pass found three
blockers, all real.

Blocker: the parity test violated ADR-1671 verbatim. The ADR lists FOUR
exclusions for the reference example, the fourth being the CI test suite, and
the test imported it from tests/ while its own justification comment cited only
three -- constructing a rationale around the exclusion it broke. Moved to
scripts/lint-example-parser-parity.cjs wired into lint:ci; a lint script is not
the test suite, so the exclusion stands. The test file keeps only the
docs/CONTEXT-INDEX.json sync check.

Blocker: the mutation test leaked its temp dir. Its callback took no `t`, so a
failing assertion skipped the bare cleanup call. Now registered via t.after(),
matching the convention adr-index-gate.test.cjs documents.

Blocker: the example's own committed index carries the identical merge-race
staleness this PR fixes for the production one, and nothing guarded it.
Deliberately NOT fixed by wiring the example's --check into CI: that artifact
bakes line numbers, so it re-drifts on any unrelated CONTEXT.md line shift --
exactly ADR-1671 open question 4 -- and would make CI routinely red. The new
lint asserts the line-INDEPENDENT facts instead: count, class map, duplicate
set, and every (id, value) pair. Proven non-vacuous both ways: mutating a value
fails and names the id, mutating only a line number passes.

Major: a real divergence the parity claim would have missed. Production rejects
values containing an embedded CR, LF, U+2028 or U+2029; the example did not, so
a value with an embedded lone CR was rejected by one copy and accepted by the
other. Ported, and now covered by the parity table.

Also, found while verifying rather than reported: malformed diagnostics covered
only empty values. A doubled-dot id, a space in an id, and a lowercase-leading
id were all dropped silently. That contradicts the module's own intent -- a
typo should be diagnosable, and a space in an id is a likely one -- and
predicates are contractually cited, so a silently vanished predicate is the
failure mode that matters. Each rejection class now carries a named reason in
both copies, while ordinary inline code still yields none.

Trues up counts my own change staled: the example README and ADR-1671's
prototype figures said 416 and 393/18 against a real 415/20/0.

Closes #2944

* chore(#2944): backfill changeset PR number 2950

---------

Co-authored-by: sim <sim@local>
2026-07-31 15:44:19 -04:00

154 lines
6.4 KiB
JavaScript

'use strict';
/**
* Regression test for #2944 — 85140eac8 "refresh the predicate index staled
* by a merge race on next" (docs/CONTEXT-INDEX.json) shipped with zero
* behavioral test coverage.
*
* docs/CONTEXT-INDEX.json is a committed generated artifact guarded by
* `scripts/gen-context-index.cjs --check` in `lint:generated-sync`. A
* concurrent-merge race landed one PR's CONTEXT.md alongside another PR's
* index; each PR was green alone (lint only runs on the PR's own diff), the
* combination was red, and it only surfaced on the NEXT PR to run `lint:ci`.
* This file puts the same drift check inside the test suite (which
* `gsd-test` runs on every PR), so a future racing merge fails here directly
* instead of waiting for a downstream PR to trip over `lint:generated-sync`.
*
* The example/production parser parity guard (the OTHER defect #2944
* introduced regression coverage for) lives in
* scripts/lint-example-parser-parity.cjs, wired into `npm run lint:ci` — NOT
* here. ADR-1671 ("Dynamic context management platform",
* docs/adr/1671-dynamic-context-management-platform.md:102) places
* examples/dynamic-context-management/ deliberately outside four surfaces:
* the build (src/ -> bin/lib/), the npm package files[], the installer, and
* the CI test suite (tests/) — this file. A `require()` of the example from
* inside tests/ would violate that fourth exclusion directly; a lint script
* that only reads both modules from a repo-root script does not.
*/
process.env.GSD_TEST_MODE = '1';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const helpers = require('./helpers.cjs');
const REPO_ROOT = path.resolve(__dirname, '..');
const LIB_DIR = path.join(REPO_ROOT, 'gsd-core', 'bin', 'lib');
const PROD_PREDICATES_PATH = path.join(LIB_DIR, 'context-predicates.cjs');
const CONTEXT_PATH = path.join(REPO_ROOT, 'CONTEXT.md');
const INDEX_PATH = path.join(REPO_ROOT, 'docs', 'CONTEXT-INDEX.json');
const prodPredicates = require(PROD_PREDICATES_PATH);
function readContextMarkdown() {
return fs.readFileSync(CONTEXT_PATH, 'utf8');
}
function readCommittedIndex() {
return JSON.parse(fs.readFileSync(INDEX_PATH, 'utf8'));
}
/**
* Diff two ContextIndex-shaped `{predicates:[{id,klass,value}]}` objects by
* id, returning human-readable divergence strings naming the exact
* predicate id(s) involved — so a failure reads as an actionable list, never
* "objects differ".
*/
function diffPredicatesById(leftPredicates, rightPredicates, leftLabel, rightLabel) {
const leftMap = new Map(leftPredicates.map((p) => [p.id, p]));
const rightMap = new Map(rightPredicates.map((p) => [p.id, p]));
const allIds = new Set([...leftMap.keys(), ...rightMap.keys()]);
const diffs = [];
for (const id of Array.from(allIds).sort()) {
const l = leftMap.get(id);
const r = rightMap.get(id);
if (l && !r) {
diffs.push(`${id}: present in ${leftLabel} but absent from ${rightLabel}`);
} else if (!l && r) {
diffs.push(`${id}: present in ${rightLabel} but absent from ${leftLabel}`);
} else if (l.value !== r.value) {
diffs.push(
`${id}: value diverged (${leftLabel}=${JSON.stringify(l.value)}, ${rightLabel}=${JSON.stringify(r.value)})`,
);
} else if (l.klass !== r.klass) {
diffs.push(
`${id}: klass diverged (${leftLabel}=${JSON.stringify(l.klass)}, ${rightLabel}=${JSON.stringify(r.klass)})`,
);
}
}
return diffs;
}
// ─── docs/CONTEXT-INDEX.json vs. a fresh CONTEXT.md parse ────────────────────
describe('docs/CONTEXT-INDEX.json sync with CONTEXT.md (#2944 concurrent-merge regression)', () => {
test('committed index matches a fresh parse of the real CONTEXT.md, predicate-by-predicate', () => {
const { parsePredicates, buildIndex } = prodPredicates;
const markdown = readContextMarkdown();
const { predicates } = parsePredicates(markdown);
const fresh = buildIndex(predicates);
const committed = readCommittedIndex();
const diffs = diffPredicatesById(
committed.predicates,
fresh.predicates,
'committed docs/CONTEXT-INDEX.json',
'fresh CONTEXT.md parse',
);
assert.deepEqual(
diffs,
[],
'docs/CONTEXT-INDEX.json has drifted from CONTEXT.md for predicate id(s) ' +
'(run `node scripts/gen-context-index.cjs --write` to refresh):\n' +
diffs.join('\n'),
);
assert.equal(
committed.count,
fresh.count,
`predicate count diverged: committed=${committed.count} fresh=${fresh.count}`,
);
assert.deepEqual(
committed.classes,
fresh.classes,
'class-count map diverged between committed index and fresh CONTEXT.md parse:\n' +
`committed=${JSON.stringify(committed.classes)}\nfresh=${JSON.stringify(fresh.classes)}`,
);
});
test('divergence detector is not vacuous: catches a mutated index in a throwaway temp copy (never the real artifact)', (t) => {
const { parsePredicates, buildIndex } = prodPredicates;
const markdown = readContextMarkdown();
const { predicates } = parsePredicates(markdown);
const fresh = buildIndex(predicates);
// Mutate a COPY of the fresh index in a fresh temp dir. docs/CONTEXT-
// INDEX.json itself is never opened for write anywhere in this file.
const mutated = JSON.parse(JSON.stringify(fresh));
const target =
mutated.predicates.find((p) => p.id === 'RULESET.WORKFLOW_SIZE_BUDGET') || mutated.predicates[0];
target.value = target.value + ' MUTATED-FOR-TEST';
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'context-index-sync-'));
t.after(() => helpers.cleanup(tmpDir));
const tmpIndexPath = path.join(tmpDir, 'CONTEXT-INDEX.json');
fs.writeFileSync(tmpIndexPath, JSON.stringify(mutated, null, 2) + '\n', 'utf8');
const mutatedCommitted = JSON.parse(fs.readFileSync(tmpIndexPath, 'utf8'));
const diffs = diffPredicatesById(
mutatedCommitted.predicates,
fresh.predicates,
'mutated temp-copy index',
'fresh CONTEXT.md parse',
);
assert.ok(diffs.length > 0, 'expected the mutated temp copy to diverge from the fresh parse');
assert.ok(
diffs.some((d) => d.startsWith(`${target.id}:`)),
`expected the diff to name ${target.id}; got:\n${diffs.join('\n')}`,
);
});
});