Files
msd-core/tests/worktree-merge-protection.test.cjs
Tom Boucher 918f987a19 feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes() (#2985)
* feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes()

The base lint (scripts/lint-no-source-grep.cjs) only catches
readFileSync(...).<text-method>() chained directly. The much more
common var-binding form escapes it:

  const src = fs.readFileSync(p, 'utf8');
  // 50 lines later
  if (src.includes('foo')) {}        // ← still grep, lint missed it

Scan of the test suite found ~141 files using this pattern.

Implementation built TDD per #2982 with structured-IR assertions:

  scripts/lint-no-source-grep-extras.cjs
    - detectVarBindingViolations(src) — pure detector, two passes:
      pass 1 collects vars bound from readFileSync, pass 2 finds any
      <var>.<includes|startsWith|endsWith|match|search>( on those vars.
    - detectWrappedAssertOkMatch(src) — flags
      assert.ok(<expr>.match(...)) which escapes the assert.match rule.
    - VIOLATION enum exposes stable codes for tests to assert on.

  scripts/lint-no-source-grep.cjs
    - Wires the new detectors into the existing per-file check; one
      additional violation row per file with the first 3 sample tokens.

  tests/bug-2982-lint-var-binding.test.cjs
    - 13 tests, all assertions on typed VIOLATION enum / structured
      records. Covers all 5 text-match methods, multi-var, no-bind,
      string literal (must NOT trigger), wrapped assert.ok(.match),
      and assert.match (must NOT double-flag).

Migration backlog (#2974 expanded scope):

  - 42 files annotated `// allow-test-rule: source-text-is-the-product`
    (legitimate — they read .md/.json/.yml files whose deployed text
    IS the product)
  - 3 files annotated `// allow-test-rule: pending-migration-to-typed-ir [#2974]`
    (read .cjs/.js source — clear migration debt)
  - 95 files annotated `pending-migration-to-typed-ir [#2974]` with
    `Per-file review may reclassify as source-text-is-the-product
    during migration` (mixed — manual review under #2974)

After this lands the lint reports 0 violations on main; new
violations in PRs surface immediately.

Closes #2982
Refs #2974

* test(#2982): fix truncated test name per CR

The label ended with a bare '(' from a copy-paste mishap. Now reads
'does NOT flag .matchAll(...) — matchAll is not match, so
assert.ok(.matchAll(...)) is not flagged'.

* chore(#2982): add changeset fragment for PR #2985

* chore(#2982): add changeset fragment for PR #2985
2026-05-01 19:50:10 -04:00

107 lines
4.4 KiB
JavaScript

// allow-test-rule: pending-migration-to-typed-ir [#2974]
// Tracked in #2974 for migration to typed-IR assertions per CONTRIBUTING.md
// "Prohibited: Raw Text Matching on Test Outputs". Per-file review may
// reclassify some entries as source-text-is-the-product during migration.
/**
* Worktree merge orchestrator file protection tests
*
* Guards against bug #1756: when a worktree branch outlives a milestone
* transition, git merge silently overwrites STATE.md and ROADMAP.md with
* stale content and resurrects archived phase directories.
*
* Fix: The worktree merge step must backup and restore orchestrator-owned
* files (STATE.md, ROADMAP.md) and detect/remove files that main deleted
* but the worktree branch re-adds.
*/
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const EXECUTE_PHASE_PATH = path.join(__dirname, '..', 'get-shit-done', 'workflows', 'execute-phase.md');
const QUICK_PATH = path.join(__dirname, '..', 'get-shit-done', 'workflows', 'quick.md');
describe('worktree merge: orchestrator file protection (#1756)', () => {
test('execute-phase.md backs up STATE.md before worktree merge', () => {
const content = fs.readFileSync(EXECUTE_PHASE_PATH, 'utf-8');
// The workflow must snapshot STATE.md from main before merging
// to prevent stale worktree content from overwriting it
const mergeIdx = content.indexOf('git merge');
assert.ok(mergeIdx > -1, 'workflow should contain git merge');
// Look for STATE.md backup/snapshot before the merge command
const hasStateBackup = (
content.includes('STATE.md') &&
(content.includes('git show HEAD:.planning/STATE.md') ||
content.includes('state-backup') ||
content.includes('STATE_BACKUP'))
);
assert.ok(hasStateBackup,
'execute-phase must backup STATE.md before worktree merge to prevent stale overwrite');
});
test('execute-phase.md backs up ROADMAP.md before worktree merge', () => {
const content = fs.readFileSync(EXECUTE_PHASE_PATH, 'utf-8');
const hasRoadmapBackup = (
content.includes('ROADMAP.md') &&
(content.includes('git show HEAD:.planning/ROADMAP.md') ||
content.includes('roadmap-backup') ||
content.includes('ROADMAP_BACKUP'))
);
assert.ok(hasRoadmapBackup,
'execute-phase must backup ROADMAP.md before worktree merge to prevent stale overwrite');
});
test('execute-phase.md restores orchestrator files after worktree merge', () => {
const content = fs.readFileSync(EXECUTE_PHASE_PATH, 'utf-8');
// After merge, orchestrator files must be restored from backup
const mergeIdx = content.indexOf('git merge');
const restoreSection = content.slice(mergeIdx);
const hasRestore = (
restoreSection.includes('cp ') ||
restoreSection.includes('git checkout HEAD') ||
restoreSection.includes('restore') ||
restoreSection.includes('BACKUP')
);
assert.ok(hasRestore,
'execute-phase must restore orchestrator files after merge (main always wins)');
});
test('execute-phase.md detects files deleted on main but re-added by worktree', () => {
const content = fs.readFileSync(EXECUTE_PHASE_PATH, 'utf-8');
// The merge step should detect and remove resurrected files
// (e.g., archived phase directories that main deleted)
const hasResurrectionDetection = (
content.includes('git diff') && content.includes('--diff-filter') ||
content.includes('resurrect') ||
content.includes('re-added') ||
content.includes('deleted on main') ||
content.includes('DELETED_FILES') ||
content.includes('PRE_MERGE_FILES')
);
assert.ok(hasResurrectionDetection,
'execute-phase must detect and remove files that main deleted but worktree re-added');
});
test('quick.md has the same orchestrator file protection', () => {
const content = fs.readFileSync(QUICK_PATH, 'utf-8');
const hasProtection = (
(content.includes('git show HEAD:.planning/STATE.md') ||
content.includes('state-backup') ||
content.includes('STATE_BACKUP')) &&
(content.includes('git show HEAD:.planning/ROADMAP.md') ||
content.includes('roadmap-backup') ||
content.includes('ROADMAP_BACKUP'))
);
assert.ok(hasProtection,
'quick.md must also protect orchestrator files during worktree merge');
});
});