Files
msd-core/tests/worktree-safety.test.cjs
Tom Boucher 918f987a19 feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes() (#2985)
* feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes()

The base lint (scripts/lint-no-source-grep.cjs) only catches
readFileSync(...).<text-method>() chained directly. The much more
common var-binding form escapes it:

  const src = fs.readFileSync(p, 'utf8');
  // 50 lines later
  if (src.includes('foo')) {}        // ← still grep, lint missed it

Scan of the test suite found ~141 files using this pattern.

Implementation built TDD per #2982 with structured-IR assertions:

  scripts/lint-no-source-grep-extras.cjs
    - detectVarBindingViolations(src) — pure detector, two passes:
      pass 1 collects vars bound from readFileSync, pass 2 finds any
      <var>.<includes|startsWith|endsWith|match|search>( on those vars.
    - detectWrappedAssertOkMatch(src) — flags
      assert.ok(<expr>.match(...)) which escapes the assert.match rule.
    - VIOLATION enum exposes stable codes for tests to assert on.

  scripts/lint-no-source-grep.cjs
    - Wires the new detectors into the existing per-file check; one
      additional violation row per file with the first 3 sample tokens.

  tests/bug-2982-lint-var-binding.test.cjs
    - 13 tests, all assertions on typed VIOLATION enum / structured
      records. Covers all 5 text-match methods, multi-var, no-bind,
      string literal (must NOT trigger), wrapped assert.ok(.match),
      and assert.match (must NOT double-flag).

Migration backlog (#2974 expanded scope):

  - 42 files annotated `// allow-test-rule: source-text-is-the-product`
    (legitimate — they read .md/.json/.yml files whose deployed text
    IS the product)
  - 3 files annotated `// allow-test-rule: pending-migration-to-typed-ir [#2974]`
    (read .cjs/.js source — clear migration debt)
  - 95 files annotated `pending-migration-to-typed-ir [#2974]` with
    `Per-file review may reclassify as source-text-is-the-product
    during migration` (mixed — manual review under #2974)

After this lands the lint reports 0 violations on main; new
violations in PRs surface immediately.

Closes #2982
Refs #2974

* test(#2982): fix truncated test name per CR

The label ended with a bare '(' from a copy-paste mishap. Now reads
'does NOT flag .matchAll(...) — matchAll is not match, so
assert.ok(.matchAll(...)) is not flagged'.

* chore(#2982): add changeset fragment for PR #2985

* chore(#2982): add changeset fragment for PR #2985
2026-05-01 19:50:10 -04:00

118 lines
4.8 KiB
JavaScript

// allow-test-rule: pending-migration-to-typed-ir [#2974]
// Tracked in #2974 for migration to typed-IR assertions per CONTRIBUTING.md
// "Prohibited: Raw Text Matching on Test Outputs". Do not copy this pattern.
/**
* Worktree commit safety hardening tests (#1977)
*
* Three checks:
* 1. worktree_branch_check in execute-plan.md is NOT labeled as Windows-only
* (the bug affects all platforms — no platform qualifier should narrow the fix)
* 2. gsd-executor.md task_commit_protocol includes post-commit deletion verification
* (using --diff-filter=D to catch accidental file deletions per task)
* 3. execute-phase.md worktree merge section includes pre-merge deletion check
* (using --diff-filter=D to block merges that would delete tracked files)
*/
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('fs');
const path = require('path');
const EXECUTE_PLAN_PATH = path.join(__dirname, '..', 'get-shit-done', 'workflows', 'execute-plan.md');
const EXECUTOR_AGENT_PATH = path.join(__dirname, '..', 'agents', 'gsd-executor.md');
const EXECUTE_PHASE_PATH = path.join(__dirname, '..', 'get-shit-done', 'workflows', 'execute-phase.md');
describe('worktree commit safety hardening (#1977)', () => {
test('execute-plan worktree_branch_check has no Windows-only platform qualifier', () => {
const content = fs.readFileSync(EXECUTE_PLAN_PATH, 'utf-8');
// The worktree_branch_check block must exist
assert.ok(
content.includes('worktree_branch_check'),
'execute-plan.md must contain a worktree_branch_check block'
);
// Search the whole file for any Windows-only qualifier near worktree_branch_check
// Must NOT say "Windows-only" or restrict the check to Windows
const hasWindowsOnlyQualifier = (
/Windows.only/i.test(content) ||
/affects Windows only/i.test(content) ||
/only on Windows/i.test(content) ||
/Windows-specific/i.test(content)
);
assert.ok(
!hasWindowsOnlyQualifier,
'worktree_branch_check must not be labeled as Windows-only — the bug affects all platforms'
);
// Must indicate the fix is universal (affects all platforms or similar)
// The description must exist somewhere in the file
const isUniversal = (
/affects all platforms/i.test(content) ||
/all platforms/i.test(content) ||
/cross.platform/i.test(content)
);
assert.ok(
isUniversal,
'worktree_branch_check description must indicate the fix applies to all platforms'
);
});
test('gsd-executor.md task_commit_protocol includes post-commit deletion verification', () => {
const content = fs.readFileSync(EXECUTOR_AGENT_PATH, 'utf-8');
// Must contain --diff-filter=D deletion check
assert.ok(
content.includes('--diff-filter=D'),
'gsd-executor.md must include --diff-filter=D deletion verification after each task commit'
);
// Must include a WARNING or notice about deletions
assert.ok(
content.includes('WARNING') || content.includes('DELETIONS'),
'gsd-executor.md must warn when a commit includes file deletions'
);
});
test('execute-phase.md worktree merge section includes pre-merge deletion check', () => {
const content = fs.readFileSync(EXECUTE_PHASE_PATH, 'utf-8');
// The merge section must exist
const mergeIdx = content.indexOf('git merge');
assert.ok(mergeIdx > -1, 'execute-phase.md must contain a git merge operation');
// Find the window before the merge command to check for pre-merge deletion detection
// Look broadly for --diff-filter=D in the worktree cleanup section
const worktreeCleanupStart = content.indexOf('Worktree cleanup');
assert.ok(
worktreeCleanupStart > -1,
'execute-phase.md must have a worktree cleanup section'
);
const cleanupSection = content.slice(worktreeCleanupStart);
// Must include --diff-filter=D for deletion detection
assert.ok(
cleanupSection.includes('--diff-filter=D'),
'execute-phase.md worktree merge section must include --diff-filter=D to check for deletions before merge'
);
// The deletion check must appear BEFORE the git merge call within the cleanup section
const deletionCheckIdx = cleanupSection.indexOf('--diff-filter=D');
const gitMergeIdx = cleanupSection.indexOf('git merge');
assert.ok(
deletionCheckIdx < gitMergeIdx,
'deletion check (--diff-filter=D) must appear before git merge in the worktree cleanup section'
);
// Must have a BLOCKED or warning message for when deletions are found
assert.ok(
cleanupSection.includes('BLOCKED') || cleanupSection.includes('DELETIONS') || cleanupSection.includes('deletion'),
'execute-phase.md must warn or block when the worktree branch contains file deletions'
);
});
});