* feat(#2982): extend no-source-grep lint to catch var-binding readFileSync.includes() The base lint (scripts/lint-no-source-grep.cjs) only catches readFileSync(...).<text-method>() chained directly. The much more common var-binding form escapes it: const src = fs.readFileSync(p, 'utf8'); // 50 lines later if (src.includes('foo')) {} // ← still grep, lint missed it Scan of the test suite found ~141 files using this pattern. Implementation built TDD per #2982 with structured-IR assertions: scripts/lint-no-source-grep-extras.cjs - detectVarBindingViolations(src) — pure detector, two passes: pass 1 collects vars bound from readFileSync, pass 2 finds any <var>.<includes|startsWith|endsWith|match|search>( on those vars. - detectWrappedAssertOkMatch(src) — flags assert.ok(<expr>.match(...)) which escapes the assert.match rule. - VIOLATION enum exposes stable codes for tests to assert on. scripts/lint-no-source-grep.cjs - Wires the new detectors into the existing per-file check; one additional violation row per file with the first 3 sample tokens. tests/bug-2982-lint-var-binding.test.cjs - 13 tests, all assertions on typed VIOLATION enum / structured records. Covers all 5 text-match methods, multi-var, no-bind, string literal (must NOT trigger), wrapped assert.ok(.match), and assert.match (must NOT double-flag). Migration backlog (#2974 expanded scope): - 42 files annotated `// allow-test-rule: source-text-is-the-product` (legitimate — they read .md/.json/.yml files whose deployed text IS the product) - 3 files annotated `// allow-test-rule: pending-migration-to-typed-ir [#2974]` (read .cjs/.js source — clear migration debt) - 95 files annotated `pending-migration-to-typed-ir [#2974]` with `Per-file review may reclassify as source-text-is-the-product during migration` (mixed — manual review under #2974) After this lands the lint reports 0 violations on main; new violations in PRs surface immediately. Closes #2982 Refs #2974 * test(#2982): fix truncated test name per CR The label ended with a bare '(' from a copy-paste mishap. Now reads 'does NOT flag .matchAll(...) — matchAll is not match, so assert.ok(.matchAll(...)) is not flagged'. * chore(#2982): add changeset fragment for PR #2985 * chore(#2982): add changeset fragment for PR #2985
101 lines
4.2 KiB
JavaScript
101 lines
4.2 KiB
JavaScript
'use strict';
|
|
// allow-test-rule: pending-migration-to-typed-ir [#2974]
|
|
// Tracked in #2974 for migration to typed-IR assertions per CONTRIBUTING.md
|
|
// "Prohibited: Raw Text Matching on Test Outputs". Do not copy this pattern.
|
|
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const path = require('node:path');
|
|
|
|
const { detectVarBindingViolations, VIOLATION } = require(path.join(__dirname, '..', 'scripts', 'lint-no-source-grep-extras.cjs'));
|
|
|
|
// detectVarBindingViolations is pure: takes source text, returns a list of
|
|
// violation records. Tests assert on the structured records, not on the
|
|
// detector's prose (per "Prohibited: Raw Text Matching on Test Outputs").
|
|
|
|
describe('Bug #2982: var-binding readFileSync.includes() detector', () => {
|
|
test('VIOLATION enum exposes the documented codes', () => {
|
|
assert.deepEqual(
|
|
Object.keys(VIOLATION).sort(),
|
|
['VAR_FROM_READFILE_USED_IN_TEXT_MATCH', 'WRAPPED_ASSERT_OK_MATCH'].sort(),
|
|
);
|
|
});
|
|
|
|
test('flags a single var bound from readFileSync then used with .includes() later', () => {
|
|
const src = [
|
|
"const x = fs.readFileSync('foo.cjs', 'utf8');",
|
|
'// some lines later',
|
|
"if (x.includes('foo')) { /* ... */ }",
|
|
].join('\n');
|
|
const findings = detectVarBindingViolations(src);
|
|
assert.equal(findings.length, 1);
|
|
assert.equal(findings[0].kind, VIOLATION.VAR_FROM_READFILE_USED_IN_TEXT_MATCH);
|
|
assert.equal(findings[0].variable, 'x');
|
|
assert.equal(findings[0].method, 'includes');
|
|
});
|
|
});
|
|
|
|
describe('Bug #2982: var-binding detector — coverage of methods (#2982)', () => {
|
|
const { detectVarBindingViolations, VIOLATION } = require(require('node:path').join(__dirname, '..', 'scripts', 'lint-no-source-grep-extras.cjs'));
|
|
|
|
for (const method of ['includes', 'startsWith', 'endsWith', 'match', 'search']) {
|
|
test(`flags <var>.${method}( on a readFileSync-bound variable`, () => {
|
|
const src = `const c = fs.readFileSync('x.cjs','utf8');\nc.${method}('foo');\n`;
|
|
const findings = detectVarBindingViolations(src);
|
|
assert.equal(findings.length, 1);
|
|
assert.equal(findings[0].method, method);
|
|
});
|
|
}
|
|
|
|
test('flags multiple violations across multiple variables', () => {
|
|
const src = [
|
|
"const a = readFileSync('a.cjs', 'utf8');",
|
|
"const b = fs.readFileSync('b.cjs');",
|
|
"if (a.includes('x')) {}",
|
|
"if (b.startsWith('y')) {}",
|
|
"a.endsWith('z');",
|
|
].join('\n');
|
|
const findings = detectVarBindingViolations(src);
|
|
assert.equal(findings.length, 3);
|
|
const byVar = findings.reduce((acc, f) => {
|
|
acc[f.variable] = (acc[f.variable] || []).concat(f.method);
|
|
return acc;
|
|
}, {});
|
|
assert.deepEqual(byVar.a.sort(), ['endsWith', 'includes']);
|
|
assert.deepEqual(byVar.b, ['startsWith']);
|
|
});
|
|
|
|
test('does NOT flag .includes() on a variable that was not bound from readFileSync', () => {
|
|
const src = "const arr = [1, 2, 3];\nif (arr.includes(2)) {}";
|
|
assert.deepEqual(detectVarBindingViolations(src), []);
|
|
});
|
|
|
|
test('does NOT flag a fresh string literal substring check', () => {
|
|
const src = "if ('hello world'.includes('world')) {}";
|
|
assert.deepEqual(detectVarBindingViolations(src), []);
|
|
});
|
|
});
|
|
|
|
describe('Bug #2982: assert.ok(...match(...)) detector', () => {
|
|
const { detectWrappedAssertOkMatch, VIOLATION } = require(require('node:path').join(__dirname, '..', 'scripts', 'lint-no-source-grep-extras.cjs'));
|
|
|
|
test('flags assert.ok(text.match(/.../)) which escapes assert.match', () => {
|
|
const src = "assert.ok(text.match(/Failures: \\d+/));";
|
|
const findings = detectWrappedAssertOkMatch(src);
|
|
assert.equal(findings.length, 1);
|
|
assert.equal(findings[0].kind, VIOLATION.WRAPPED_ASSERT_OK_MATCH);
|
|
});
|
|
|
|
test('does NOT flag assert.match itself (covered by base lint)', () => {
|
|
const src = "assert.match(text, /foo/);";
|
|
assert.deepEqual(detectWrappedAssertOkMatch(src), []);
|
|
});
|
|
|
|
test('does NOT flag .matchAll(...) — matchAll is not match, so assert.ok(.matchAll(...)) is not flagged', () => {
|
|
const src = "assert.ok([...text.matchAll(/foo/g)].length > 0);";
|
|
assert.deepEqual(detectWrappedAssertOkMatch(src), []);
|
|
});
|
|
});
|