Files
msd-core/tests/worktree-safety-policy.test.cjs
Tom Boucher 8bc255c266 fix(workstream): normalize migration workstream names (#3269)
* fix(workstream): normalize migrate-name to valid slug

* docs(context): record workstream migrate-name slug invariant

* fix(catalog-cjs): balanced fallback for unknown profile (CR finding A)

profiles[profile] could return undefined for any profile key absent from
the catalog entry, causing downstream callers like formatAgentToModelMapAsTable
to crash on .length. Add ?? profiles.balanced fallback to match the SDK adapter.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test(sdk): anchor path resolution on import.meta.url not cwd (CR finding B)

resolve(process.cwd(), '..') breaks when Vitest is invoked from the repo root
because cwd is already the repo root and '..' goes one level above. Replace
with a file-relative path using fileURLToPath(new URL('../../../', import.meta.url))
anchored at the test file's location (sdk/src/query/).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test: derive Group B runtime list from catalog (CR finding C)

Hardcoded ['kilo', 'cline', ...] throws TypeError if a runtime name is
removed from the catalog. Derive group B dynamically via
Object.keys(catalog.runtimeTierDefaults).filter(r => !r.opus) so the
test never goes stale and auto-covers future Group B additions.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(workflow): add hermes to Step B runtime options (CR finding D)

hermes appears in the Group A built-in defaults table but was missing from
the AskUserQuestion options in Step B, forcing users to manually type it via
'Other (Group B or custom)'. Add explicit hermes entry for UI consistency.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* docs(config): refresh dynamic_routing tier table; fix stale L671 (findings E+F)

Finding E: tier table was missing 6 heavy-tier agents and 15 standard/light
agents added by this PR. Updated all three rows to match catalog routingTier
assignments (33 agents total).

Finding F: removed stale '18 of 31' claim and agent enumeration; replaced
with accurate note that all 33 agents have explicit catalog entries. Updated
authoritative source pointers to model-catalog.cjs / model-catalog.ts.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* test(core): add profile-fallback unit tests for quality and budget (CR nitpick G)

The PR introduced quality→opus and budget→haiku unknown-agent fallbacks but
only balanced→sonnet and inherit→inherit were tested. Add two tests covering
the remaining two branches to complete coverage.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* adr: define planning workspace and worktree seam

* refactor(worktree): extract worktree safety policy module

* refactor(workstream): extract active workstream pointer store seam

* test(worktree): cover policy branch paths and persist seam guardrails

* refactor(worktree): centralize health inventory seam for W017

* fix(workspace): align SDK project path policy with CJS planningDir

* refactor(query): unify SDK planning path projection seam

* refactor(init): route workspace projection through planningPaths seam

* docs(adr): add SDK architecture and planning path ADRs

* refactor(worktree): deepen name, pointer, inventory, and config seams

* docs(config): harmonize claude-opus-4-6 to 4-7 in resolve_model_ids example (CR finding 2)

* fix(sdk): return undefined for model_profile='inherit' sentinel (CR finding 3)

* docs(adr): renumber conflicting 0003-sdk-package-seam-module to 0007, update seam-map reference (CR finding 4)

* fix(workstream): align CJS and SDK name validation to accept dots, guard path traversal via includes('..') (CR finding 5)

* fix(sdk): guard writeActiveWorkstream against non-existent workstream directory, k014/k031 parity (CR finding 6)

* chore(changeset): add #3269 changeset (CR finding 1 — proper changeset for this PR)

* docs(inventory): register 3 new CLI modules in INVENTORY.md/MANIFEST (active-workstream-store, workstream-name-policy, worktree-safety)

* fix(sdk): use relPlanningPath(workstream) in planningPaths, fix setActiveWorkstream/getActiveWorkstream name errors in workstream.ts

* fix(sdk): validate GSD_WORKSTREAM in planningPaths before use (#3269 regression)

planningPaths() called resolveWorkspaceContext() which returned GSD_WORKSTREAM
raw (no validation). An invalid value like '../evil' was used as effectiveWorkstream,
constructing a bad path; roadmapAnalyze() caught the ENOENT and returned a
no-phase_count error object instead of the root ROADMAP result.

Fix: validate envCtx.workstream with validateWorkstreamName() in planningPaths()
before accepting it as effectiveWorkstream. Invalid env → null → root .planning/
fallback, preserving the bug-2791 contract: invalid GSD_WORKSTREAM is silently
ignored and falls back to the root context (phase_count: 0 for empty root ROADMAP).

The bug-2791 regression test now passes. No other call sites read GSD_WORKSTREAM
without validation: query-runtime-context.ts already validates; cli.ts already
validates; context-engine.ts takes a caller-validated workstream parameter.

Closes #3268 (regression introduced by #3269 workstream-name-policy work).

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-09 00:15:04 -04:00

273 lines
9.3 KiB
JavaScript

'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const {
resolveWorktreeContext,
parseWorktreePorcelain,
planWorktreePrune,
executeWorktreePrunePlan,
listLinkedWorktreePaths,
inspectWorktreeHealth,
snapshotWorktreeInventory,
} = require('../get-shit-done/bin/lib/worktree-safety.cjs');
describe('worktree-safety policy module', () => {
test('resolveWorktreeContext prefers current directory when .planning exists', () => {
const context = resolveWorktreeContext('/repo/wt', {
existsSync: () => true,
execGit: () => ({ exitCode: 1, stdout: '', stderr: '' }),
});
assert.strictEqual(context.effectiveRoot, '/repo/wt');
assert.strictEqual(context.reason, 'has_local_planning');
assert.strictEqual(context.mode, 'current_directory');
});
test('resolveWorktreeContext maps linked worktree to common-dir parent', () => {
const context = resolveWorktreeContext('/repo/wt', {
existsSync: () => false,
execGit: (_, args) => {
if (args[1] === '--git-dir') return { exitCode: 0, stdout: '.git/worktrees/wt', stderr: '' };
if (args[1] === '--git-common-dir') return { exitCode: 0, stdout: '../.git', stderr: '' };
return { exitCode: 1, stdout: '', stderr: '' };
},
});
assert.strictEqual(context.effectiveRoot, '/repo');
assert.strictEqual(context.reason, 'linked_worktree');
assert.strictEqual(context.mode, 'linked_worktree_root');
});
test('resolveWorktreeContext falls back when git metadata is unavailable', () => {
const context = resolveWorktreeContext('/repo/wt', {
existsSync: () => false,
execGit: () => ({ exitCode: 1, stdout: '', stderr: '' }),
});
assert.strictEqual(context.effectiveRoot, '/repo/wt');
assert.strictEqual(context.reason, 'not_git_repo');
});
test('resolveWorktreeContext keeps cwd for main worktree checkout', () => {
const context = resolveWorktreeContext('/repo/main', {
existsSync: () => false,
execGit: (_, args) => {
if (args[1] === '--git-dir') return { exitCode: 0, stdout: '.git', stderr: '' };
if (args[1] === '--git-common-dir') return { exitCode: 0, stdout: '.git', stderr: '' };
return { exitCode: 1, stdout: '', stderr: '' };
},
});
assert.strictEqual(context.effectiveRoot, '/repo/main');
assert.strictEqual(context.reason, 'main_worktree');
assert.strictEqual(context.mode, 'current_directory');
});
test('parseWorktreePorcelain skips detached HEAD entries', () => {
const porcelain = [
'worktree /repo/main',
'HEAD deadbeef',
'branch refs/heads/main',
'',
'worktree /repo/wt-detached',
'HEAD cafe1234',
'detached',
'',
'worktree /repo/wt-feature',
'HEAD f00dbabe',
'branch refs/heads/feature-x',
'',
].join('\n');
const parsed = parseWorktreePorcelain(porcelain);
assert.deepStrictEqual(parsed, [
{ path: '/repo/main', branch: 'main' },
{ path: '/repo/wt-feature', branch: 'feature-x' },
]);
});
test('planWorktreePrune is non-destructive by default', () => {
const plan = planWorktreePrune('/repo/main', {}, {
execGit: () => ({ exitCode: 0, stdout: 'worktree /repo/main\nbranch refs/heads/main\n', stderr: '' }),
parseWorktreePorcelain: () => [{ path: '/repo/main', branch: 'main' }],
});
assert.strictEqual(plan.action, 'metadata_prune_only');
assert.strictEqual(plan.reason, 'worktrees_present');
assert.strictEqual(plan.destructiveModeRequested, false);
});
test('planWorktreePrune keeps metadata-prune action when destructive mode is requested (scaffold)', () => {
const plan = planWorktreePrune('/repo/main', { allowDestructive: true }, {
execGit: () => ({ exitCode: 0, stdout: '', stderr: '' }),
parseWorktreePorcelain: () => [],
});
assert.strictEqual(plan.action, 'metadata_prune_only');
assert.strictEqual(plan.reason, 'no_worktrees');
assert.strictEqual(plan.destructiveModeRequested, true);
});
test('planWorktreePrune skips when git worktree list fails', () => {
const plan = planWorktreePrune('/repo/main', {}, {
execGit: () => ({ exitCode: 2, stdout: '', stderr: 'fatal' }),
});
assert.strictEqual(plan.action, 'skip');
assert.strictEqual(plan.reason, 'git_list_failed');
});
test('planWorktreePrune still metadata-prunes when porcelain parser throws', () => {
const plan = planWorktreePrune('/repo/main', {}, {
execGit: () => ({ exitCode: 0, stdout: 'not-porcelain', stderr: '' }),
parseWorktreePorcelain: () => {
throw new Error('parse failed');
},
});
assert.strictEqual(plan.action, 'metadata_prune_only');
assert.strictEqual(plan.reason, 'no_worktrees');
});
test('executeWorktreePrunePlan runs git worktree prune for metadata plan', () => {
const calls = [];
const result = executeWorktreePrunePlan(
{ repoRoot: '/repo/main', action: 'metadata_prune_only', reason: 'worktrees_present' },
{
execGit: (cwd, args) => {
calls.push({ cwd, args });
return { exitCode: 0, stdout: '', stderr: '' };
},
}
);
assert.strictEqual(result.ok, true);
assert.deepStrictEqual(calls, [{ cwd: '/repo/main', args: ['worktree', 'prune'] }]);
});
test('executeWorktreePrunePlan returns skip for missing plan', () => {
const result = executeWorktreePrunePlan(null, {
execGit: () => ({ exitCode: 0, stdout: '', stderr: '' }),
});
assert.strictEqual(result.ok, false);
assert.strictEqual(result.action, 'skip');
assert.strictEqual(result.reason, 'missing_plan');
});
test('executeWorktreePrunePlan returns skip plan unchanged without git call', () => {
let called = false;
const result = executeWorktreePrunePlan(
{ repoRoot: '/repo/main', action: 'skip', reason: 'git_list_failed' },
{
execGit: () => {
called = true;
return { exitCode: 0, stdout: '', stderr: '' };
},
}
);
assert.strictEqual(result.ok, false);
assert.strictEqual(result.action, 'skip');
assert.strictEqual(result.reason, 'git_list_failed');
assert.strictEqual(called, false);
});
test('executeWorktreePrunePlan rejects unsupported actions', () => {
const result = executeWorktreePrunePlan(
{ repoRoot: '/repo/main', action: 'remove_missing_paths', reason: 'explicit' },
{
execGit: () => ({ exitCode: 0, stdout: '', stderr: '' }),
}
);
assert.strictEqual(result.ok, false);
assert.strictEqual(result.action, 'remove_missing_paths');
assert.strictEqual(result.reason, 'unsupported_action');
});
test('listLinkedWorktreePaths parses porcelain and skips first/main path', () => {
const listed = listLinkedWorktreePaths('/repo/main', {
execGit: () => ({
exitCode: 0,
stdout: [
'worktree /repo/main',
'HEAD aaa',
'branch refs/heads/main',
'',
'worktree /repo/wt-a',
'HEAD bbb',
'branch refs/heads/feat-a',
'',
'worktree /repo/wt-b',
'HEAD ccc',
'detached',
'',
].join('\n'),
stderr: '',
}),
});
assert.strictEqual(listed.ok, true);
assert.deepStrictEqual(listed.paths, ['/repo/wt-a', '/repo/wt-b']);
});
test('inspectWorktreeHealth reports orphan and stale findings', () => {
const health = inspectWorktreeHealth(
'/repo/main',
{ staleAfterMs: 60 * 60 * 1000, nowMs: 2 * 60 * 60 * 1000 },
{
execGit: () => ({
exitCode: 0,
stdout: [
'worktree /repo/main',
'HEAD aaa',
'branch refs/heads/main',
'',
'worktree /repo/wt-orphan',
'HEAD bbb',
'branch refs/heads/feat-a',
'',
'worktree /repo/wt-stale',
'HEAD ccc',
'branch refs/heads/feat-b',
'',
].join('\n'),
stderr: '',
}),
existsSync: p => p !== '/repo/wt-orphan',
statSync: () => ({ mtimeMs: 0 }),
}
);
assert.strictEqual(health.ok, true);
assert.deepStrictEqual(health.findings, [
{ kind: 'orphan', path: '/repo/wt-orphan' },
{ kind: 'stale', path: '/repo/wt-stale', ageMinutes: 120 },
]);
});
test('snapshotWorktreeInventory returns typed linked-worktree entries', () => {
const inventory = snapshotWorktreeInventory(
'/repo/main',
{ staleAfterMs: 60 * 60 * 1000, nowMs: 2 * 60 * 60 * 1000 },
{
execGit: () => ({
exitCode: 0,
stdout: [
'worktree /repo/main',
'HEAD aaa',
'branch refs/heads/main',
'',
'worktree /repo/wt-a',
'HEAD bbb',
'branch refs/heads/feat-a',
'',
'worktree /repo/wt-b',
'HEAD ccc',
'branch refs/heads/feat-b',
'',
].join('\n'),
stderr: '',
}),
existsSync: p => p !== '/repo/wt-b',
statSync: () => ({ mtimeMs: 0 }),
}
);
assert.strictEqual(inventory.ok, true);
assert.deepStrictEqual(inventory.entries, [
{ path: '/repo/wt-a', exists: true, isStale: true, ageMinutes: 120 },
{ path: '/repo/wt-b', exists: false, isStale: false, ageMinutes: null },
]);
});
});