Files
msd-core/scripts/affected-tests-lib.cjs
Tom Boucher 463cffd894 chore(#604): rename get-shit-done/ runtime directory to gsd-core/ (#615)
* chore(#604): rename get-shit-done/ runtime directory to gsd-core/

Renames the installed runtime directory `get-shit-done/` to `gsd-core/` so the
on-disk name matches the package (`@opengsd/gsd-core`), repo, and binary
(`gsd-tools`). The npm package name and binary are unchanged; npx/npm consumers
are unaffected.

Mechanical (bulk, ~90% of the diff):
- `git mv get-shit-done gsd-core`
- Swept path/identifier references across the repo via
  `perl -pe 's/get-shit-done(?!-\w)/gsd-core/g'`. The negative lookahead
  preserves the five legitimate slug variants that are NOT the directory:
  get-shit-done-{OLD,cc,classic,cli,redux} (old package/repo names).
- Build/manifest wiring: package.json (bin, files, coverage globs),
  tsconfig.build.json (outDir), ~86 .gitignore build-output entries,
  stryker.config.mjs, scan-ignore files, install.js path strings.
- Frozen (not rewritten): CHANGELOG.md history; translated docs
  (README.<locale>.md and docs/{ja-JP,ko-KR,pt-BR,zh-CN}/).

New logic (review here):
- src/installer-migrations/003-rename-get-shit-done-to-gsd-core.cts: a proper
  ADR-0008 installer migration. On upgrade it walks the legacy
  `~/.claude/get-shit-done/` tree, classifies each file via the prior install
  manifest, and emits remove-managed / backup-and-remove for managed files
  while PRESERVING unknown user-added files. Symlink-safe (skips a symlinked
  root and symlinked entries; bounds-checks every path under configDir). The
  framework rolls back on install failure. Emptied dirs may remain (framework
  has no recursive dir-removal primitive) — documented.
- scripts/lint-legacy-dir-name.cjs: CI regression guard forbidding the bare
  `get-shit-done` directory token (split token to avoid self-match; case-
  insensitive; `(?!-\w)` lookahead allows the slug variants; allowlists
  CHANGELOG, translated docs, and `gsd-allow-legacy-name` marker lines).
  Wired into the lint-tests CI job.
- Restored scripts/lint-package-identity-drift.cjs detection regexes (the
  mechanical sweep had wrongly rewritten the old-name patterns it exists to
  detect) and marked them as intentional legacy references.
- TDD tests for the migration and the guard; do.md slash-command guard regex
  tightened so a `/gsd-core/bin` path segment is not mistaken for a command;
  changeset + docs/installer-migrations.md row added.

Breaking: the installed runtime path moves `~/.claude/get-shit-done/` ->
`~/.claude/gsd-core/`. Migration 003 removes the stale legacy dir's managed
files (preserving user files) on upgrade. Users with custom hooks/configs
hardcoding the old path must update them.

Closes #604

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): unsweep pending changesets + allowlist injection-example docs

CI fixes for the rename PR:
- Do not sweep pending .changeset/*.md (ephemeral release-note fragments,
  like CHANGELOG); reverted those body edits so 5 pre-existing malformed
  fragments (missing type/pr) no longer enter the PR diff and trip docs-lint.
  Allowlisted .changeset/ in the legacy-name guard accordingly.
- Allowlisted TEST-EXAMPLES.md and docs/explanation/security-model.md in
  prompt-injection-scan.sh: they contain intentional injection examples /
  security-model prose; the path-reference rewrites are kept.

CodeQL alerts on this PR are pre-existing (alert lines unchanged by this PR;
none in the new migration/guard) and are out of scope for the rename.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): resolve CodeQL alerts surfaced on this PR

The rename diff touched files carrying pre-existing CodeQL findings; per the
no-pre-existing-dismissal rule, fixing every surfaced alert rather than waving
them off. All behavior-preserving:

- scripts/ci-test-scope.cjs: build the config-path match from string
  .includes() instead of a RegExp over an arg-derived value (js/regex-injection).
- src/profile-output.cts: escape backslashes before pipe-escaping desc/safeName
  so the table-cell escape is complete (js/incomplete-sanitization).
- tests/{bug-2643,bug-2808,docs-parity-live-registry}: two-pass HTML-comment
  strip so a bare/unclosed `<!--` cannot survive (js/incomplete-multi-character-sanitization).
- tests/inline-plan-threshold: drop the no-op `\s`->`\s` identity replace,
  keep the meaningful POSIX-class conversion (js/identity-replacement).

Verified: build:lib green; the touched test files + ci-test-scope + profile-output
suites pass; lint:legacy-name clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): correctly resolve remaining CodeQL alerts (regex-injection + sanitization)

The prior commit's fixes for two alerts were ineffective:
- ci-test-scope.cjs js/regex-injection: the alert is the CLI-arg-derived `file`
  reaching static regex `.test(file)` calls (not the config rule). Removed ALL
  regex over file/t — startsWith/includes/=== string checks + an isWindowsHint
  helper — so there is no regex sink for the tainted value.
- js/incomplete-multi-character-sanitization (3 test files): a single
  `.replace(/<!--...-->/g,'')` can let `<!--` re-form. Replaced with a fixpoint
  loop (replace until stable) plus a final bare-opener strip.

Verified: no regex over file/t remains; ci-test-scope + the 3 test suites pass;
lint:legacy-name clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): make ci-test-scope + comment-strippers regex-free to clear CodeQL

CodeQL flags the regex PATTERNS syntactically (regex-injection on the
--files arg split; incomplete-multi-character-sanitization on the <!--...-->
replace), so loop fixes do not satisfy it. Made these paths regex-free:
- ci-test-scope.cjs splitFiles: char-by-char separator tokenizer (no /[,\\s]+/).
- 3 test files: indexOf/slice HTML-comment stripper (no .replace(/<!--/)).
Behavior preserved; ci-test-scope + the 3 suites pass; guard clean.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): unblock security base64 scan on the large rename diff

The security job hit its 10m timeout: base64-scan.sh choked on the binary
test fixture tests/feat-3594-parser-property-style.test.cjs (embedded NUL/
non-UTF8 bytes -> thousands of bogus blobs + "ignored null byte" warnings),
and the ~800-file rename diff is slow to scan regardless.

- scripts/base64-scan.sh: skip binary-by-content files (grep -Iq .) — they
  can't carry base64-obfuscated *text* and feeding NUL bytes through the
  per-line scanner is pathologically slow. collect_files already filtered
  binary *extensions*; this catches binary *content* in text extensions.
- .github/workflows/security-scan.yml: raise the security job timeout 10m->30m
  to accommodate very large diffs (the scan itself is unchanged).

Verified locally: scan skips the fixture, 0 "ignored null byte" warnings,
0 findings, exit 0.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): sweep get-shit-done refs introduced by merging next

The branch was updated with next (#614/#384/#618 etc.), which reference the
get-shit-done/ dir (still named that on next). Swept the stale references in
the merged files to gsd-core so the rename stays consistent and lint:legacy-name
passes:
- commands/gsd/discuss-phase.md (runtime-launcher shim paths)
- src/core.cts (getAgentsDir layout comments)
- tests/bug-384-agents-runtime-aware.test.cjs (require path to runtime lib)

Verified: guard 0 violations; build green.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): exclude gsd-core/ path segments from bug-3683 command cross-ref invariant

The #614 runtime-launcher shim added to discuss-phase.md references
`${_GSD_RUNTIME_ROOT}/gsd-core/bin/...`. bug-3683's REF_PATTERN excluded path-y
refs only via lookbehind, but `}` precedes `/gsd-core/` in the shim, so it
mis-read the directory path as a dangling `/gsd-core` command ref (same class as
the #604 bug-2954 fix). Added a trailing `(?![\w-]*\/)` so `/gsd-<x>/...` path
segments are not treated as slash-command references.

Verified locally on BOTH platforms before pushing:
- mac (node 26) full suite: 0 failures
- gsd-test-runner (linux, node22 image) full suite: 0 failures
- bug-3683 + bug-2954 pass.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): lazily resolve findProjectRoot in gsd-tools (harden flaky CI)

CI intermittently failed state.test's gsd-tools subprocess with
"findProjectRoot is not a function" (flip-flopping across legs; not reproducible
on mac full suite, gsd-test linux full suite, test:unit, or state.test x8).
findProjectRoot is a re-export from core.cjs (sourced from project-root.cjs);
binding it via destructure at module-load can be undefined under a load-ordering
edge. Resolve it lazily at call time via a small wrapper so the lookup happens
after core.cjs is fully initialized.

Verified green on BOTH platforms before pushing:
- mac (node 26) full suite: 0 failures
- gsd-test-runner (linux, node22) full suite: 0 failures
- state.test.cjs: 106/106; gsd-tools loads cleanly.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#604): allowlist verification-patterns.md placeholder examples in secret scan

The rename git-mv'd references/verification-patterns.md into gsd-core/, pulling
it into the secret-scan diff. It documents stub/placeholder RED-FLAG env-var
examples (illustrative Stripe test-key / database-URL / API-key placeholders) —
not real credentials. Added it to .secretscanignore with the strict annotation,
mirroring the existing gsd-core/workflows/plan-phase.md exception.

Verified locally: secret-scan-lint --strict OK; secret-scan --diff origin/next
exits 0 with 0 findings.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-02 18:35:29 -04:00

542 lines
18 KiB
JavaScript

'use strict';
const { execFileSync } = require('node:child_process');
const { readdirSync, readFileSync, existsSync } = require('node:fs');
const path = require('node:path');
const { suiteOf } = require('./run-tests.cjs');
const CRITICAL_PATHS = [
'.github/workflows/',
'package.json',
'package-lock.json',
'scripts/run-tests.cjs',
'scripts/affected-tests-lib.cjs',
'scripts/run-affected-tests.cjs',
];
// Suites that are push-only. PRs must never select or run these.
const PR_EXCLUDED_SUITES = new Set(['install', 'slow']);
// Suites run on every PR cell when the critical-path fallback fires.
const PR_FULL_SUITES = ['unit', 'integration', 'security'];
// Source trees to walk when building the forward graph (in addition to tests/).
// Relative to repoRoot. We walk these to discover SUT-internal requires so that
// a change to a deep helper propagates through re-export chains to tests.
const SOURCE_TREES = [
'gsd-core/bin/lib',
'bin/lib',
'bin',
'scripts',
'commands',
'hooks',
'agents',
'eslint-rules',
];
function toPosixPath(input) {
return input.split(path.sep).join('/');
}
function parseRelativeSpecifiers(source) {
const specifiers = [];
const requireRe = /require\((['"])(.+?)\1\)/g;
const importFromRe = /from\s+(['"])(.+?)\1/g;
let match;
while ((match = requireRe.exec(source)) !== null) {
specifiers.push(match[2]);
}
while ((match = importFromRe.exec(source)) !== null) {
specifiers.push(match[2]);
}
return specifiers.filter(specifier => specifier.startsWith('.'));
}
// Extended candidate list now includes .ts/.cts/.mts/.json as well as the
// standard .js/.cjs/.mjs and index variants.
function resolveRelativeDependency(repoRoot, fromAbs, specifier) {
const base = path.resolve(path.dirname(fromAbs), specifier);
const candidates = [
base,
`${base}.js`,
`${base}.cjs`,
`${base}.mjs`,
`${base}.ts`,
`${base}.cts`,
`${base}.mts`,
`${base}.json`,
path.join(base, 'index.js'),
path.join(base, 'index.cjs'),
path.join(base, 'index.mjs'),
path.join(base, 'index.ts'),
];
for (const candidate of candidates) {
if (existsSync(candidate)) {
return toPosixPath(path.relative(repoRoot, candidate));
}
}
return null;
}
// ---------------------------------------------------------------------------
// Source-file walker
// ---------------------------------------------------------------------------
/**
* Collect all .cjs / .mjs / .js / .ts / .cts / .mts / .json files under a
* directory tree, returned as repo-relative POSIX paths. Silently skips
* trees that don't exist.
*/
function walkTree(repoRoot, relDir) {
const absDir = path.join(repoRoot, relDir);
if (!existsSync(absDir)) return [];
const results = [];
const queue = [absDir];
while (queue.length > 0) {
const cur = queue.shift();
let entries;
try {
entries = readdirSync(cur, { withFileTypes: true });
} catch {
continue;
}
for (const entry of entries) {
const abs = path.join(cur, entry.name);
if (entry.isDirectory()) {
// Skip node_modules
if (entry.name === 'node_modules') continue;
queue.push(abs);
} else if (entry.isFile()) {
const ext = path.extname(entry.name);
if (['.js', '.cjs', '.mjs', '.ts', '.cts', '.mts', '.json'].includes(ext)) {
results.push(toPosixPath(path.relative(repoRoot, abs)));
}
}
}
}
return results;
}
// ---------------------------------------------------------------------------
// Forward graph: Map<fileRel, Set<depRel>>
// ---------------------------------------------------------------------------
/**
* Build a forward dependency graph over test files PLUS source trees.
* For each file: read, parseRelativeSpecifiers, resolve each specifier.
* Returns Map<fileRel, Set<depRel>>.
*/
function buildForwardGraph(repoRoot, testFiles) {
// Collect all files to index: test files + source files
const sourceFiles = [];
for (const tree of SOURCE_TREES) {
for (const f of walkTree(repoRoot, tree)) {
sourceFiles.push(f);
}
}
const allFiles = [...new Set([...testFiles, ...sourceFiles])];
const forward = new Map();
for (const fileRel of allFiles) {
const absFile = path.join(repoRoot, fileRel);
let source;
try {
source = readFileSync(absFile, 'utf8');
} catch {
continue;
}
const specs = parseRelativeSpecifiers(source);
const deps = new Set();
for (const specifier of specs) {
const dep = resolveRelativeDependency(repoRoot, absFile, specifier);
if (dep) deps.add(dep);
}
forward.set(fileRel, deps);
}
return forward;
}
// ---------------------------------------------------------------------------
// Reverse-transitive index: Map<depRel, Set<testRel>>
// ---------------------------------------------------------------------------
/**
* Build the TRANSITIVE reverse index: Map<depRel, Set<testRel>>.
*
* Algorithm:
* 1. Build forward graph over all test + source files.
* 2. Invert to direct reverse edges: Map<depRel, Set<dependentRel>>.
* 3. For each test file, BFS backwards through all direct reverse edges
* to find every ancestor. Map each ancestor → the test.
*
* Cycle safety: visited set per BFS — each node is enqueued at most once.
*
* @param {string} repoRoot
* @param {string[]} testFiles repo-relative posix paths (e.g. ['tests/foo.test.cjs'])
* @returns {Map<string, Set<string>>}
*/
function buildTransitiveReverseIndex(repoRoot, testFiles) {
const forward = buildForwardGraph(repoRoot, testFiles);
// Build direct reverse edges: dep → Set of files that directly require dep
const directReverse = new Map();
for (const [fileRel, deps] of forward) {
for (const dep of deps) {
if (!directReverse.has(dep)) directReverse.set(dep, new Set());
directReverse.get(dep).add(fileRel);
}
}
// For each test file, BFS through direct reverse edges to collect all
// ancestors, then invert: ancestor → test.
// We do this test-file-first (not dep-first) so we know which test reached
// each ancestor.
const transitiveReverse = new Map();
for (const testFile of testFiles) {
// BFS from testFile following reverse edges (files that point TO testFile,
// then files that point to THOSE files, etc.).
// We want: "if X changed, would that eventually pull in testFile?"
// So we walk the FORWARD graph starting from testFile to find all deps,
// then any of those deps maps back to testFile.
// Actually simpler: for each test we do a forward BFS to find ALL files
// the test transitively depends on. Then we record testFile as a
// dependent of each of those files.
const visited = new Set();
visited.add(testFile);
const queue = [testFile];
while (queue.length > 0) {
const current = queue.shift();
const deps = forward.get(current);
if (!deps) continue;
for (const dep of deps) {
if (visited.has(dep)) continue;
visited.add(dep);
queue.push(dep);
}
}
// Every file in `visited` (except testFile itself) is a transitive dep.
// Record testFile as a dependent of each.
for (const dep of visited) {
if (dep === testFile) continue;
if (!transitiveReverse.has(dep)) transitiveReverse.set(dep, new Set());
transitiveReverse.get(dep).add(testFile);
}
}
return transitiveReverse;
}
// ---------------------------------------------------------------------------
// Legacy shim — kept so that runAffectedTests can call buildTransitiveReverseIndex
// and existing call sites that still call buildReverseIndex still work.
// ---------------------------------------------------------------------------
function buildReverseIndex(repoRoot, testFiles) {
return buildTransitiveReverseIndex(repoRoot, testFiles);
}
function shouldRunFullSuite(changedFiles) {
return changedFiles.some(file =>
CRITICAL_PATHS.some(critical => file === critical || file.startsWith(critical)),
);
}
function listTestFiles(repoRoot) {
return readdirSync(path.join(repoRoot, 'tests'))
.filter(file => file.endsWith('.test.cjs'))
.map(file => `tests/${file}`)
.sort();
}
/**
* Select the affected tests given a set of changed files and a reverse index.
*
* Options:
* detectWiden {boolean} — when true, attach `._widenRequired = true` to the
* returned array when a changed source file has zero transitive test
* dependents. The caller (runAffectedTests) uses this to widen to unit/all.
*
* The returned array is sorted and may have `._widenRequired` attached.
*/
function pickAffectedTests(changedFiles, allTests, reverseIndex, options = {}) {
const { detectWiden = false } = options;
const selected = new Set();
let widenRequired = false;
// Build a fast lookup of currently-existing test files (from readdirSync — deleted files absent).
const allTestsSet = new Set(allTests);
// (a) directly-changed test files + (b) transitive test dependents
// Deleted test files are filtered out — they no longer exist and cannot be run.
// A deleted test file also must NOT trigger widen (the test is simply gone).
for (const file of changedFiles) {
if (file.startsWith('tests/') && file.endsWith('.test.cjs')) {
// Only select if the test file still exists (i.e. is present in allTests from readdirSync).
if (allTestsSet.has(file)) {
selected.add(file);
}
// Deleted test file — do not add to selected; do not look up reverse index.
} else {
const dependents = reverseIndex.get(file);
if (dependents) {
for (const testFile of dependents) selected.add(testFile);
}
}
}
// (c) stem heuristic — kept as secondary mechanism
for (const file of changedFiles) {
const stem = path.basename(file).replace(/\.[^.]+$/, '').toLowerCase();
if (!stem) continue;
for (const testFile of allTests) {
if (testFile.toLowerCase().includes(stem)) selected.add(testFile);
}
}
// Widen backstop: if a changed file is a non-test, non-CRITICAL_PATH source file
// (recognised extension) under a SOURCE_TREE, AND it is either deleted (no longer
// on disk — so never in the forward graph and has no static dependents) OR it
// exists with ZERO transitive test dependents — signal a widen.
// NOTE: we deliberately do NOT skip deleted files here; a deleted source file's
// absence from the forward graph means dependents===undefined, which is the same
// as zero static dependents, and is itself the widen trigger.
if (detectWiden) {
for (const file of changedFiles) {
// Only care about source files, not test files or docs
if (file.startsWith('tests/')) continue;
if (shouldRunFullSuite([file])) continue; // critical path already triggers full suite
// Check: is this a source file (has a recognised extension)?
const ext = path.extname(file);
const isSourceFile = ['.js', '.cjs', '.mjs', '.ts', '.cts', '.mts', '.json'].includes(ext);
if (!isSourceFile) continue;
// Check: is this file under a recognised source tree?
const isUnderSourceTree = SOURCE_TREES.some(
tree => file === tree || file.startsWith(tree + '/'),
);
if (!isUnderSourceTree) continue;
// Does it have any test dependents?
// A deleted file will have undefined here (not in the graph) — that is
// treated as zero static dependents and triggers widen conservatively.
const dependents = reverseIndex.get(file);
const hasStaticDependents = dependents && dependents.size > 0;
if (!hasStaticDependents) {
widenRequired = true;
break;
}
}
}
// Drop any file whose suite is push-only. This is the single chokepoint —
// it catches direct-change, reverse-index, AND stem-match selections.
for (const file of selected) {
const suite = suiteOf(path.basename(file));
if (PR_EXCLUDED_SUITES.has(suite)) selected.delete(file);
}
// When nothing maps, return an empty array. The caller decides the fallback.
const result = [...selected].sort();
if (widenRequired) result._widenRequired = true;
return result;
}
function changedFilesSinceBase(repoRoot, baseRef) {
const out = execFileSync(
'git',
['diff', '--name-only', '--no-renames', '--diff-filter=ACMRD', `${baseRef}...HEAD`],
{ cwd: repoRoot, encoding: 'utf8' },
).trim();
if (!out) return [];
return out.split('\n').map(line => line.trim()).filter(Boolean);
}
function runNodeTestFiles(repoRoot, files) {
const defaultConcurrency = process.platform === 'win32' ? 2 : 4;
const concurrency = process.env.TEST_CONCURRENCY
? `--test-concurrency=${process.env.TEST_CONCURRENCY}`
: `--test-concurrency=${defaultConcurrency}`;
const absoluteFiles = files.map(file => path.join(repoRoot, file));
// Keep chunks bounded for Windows CreateProcess command-length limits.
const maxChars = process.env.RUN_TESTS_MAX_CMDLINE_CHARS
? Number(process.env.RUN_TESTS_MAX_CMDLINE_CHARS)
: 28000;
const fixed = process.execPath.length + '--test'.length + concurrency.length + 8;
const chunks = [];
let current = [];
let currentLen = fixed;
for (const file of absoluteFiles) {
const add = file.length + 1;
if (current.length > 0 && currentLen + add > maxChars) {
chunks.push(current);
current = [];
currentLen = fixed;
}
current.push(file);
currentLen += add;
}
if (current.length > 0) chunks.push(current);
let firstFailure = 0;
for (let i = 0; i < chunks.length; i++) {
if (chunks.length > 1) {
console.error(`affected-tests: chunk ${i + 1}/${chunks.length} (${chunks[i].length} files)`);
}
try {
execFileSync(process.execPath, ['--test', concurrency, ...chunks[i]], {
cwd: repoRoot,
stdio: 'inherit',
env: { ...process.env },
});
} catch (error) {
const code = error.status || 1;
if (firstFailure === 0) firstFailure = code;
}
}
if (firstFailure !== 0) process.exit(firstFailure);
}
function runSuite(repoRoot, suite) {
execFileSync(process.execPath, ['scripts/run-tests.cjs', '--suite', suite], {
cwd: repoRoot,
stdio: 'inherit',
env: { ...process.env },
});
}
function resolveBaseRef() {
if (process.env.GSD_AFFECTED_BASE) return process.env.GSD_AFFECTED_BASE;
if (process.env.GITHUB_BASE_REF) return `origin/${process.env.GITHUB_BASE_REF}`;
return 'origin/main';
}
/**
* Pure function: given the outputs of the selection phase, return a run plan
* describing what should be executed. No I/O is performed here.
*
* Return shapes:
* { mode: 'suite', suite: 'unit' } — no changed files
* { mode: 'suites', suites: PR_FULL_SUITES } — critical path triggered
* { mode: 'suites', suites: PR_FULL_SUITES } — widen required (orphan src file)
* { mode: 'suite', suite: 'unit' } — selection empty after widen=false
* { mode: 'files', files: string[] } — concrete selection, no widen
*
* Invariant: when widenRequired is true the executed set is ALWAYS ⊇ selected,
* because PR_FULL_SUITES covers every PR-eligible suite (unit + integration +
* security), so every concrete match that pickAffectedTests put into `selected`
* belongs to one of those suites and will be exercised by running all three.
*/
function resolveRunPlan({ changedFiles, selected, widenRequired, criticalPath, noChanges }) {
if (noChanges) {
return { mode: 'suite', suite: 'unit' };
}
if (criticalPath) {
return { mode: 'suites', suites: PR_FULL_SUITES };
}
if (widenRequired) {
return { mode: 'suites', suites: PR_FULL_SUITES };
}
if (selected.length === 0) {
return { mode: 'suite', suite: 'unit' };
}
return { mode: 'files', files: selected };
}
function runAffectedTests(options = {}) {
const repoRoot = options.repoRoot || path.resolve(__dirname, '..');
const baseRef = options.baseRef || resolveBaseRef();
const changed = changedFilesSinceBase(repoRoot, baseRef);
if (changed.length === 0) {
console.error(`affected-tests: no changed files against ${baseRef}; running unit suite`);
runSuite(repoRoot, 'unit');
return;
}
if (shouldRunFullSuite(changed)) {
console.error('affected-tests: critical CI/runtime files changed; running PR suites (unit, integration, security)');
for (const suite of PR_FULL_SUITES) {
runSuite(repoRoot, suite);
}
return;
}
const allTests = listTestFiles(repoRoot);
const reverseIndex = buildTransitiveReverseIndex(repoRoot, allTests);
const selected = pickAffectedTests(changed, allTests, reverseIndex, { detectWiden: true });
console.error(`affected-tests: base=${baseRef} changed=${changed.length} selected=${selected.length}`);
console.error(`affected-tests: ${selected.join(' ')}`);
const plan = resolveRunPlan({
changedFiles: changed,
selected,
widenRequired: selected._widenRequired === true,
criticalPath: false,
noChanges: false,
});
if (plan.mode === 'suites') {
// Widen backstop: a source file changed that has no static test dependents.
// Run all PR suites (unit + integration + security) — a strict superset of
// the concretely-selected tests — so no integration/security match is lost.
for (const file of changed) {
const ext = path.extname(file);
const isSourceFile = ['.js', '.cjs', '.mjs', '.ts', '.cts', '.mts', '.json'].includes(ext);
if (!isSourceFile || file.startsWith('tests/') || shouldRunFullSuite([file])) continue;
const dependents = reverseIndex.get(file);
if (!dependents || dependents.size === 0) {
console.error(
`affected-tests: ${file} has no static test dependents; widening to PR suites (unit+integration+security)`,
);
}
}
for (const suite of plan.suites) {
runSuite(repoRoot, suite);
}
return;
}
if (plan.mode === 'suite') {
console.error('affected-tests: no affected tests found; running unit suite as smoke');
runSuite(repoRoot, plan.suite);
return;
}
// plan.mode === 'files'
runNodeTestFiles(repoRoot, plan.files);
}
module.exports = {
CRITICAL_PATHS,
PR_EXCLUDED_SUITES,
PR_FULL_SUITES,
buildForwardGraph,
buildReverseIndex,
buildTransitiveReverseIndex,
parseRelativeSpecifiers,
pickAffectedTests,
resolveBaseRef,
resolveRelativeDependency,
resolveRunPlan,
shouldRunFullSuite,
toPosixPath,
runAffectedTests,
};