Phase 1 of #3464. Removes the `// allow-test-rule:` marker from 22 test files where it is provably vestigial, and tightens the ratchet ceiling in scripts/lint-allow-test-rule-refs.ceiling.json from 305 to 285. Eligibility is decided by two independent AST discriminators, both conservative (any doubt => keep): (a) Read-target type. Every readFileSync/readFile call in the file resolves statically to a prose/config extension (.md/.json/.yml/.yaml/.toml/.txt), or the file performs no reads at all. Any read of a source extension (.cjs/.js/.mjs/.ts/.cts/.mts/.jsx/.tsx), any dynamic/unresolvable path, and any other extension all disqualify the file. (b) Marker context. Every `allow-test-rule:` occurrence is a genuine comment node, never string- or template-literal payload. A marker that lives inside a RuleTester `code:` fixture is test DATA, not a suppression directive; stripping it corrupts the test. tests/eslint-rules.test.cjs is the one such fixture host and is deliberately untouched. An earlier attempt at this phase classified markers by "strip it and see if local/no-source-grep still passes" and was reverted in full before commit. That oracle is unsound: the rule only fires on a literal .cjs/.js/.ts path containing a quoted bin/lib/gsd-core/src segment, tracked one hop from the binding, so files that genuinely source-grep real JavaScript pass it silently -- tests/no-unbounded-spawn-allowlist.test.cjs (reads test sources through a listTestFiles() walk) and tests/claude-imperative-reference.test.cjs (matches bin/install.js through an intermediate variable) both cleared it while being real source-greps. The rule's implementation is narrower than its intent, so it cannot adjudicate whether an exemption is load-bearing. Scope is limited to comment deletions: the diff over the test tree is 100% line removals with zero insertions, and no executable line is altered. On the ceiling value. The measured count at this HEAD is 283, so 285 leaves 2 slack -- deliberate, and well inside the documented grace band of 3. Pinning the ceiling to the exact count makes this change effectively unmergeable: any concurrent PR that lands one marker-bearing test file re-reds it. That race fired twice while preparing this branch (once mid-rebase taking the count 304->305 on next, once between rebase and the verification run taking it 282->283), and it is the same race that broke next in #3461. A ceiling of actual+2 preserves a merge window while still ratcheting 305 -> 285. Known limit, disclosed rather than papered over: this clears 22 of 303 markers and does not reach #3464's trend-to-zero goal. Most of the remaining markers sit on dynamic-path reads, commonly a hoisted `const p = path.join(tmpDir, 'STATE.md')` whose target is prose but is unresolvable to this classifier. A stricter one-hop const resolution would flip an estimated 95 more; that is deliberately left to a follow-up so it can be reviewed on its own evidence. Marker discovery reads bytes rather than shelling out to grep: tests/security-prompt-injection.security.test.cjs carries a literal NUL byte (an intentional injection fixture) that makes grep treat it as binary and skip it, which is why the true marked-file count is 303 and not the 302 a shell scan reports. Closes #3465 Co-authored-by: sim <sim@local> Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
73 lines
3.4 KiB
JavaScript
73 lines
3.4 KiB
JavaScript
// The gsd-codebase-mapper agent and map-codebase workflow .md files ARE the
|
|
// contract the model loads at runtime. Regression lock for #2279: on an Update
|
|
// run the agent must restamp the codebase-doc dates unconditionally, not merely
|
|
// substitute the [YYYY-MM-DD] placeholder (absent once a doc holds a real date).
|
|
|
|
const { describe, test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
|
|
const ROOT = path.join(__dirname, '..');
|
|
const MAPPER = fs.readFileSync(path.join(ROOT, 'agents', 'gsd-codebase-mapper.md'), 'utf-8');
|
|
const WORKFLOW = fs.readFileSync(path.join(ROOT, 'gsd-core', 'workflows', 'map-codebase.md'), 'utf-8');
|
|
|
|
// The pre-fix framing: substitute-the-placeholder-only, which never fires on an
|
|
// Update run because the placeholder was already replaced by a concrete date.
|
|
// The two files phrased the bug differently, so each needs its own stale regex;
|
|
// a single regex asserted against both silently passes on the file it never
|
|
// matched, leaving that file's negative guard dead. map-codebase.md itself used
|
|
// two pre-fix phrasings (the four per-spawn prompts plain, the sequential
|
|
// fallback backtick-wrapped and carrying "from init context"), so its stale
|
|
// regex has to cover both or the fallback site's guard is dead for the same
|
|
// reason.
|
|
const WORKFLOW_STALE_PLACEHOLDER_ONLY =
|
|
/Use `?\{date\}`?(?: from init context)? for all `?\[YYYY-MM-DD\]`? date placeholders/;
|
|
const MAPPER_STALE_PLACEHOLDER_ONLY = /Replace `?\[YYYY-MM-DD\]`? with the date/i;
|
|
|
|
// The fixed framing. Both files say "overwriting <any|whatever> ... date"; the
|
|
// regex stays loose on the object so a future rewording of the tail does not
|
|
// break the lock, while still requiring the overwrite verb the bug lacked.
|
|
const OVERWRITE_INSTRUCTION = /overwrit(?:e|ing)\s+(?:any|whatever)[^.\n]*date/i;
|
|
const WORKFLOW_OVERWRITE_SITE = /overwrit(?:e|ing) any existing date/gi;
|
|
|
|
describe('map-codebase date restamp (#2279)', () => {
|
|
test('mapper instructs overwriting an existing date on update runs', () => {
|
|
assert.match(
|
|
MAPPER,
|
|
OVERWRITE_INSTRUCTION,
|
|
'gsd-codebase-mapper.md must tell the agent to overwrite a prior concrete date, not only fill [YYYY-MM-DD]',
|
|
);
|
|
});
|
|
|
|
test('workflow reminder requires overwriting an existing date', () => {
|
|
assert.match(
|
|
WORKFLOW,
|
|
OVERWRITE_INSTRUCTION,
|
|
'map-codebase.md must instruct overwriting an existing date, not only [YYYY-MM-DD] placeholders',
|
|
);
|
|
});
|
|
|
|
test('no date-instruction site retains the placeholder-only framing', () => {
|
|
// Every site must carry the overwrite instruction: the per-spawn Agent()
|
|
// prompts in spawn_agents (the primary path) regressed independently of
|
|
// the sequential_mapping fallback, so a whole-file "fix appears somewhere"
|
|
// match is not enough.
|
|
assert.doesNotMatch(
|
|
MAPPER,
|
|
MAPPER_STALE_PLACEHOLDER_ONLY,
|
|
'gsd-codebase-mapper.md still contains a placeholder-only date instruction',
|
|
);
|
|
assert.doesNotMatch(
|
|
WORKFLOW,
|
|
WORKFLOW_STALE_PLACEHOLDER_ONLY,
|
|
'map-codebase.md still contains a placeholder-only date instruction',
|
|
);
|
|
const overwriteSites = WORKFLOW.match(WORKFLOW_OVERWRITE_SITE) ?? [];
|
|
assert.ok(
|
|
overwriteSites.length >= 5,
|
|
`expected the overwrite instruction at every date-instruction site in map-codebase.md (4 per-spawn prompts + the sequential fallback), found ${overwriteSites.length}`,
|
|
);
|
|
});
|
|
});
|