* fix(#2544): stage the CommonJS marker in GSD-owned dirs, not the config root installSharedHooksBundle wrote `{"type":"commonjs"}` over <configRoot>/package.json unconditionally — no existence check, no merge, no backup — on every install and every /gsd-update re-install. On the 11 affected runtimes that file is often user-owned; on OpenCode and Kilo it is the documented place to declare local-plugin npm dependencies, so a user's name/type/dependencies/scripts were destroyed on each run. The uninstall path already read the file and unlinked it only on an exact content match. That asymmetry was the defect: the discipline existed in the codebase, it just was not applied on the write side. Move the marker into the directories GSD creates and fills with its own .js files — hooks/ (all shared-hooks runtimes, incl. Kimi's own root) and the nativePlugin dir (plugins/ for OpenCode+Kilo, extensions/ for pi) — and stop writing the config root entirely. New src/commonjs-marker.cts owns the marker string plus one ownership predicate (absent / gsd-owned / foreign, fail-closed on an unreadable file) shared by ensureCommonJsMarker and removeCommonJsMarker, so install and uninstall cannot drift apart again. Nothing else depended on the config-root marker: package identity is baked at build time (#378/#498) and version resolution prefers gsd-core/VERSION and already tolerates a missing root package.json (#1383) — Codex has installed without one all along. A package.json in plugins/ or extensions/ is inert to plugin discovery, which globs *.{ts,js} only (see installer-migration 006). Uninstall retires the pre-fix config-root marker, so upgrading users are cleaned up on removal, and still never touches a file it did not write. * fix(#2544): point the changeset fragment at the filed PR The fragment's `pr:` field is only knowable after `gh pr create` returns. * fix(#2544): register commonjs-marker.cjs in the tsc-generated ESLint ignore set bin/lib/commonjs-marker.cjs is tsc output (src/commonjs-marker.cts is the linted source), so it belongs in the ADR-457 ignore list like its siblings. Clears the lint-tests no-var failure and the repo-invariants "linted xor ignored" migration-state test. * fix(#2544): pin the kimi CommonJS marker to hooks/, not the ~/.kimi root The UPGRADE 1 test still asserted the pre-#2544 marker location (~/.kimi/package.json). The marker now lives inside ~/.kimi/hooks — the directory GSD itself creates — matching the updated golden-install-parity and install-tree fixtures. Also asserts the root marker is NOT written. * fix(#2544): make the CommonJS marker write path non-fatal Review round 2, Major 3 + Minor 1 + the stagedHooks nit. ensureCommonJsMarker rethrew any non-EEXIST write error and neither call site caught it, so EACCES on a read-only hooks/, EROFS, or ENOSPC aborted the whole install with a raw stack trace. Every other marker interaction in the module is best-effort — removeCommonJsMarker swallows unlink failures, classifyMarker swallows read failures — and this was the write path, i.e. the one most likely to fail on a locked-down config dir. It now returns a new 'failed' outcome and both call sites warn and continue. Sibling found while sweeping for the same defect class: fs.mkdirSync sat OUTSIDE the try block, so an unwritable parent threw past the guard entirely. Creating the directory is the same environmental hazard as writing into it, so it moved inside. Also in this file: - The hooks marker is now gated on `stagedHooks && hooksOk`, not stagedHooks alone. stagedHooks is computed from the SOURCE listing before the copy loop, so it stays true when the copies land but verifyInstalled() then fails — marking a hooks/ GSD did not successfully populate claims an ownership the install did not earn. - The uninstall rmdir of the native plugin dir is gated on GSD having actually removed something from it. Hoisting it out of the adapter-exists guard (so the marker-only case could prune) had silently widened it into deleting a user-created but empty plugins/ or extensions/ dir — the same "don't touch territory GSD didn't fill" principle this issue is about, inverted. - Kimi's pre-#2544 marker at its native hook root (~/.kimi) is retired at the same call site that writes its replacement. That path is outside kimi's configDir, so installer-migration 007 structurally cannot reach it. * fix(#2544): retire the stale config-root marker via installer-migration 007 Review round 2, Major 1 — the PR's headline claim was false for existing installs. Upgraders kept BOTH markers: the new one under hooks/ and the stale {"type":"commonjs"} at the config root, so their config root stayed pinned to CommonJS and their dependency manifest stayed gone until they uninstalled. The migration is unusual in one way, and it is the part worth reviewing: the config-root marker was never recorded in gsd-file-manifest.json (writeManifest records hooks/, agents/, commands/, scripts/ and the native plugin, never a root package.json), so classifyArtifact answers 'unknown' for it and the planner's own guard downgrades a remove-managed on an 'unknown' classification to preserve-user. 007 therefore supplies the "purpose-built detector for an old GSD-owned shape" that docs/installer-migrations.md#remove-managed sanctions — exact content match, the same predicate removeCommonJsMarker has always used — and declares the resulting classification on the action. A package.json with any other content is left untouched, and there is deliberately no backup-and-remove branch: a non-matching file here is not a patched GSD artifact, it is somebody else's file. Scope is all runtimes. The `runtimes` field is OMITTED rather than `[]`: validateStringArray requires the field to be non-empty WHEN PRESENT, while the runtime filter treats an empty array as "all" — so `runtimes: []` throws at plan time and the migration never runs. The metadata test pins this. Kimi is a deliberate carve-out, named in the migration's own header: its marker lived at ~/.kimi, outside kimi's configDir, and migration relPaths are structurally confined to configDir. It is retired by the installer instead. Registration: shipped-migrations table, .gitignore for the emitted .cjs, the EXPECTED_CHECKSUMS baseline, and the ESLint ignore set. That last one is not copied from migration 006 by rote — 006 needs no entry because it imports nothing, while 007 imports node builtins, so tsc emits its __importDefault helper and the `var` in it trips no-var. This is the same lint gate that made round 1 red. * test(#2544): fault-injection and multi-runtime marker coverage Review round 2, Major 2 + Minors 4 and 5. Major 2 — CONTRIBUTING.md:514-531 is mandatory for install/uninstall flows and the suite had no fs monkeypatching at all. Every branch now covered is one whose doc comment claims it as the module's safety posture: - classifyMarker non-ENOENT lstat error -> 'foreign' (the fail-closed rule), with an ENOENT control alongside it so the test discriminates rather than just asserting one side - classifyMarker readFileSync throw -> 'foreign' (present-but-unreadable never downgrades to the permissive answer) — the fixture's bytes are exactly GSD's marker, so the test fails if the code ever answers on content it could not read - a DIRECTORY at the marker path (CONTRIBUTING:521; the symlink case was already covered with a real symlink, the directory case needs no injection at all) - the ensureCommonJsMarker TOCTOU EEXIST branch — the entire reason for flag:'wx' - the new 'failed' outcome, for both writeFileSync (EACCES/EROFS/ENOSPC) and the mkdirSync that used to sit outside the guard - removeCommonJsMarker unlink throw -> false These save and restore fs methods in `finally` rather than using chmod 0o000, which does not fault under root and would pass vacuously in root Docker and CI. Minor 4 — uninstall was driven for opencode only. pi's extensions/ and both kimi locations now have behavioral coverage, install and uninstall, each paired with a user-authored-file case proving GSD leaves it alone. Minor 5 — the stagedHooks gate had no assertion behind its stated reason. A pre-existing, GSD-untouched hooks/ directory is now driven through a runtime that declares skipSharedHooksInstall and asserted to stay marker-free, with its user content intact. Also regression-tests the uninstall rmdir gate from the previous commit: an empty plugin dir GSD removed nothing from must survive. * docs(#2544): correct stale marker prose, register the module, document the trade-off Review round 2, Minors 2, 3 and 6. Minor 2 — six files asserted the installed ROOT ships the synthetic marker. None was load-bearing (all three walk-up consumers are VERSION-first with try/catch and the marker never carried a `version`), but ADR-457:52 is the rationale for keeping a generated module, so a future reader would mis-derive the constraint from it. Each site is corrected to what is now true: the installed tree carries no package.json with a .name at all, because the only ones GSD stages are {"type":"commonjs"} markers and they now live in GSD's own directories. Two of the six needed more than a location swap. hooks/gsd-check-update-worker.js and the platform-gate test both described `require('../package.json').name` resolving to undefined; post-#2544 that require does not resolve at all, so the history is kept accurate and the present-tense claim corrected rather than just moved. And src/runtime-artifact-conversion.cts described the no-root-package.json case as Codex-only — it is now every runtime, which strengthens that comment's own argument for lazy resolution. The generated .cjs sibling needs no edit: it is gitignored build output, not a tracked file. Minor 3 — src/commonjs-marker.cts had no CONTEXT.md entry, unlike every peer module, and CONTEXT.md is the #2 co-change partner of bin/install.js. Added, including the fail-closed posture and the never-throws contract. Minor 6 — the plugins//extensions/ marker shadows the config root for all .js siblings, so an OpenCode/Kilo user's ESM plugin/*.js stays broken. That is exactly what #2544's Fix section prescribed and it is disclosed in the PR body, but the PR body is not documentation. It now lives in the OpenCode section of docs/how-to/install-on-your-runtime.md, stated as a real constraint rather than a pure improvement, with the .ts mitigation and a fallback for ESM plugins. * test(#2544): attribute the CommonJS marker in the emitted-provenance rules The differential emitted-attribution gate (#2723, landed on `next` after this branch was cut) went red on the macOS shards once this PR rebased onto it. Two distinct causes, both real gaps rather than noise: 1. `plugins/package.json` and `extensions/package.json` matched NO rule — the `native-plugin` rule covers `*.{js,cjs,mjs}` only, so the marker read as an unattributed emitted family. 2. `hooks/package.json` fell through to `hooks-built`, which attributes an emitted `hooks/<X>` to a repo source `hooks/<X>`. There is no `hooks/package.json` in the repo, so it resolved to a nonexistent path. Cause 2 is exactly the failure already documented three lines above it for Copilot's `gsd-session.json` — "a code literal, not a built script" — so the fix follows that precedent rather than inventing one: `package.json` is excluded from `hooks-built` the same way, and a dedicated `commonjs-marker` rule attributes the family across all four roots it can appear in (both hooks roots plus `plugins`/`extensions`) to the sources that actually emit it. Deliberately a RULE, not an entry in tests/emitted-drift-ack.json. An ack is for a one-off ripple and goes stale by design — the gate fails a stale ack precisely so it cannot pre-clear the next change on that path. These markers are a permanent part of the emitted tree from #2544 onward, so they need standing attribution. Verified by reproducing the CI failure locally with GSD_EMITTED_BASE: 3 provenance errors + 12 unattributed paths before, 35/35 green after. * fix(#2544): route the #2717 hooks-surface marker helpers through commonjs-marker #2717 landed a second copy of ensureCommonJsMarker/removeCommonJsMarkerIfGsdOwned in src/runtime-hooks-surface.cts for the runtimes that stage .js hooks via dedicated paths (cursor/windsurf/codex). That copy had drifted from this PR's module on the two properties that matter: - ownership probe: `fs.existsSync` FOLLOWS symlinks and reports false for a DANGLING one, so a dangling package.json symlink classified as absent and the write went straight through it. Demonstrated: against the pre-fix copy, ensureCommonJsMarker() on a hooks/ dir holding a dangling package.json symlink returns true and creates {"type":"commonjs"} OUTSIDE that directory. - create: a plain writeFileSync leaves the classify->write window open, where commonjs-marker creates with flag:'wx' (O_EXCL). Both helpers now delegate to src/commonjs-marker.cts, which is what this PR's own docstring already claimed was the single place these rules are enforced. Exported signatures are unchanged (still boolean), so bin/install.js and the #2717 tests are unaffected. The new subtest is the only coverage that fails if the duplicate is ever reintroduced — the two implementations agree on every non-adversarial input, so the existing suites pass against both. * test(#2544): pin the stagedHooks gate on zcode, not windsurf The Minor-5 coverage picked windsurf because hostBehaviors.skipSharedHooksInstall kept it out of the shared hooks bundle, so GSD staged nothing into hooks/ and the marker was correctly absent. #2717 changed that premise: cursor/windsurf/codex now stage their .js hooks via dedicated paths and get the marker beside those scripts. Measured on this tree, windsurf stages 2 .js hooks and receives a marker — so the assertion was pinning behaviour that is now wrong, not the gate it was written for. ZCode is the durable choice: per #1821 it has hooksSurface:'none' AND no plugin surface to spawn hooks, so GSD stages no .js there by either route (measured: 0 staged, no marker). The property under test is unchanged — a user-created hooks/ directory GSD never fills stays marker-free. * test(#2544): use the shared cleanup helper in the migration test Addresses the review's Major 1. The suppression's stated reason — "no helpers import available" — was not correct: tests/helpers.cjs exports cleanup, and the other test file added in this same PR imports it (tests/commonjs-marker.test.cjs). The local reimplementation dropped two protections that are live on this repo's windows-latest lane: the CWD guard (Windows cannot remove a directory that is the current working directory) and the 20 x 250ms retry budget that absorbs the deferred-scan handle Windows Defender holds on newly-written files. Local function and suppression both removed; local/no-raw-rmsync-in-tests now passes without one. * test(#2544): expect hooks/package.json for the #2717 runtimes The fresh-install contract table predates #2717, which stages cursor/windsurf/ codex .js hooks via dedicated paths and writes the CommonJS marker beside them. All three therefore now receive hooks/package.json legitimately. Measured on this tree: codex stages 3 .js hooks, cursor 6, windsurf 2 — each with the marker; cline/copilot/trae/zcode stage none and get none, so their contracts are unchanged. * fix(#2544): gate the #2717 marker writes on having staged something The three dedicated marker writers #2717 added ran unconditionally. Each one mkdirs hooks/ up front and stages its scripts conditionally on the source existing, so with an absent or empty hook source they created a directory, filled it with nothing, and marked it as GSD's anyway. That is the same write-into-someone-else's-territory this issue is about, and installSharedHooksBundle already guards the identical case with `stagedHooks`. The dedicated paths now carry the matching gate: - cursor / windsurf: `installedScripts.size > 0` - codex: a new `codexStagedHooks` flag. The enclosing guard only proves that hooks/dist EXISTS; it says nothing about whether any CODEX_HOOKS_TO_COPY entry landed. Covered for cursor and windsurf by driving each writer against a src tree whose hooks/ dir is empty. The codex leg is defensive and deliberately uncovered: its trigger state needs a package tree where hooks/dist exists but holds none of the allowlist, which is not constructible from a real checkout. * test(#2544): scope the commonjs-marker sources per root The rule declared one flat source list for every marker root, so `extensions/package.json` was attributed to runtime-hooks-surface.cts (which never writes there) and `.kimi/hooks/package.json` to install-engine.cts. That is not merely untidy. emitted-diff.cjs accepts the FIRST satisfied source, so a flat list containing bin/install.js let any change anywhere in that 13k-line file authorise marker drift for every root — the blanket escape hatch this file's own agents-verbatim comment refuses for exactly the same reason. Sources are now derived per root from ctx.rel. Note the rule ctx is `{ rel, runtime }` and carries no `root`, so keying on ctx.root would have sent every path down one branch silently. * test(#2544): state precisely what the zcode assertion pins The comment claimed the test pinned installSharedHooksBundle's `stagedHooks` gate. It does not, and neither did the windsurf version it replaced: zcode declares skipSharedHooksInstall, so the outer guard skips that helper entirely and the gate is never evaluated. The test passes on the runtime exclusion. What it does pin — the outcome a pre-existing, GSD-untouched hooks/ stays marker-free — is still worth having, and is what the review asked for. The two `staging zero hook scripts` tests are the ones that pin a real staged-nothing gate. Comment corrected rather than left implying coverage that is not there. --------- Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
660 lines
28 KiB
JavaScript
660 lines
28 KiB
JavaScript
'use strict';
|
|
|
|
/**
|
|
* CommonJS marker ownership — regression coverage for #2544.
|
|
*
|
|
* `installSharedHooksBundle` used to write `{"type":"commonjs"}` over
|
|
* `<configRoot>/package.json` unconditionally — no existence check, no merge,
|
|
* no backup. On OpenCode and Kilo that file is documented, user-writable
|
|
* territory (it is where local-plugin npm dependencies are declared), so every
|
|
* install and every `/gsd-update` destroyed the user's `name`, `type`,
|
|
* `dependencies`, and `scripts`.
|
|
*
|
|
* The uninstall path had always read the file first and unlinked it only on an
|
|
* exact content match. The defect was that asymmetry: the discipline existed,
|
|
* it just was not applied on the write side.
|
|
*
|
|
* The fix moves the marker into the directories GSD actually fills with its own
|
|
* `.js` files — `hooks/` and the `nativePlugin.dir` — and routes install and
|
|
* uninstall through one shared ownership predicate. These tests pin both
|
|
* halves: the config root is never written, and a user-authored package.json is
|
|
* never overwritten even where GSD does write.
|
|
*
|
|
* Coverage maps to the issue's acceptance criteria:
|
|
* AC1 — a user-authored config-root package.json survives a fresh install
|
|
* AC2 — it survives a second install (the `/gsd-update` re-install path)
|
|
* AC3 — GSD's staged .js files still resolve as CommonJS
|
|
* AC4 — uninstall removes only markers GSD wrote
|
|
*/
|
|
|
|
const { test, describe, before } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const os = require('node:os');
|
|
const path = require('node:path');
|
|
const crypto = require('node:crypto');
|
|
const { spawnSync } = require('node:child_process');
|
|
|
|
const { cleanup } = require('./helpers.cjs');
|
|
|
|
const {
|
|
COMMONJS_MARKER,
|
|
classifyMarker,
|
|
ensureCommonJsMarker,
|
|
removeCommonJsMarker,
|
|
} = require('../gsd-core/bin/lib/commonjs-marker.cjs');
|
|
|
|
const INSTALL_SCRIPT = path.join(__dirname, '..', 'bin', 'install.js');
|
|
const BUILD_SCRIPT = path.join(__dirname, '..', 'scripts', 'build-hooks.js');
|
|
|
|
/** A realistic OpenCode-shape config-root package.json (the issue's repro). */
|
|
const USER_PACKAGE_JSON = JSON.stringify(
|
|
{
|
|
name: 'my-opencode-config',
|
|
type: 'module',
|
|
dependencies: { shescape: '^2.1.0', zod: '^3.23.8' },
|
|
scripts: { postinstall: 'echo user-owned' },
|
|
},
|
|
null,
|
|
2,
|
|
) + '\n';
|
|
|
|
const sha256 = (buf) => crypto.createHash('sha256').update(buf).digest('hex');
|
|
|
|
function mkTmp(prefix) {
|
|
return fs.mkdtempSync(path.join(os.tmpdir(), prefix));
|
|
}
|
|
|
|
/**
|
|
* Run the real installer against a throwaway config root.
|
|
*
|
|
* HOME/USERPROFILE/CLAUDE_CONFIG_DIR are all redirected into the temp tree so
|
|
* the installer can never reach the developer's live profile — gsd-core's
|
|
* installer resolves through exactly those variables.
|
|
*/
|
|
function runInstall(root, runtime, extraArgs = []) {
|
|
const env = { ...process.env, HOME: root, USERPROFILE: root, CLAUDE_CONFIG_DIR: root };
|
|
delete env.GSD_TEST_MODE;
|
|
const result = spawnSync(
|
|
process.execPath,
|
|
[INSTALL_SCRIPT, `--${runtime}`, '--global', '--config-dir', root, ...extraArgs],
|
|
{ cwd: root, encoding: 'utf8', env },
|
|
);
|
|
assert.equal(
|
|
result.status,
|
|
0,
|
|
`installer exited ${result.status}\nstdout: ${result.stdout}\nstderr: ${result.stderr}`,
|
|
);
|
|
return result;
|
|
}
|
|
|
|
describe('commonjs-marker: ownership predicate', () => {
|
|
test('classifies absent, GSD-owned, and foreign package.json files', (t) => {
|
|
const dir = mkTmp('cjs-marker-classify-');
|
|
t.after(() => cleanup(dir));
|
|
|
|
assert.equal(classifyMarker(dir), 'absent');
|
|
|
|
fs.writeFileSync(path.join(dir, 'package.json'), `${COMMONJS_MARKER}\n`);
|
|
assert.equal(classifyMarker(dir), 'gsd-owned');
|
|
|
|
fs.writeFileSync(path.join(dir, 'package.json'), USER_PACKAGE_JSON);
|
|
assert.equal(classifyMarker(dir), 'foreign');
|
|
});
|
|
|
|
test('ensureCommonJsMarker never overwrites a foreign package.json', (t) => {
|
|
const dir = mkTmp('cjs-marker-ensure-');
|
|
t.after(() => cleanup(dir));
|
|
const target = path.join(dir, 'package.json');
|
|
|
|
assert.equal(ensureCommonJsMarker(dir), 'written');
|
|
assert.equal(fs.readFileSync(target, 'utf8').trim(), COMMONJS_MARKER);
|
|
|
|
// Idempotent: a re-install must not churn the file.
|
|
assert.equal(ensureCommonJsMarker(dir), 'unchanged');
|
|
|
|
// Foreign content is preserved byte-for-byte.
|
|
fs.writeFileSync(target, USER_PACKAGE_JSON);
|
|
const before = sha256(fs.readFileSync(target));
|
|
assert.equal(ensureCommonJsMarker(dir), 'preserved-foreign');
|
|
assert.equal(sha256(fs.readFileSync(target)), before);
|
|
});
|
|
|
|
test('a symlinked package.json is foreign — never followed, never removed', (t) => {
|
|
const dir = mkTmp('cjs-marker-symlink-');
|
|
t.after(() => cleanup(dir));
|
|
const outside = path.join(dir, 'outside.json');
|
|
const owned = path.join(dir, 'owned');
|
|
fs.mkdirSync(owned);
|
|
const link = path.join(owned, 'package.json');
|
|
|
|
// A DANGLING symlink is the dangerous case: existsSync() reports false for
|
|
// it, so an existsSync-based guard would classify `absent` and then write
|
|
// straight through the link, landing outside the directory GSD owns.
|
|
fs.symlinkSync(outside, link);
|
|
assert.equal(classifyMarker(owned), 'foreign');
|
|
assert.equal(ensureCommonJsMarker(owned), 'preserved-foreign');
|
|
assert.ok(!fs.existsSync(outside), 'the write must not follow the symlink out of the directory');
|
|
assert.equal(removeCommonJsMarker(owned), false, 'a symlink is never GSD-owned');
|
|
assert.ok(fs.lstatSync(link).isSymbolicLink(), 'the symlink itself must survive');
|
|
});
|
|
|
|
test('the #2717 hooks-surface helpers inherit the same symlink guard', (t) => {
|
|
const dir = mkTmp('cjs-marker-hookssurface-');
|
|
t.after(() => cleanup(dir));
|
|
|
|
// #2717 added a SECOND copy of these helpers in runtime-hooks-surface.cts
|
|
// for the runtimes that stage .js hooks via dedicated paths
|
|
// (cursor/windsurf/codex). That copy probed with `fs.existsSync`, which
|
|
// follows symlinks and reports false for a DANGLING one — so it classified
|
|
// the link `absent` and wrote straight through it, landing outside the
|
|
// directory GSD owns. #2544 makes it delegate to commonjs-marker instead.
|
|
//
|
|
// This asserts the hardening reaches that path, not just the module: it is
|
|
// the only coverage that fails if the duplicate is ever reintroduced, since
|
|
// the two implementations agree on every non-adversarial input.
|
|
const hooksSurface = require('../gsd-core/bin/lib/runtime-hooks-surface.cjs');
|
|
|
|
const outside = path.join(dir, 'escaped.json');
|
|
const owned = path.join(dir, 'hooks');
|
|
fs.mkdirSync(owned);
|
|
fs.symlinkSync(outside, path.join(owned, 'package.json'));
|
|
|
|
assert.equal(
|
|
hooksSurface.ensureCommonJsMarker(owned),
|
|
false,
|
|
'a dangling symlink is not GSD-owned, so the marker must not be reported present',
|
|
);
|
|
assert.ok(
|
|
!fs.existsSync(outside),
|
|
'the write must not follow the symlink out of the hooks directory',
|
|
);
|
|
assert.equal(
|
|
hooksSurface.removeCommonJsMarkerIfGsdOwned(owned),
|
|
false,
|
|
'a symlink is never GSD-owned, so uninstall must not remove it',
|
|
);
|
|
});
|
|
|
|
// The #2717 writers mkdir hooks/ unconditionally, then staged their scripts
|
|
// conditionally on the source existing — so with an empty hooks source they
|
|
// created a directory, filled it with nothing, and marked it as GSD's anyway.
|
|
// That is the same write-into-territory-GSD-did-not-fill this issue is about,
|
|
// and it is what `stagedHooks` guards on the shared-bundle path. These pin the
|
|
// matching gate on the two dedicated writers.
|
|
for (const rt of ['cursor', 'windsurf']) {
|
|
test(`${rt}: staging zero hook scripts leaves hooks/ marker-free`, (t) => {
|
|
const hooksSurface = require('../gsd-core/bin/lib/runtime-hooks-surface.cjs');
|
|
const root = mkTmp(`gsd-2544-${rt}-nostage-`);
|
|
t.after(() => cleanup(root));
|
|
|
|
// A src tree whose hooks/ dir exists but holds none of the runtime's
|
|
// scripts — the writer stages nothing and must not claim the directory.
|
|
const emptySrc = path.join(root, 'src');
|
|
fs.mkdirSync(path.join(emptySrc, 'hooks'), { recursive: true });
|
|
const targetDir = path.join(root, 'target');
|
|
fs.mkdirSync(targetDir, { recursive: true });
|
|
|
|
const write = rt === 'cursor'
|
|
? hooksSurface.writeCursorHooksJson
|
|
: hooksSurface.writeWindsurfHooksJson;
|
|
write(targetDir, emptySrc);
|
|
|
|
const hooksDir = path.join(targetDir, 'hooks');
|
|
const staged = fs.existsSync(hooksDir)
|
|
? fs.readdirSync(hooksDir).filter((f) => f.endsWith('.js'))
|
|
: [];
|
|
assert.equal(staged.length, 0, 'precondition: the writer staged no scripts');
|
|
assert.ok(
|
|
!fs.existsSync(path.join(hooksDir, 'package.json')),
|
|
`${rt} must not mark a hooks/ directory it staged nothing into`,
|
|
);
|
|
});
|
|
}
|
|
|
|
test('removeCommonJsMarker removes only GSD-owned markers', (t) => {
|
|
const dir = mkTmp('cjs-marker-remove-');
|
|
t.after(() => cleanup(dir));
|
|
const target = path.join(dir, 'package.json');
|
|
|
|
fs.writeFileSync(target, USER_PACKAGE_JSON);
|
|
assert.equal(removeCommonJsMarker(dir), false);
|
|
assert.ok(fs.existsSync(target), 'a foreign package.json must survive uninstall');
|
|
|
|
fs.writeFileSync(target, `${COMMONJS_MARKER}\n`);
|
|
assert.equal(removeCommonJsMarker(dir), true);
|
|
assert.ok(!fs.existsSync(target));
|
|
});
|
|
});
|
|
|
|
/**
|
|
* Fault injection (CONTRIBUTING.md:514-531, mandatory for install/uninstall
|
|
* flows). Every branch below is one whose doc comment claims it as the module's
|
|
* safety posture, and none of them is reachable from a happy-path test.
|
|
*
|
|
* These override fs methods and restore in `finally` rather than using
|
|
* `chmod 0o000`: chmod does not fault under root, so a permissions-based test
|
|
* passes vacuously with zero coverage in root Docker and CI containers.
|
|
*/
|
|
describe('commonjs-marker: fault injection', () => {
|
|
/** Swap one fs method for the duration of `fn`, restoring even on throw. */
|
|
function withPatched(key, impl, fn) {
|
|
const original = fs[key];
|
|
fs[key] = impl;
|
|
try {
|
|
return fn();
|
|
} finally {
|
|
fs[key] = original;
|
|
}
|
|
}
|
|
|
|
const errWith = (code) => Object.assign(new Error(`synthetic ${code}`), { code });
|
|
|
|
test('classifyMarker: a non-ENOENT lstat error fails CLOSED to foreign', (t) => {
|
|
const dir = mkTmp('cjs-marker-lstat-fault-');
|
|
t.after(() => cleanup(dir));
|
|
fs.writeFileSync(path.join(dir, 'package.json'), `${COMMONJS_MARKER}\n`);
|
|
|
|
// EACCES on the stat itself. Reporting `absent` here would license the
|
|
// overwrite this module exists to prevent, so the answer must be `foreign`.
|
|
const result = withPatched('lstatSync', () => { throw errWith('EACCES'); },
|
|
() => classifyMarker(dir));
|
|
assert.equal(result, 'foreign');
|
|
});
|
|
|
|
test('classifyMarker: ENOENT from lstat still reports absent', (t) => {
|
|
const dir = mkTmp('cjs-marker-enoent-');
|
|
t.after(() => cleanup(dir));
|
|
// The discriminating control for the test above: only ENOENT means absent.
|
|
const result = withPatched('lstatSync', () => { throw errWith('ENOENT'); },
|
|
() => classifyMarker(dir));
|
|
assert.equal(result, 'absent');
|
|
});
|
|
|
|
test('classifyMarker: an unreadable file fails CLOSED to foreign', (t) => {
|
|
const dir = mkTmp('cjs-marker-read-fault-');
|
|
t.after(() => cleanup(dir));
|
|
fs.writeFileSync(path.join(dir, 'package.json'), `${COMMONJS_MARKER}\n`);
|
|
|
|
// Present-but-unreadable never downgrades to the permissive answer — the
|
|
// file's bytes are exactly GSD's marker, and it must STILL classify foreign
|
|
// because we could not prove it.
|
|
const result = withPatched('readFileSync', () => { throw errWith('EACCES'); },
|
|
() => classifyMarker(dir));
|
|
assert.equal(result, 'foreign');
|
|
});
|
|
|
|
test('classifyMarker: a DIRECTORY at the marker path is foreign', (t) => {
|
|
const dir = mkTmp('cjs-marker-dir-');
|
|
t.after(() => cleanup(dir));
|
|
// CONTRIBUTING.md:521 names this case explicitly. The symlink case is
|
|
// covered above with a real symlink; the directory case needs no fault
|
|
// injection at all, just a real directory.
|
|
fs.mkdirSync(path.join(dir, 'package.json'));
|
|
|
|
assert.equal(classifyMarker(dir), 'foreign');
|
|
assert.equal(ensureCommonJsMarker(dir), 'preserved-foreign');
|
|
assert.equal(removeCommonJsMarker(dir), false);
|
|
assert.ok(fs.statSync(path.join(dir, 'package.json')).isDirectory(),
|
|
'the directory must survive untouched');
|
|
});
|
|
|
|
test('ensureCommonJsMarker: the TOCTOU EEXIST branch returns preserved-foreign', (t) => {
|
|
const dir = mkTmp('cjs-marker-toctou-');
|
|
t.after(() => cleanup(dir));
|
|
|
|
// classifyMarker says `absent`, then something appears at the path before
|
|
// the write lands. `flag:'wx'` turns that race into EEXIST instead of a
|
|
// follow-or-overwrite — this branch is the entire reason for `wx`.
|
|
const result = withPatched('writeFileSync', () => { throw errWith('EEXIST'); },
|
|
() => ensureCommonJsMarker(dir));
|
|
assert.equal(result, 'preserved-foreign');
|
|
});
|
|
|
|
test('ensureCommonJsMarker: a write error is reported, never thrown', (t) => {
|
|
const dir = mkTmp('cjs-marker-write-fault-');
|
|
t.after(() => cleanup(dir));
|
|
|
|
// EACCES on a read-only hooks/, EROFS, ENOSPC. Every other marker
|
|
// interaction is best-effort; this one used to be fatal and abort the whole
|
|
// install with a raw stack trace.
|
|
for (const code of ['EACCES', 'EROFS', 'ENOSPC']) {
|
|
const result = withPatched('writeFileSync', () => { throw errWith(code); },
|
|
() => ensureCommonJsMarker(dir));
|
|
assert.equal(result, 'failed', `${code} must report failed, not throw`);
|
|
}
|
|
});
|
|
|
|
test('ensureCommonJsMarker: a mkdir error is reported, never thrown', (t) => {
|
|
const dir = mkTmp('cjs-marker-mkdir-fault-');
|
|
t.after(() => cleanup(dir));
|
|
|
|
// Creating the directory is the same environmental hazard as writing into
|
|
// it, so it lives inside the same guard. This sat OUTSIDE the try until
|
|
// #2544 review round 2.
|
|
const result = withPatched('mkdirSync', () => { throw errWith('EROFS'); },
|
|
() => ensureCommonJsMarker(path.join(dir, 'nested')));
|
|
assert.equal(result, 'failed');
|
|
});
|
|
|
|
test('removeCommonJsMarker: an unlink failure returns false, never throws', (t) => {
|
|
const dir = mkTmp('cjs-marker-unlink-fault-');
|
|
t.after(() => cleanup(dir));
|
|
const target = path.join(dir, 'package.json');
|
|
fs.writeFileSync(target, `${COMMONJS_MARKER}\n`);
|
|
|
|
const result = withPatched('unlinkSync', () => { throw errWith('EACCES'); },
|
|
() => removeCommonJsMarker(dir));
|
|
assert.equal(result, false);
|
|
assert.ok(fs.existsSync(target), 'the file is still there — the report must say so');
|
|
});
|
|
});
|
|
|
|
describe('#2544 regression: install must not clobber the config-root package.json', () => {
|
|
// hooks/dist is gitignored and built; scoped CI lanes do not run build:hooks,
|
|
// so build it idempotently before driving a real install.
|
|
before(() => {
|
|
const build = spawnSync(process.execPath, [BUILD_SCRIPT], { encoding: 'utf8' });
|
|
assert.equal(build.status, 0, `build:hooks failed: ${build.stderr}`);
|
|
});
|
|
|
|
for (const runtime of ['opencode', 'claude']) {
|
|
test(`${runtime}: a user-authored package.json survives install and re-install`, (t) => {
|
|
const root = mkTmp(`gsd-2544-${runtime}-`);
|
|
t.after(() => cleanup(root));
|
|
const userPkg = path.join(root, 'package.json');
|
|
fs.writeFileSync(userPkg, USER_PACKAGE_JSON);
|
|
const before = sha256(fs.readFileSync(userPkg));
|
|
|
|
// AC1 — fresh install leaves it untouched.
|
|
runInstall(root, runtime);
|
|
assert.equal(
|
|
sha256(fs.readFileSync(userPkg)),
|
|
before,
|
|
'fresh install must not modify the user-authored config-root package.json',
|
|
);
|
|
|
|
// AC2 — the /gsd-update re-install path leaves it untouched too.
|
|
runInstall(root, runtime);
|
|
assert.equal(
|
|
sha256(fs.readFileSync(userPkg)),
|
|
before,
|
|
're-install must not modify the user-authored config-root package.json',
|
|
);
|
|
|
|
// The user's own keys are still readable and intact.
|
|
const parsed = JSON.parse(fs.readFileSync(userPkg, 'utf8'));
|
|
assert.equal(parsed.name, 'my-opencode-config');
|
|
assert.equal(parsed.type, 'module');
|
|
assert.deepEqual(parsed.dependencies, { shescape: '^2.1.0', zod: '^3.23.8' });
|
|
assert.deepEqual(parsed.scripts, { postinstall: 'echo user-owned' });
|
|
|
|
// AC3 — GSD's own staged scripts still get a CommonJS marker, from the
|
|
// directory GSD owns, so `require` keeps working under "type": "module".
|
|
const hooksMarker = path.join(root, 'hooks', 'package.json');
|
|
assert.ok(fs.existsSync(hooksMarker), 'hooks/package.json marker must be staged');
|
|
assert.equal(JSON.parse(fs.readFileSync(hooksMarker, 'utf8')).type, 'commonjs');
|
|
});
|
|
}
|
|
|
|
test('staged hook helpers still load as CommonJS under a "type": "module" config root', (t) => {
|
|
const root = mkTmp('gsd-2544-esm-');
|
|
t.after(() => cleanup(root));
|
|
// The config root declares ESM — the exact shape that breaks Node's
|
|
// walk-up resolution for GSD's staged .js files.
|
|
fs.writeFileSync(path.join(root, 'package.json'), USER_PACKAGE_JSON);
|
|
runInstall(root, 'opencode');
|
|
|
|
// Actually require a staged CommonJS helper. Without a marker inside
|
|
// hooks/, the walk-up lands on the user's "type": "module" and this throws
|
|
// ERR_REQUIRE_ESM / "require is not defined" — the regression AC3 forbids.
|
|
const target = path.join(root, 'hooks', 'lib', 'git-cmd.js');
|
|
assert.ok(fs.existsSync(target), 'hooks/lib/git-cmd.js must be staged');
|
|
const probe = spawnSync(
|
|
process.execPath,
|
|
['-e', `const m = require(${JSON.stringify(target)}); if (typeof m.isGitSubcommand !== 'function') { throw new Error('unexpected exports'); } console.log('loaded');`],
|
|
{ cwd: root, encoding: 'utf8' },
|
|
);
|
|
assert.equal(
|
|
probe.status,
|
|
0,
|
|
`staged hook helper must load as CommonJS under an ESM config root\nstderr: ${probe.stderr}`,
|
|
);
|
|
assert.match(probe.stdout, /loaded/);
|
|
});
|
|
|
|
test('opencode: the native plugin dir gets its own marker', (t) => {
|
|
const root = mkTmp('gsd-2544-plugin-');
|
|
t.after(() => cleanup(root));
|
|
runInstall(root, 'opencode');
|
|
|
|
// The adapter is staged as .js, so it needs a marker in its own directory
|
|
// now that the config root no longer carries one. A package.json here is
|
|
// inert to plugin discovery: OpenCode globs plugins/*.{ts,js}.
|
|
assert.ok(fs.existsSync(path.join(root, 'plugins', 'gsd-core.js')));
|
|
const pluginMarker = path.join(root, 'plugins', 'package.json');
|
|
assert.ok(fs.existsSync(pluginMarker), 'plugins/package.json marker must be staged');
|
|
assert.equal(JSON.parse(fs.readFileSync(pluginMarker, 'utf8')).type, 'commonjs');
|
|
});
|
|
|
|
test('install writes no package.json at the config root when none existed', (t) => {
|
|
const root = mkTmp('gsd-2544-noroot-');
|
|
t.after(() => cleanup(root));
|
|
runInstall(root, 'opencode');
|
|
|
|
assert.ok(
|
|
!fs.existsSync(path.join(root, 'package.json')),
|
|
'GSD must not create a package.json in the runtime config root',
|
|
);
|
|
});
|
|
|
|
test('uninstall removes GSD markers but preserves a user-authored one', (t) => {
|
|
const root = mkTmp('gsd-2544-uninstall-');
|
|
t.after(() => cleanup(root));
|
|
const userPkg = path.join(root, 'package.json');
|
|
fs.writeFileSync(userPkg, USER_PACKAGE_JSON);
|
|
const before = sha256(fs.readFileSync(userPkg));
|
|
|
|
runInstall(root, 'opencode');
|
|
runInstall(root, 'opencode', ['--uninstall']);
|
|
|
|
// AC4 — GSD's own markers are gone; the user's file is untouched.
|
|
assert.ok(fs.existsSync(userPkg), 'uninstall must not remove a user-authored package.json');
|
|
assert.equal(sha256(fs.readFileSync(userPkg)), before);
|
|
assert.ok(
|
|
!fs.existsSync(path.join(root, 'hooks', 'package.json')),
|
|
'uninstall must remove the hooks/ marker it wrote',
|
|
);
|
|
assert.ok(
|
|
!fs.existsSync(path.join(root, 'plugins', 'package.json')),
|
|
'uninstall must remove the plugin-dir marker it wrote',
|
|
);
|
|
});
|
|
|
|
test('uninstall does not prune a plugin dir GSD removed nothing from', (t) => {
|
|
const root = mkTmp('gsd-2544-rmdir-');
|
|
t.after(() => cleanup(root));
|
|
runInstall(root, 'opencode');
|
|
|
|
// Strip GSD's own artifacts by hand, leaving an EMPTY plugins/ directory
|
|
// that — from uninstall's point of view — GSD never filled. Hoisting the
|
|
// rmdir out of the adapter-exists guard (so the marker-only case could
|
|
// prune) must not widen it into deleting a user-created empty plugin dir:
|
|
// that is the same "don't touch territory GSD didn't fill" principle this
|
|
// issue is about, inverted.
|
|
const pluginsDir = path.join(root, 'plugins');
|
|
fs.unlinkSync(path.join(pluginsDir, 'gsd-core.js'));
|
|
fs.unlinkSync(path.join(pluginsDir, 'package.json'));
|
|
assert.deepEqual(fs.readdirSync(pluginsDir), [], 'precondition: the dir is empty');
|
|
|
|
runInstall(root, 'opencode', ['--uninstall']);
|
|
|
|
assert.ok(
|
|
fs.existsSync(pluginsDir),
|
|
'an empty plugin dir GSD removed nothing from must survive uninstall',
|
|
);
|
|
});
|
|
|
|
test('uninstall reclaims the plugin-dir marker even if the adapter is already gone', (t) => {
|
|
const root = mkTmp('gsd-2544-partial-');
|
|
t.after(() => cleanup(root));
|
|
runInstall(root, 'opencode');
|
|
|
|
// Model a partial install / hand-deleted adapter. The marker cleanup must
|
|
// not be gated on the adapter still being present, or it is stranded and
|
|
// the directory can never prune.
|
|
fs.unlinkSync(path.join(root, 'plugins', 'gsd-core.js'));
|
|
runInstall(root, 'opencode', ['--uninstall']);
|
|
|
|
assert.ok(
|
|
!fs.existsSync(path.join(root, 'plugins', 'package.json')),
|
|
'the plugin-dir marker must be reclaimed even without the adapter',
|
|
);
|
|
});
|
|
|
|
test('a pre-existing hooks/ dir GSD never fills stays marker-free', (t) => {
|
|
const root = mkTmp('gsd-2544-stagedhooks-');
|
|
t.after(() => cleanup(root));
|
|
|
|
// Scope, stated precisely: this pins the OUTCOME — a pre-existing,
|
|
// GSD-untouched hooks/ stays marker-free — for a runtime GSD stages no .js
|
|
// into. It does NOT exercise installSharedHooksBundle's `stagedHooks` gate:
|
|
// zcode declares skipSharedHooksInstall, so the outer guard in bin/install.js
|
|
// skips that helper entirely and the gate is never evaluated. For a runtime
|
|
// that DOES reach the bundle, `stagedHooks` is true whenever any hook source
|
|
// exists, so the gate is only distinguishable under fault injection. The two
|
|
// `staging zero hook scripts` tests above are the ones that pin a real
|
|
// staged-nothing gate, on the #2717 writers.
|
|
//
|
|
// ZCode, not Windsurf. Windsurf was the original choice because
|
|
// hostBehaviors.skipSharedHooksInstall kept it out of the shared bundle —
|
|
// but #2717 then began staging cursor/windsurf/codex .js hooks via dedicated
|
|
// paths and writing the marker beside them, so for those three GSD now DOES
|
|
// fill hooks/ and the marker is correct. ZCode is the durable choice: per
|
|
// #1821 it has hooksSurface:'none' AND no plugin surface to spawn hooks, so
|
|
// GSD stages no .js there by either route. (Measured on this tree: zcode
|
|
// stages 0 .js hooks and gets no marker; windsurf stages 2 and gets one.)
|
|
const userHooks = path.join(root, 'hooks');
|
|
fs.mkdirSync(userHooks, { recursive: true });
|
|
fs.writeFileSync(path.join(userHooks, 'my-hook.js'), '// user-authored\n');
|
|
|
|
runInstall(root, 'zcode');
|
|
|
|
assert.ok(
|
|
!fs.existsSync(path.join(userHooks, 'package.json')),
|
|
'GSD must not mark a hooks/ directory it never staged into',
|
|
);
|
|
assert.ok(
|
|
fs.existsSync(path.join(userHooks, 'my-hook.js')),
|
|
"the user's own hooks/ contents must be untouched",
|
|
);
|
|
});
|
|
|
|
test('pi: the extensions/ marker is installed and reclaimed on uninstall', (t) => {
|
|
const root = mkTmp('gsd-2544-pi-');
|
|
t.after(() => cleanup(root));
|
|
|
|
runInstall(root, 'pi');
|
|
const marker = path.join(root, 'extensions', 'package.json');
|
|
assert.ok(fs.existsSync(marker), 'pi extensions/package.json marker must be staged');
|
|
assert.equal(JSON.parse(fs.readFileSync(marker, 'utf8')).type, 'commonjs');
|
|
|
|
runInstall(root, 'pi', ['--uninstall']);
|
|
assert.ok(!fs.existsSync(marker), 'uninstall must remove the extensions/ marker it wrote');
|
|
});
|
|
|
|
test('pi: a user-authored extensions/package.json survives install and uninstall', (t) => {
|
|
const root = mkTmp('gsd-2544-pi-user-');
|
|
t.after(() => cleanup(root));
|
|
|
|
const extDir = path.join(root, 'extensions');
|
|
fs.mkdirSync(extDir, { recursive: true });
|
|
const userPkg = path.join(extDir, 'package.json');
|
|
fs.writeFileSync(userPkg, USER_PACKAGE_JSON);
|
|
const before = sha256(fs.readFileSync(userPkg));
|
|
|
|
runInstall(root, 'pi');
|
|
assert.equal(sha256(fs.readFileSync(userPkg)), before,
|
|
'install must not overwrite a user-authored extensions/package.json');
|
|
|
|
runInstall(root, 'pi', ['--uninstall']);
|
|
assert.ok(fs.existsSync(userPkg), 'uninstall must not remove it either');
|
|
assert.equal(sha256(fs.readFileSync(userPkg)), before);
|
|
});
|
|
|
|
test('kimi: the marker lives under hooks/, and the legacy root marker is retired', (t) => {
|
|
const root = mkTmp('gsd-2544-kimi-');
|
|
t.after(() => cleanup(root));
|
|
|
|
// HOME is redirected to `root`, so kimi's native hook root
|
|
// (resolveKimiHooksTomlDir → the `.kimi` dot-home) resolves inside the
|
|
// temp tree. That root is OUTSIDE kimi's configDir, which is why migration
|
|
// 007 cannot reach it and bin/install.js retires it directly.
|
|
const kimiRoot = path.join(root, '.kimi');
|
|
|
|
runInstall(root, 'kimi');
|
|
assert.ok(
|
|
fs.existsSync(path.join(kimiRoot, 'hooks', 'package.json')),
|
|
'kimi marker must be staged inside .kimi/hooks/',
|
|
);
|
|
assert.ok(
|
|
!fs.existsSync(path.join(kimiRoot, 'package.json')),
|
|
'kimi must not carry a marker at its native hook root',
|
|
);
|
|
|
|
// Model a pre-#2544 install, which left the marker at the .kimi root, then
|
|
// upgrade. The stale marker must be retired by the install itself.
|
|
fs.writeFileSync(path.join(kimiRoot, 'package.json'), `${COMMONJS_MARKER}\n`);
|
|
runInstall(root, 'kimi');
|
|
assert.ok(
|
|
!fs.existsSync(path.join(kimiRoot, 'package.json')),
|
|
'upgrading must retire the pre-#2544 marker at kimi\'s root',
|
|
);
|
|
});
|
|
|
|
test('kimi: a user-authored package.json at the .kimi root is never retired', (t) => {
|
|
const root = mkTmp('gsd-2544-kimi-user-');
|
|
t.after(() => cleanup(root));
|
|
const kimiRoot = path.join(root, '.kimi');
|
|
fs.mkdirSync(kimiRoot, { recursive: true });
|
|
const userPkg = path.join(kimiRoot, 'package.json');
|
|
fs.writeFileSync(userPkg, USER_PACKAGE_JSON);
|
|
const before = sha256(fs.readFileSync(userPkg));
|
|
|
|
runInstall(root, 'kimi');
|
|
|
|
assert.ok(fs.existsSync(userPkg), 'a user file at the .kimi root must survive');
|
|
assert.equal(sha256(fs.readFileSync(userPkg)), before);
|
|
});
|
|
|
|
test('kimi: uninstall reclaims the hooks/ marker', (t) => {
|
|
const root = mkTmp('gsd-2544-kimi-uninstall-');
|
|
t.after(() => cleanup(root));
|
|
const kimiRoot = path.join(root, '.kimi');
|
|
|
|
runInstall(root, 'kimi');
|
|
assert.ok(fs.existsSync(path.join(kimiRoot, 'hooks', 'package.json')));
|
|
|
|
runInstall(root, 'kimi', ['--uninstall']);
|
|
assert.ok(
|
|
!fs.existsSync(path.join(kimiRoot, 'hooks', 'package.json')),
|
|
'uninstall must remove the kimi hooks/ marker it wrote',
|
|
);
|
|
});
|
|
|
|
test('uninstall retires a pre-#2544 config-root marker', (t) => {
|
|
const root = mkTmp('gsd-2544-legacy-');
|
|
t.after(() => cleanup(root));
|
|
|
|
runInstall(root, 'opencode');
|
|
// Model an install made before the fix, which left the marker at the root.
|
|
fs.writeFileSync(path.join(root, 'package.json'), `${COMMONJS_MARKER}\n`);
|
|
|
|
runInstall(root, 'opencode', ['--uninstall']);
|
|
assert.ok(
|
|
!fs.existsSync(path.join(root, 'package.json')),
|
|
'uninstall must still retire the legacy config-root marker',
|
|
);
|
|
});
|
|
});
|