The windows-test-parity ratchet greps test source for fs.rmSync-without-
maxRetries (and six other Windows-portability anti-patterns), failing when an
integer offender COUNT exceeds a frozen baseline (rmSync: 95). A count ratchet
is a Goodhart metric: fixing one offender and adding another keeps the count
constant, so a new defect slips through green. Replace it — and every other
count ratchet in the repo — with a layered, masking-proof design.
Behavioral seam test
- tests/helpers-cleanup.test.cjs proves helpers.cleanup() carries the Windows
EBUSY retry budget. cleanup() delegates retries to Node's fs.rmSync via
maxRetries (it owns no loop), so the test asserts the option contract
(recursive/force/maxRetries>0/retryDelay>0) + real-FS removal + the cwd-guard,
rather than a loop that does not exist. The EBUSY risk is now tested ONCE at
the helper, not approximated textually at every call site.
Write-time ESLint rule (AST-accurate, replaces the grep)
- eslint-rules/no-raw-rmsync-in-tests.cjs (error in tests/**/*.test.cjs) bans
raw fs.rmSync, steering to cleanup(). Catches member, computed (fs['rmSync']),
destructured and aliased forms; escape hatch is inline
`// eslint-disable-next-line local/no-raw-rmsync-in-tests -- <reason>` only.
- Migrated 336 raw fs.rmSync teardown calls across ~116 test files to cleanup().
~18 genuinely load-bearing sites (mid-test SUT/fault-injection removals,
error-swallowing or name-colliding local teardown helpers) keep the raw call
with an inline eslint-disable + reason.
Shared anti-ratchet primitive
- scripts/lib/allowlist-ratchet.cjs:
- assertWithinAllowlist: fails on NOVEL ids (new offender introduced) AND on
STALE ids (a known offender was fixed but not pruned) — identity, not count,
and a ratchet DOWN toward zero.
- assertTightCeiling: a size/length budget whose ceiling must stay within a
grace band of the high-water mark, so budgets may only tighten, never creep.
Ratchets converted onto the primitive
- windows-test-parity-guard.test.cjs: rmSync rule deleted (now ESLint-enforced);
the remaining six patterns moved from integer baselines to named-set
allowlists with ratchet-down.
- scripts/lint-test-file-count.{cjs,allowlist.json}: per-module integer counts →
named filename sets (closes the swap-a-file-keep-the-count blind spot); a
module dropping under cap now FAILS to force pruning its allowlist entry.
- enh-2790 skill-count `<= 63` → named skill allowlist (ratchets toward ~58).
Size budgets hardened (tighten-only)
- agent-size / workflow-size / feat-3039 help-tiered: ceilings lowered to the
current high-water mark and an assertTightCeiling anti-creep check added per
tier. Fixed external-contract limits (description ≤100 chars, agent ≤100 KB)
are intentionally left as-is — they are not grandfathered creeping budgets.
No user-facing behavior change (tests + tooling only); no USER_FACING_PREFIXES
touched, so no changeset fragment is required.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
284 lines
10 KiB
JavaScript
284 lines
10 KiB
JavaScript
/**
|
|
* Regression: issue #3285 — Codex install fails when config.toml contains
|
|
* hooks.state entries.
|
|
*
|
|
* Root cause: validateCodexConfigSchema walks every `hooks.*` table section
|
|
* and asserts array-of-tables (AoT) shape, without distinguishing the
|
|
* `hooks.state.*` namespace (Codex-managed per-hook trust persistence, a
|
|
* regular table) from `hooks.<EVENT>` (event handlers like SessionStart,
|
|
* which DO require AoT shape via [[hooks.SessionStart]]).
|
|
*
|
|
* Fix: add a carve-out so that any table whose path starts with `hooks.state`
|
|
* is validated as a regular table (not AoT). All `hooks.<EVENT>` paths still
|
|
* require AoT.
|
|
*/
|
|
|
|
// GSD_TEST_MODE must be set before require('../bin/install.js') so the module
|
|
// skips the main CLI entry point and exports its internals.
|
|
const previousGsdTestMode = process.env.GSD_TEST_MODE;
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
const os = require('os');
|
|
const { execFileSync } = require('child_process');
|
|
|
|
const { validateCodexConfigSchema, install } = require('../bin/install.js');
|
|
const installModule = require('../bin/install.js');
|
|
const { cleanup } = require('./helpers.cjs');
|
|
|
|
if (previousGsdTestMode === undefined) {
|
|
delete process.env.GSD_TEST_MODE;
|
|
} else {
|
|
process.env.GSD_TEST_MODE = previousGsdTestMode;
|
|
}
|
|
|
|
// Ensure hooks/dist/ is populated — mirrors the pattern used by codex-config.test.cjs.
|
|
const { before, beforeEach, afterEach } = require('node:test');
|
|
const HOOKS_DIST = path.join(__dirname, '..', 'hooks', 'dist');
|
|
const BUILD_HOOKS_SCRIPT = path.join(__dirname, '..', 'scripts', 'build-hooks.js');
|
|
before(() => {
|
|
if (!fs.existsSync(HOOKS_DIST) || fs.readdirSync(HOOKS_DIST).length === 0) {
|
|
execFileSync(process.execPath, [BUILD_HOOKS_SCRIPT], { encoding: 'utf-8', stdio: 'pipe' });
|
|
}
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// Validator unit tests (no install, just validateCodexConfigSchema)
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('#3285 — validateCodexConfigSchema: hooks.state is a regular table (not AoT)', () => {
|
|
test('bare [hooks.state] table header passes validation', () => {
|
|
const content = [
|
|
'[hooks.state]',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, true,
|
|
'bare [hooks.state] must be allowed (regular-table namespace): ' + result.reason);
|
|
});
|
|
|
|
test('bare [hooks.state.<project-key>] table header passes validation', () => {
|
|
// Mirrors the exact shape Codex CLI 0.130.0+ writes for per-hook trust entries.
|
|
// The key contains slashes and colons — must be quoted in TOML.
|
|
const content = [
|
|
'[hooks.state]',
|
|
'',
|
|
"[hooks.state.'/home/user/.codex/hooks.json:pre_tool_use:0:0']",
|
|
'enabled = true',
|
|
'trusted_hash = "sha256:abc123"',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, true,
|
|
'bare [hooks.state.<key>] with trust fields must be allowed: ' + result.reason);
|
|
});
|
|
|
|
test('hooks.state alongside [[hooks.SessionStart]] AoT both pass', () => {
|
|
// The real-world fixture: user has both Codex trust state AND GSD-managed
|
|
// event hooks in the same config.toml.
|
|
const content = [
|
|
'[hooks.state]',
|
|
'',
|
|
"[hooks.state.'/home/user/.codex/hooks.json:pre_tool_use:0:0']",
|
|
'enabled = true',
|
|
'trusted_hash = "sha256:abc123"',
|
|
'',
|
|
'[[hooks.SessionStart]]',
|
|
'',
|
|
'[[hooks.SessionStart.hooks]]',
|
|
'type = "command"',
|
|
'command = "/usr/local/bin/gsd-check-update"',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, true,
|
|
'mixed hooks.state (regular table) + [[hooks.SessionStart]] (AoT) must pass: ' + result.reason);
|
|
});
|
|
|
|
test('[[hooks.SessionStart]] AoT still requires array-of-tables shape', () => {
|
|
// Regression guard: the fix must NOT relax AoT requirements for event hooks.
|
|
// [hooks.SessionStart] (single-bracket) must still fail.
|
|
const content = [
|
|
'[hooks.SessionStart]',
|
|
'type = "command"',
|
|
'command = "/some/command"',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, false,
|
|
'[hooks.SessionStart] bare table (not AoT) must still be rejected');
|
|
assert.ok(
|
|
result.reason.includes('hooks.SessionStart'),
|
|
'rejection reason must mention hooks.SessionStart, got: ' + result.reason
|
|
);
|
|
});
|
|
|
|
test('hooks.state object in parsed structure does not trigger non-array rejection', () => {
|
|
// The parsed-object check loops over Object.entries(parsed.hooks) and
|
|
// asserts !Array.isArray(value) → error. hooks.state is an object, not
|
|
// an array. The fix must skip hooks.state in that loop too.
|
|
const content = [
|
|
'[hooks.state]',
|
|
'',
|
|
"[hooks.state.'some-key']",
|
|
'enabled = true',
|
|
'trusted_hash = "sha256:deadbeef"',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, true,
|
|
'parsed hooks.state object must not trigger "hooks.state must be an array" rejection: ' + result.reason);
|
|
});
|
|
|
|
test('multiple hooks.state sub-keys all pass validation', () => {
|
|
const content = [
|
|
'[hooks.state]',
|
|
'',
|
|
"[hooks.state.'/project/a/.codex/hooks.json:pre_tool_use:0:0']",
|
|
'enabled = true',
|
|
'trusted_hash = "sha256:aaa"',
|
|
'',
|
|
"[hooks.state.'/project/b/.codex/hooks.json:pre_tool_use:0:0']",
|
|
'enabled = false',
|
|
'trusted_hash = "sha256:bbb"',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, true,
|
|
'multiple hooks.state sub-keys must all pass: ' + result.reason);
|
|
});
|
|
|
|
test('[[hooks.state]] AoT form is rejected', () => {
|
|
// hooks.state must be a regular table — array-of-tables shape is invalid.
|
|
const content = [
|
|
'[[hooks.state]]',
|
|
'enabled = true',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, false,
|
|
'[[hooks.state]] (AoT) must be rejected');
|
|
assert.ok(
|
|
result.reason.includes('hooks.state'),
|
|
'rejection reason must mention hooks.state, got: ' + result.reason
|
|
);
|
|
});
|
|
|
|
test('[[hooks.state.foo]] AoT sub-key form is rejected', () => {
|
|
// hooks.state.* sub-keys must be regular tables — AoT sub-key shape is invalid.
|
|
const content = [
|
|
'[[hooks.state.foo]]',
|
|
'enabled = true',
|
|
'',
|
|
].join('\n');
|
|
const result = validateCodexConfigSchema(content);
|
|
assert.strictEqual(result.ok, false,
|
|
'[[hooks.state.foo]] (AoT sub-key) must be rejected');
|
|
assert.ok(
|
|
result.reason.includes('hooks.state'),
|
|
'rejection reason must mention hooks.state, got: ' + result.reason
|
|
);
|
|
});
|
|
});
|
|
|
|
// ---------------------------------------------------------------------------
|
|
// Full install integration test
|
|
// ---------------------------------------------------------------------------
|
|
|
|
describe('#3285 — install succeeds when config.toml contains hooks.state entries', { concurrency: false }, () => {
|
|
let tmpDir;
|
|
let codexHome;
|
|
|
|
function writeCodexConfig(content) {
|
|
fs.mkdirSync(codexHome, { recursive: true });
|
|
fs.writeFileSync(path.join(codexHome, 'config.toml'), content, 'utf8');
|
|
}
|
|
|
|
function runCodexInstall() {
|
|
const previousCodexHome = process.env.CODEX_HOME;
|
|
const previousCwd = process.cwd();
|
|
process.env.CODEX_HOME = codexHome;
|
|
try {
|
|
process.chdir(path.join(__dirname, '..'));
|
|
return install(true, 'codex');
|
|
} finally {
|
|
process.chdir(previousCwd);
|
|
if (previousCodexHome === undefined) {
|
|
delete process.env.CODEX_HOME;
|
|
} else {
|
|
process.env.CODEX_HOME = previousCodexHome;
|
|
}
|
|
}
|
|
}
|
|
|
|
beforeEach(() => {
|
|
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-3285-'));
|
|
codexHome = path.join(tmpDir, 'codex-home');
|
|
});
|
|
|
|
afterEach(() => {
|
|
cleanup(tmpDir);
|
|
});
|
|
|
|
test('install does not throw when config.toml contains hooks.state trust entries', () => {
|
|
// This is the exact failure scenario reported in #3285.
|
|
const preInstall = [
|
|
'[hooks.state]',
|
|
'',
|
|
"[hooks.state.'/home/user/.codex/hooks.json:pre_tool_use:0:0']",
|
|
'enabled = true',
|
|
'trusted_hash = "sha256:abc123def456"',
|
|
'',
|
|
].join('\n');
|
|
writeCodexConfig(preInstall);
|
|
|
|
assert.doesNotThrow(
|
|
() => runCodexInstall(),
|
|
'install must not throw when config.toml contains hooks.state trust entries'
|
|
);
|
|
});
|
|
|
|
test('hooks.state entries are preserved in post-install config.toml', () => {
|
|
const preInstall = [
|
|
'[hooks.state]',
|
|
'',
|
|
"[hooks.state.'/home/user/.codex/hooks.json:pre_tool_use:0:0']",
|
|
'enabled = true',
|
|
'trusted_hash = "sha256:abc123def456"',
|
|
'',
|
|
].join('\n');
|
|
writeCodexConfig(preInstall);
|
|
|
|
runCodexInstall();
|
|
|
|
const after = fs.readFileSync(path.join(codexHome, 'config.toml'), 'utf8');
|
|
// Verify structurally: the trust hash key must survive the install.
|
|
// Do NOT grep for the literal string — parse the TOML structure.
|
|
const { parseTomlToObject } = require('../bin/install.js');
|
|
const parsed = parseTomlToObject(after);
|
|
assert.ok(
|
|
parsed.hooks && typeof parsed.hooks.state === 'object' && parsed.hooks.state !== null,
|
|
'post-install config.toml must have hooks.state as an object'
|
|
);
|
|
// Verify the actual trust entry survives — not just that hooks.state is an object.
|
|
const trustKey = "/home/user/.codex/hooks.json:pre_tool_use:0:0";
|
|
assert.ok(
|
|
parsed.hooks.state[trustKey] != null,
|
|
`post-install must preserve the original trust entry for key: ${trustKey}`
|
|
);
|
|
assert.strictEqual(
|
|
parsed.hooks.state[trustKey].enabled,
|
|
true,
|
|
'preserved trust entry must have enabled = true'
|
|
);
|
|
assert.strictEqual(
|
|
parsed.hooks.state[trustKey].trusted_hash,
|
|
'sha256:abc123def456',
|
|
'preserved trust entry must have the original trusted_hash'
|
|
);
|
|
});
|
|
});
|