* test(#3338): fold the verify/validate & workflow-text issue-* cluster — Wave 6 Folds 10 legacy issue-*.test.cjs regression files (75 test() blocks) into their module's main suite, per H3 (#3315) of the test-hygiene epic (#3053). Third of 4 issue-* waves. - issue-2701-nul-corrupted-validators.test.cjs (9) + issue-429-comment- text-gate.test.cjs (31, incl. fast-check property tests): both target verify.cjs/validate.cjs via different calling styles (CLI vs direct- require) — merged jointly into verify.test.cjs, 0 dropped. - issue-2762-plan-reviews-chunked.test.cjs (3) merged into plan-phase-drift-guard.test.cjs. - issue-2771-advisor-subagent-type.test.cjs (1) + issue-2772-discuss- phase-text-inconsistencies.test.cjs (6) merged jointly into discuss-phase-power.test.cjs. - issue-498-update-backup-runtime-dir.test.cjs (3, rename basis) + issue-815-update-next-channel.test.cjs (7, merged in): both concern update.md workflow-text contracts, now update-workflow.test.cjs. - issue-498-update-context.test.cjs (13): pure rename to update-context.test.cjs, sole comprehensive suite for its module. - issue-2765-brace-expansion-lockfile.test.cjs (1, rename basis) + issue-3238-js-yaml-lockfile.test.cjs (1, merged in): two distinct CVE regression pins against package-lock.json, now lockfile-cve-audit.test.cjs, shared ROOT/npmLs helpers deduped instead of double-declared. Ratchet upkeep to keep this wave's own gates green: pruned 3 stale allow-test-rule allowlist entries, cited 2 previously-uncited comments that surfaced in the folded content (#3338), tightened the exemption-file ceiling 305 -> 297. Fixed one stale filename reference in production code (src/init.cts) plus one in docs/reference/workflow-fragments.md. Zero net test-coverage loss. No production code BEHAVIOR changed. * test(#3338): fix orthogonal-review findings — Wave 6 fold Standards-axis review found a real structural defect in two files, both the same root cause and both fixed here: - tests/update-workflow.test.cjs: the folded:issue-815-update-next-channel wrapper's closing brace was placed after the file's pre-existing tail instead of before it, making the already-established folded:bug-2470 and folded:bug-3130 wrappers CHILDREN of issue-815's block in the test hierarchy instead of independent siblings — confirmed via an actual node --test run showing the mislabeled TAP nesting. Moved the closing brace to the correct position; all three fold wrappers are now top-level siblings again (verified via node --test, TAP hierarchy correct, 10/10 tests, 5 suites, identical count before and after). - tests/plan-phase-drift-guard.test.cjs: same mistake in the other direction — folded:issue-2762-plan-reviews-chunked was spliced inside the pre-existing folded:bug-2492-context-coverage-gate wrapper instead of after it. Fixed the same way (227/227 tests, 38 suites, identical count before and after). - Reverted unnecessary 815-suffixed local renames (assert815/fs815/etc.) introduced by the fold — the wrapper is genuinely block-scoped once correctly closed, so no collision existed (same class as Wave 4's __foldSetNested finding). No test() count changed in either file. No production code touched. --------- Co-authored-by: sim <sim@local>
100 lines
5.4 KiB
JavaScript
100 lines
5.4 KiB
JavaScript
// allow-test-rule: structural-implementation-guard (#2765, #3238)
|
|
'use strict';
|
|
|
|
// Regression guard for #2765: the lockfile must pin the patched brace-expansion
|
|
// versions (>=1.1.18 for the 1.x line, >=5.0.9 for the 5.x line) published 2026-07-30
|
|
// to resolve the high-severity DoS/OOM advisories (GHSA-3jxr-9vmj-r5cp /
|
|
// GHSA-mh99-v99m-4gvg, range <=5.0.7). This is a lockfile-only devDependency bump
|
|
// (eslint/stryker → minimatch → brace-expansion); production (npm audit --omit=dev) is
|
|
// unaffected. The test pins the installed versions so the bump can't silently regress.
|
|
//
|
|
// Regression guard for #3238: the lockfile must also pin a patched js-yaml (>=4.3.1 on
|
|
// the 4.x line, >=3.15.1 on the 3.x line) to resolve GHSA-5p4m-2wfm-xmqj — a
|
|
// high-severity (CVSS 7.5, CWE-407) quadratic-CPU DoS in `!!omap` resolution,
|
|
// vulnerable range `>=4.0.0 <4.3.1`. `!!omap` is in the DEFAULT schema, so a plain
|
|
// yaml.load() is affected. This is a lockfile-only devDependency bump (direct, plus
|
|
// an @eslint/eslintrc dedupe); production (npm audit --omit=dev) was already clean.
|
|
// The test pins every installed copy so the bump can't silently regress. Folded into
|
|
// this file (originally tests/issue-3238-js-yaml-lockfile.test.cjs) because it is the
|
|
// same shape of lockfile CVE-pin regression test for a different package/CVE; it
|
|
// shares the ROOT/npmLs/NPM_LS_TIMEOUT_MS helpers below rather than duplicating them.
|
|
|
|
const { test } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const { execFileSync } = require('node:child_process');
|
|
const path = require('node:path');
|
|
|
|
const ROOT = path.join(__dirname, '..');
|
|
|
|
// `npm` is not process.execPath, git, or a bash script/hook, so this does not
|
|
// route through tests/helpers/process-seam.cjs (whose runNode/runGit/runHook
|
|
// primitives cover exactly those three shapes and forward no `shell` option)
|
|
// — `npm` needs `shell: true` on Windows (npm.cmd), which the seam has no
|
|
// surface for. Bounding this directly with an explicit `timeout` is the
|
|
// documented alternative in eslint-rules/no-unbounded-spawn.cjs.
|
|
const NPM_LS_TIMEOUT_MS = 30000;
|
|
|
|
function npmLs(pkg) {
|
|
// `npm ls <pkg> --json --all` lists every installed copy with its version. Collect
|
|
// the version of every node whose key is `pkg` (not the parent packages).
|
|
const out = execFileSync('npm', ['ls', pkg, '--json', '--all'], {
|
|
cwd: ROOT, encoding: 'utf8', shell: true, stdio: ['ignore', 'pipe', 'ignore'],
|
|
timeout: NPM_LS_TIMEOUT_MS,
|
|
});
|
|
const versions = [];
|
|
const walk = (node) => {
|
|
if (!node || !node.dependencies) return;
|
|
for (const [k, v] of Object.entries(node.dependencies)) {
|
|
if (k === pkg && v && v.version) versions.push(v.version);
|
|
walk(v);
|
|
}
|
|
};
|
|
walk(JSON.parse(out));
|
|
return versions;
|
|
}
|
|
|
|
test('all installed brace-expansion copies are patched (>=1.1.18 / >=5.0.9) — #2765', () => {
|
|
const versions = npmLs('brace-expansion');
|
|
assert.ok(versions.length > 0, 'brace-expansion must be installed (devDependency) to guard');
|
|
for (const v of versions) {
|
|
const [maj, min, pat] = v.split('.').map(Number);
|
|
const ok = (maj === 1 && (min > 1 || (min === 1 && pat >= 18))) // 1.x >= 1.1.18
|
|
|| (maj === 5 && (min > 0 || pat >= 9)) // 5.x >= 5.0.9
|
|
|| (maj > 5); // >5.x
|
|
assert.ok(ok,
|
|
`brace-expansion@${v} is within the vulnerable range (<=5.0.7) — lockfile regressed the #2765 patch bump. ` +
|
|
'Re-apply: npm audit fix (non-breaking) to bump to 1.1.18 / 5.0.9.');
|
|
}
|
|
});
|
|
|
|
// GHSA-5p4m-2wfm-xmqj names only the 3.x (<3.15.1) and 4.x (<4.3.1) lines. The SAME
|
|
// weakness in the 5.x line is CVE-2026-59870 / GHSA-724g-mxrg-4qvm, fixed in 5.2.1 —
|
|
// so a guard against this bug CLASS must require 5.2.1 there too rather than waving
|
|
// every 5.x through, or an accidental major bump to 5.0.0 would reintroduce the exact
|
|
// quadratic `!!omap` resolution this test exists to prevent.
|
|
function isPatchedJsYaml(version) {
|
|
const core = String(version).split('+')[0]; // drop build metadata
|
|
// A prerelease of the patched version (e.g. 4.3.1-beta.1) sorts BELOW it in semver
|
|
// and may predate the fix — fail closed rather than guess.
|
|
if (core.includes('-')) return false;
|
|
const [maj, min, pat] = core.split('.').map(Number);
|
|
if (![maj, min, pat].every(Number.isInteger)) return false; // unparseable — fail closed
|
|
if (maj < 3) return true; // predates the affected lines
|
|
if (maj === 3) return min > 15 || (min === 15 && pat >= 1); // 3.x >= 3.15.1
|
|
if (maj === 4) return min > 3 || (min === 3 && pat >= 1); // 4.x >= 4.3.1
|
|
if (maj === 5) return min > 2 || (min === 2 && pat >= 1); // 5.x >= 5.2.1 (CVE-2026-59870)
|
|
return true; // >5.x
|
|
}
|
|
|
|
test('all installed js-yaml copies are patched (>=4.3.1 / >=3.15.1 / >=5.2.1) — #3238', () => {
|
|
const versions = npmLs('js-yaml');
|
|
// Vacuity guard: an empty list would make every assertion below trivially true.
|
|
assert.ok(versions.length > 0, 'js-yaml must be installed (devDependency) to guard');
|
|
for (const v of versions) {
|
|
assert.ok(isPatchedJsYaml(v),
|
|
`js-yaml@${v} is not a patched version — the quadratic \`!!omap\` resolution bug is ` +
|
|
'present in 3.x <3.15.1 (GHSA-5p4m-2wfm-xmqj), 4.x <4.3.1 (same), and 5.x <5.2.1 ' +
|
|
'(CVE-2026-59870). Re-apply: npm install js-yaml@^4.3.1');
|
|
}
|
|
});
|