Files
msd-core/tests/release-tarball-smoke.install.test.cjs
Tom Boucher 4d65c248e5 fix(#4641): make test-conformance the sole Windows selector and narrow the tier to 28.5% (#4643)
* test(#4641): failing-first tests for the tier ceiling and a single Windows selector

Tests only, committed ahead of the implementation so the RED run is real.

- tests/platform-conformance-tier.test.cjs: tier-size ceiling asserted as a
  ratio against a live denominator (Windows 33%, macOS 25%); per-helper negative
  cases proving seam calls and path-call-plus-slash-literal are not platform
  signals; positive pins that genuine platform content, seam-bypassing spawns,
  chmod and symlink still classify in; macOS signal set and generated list
  unchanged.
- tests/ci-full-lane-sharding.test.cjs: the test job has zero windows-latest
  rows and test-conformance still has 3 windows + 1 macOS.
- tests/ci-test-scope.test.cjs: windows_tests is absent rather than empty, a
  non-tier test file no longer forces full_matrix, a RULE-pulled windows-hint
  test does, and resolveSelection rejects the retired windows scope.

Refs #4589, #4591, #4592, #4593, #4603

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4641): delete the second Windows selector and narrow the conformance tier

Epic #4589's goal — the OS-agnostic bulk on Linux, a small explicitly-scoped
conformance tier on real Windows/macOS — was not met. Measured on PR #4640
(run 34618834118): 7 non-Linux jobs, a 546/930 (58.7%) "tier", and 5 of 7
changed test files running on a real Windows runner twice.

Two selectors, only one in the epic's scope. The test job's three scope:windows
shards predate the epic (#494, sharded #3057) and gate on product_changed, not
full_matrix, so they fire on every product PR whatever Phase 3's classifier
decides. They are deleted; test-conformance becomes the sole Windows selector,
as it already was for macOS. Non-Linux jobs 7 -> 4.

Gating the lane instead was rejected as provably redundant: for a test file
reachesConformanceTierOrSeam is literally CONFORMANCE_TIER_FILES.includes(file),
and that same predicate sets full_matrix, which turns test-conformance on. Every
file a gated lane would run is already covered in the same run. The lane's one
non-redundant residue -- RULE-pulled tests matched by the isWindowsHint filename
heuristic -- is ported into reachesConformanceTierOrSeam so it sets full_matrix
instead of feeding a parallel lane.

Two detectors matched the repo's own test idiom rather than any platform signal
and carried 226 of the tier's sole-signal membership against 41 for the other
eight: process-seam-subprocess (335 files, 118 unique) matches the
tests/helpers.cjs entry points nearly every CLI test uses, and going through the
seam is the opposite of a platform signal since shell-command-projection takes
platform as an injected parameter; hardcoded-path-vs-path-call (328, 108) needs
only a path call anywhere plus a slash literal anywhere, and that class is
already enforced by ADR-1703's Linux-runnable ESLint rules. Both are removed.
Tier 546 -> 254 (27.3%). src/ reachability is unchanged at 28 files, measured.

Adds the size gate Phase 2 never had, as a ratio against a live denominator so
it cannot stop binding as the suite grows.

292 files leave real-OS Windows execution. The drop-out set was audited: 14 have
a platform-suggestive filename and all 14 are static source-text analyses or
seam-mediated CLI tests. raw-child-process was investigated as a suspected false
negative and left unchanged -- relaxing it adds 13 files, all false positives.

macOS is untouched: MACOS_CATEGORIES is a separate array and the regenerated
macos-conformance-tier.generated.cjs is byte-identical at 196 files.

Fixes #4641
Refs #4589, #4591, #4592, #4593, #4603

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4641): register the new ADR path in the docs-guard exempt baseline

tests/ci-test-scope.test.cjs references docs/adr/4641-windows-selector-consolidation.md
in a comment justifying the retired windows scope; lint-docs-guard-registration
tracks that reference set, so the baseline needs the new path. Verified the
exemption still holds: the path is prose, not a filesystem read.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4641): make the escalation tier-backed and drop every hardcoded count

Three follow-ups from measuring the first pass rather than trusting it.

The windows-hint escalation now requires tier membership as well as the
filename hint. Setting full_matrix runs test-conformance, which runs only the
tier; escalating on a test that is NOT in the tier costs four jobs and still
never runs that test on Windows. Measured over the 16 RULES entries the
narrowed predicate fires on exactly the same rules today, so this is
correct-by-construction rather than a behavior change. The broader variant --
escalate on any tier member a rule pulls in, ignoring the hint -- was measured
at 14/16 rules and rejected as over-broad.

Removes the hardcoded counts. A hardcoded macOS tier length of 196 broke as
soon as the rebase pulled in one new test file from #4253, which is the whole
argument against them: the ceilings are ratios against a live denominator, the
committed lists are pinned by comparison against a fresh classification of the
live tree, and the three named probe files now assert on their SIGNAL rather
than on membership in a literal list -- asserting by filename is the exact
error this PR fixes in the classifier.

Regenerates both lists against the rebased tree. Same-tree figures are now
547 -> 255 of 931 eligible (58.8% -> 27.4%), 292 entries removed and none
added; macOS is unchanged at 197 with a zero-line diff.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4641): restore real-shell-spawn coverage and repair assertions the narrowing broke

An isolated adversarial review found a real false negative. Removing the
blanket process-seam-subprocess detector also removed the only coverage for
tests that spawn a REAL shell: tests/helpers/process-seam.cjs's runHook
spawns options.interpreter via real spawnSync, so
runHook('-c', [script], { interpreter: 'bash' }) runs a real bash binary
executing a shell script extracted from workflow markdown. The seam argument
holds for src/shell-command-projection.cts, which takes platform as an
injected parameter; it does NOT hold for the test helpers, which spawn real
binaries. Conflating the two is what made the blanket detector look purely
noisy -- it was 99% noise wrapping a real signal.

Adds a narrow shell-interpreter-spawn category keyed on a real interpreter
option. Measured 2026-09-11: 33 files match, 9 were outside the tier and are
added back, taking it 255 -> 264 of 931 (27.4% -> 28.4%), still under the 33%
ceiling. All 9 confirmed by reading the matching source line, zero comment or
fixture matches. runGit-alone and non-node-spawnSeam alternatives were measured
and rejected -- each adds 9 files but misses the counterexample entirely.

Fixes a real bug the suite caught: jobs.test is ubuntu-only now that its
scope:windows rows are gone, so it must wire GSD_STRICT_LIVE_CONFIG_GUARD
strictly rather than carrying the Windows report-only carve-out. The carve-out
now lives solely on test-conformance, whose matrix does include windows.

Repairs seven pre-existing assertions the category removal invalidated,
preserving each case's purpose rather than deleting coverage, and converts the
last hardcoded tier bounds to live-derived ratios -- including the macOS
sanity range that was still a magic [100, 350].

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4641): keep the confinement test on a real OS via a documented allowlist

A security review found tests/external-descriptor-confinement.test.cjs had
dropped out of the Windows tier. It must stay in, and no content signal can
express why: it exercises isPathConfined (src/external-descriptor-trust.cts),
which uses the AMBIENT path module -- path.resolve(root, target) and path.sep
-- with no injection. Its win32 semantics (drive letters, UNC, separator) are
only reachable by actually running on Windows, and it is a security-relevant
write-confinement gate. A content classifier cannot see 'this module reads the
ambient path module', so no regex belongs here.

Adds ALWAYS_REAL_OS, a Map of path -> recorded reason, unioned into the Windows
tier only. A Map rather than a list so an entry without a reason is impossible
by construction, and tests assert every entry names a file that exists on disk
so a stale entry fails loudly instead of rotting. This is the centrally-
enumerated single source of truth epic #4589 Phase 2 asked for and ADR-1703's
portability-vocab.cjs already models -- deliberately not a heuristic.

Windows tier 264 -> 265 of 931 (28.5%), still under the 33% ceiling. macOS is
untouched and byte-identical: the win32 concern does not apply to a POSIX
runner, and a test asserts the allowlist does not leak into that tier.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#4641): inject the path impl into isPathConfined and correct the ADR count

Two review findings, both fixed rather than dispositioned.

A security review found tests/external-descriptor-confinement.test.cjs had left
real-OS execution. The allowlist pinned it back, but that only restored
INCIDENTAL coverage: isPathConfined used the ambient path module, and its test
carried POSIX-only literals, so a win32 confinement escape was unverified on
every platform including Windows. isPathConfined now takes an optional third
parameter carrying the path implementation, defaulting to the ambient module.
Blast radius is CRITICAL -- 53 affected symbols across 19 files -- so the change
is purely additive and every existing two-argument caller is byte-identical.

Tests now inject path.win32 and path.posix, covering a different drive letter,
a cross-drive absolute, backslash and forward-slash traversal, UNC, and the
startsWith prefix-boundary bug (.gsdEVIL against root .gsd) on both separators.
Proved load-bearing: dropping the + p.sep from the prefix check fails exactly
the two boundary cases and nothing else. Callers' suites 149/149.

The spec review caught an off-by-one: the ADR narrated a 264-file tier while the
committed list holds 265. The ADR now records the full chain 547 -> 255 -> 264
-> 265 (28.5%).

Also corrects a stale comment in scripts/docs-guard-registry.cjs that narrated
classify() as zeroing windows_tests, a key this change removes -- kept as
historical narration but labelled as such.

Refs #4641

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(#131): make the unwritable-HOME test actually test something

Found by sweeping for the root-bypass class after fixing commit-files-deletion.
This one is the silent variant, and it was broken twice over.

First, the condition: the test made a fake HOME unwritable with chmod 0o500.
The gsd-test Docker bench runs as root, root bypasses mode bits, so HOME stayed
writable and the hostile condition never existed. Replaced with a HOME whose
PARENT is a regular file, so every write under it fails ENOTDIR at the VFS
layer for every uid -- no permission check is involved at all.

Second, and more fundamental: the probe was npm --version, which on npm 11.19.0
performs zero filesystem I/O against HOME. Proven rather than assumed --
neutralizing runNpm()'s isolation turned the sibling test red while this one
stayed green, so its assertion could never detect the regression it guards, on
any uid, with or without the condition fix. npm config get cache was tried next
and proved vacuous the same way (it only string-resolves the path). The probe is
now npm cache verify, which really does mkdir _cacache under HOME.

Re-proved load-bearing after the change: with isolation neutralized the test now
fails with ENOTDIR on <blocker>/home/.npm/_cacache. tests/helpers.cjs was
restored and verified diff-clean; suite 13/13.

Refs #4641

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): correct the net drop-out figure in ADR-4641

The Consequences section still said 292 files leave real-OS Windows execution.
That was the count before the narrow shell-interpreter-spawn replacement
restored 9 and ALWAYS_REAL_OS pinned 1. Net is 282. Also names both real-binary
categories rather than only raw-child-process, and clarifies that the 14-file
filename audit was against the 292 initially dropped.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): record the rejected concentration ceiling and its measurement

Applying Goodhart's own question to the new ceiling -- how would you make this
metric look good without improving what it represents -- surfaces a real
weakness: a ratio can be satisfied by inflating the denominator, so adding
OS-agnostic tests loosens it without narrowing the tier.

The obvious companion gate was a sole-signal concentration ceiling, since the
original defect was one detector carrying half the tier. Measured and rejected:
peak concentration post-fix is raw-child-process at 53/265 = 20.0%, against the
historic offenders at 21.6% and 19.8%. Any threshold above 20% misses the
original defect; any threshold below it fails on a legitimate category. The
discriminator is whether a signal is platform-meaningful, which no threshold
encodes. Weakness disclosed rather than covered by a gate that does not bind.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* chore(#4641): add the changeset fragment for the confinement-check change

changeset-lint failed on PR #4643: the PR touches user-facing paths and carried
no fragment. The earlier no-changeset call matched #4604's CI-only precedent and
was correct then; it was not revisited once the PR grew a src/ change, which is
my miss.

The fragment describes the real user-visible improvement: the external-descriptor
write-confinement check's Windows semantics are now verified deterministically
rather than only when the suite happened to run on Windows.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): correct the tier count in TESTING-SUITES.md

Said the tier narrowed from 546 to 254. The final committed list is 265 of 931
eligible (58.8% -> 28.5%) after the shell-interpreter-spawn replacement restored
9 files and ALWAYS_REAL_OS pinned 1. Same error class the spec review caught in
the ADR, in a live reference page rather than a dated record, so it states the
current truth rather than carrying an amendment note.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): record the measured aggregate from real CI job lists

Epic #4589's closeout asserted its reduction from a static count; #4641's
acceptance criterion asks for a figure read off a real run. Recorded here:
test.yml job count 21 -> 15 and non-Linux 7 -> 4, comparing PR #4640's run
against this PR's own. Against the true pre-epic baseline of 9, that is 9 -> 4.

Also states the caveat that a PR's total CHECK count is not a clean before/after
comparison, since many gates are path-scoped and this change touches a broader
path set -- the like-for-like figure is the test.yml job count.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): compare job totals the same way on both sides

The measured-aggregate table put #4640's COMPLETED run total (21) against this
run's count at matrix-expansion time (15). Those are not the same measurement:
the completed total includes the post-test Coverage gate and baseline-publisher
jobs. Counted identically, it is 21 -> 17. The load-bearing figure, non-Linux
jobs 7 -> 4, was correct and is unchanged.

Called out in the table rather than silently corrected -- comparing two
differently-derived numbers is exactly the error class this ADR is about.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): record measured conformance wall-clock and date the stale counterfactual

Adds the per-job durations from both runs. The honest read is that this is a
correctness win more than a speed one: file count fell 52% but wall-clock only
9-29%, because what was removed were the cheap static tests and what remains is
concentrated in expensive spawn-heavy work. Stated explicitly so nobody expects
a future narrowing to buy time proportional to file count.

The load-bearing figure is windows shard 3/3: 40m24s against a 45-minute cap on
the 547-file tier -- 90% of the cliff #869 and #3057 were both filed about --
pulled back to 31m27s. macOS moved the wrong way (17m48s -> 21m02s) while its
tier was UNCHANGED at 197 files, which fixes that as runner variance and is
noted as a caution against reading a single duration as signal.

Also dates the symlink-keyword counterfactual, which cited a 254-file tier from
before the replacement category and allowlist took it to its final 265.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* docs(#4641): re-measure against the rebased tree and disclose the allowlist's zero

next gained #4644 mid-flight, so every absolute count shifted. Re-measured on
the tree this actually ships against (932 eligible): 548 -> 257 by detector
removal, 257 -> 266 once shell-interpreter-spawn restores 9. Net 282 removed,
9 restored. macOS 198, unchanged by this PR.

The percentages did not move across three rebases (58.8% -> 28.5%), which is
the whole argument for expressing the ceilings as ratios rather than counts --
noted in the ADR since it is now evidence rather than assertion.

Also discloses that ALWAYS_REAL_OS now contributes ZERO files: this PR's own
win32 test cases introduced the literal win32 into the pinned file, so it
classifies in on content via win32-darwin-literal. The entry stays and the
reason is written down, because the file's real-OS need is a property of the
code under test (isPathConfined reads the ambient path module), not of the
test's text -- the text that currently saves it is incidental and could be
refactored away silently.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-09-11 17:00:11 -04:00

779 lines
37 KiB
JavaScript
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
// allow-test-rule: integration-test-input
// The script under test (scripts/release-tarball-smoke.cjs) is the system
// under test. We exercise it via its exported pure function, not by reading
// source text. The tarball fixture is produced by npm pack in before().
'use strict';
process.env.GSD_TEST_MODE = '1';
const { describe, test, before, after } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const path = require('node:path');
const crypto = require('node:crypto');
const { spawnSync } = require('node:child_process');
const { cleanup, createTempDir, runNpm, isolatedNpmEnv } = require('./helpers.cjs');
const { SMOKE, runSmoke, CHILD_TIMEOUT_MS } = require('../scripts/release-tarball-smoke.cjs');
const smokeMsg = (label, result) =>
`${label}: code=${result.code} details=${JSON.stringify(result.details)}`;
const PKG_PATH = path.join(__dirname, '..', 'package.json');
const pkg = JSON.parse(fs.readFileSync(PKG_PATH, 'utf-8'));
function installedPackageRoot(prefix) {
const parts = pkg.name.split('/');
const posix = path.join(prefix, 'lib', 'node_modules', ...parts);
const windows = path.join(prefix, 'node_modules', ...parts);
return fs.existsSync(posix) ? posix : windows;
}
function hashTree(root) {
const result = new Map();
const visit = (dir) => {
for (const entry of fs.readdirSync(dir, { withFileTypes: true })) {
const absolute = path.join(dir, entry.name);
if (entry.isDirectory()) visit(absolute);
else if (entry.isFile()) {
result.set(
path.relative(root, absolute).replace(/\\/g, '/'),
crypto.createHash('sha256').update(fs.readFileSync(absolute)).digest('hex'),
);
}
}
};
visit(root);
return result;
}
// ─── runSmoke install timeout must clear a slow-host cold install (#2335) ────
// Regression: runSmoke()'s internal `npm install -g` used CHILD_TIMEOUT_MS,
// which was 120 s on non-Windows while before()'s pack+install used 600 s. A
// cold-cache install of the 1499-file tarball takes 3–6 min on a slow bench, so
// the per-test installs (B/C/D/E) fired SIGTERM at 120 s and returned a spurious
// INSTALL_FAILED (`spawnSync npm ETIMEDOUT`, empty stdout/stderr) on cartographer
// while passing on faster holodeck — a host-dependent false failure, not a flake.
// The ceiling is now a single exported constant shared by both surfaces; this
// pins it at/above the documented 600 s slow-host floor on EVERY platform, so a
// reintroduced 120 s (or a Windows-only 600 s) fails here instead of on a bench.
describe('release-tarball-smoke: install timeout ceiling', () => {
test('CHILD_TIMEOUT_MS clears the 600 s slow-host cold-install floor', () => {
assert.ok(
Number.isInteger(CHILD_TIMEOUT_MS) && CHILD_TIMEOUT_MS >= 600_000,
`CHILD_TIMEOUT_MS must be >= 600000ms for cartographer-class hosts; got ${CHILD_TIMEOUT_MS}`,
);
});
test('the ceiling is platform-uniform — no host slower than the CI matrix is left under-provisioned', () => {
// The slow-host reality (cold disk, constrained CPU) is not OS-specific, so
// the constant must not be gated behind `process.platform`. A single numeric
// constant satisfies this by construction; this guards against a future
// reintroduction of a per-platform ternary that under-provisions Linux/macOS.
assert.equal(typeof CHILD_TIMEOUT_MS, 'number');
assert.ok(CHILD_TIMEOUT_MS >= 600_000);
});
});
describe('release-tarball-smoke', () => {
// Shared fixture state: pack the tarball once, install it once, reuse for all tests.
let packDir;
let installPrefix;
let tarballPath;
// fixtureDir for lifecycle / init tests; created once in before(), cleaned in after().
let fixtureDir;
before(async () => {
// Pack once into a temp dir.
packDir = createTempDir('gsd-smoke-pack-');
installPrefix = createTempDir('gsd-smoke-prefix-');
fixtureDir = createTempDir('gsd-smoke-fixture-');
// npm pack + npm install -g on a large tarball (1499 files, ~10 MB) can take
// 3–6 minutes on slow Docker hosts (cold disk, constrained CPU). The runNpm
// default timeout of 180 s is sufficient on fast machines but insufficient on
// cartographer-class hosts. Share the smoke script's CHILD_TIMEOUT_MS ceiling
// so before() (pack+install) and runSmoke()'s per-test installs cannot diverge
// — divergence was the #2335-run defect: before() had 600 s, runSmoke had 120 s
// on Linux, so the per-test installs alone timed out on cartographer.
const SLOW_HOST_TIMEOUT = CHILD_TIMEOUT_MS;
const packOutput = runNpm(
['pack', '--pack-destination', packDir],
{ cwd: path.join(__dirname, '..'), timeout: SLOW_HOST_TIMEOUT },
);
// npm pack prints the filename as the last line of stdout.
const lines = packOutput.split(/\r?\n/).filter(Boolean);
const tgzName = lines[lines.length - 1];
tarballPath = path.join(packDir, tgzName);
if (!fs.existsSync(tarballPath)) {
const found = fs.readdirSync(packDir).find((f) => f.endsWith('.tgz'));
if (!found) throw new Error(`npm pack produced no .tgz in ${packDir}; output: ${packOutput}`);
tarballPath = path.join(packDir, found);
}
// Install once into installPrefix. All tests share this install.
runNpm(['install', '-g', '--prefix', installPrefix, tarballPath], { timeout: SLOW_HOST_TIMEOUT });
});
after(() => {
cleanup(packDir);
cleanup(installPrefix);
cleanup(fixtureDir);
});
// ── Test A — happy path ────────────────────────────────────────────────────
test('A: happy path — installed version matches package.json', () => {
const result = runSmoke({
tarballPath,
installPrefix,
expectedVersion: pkg.version,
fixtureDir,
npmEnv: isolatedNpmEnv(),
});
assert.equal(result.code, SMOKE.OK, smokeMsg('A', result));
assert.equal(result.details.version, pkg.version, smokeMsg('A', result));
});
// ── Test B — version mismatch detected ────────────────────────────────────
test('B: version mismatch detected — returns VERSION_MISMATCH', () => {
const result = runSmoke({
tarballPath,
installPrefix,
expectedVersion: '99.99.99',
fixtureDir,
npmEnv: isolatedNpmEnv(),
});
assert.equal(result.code, SMOKE.VERSION_MISMATCH, smokeMsg('B', result));
});
// ── Test C — happy lifecycle ───────────────────────────────────────────────
// Verifies that the installed package has all expected command .md files and
// that each command resolves a workflow .md file that also exists.
// Also verifies that `gsd-core --local --claude` (init) succeeds in
// the fixtureDir and creates the expected .claude/ directories.
test('C: happy lifecycle — command + workflow files resolve OK', () => {
const result = runSmoke({
tarballPath,
installPrefix,
expectedVersion: pkg.version,
fixtureDir,
lifecycleCommands: ['init', 'discuss-phase', 'plan-phase'],
npmEnv: isolatedNpmEnv(),
});
assert.equal(result.code, SMOKE.OK, smokeMsg('C', result));
// Each non-init command must be in lifecycleResolved with both paths populated
const resolved = result.details.lifecycleResolved;
assert.ok(Array.isArray(resolved));
for (const entry of resolved) {
assert.ok(
typeof entry.commandPath === 'string' && entry.commandPath.length > 0,
`expected commandPath for ${entry.command}`,
);
assert.ok(
fs.existsSync(entry.commandPath) && fs.statSync(entry.commandPath).isFile(),
`commandPath must be an existing file: ${entry.commandPath}`,
);
assert.ok(
typeof entry.workflowPath === 'string' && entry.workflowPath.length > 0,
`expected workflowPath for ${entry.command}`,
);
assert.ok(
fs.existsSync(entry.workflowPath) && fs.statSync(entry.workflowPath).isFile(),
`workflowPath must be an existing file: ${entry.workflowPath}`,
);
}
});
// ── Test D — missing command detected ─────────────────────────────────────
// Passes a nonexistent command name; expects the smoke to detect the missing
// command .md file and return COMMAND_FILE_MISSING with the right details.
test('D: missing command detected — returns COMMAND_FILE_MISSING', () => {
const result = runSmoke({
tarballPath,
installPrefix,
expectedVersion: pkg.version,
fixtureDir,
lifecycleCommands: ['init', 'nonexistent-phase-xyz'],
npmEnv: isolatedNpmEnv(),
});
assert.equal(result.code, SMOKE.COMMAND_FILE_MISSING, smokeMsg('D', result));
assert.equal(result.details.command, 'nonexistent-phase-xyz', smokeMsg('D', result));
assert.ok(typeof result.details.path === 'string' && result.details.path.length > 0, smokeMsg('D', result));
});
// ── Test E — workflow-body checks run (informational) ─────────────────────
// Asserts that the workflow-body scanning machinery ran (structural assertion).
// Does NOT assert colonLeakCount is zero — when those issues are fixed, this
// test continues to pass unchanged.
test('E: workflow-body checks run — scan counts are present integers', () => {
const result = runSmoke({
tarballPath,
installPrefix,
expectedVersion: pkg.version,
fixtureDir,
lifecycleCommands: [],
npmEnv: isolatedNpmEnv(),
});
// Structural: the scan ran and populated the counters
assert.ok(
Number.isInteger(result.details.workflowsScanned) && result.details.workflowsScanned >= 1,
smokeMsg('E', result),
);
assert.ok(
Number.isInteger(result.details.colonLeakCount),
smokeMsg('E', result),
);
});
test('F: packed package carries the complete canonical Runtime Surface corpus', () => {
const packageRoot = installedPackageRoot(installPrefix);
assert.deepStrictEqual(
hashTree(path.join(packageRoot, 'commands', 'gsd')),
hashTree(path.join(__dirname, '..', 'commands', 'gsd')),
);
assert.deepStrictEqual(
hashTree(path.join(packageRoot, 'agents')),
hashTree(path.join(__dirname, '..', 'agents')),
);
});
test('G: deployed Codex and Claude modules materially change a surface after package source is unreachable', (t) => {
const runtimeRoot = createTempDir('gsd-smoke-offline-runtime-');
const packageRoot = installedPackageRoot(installPrefix);
const hiddenPackageRoot = `${packageRoot}.offline-${process.pid}`;
t.after(() => {
if (fs.existsSync(hiddenPackageRoot) && !fs.existsSync(packageRoot)) fs.renameSync(hiddenPackageRoot, packageRoot);
cleanup(runtimeRoot);
});
const installs = [];
for (const runtime of ['codex', 'claude']) {
const configDir = path.join(runtimeRoot, `.${runtime}`);
const result = spawnSync(process.execPath, [
path.join(packageRoot, 'bin', 'install.js'),
`--${runtime}`,
'--global',
'--config-dir',
configDir,
], {
cwd: runtimeRoot,
env: {
...process.env,
...isolatedNpmEnv(),
HOME: runtimeRoot,
USERPROFILE: runtimeRoot,
GSD_TEST_MODE: '',
NO_UPDATE_NOTIFIER: '1',
npm_config_update_notifier: 'false',
},
encoding: 'utf8',
timeout: CHILD_TIMEOUT_MS,
});
assert.equal(result.status, 0, `${runtime} packed install failed:\n${result.stdout}\n${result.stderr}`);
installs.push({ runtime, configDir });
}
// Synthetic untouched 1.12-style deployed tree: converted outputs and a
// hash manifest exist, but the raw corpus/marker do not. It must not use
// those outputs as source when the executing package disappears.
const legacyConfigDir = path.join(runtimeRoot, '.legacy-codex');
fs.cpSync(installs.find((entry) => entry.runtime === 'codex').configDir, legacyConfigDir, { recursive: true });
cleanup(path.join(legacyConfigDir, 'gsd-core', 'commands'));
cleanup(path.join(legacyConfigDir, 'gsd-core', 'agents'));
const legacyMarker = path.join(legacyConfigDir, '.gsd-source');
if (fs.existsSync(legacyMarker)) fs.unlinkSync(legacyMarker);
// S04: upgrade a synthetic source-less legacy tree while the fixed
// package is available. Preserve its exact committed selection and an
// unrelated file, converge artifacts to that selection, and later prove
// an offline expansion works from the provisioned corpus alone.
const upgradedHome = path.join(runtimeRoot, 'legacy-codex-upgrade-home');
const upgradeCwd = path.join(runtimeRoot, 'legacy-codex-upgrade-worktree');
const upgradedConfigDir = path.join(upgradedHome, '.codex');
fs.mkdirSync(upgradeCwd, { recursive: true });
fs.cpSync(installs.find((entry) => entry.runtime === 'codex').configDir, upgradedConfigDir, { recursive: true });
fs.cpSync(path.join(runtimeRoot, '.agents', 'skills'), path.join(upgradedHome, '.agents', 'skills'), { recursive: true });
fs.mkdirSync(path.join(upgradedHome, '.agents', 'skills', 'user-owned-skill'), { recursive: true });
fs.writeFileSync(path.join(upgradedHome, '.agents', 'skills', 'user-owned-skill', 'SKILL.md'), '# preserve me\n');
cleanup(path.join(upgradedConfigDir, 'gsd-core', 'commands'));
cleanup(path.join(upgradedConfigDir, 'gsd-core', 'agents'));
const upgradedMarker = path.join(upgradedConfigDir, '.gsd-source');
if (fs.existsSync(upgradedMarker)) fs.unlinkSync(upgradedMarker);
const selectedState = JSON.stringify({ baseProfile: 'core', disabledClusters: [], explicitAdds: [], explicitRemoves: [] }, null, 2) + '\n';
const priorGates = JSON.stringify({ workflow: { code_review: false, research: true } }, null, 2) + '\n';
fs.writeFileSync(path.join(upgradedConfigDir, '.gsd-surface.json'), selectedState);
fs.writeFileSync(path.join(upgradedConfigDir, 'user-owned.txt'), 'preserve me\n');
fs.mkdirSync(path.join(upgradeCwd, '.planning'), { recursive: true });
fs.writeFileSync(path.join(upgradeCwd, '.planning', 'config.json'), priorGates);
const upgradeResult = spawnSync(process.execPath, [
path.join(packageRoot, 'bin', 'install.js'),
'--codex',
'--global',
'--config-dir',
upgradedConfigDir,
], {
cwd: upgradeCwd,
env: {
...process.env,
...isolatedNpmEnv(),
HOME: upgradedHome,
USERPROFILE: upgradedHome,
GSD_TEST_MODE: '',
NO_UPDATE_NOTIFIER: '1',
npm_config_update_notifier: 'false',
},
encoding: 'utf8',
timeout: CHILD_TIMEOUT_MS,
});
assert.equal(upgradeResult.status, 0, `legacy upgrade failed:\n${upgradeResult.stdout}\n${upgradeResult.stderr}`);
assert.equal(fs.readFileSync(path.join(upgradedConfigDir, '.gsd-surface.json'), 'utf8'), selectedState);
assert.equal(fs.readFileSync(path.join(upgradedConfigDir, 'user-owned.txt'), 'utf8'), 'preserve me\n');
assert.equal(fs.readFileSync(path.join(upgradeCwd, '.planning', 'config.json'), 'utf8'), priorGates);
assert.deepStrictEqual(
hashTree(path.join(upgradedConfigDir, 'gsd-core', 'commands', 'gsd')),
hashTree(path.join(packageRoot, 'commands', 'gsd')),
);
assert.deepStrictEqual(
hashTree(path.join(upgradedConfigDir, 'gsd-core', 'agents')),
hashTree(path.join(packageRoot, 'agents')),
);
const upgradedSkillRoot = path.join(upgradedHome, '.agents', 'skills');
const upgradedSkillCount = fs.readdirSync(upgradedSkillRoot).filter((name) => name.startsWith('gsd-')).length;
assert.ok(upgradedSkillCount > 0 && upgradedSkillCount < 71, `upgrade must converge the selected core surface, got ${upgradedSkillCount}`);
assert.equal(fs.readFileSync(path.join(upgradedSkillRoot, 'user-owned-skill', 'SKILL.md'), 'utf8'), '# preserve me\n');
fs.renameSync(packageRoot, hiddenPackageRoot);
const upgradedOfflineScript = [
"const fs=require('node:fs'),path=require('node:path');",
`const configDir=${JSON.stringify(upgradedConfigDir)};`,
"const lib=path.join(configDir,'gsd-core','bin','lib');",
"const surface=require(path.join(lib,'surface.cjs'));",
"const layoutModule=require(path.join(lib,'runtime-artifact-layout.cjs'));",
"const profiles=require(path.join(lib,'install-profiles.cjs'));",
"const clusters=require(path.join(lib,'clusters.cjs'));",
"const manifest=profiles.loadSkillsManifest(path.join(configDir,'gsd-core','commands','gsd'));",
"const layout=layoutModule.resolveRuntimeArtifactLayout('codex',configDir,'global');",
"const skillKind=layout.kinds.find(kind=>kind.kind==='skills');",
"const skillRoot=path.join(skillKind.home||configDir,skillKind.destSubpath);",
"const before=fs.readdirSync(skillRoot).filter(n=>n.startsWith('gsd-')).length;",
"surface.applySurface(configDir,layout,manifest,clusters.CLUSTERS,undefined,{surfaceState:{baseProfile:'full',disabledClusters:[],explicitAdds:[],explicitRemoves:[]}});",
"const after=fs.readdirSync(skillRoot).filter(n=>n.startsWith('gsd-')).length;",
"if(!(after>before))throw new Error(`offline upgraded expansion failed: ${before} -> ${after}`);",
].join('');
const upgradedOfflineResult = spawnSync(process.execPath, ['-e', upgradedOfflineScript], {
cwd: runtimeRoot,
env: { ...process.env, HOME: upgradedHome, USERPROFILE: upgradedHome, GSD_TEST_MODE: '' },
encoding: 'utf8',
timeout: CHILD_TIMEOUT_MS,
});
assert.equal(upgradedOfflineResult.status, 0, `upgraded offline surface failed:\n${upgradedOfflineResult.stdout}\n${upgradedOfflineResult.stderr}`);
const legacyChildScript = [
"const fs=require('node:fs'),path=require('node:path');",
`const configDir=${JSON.stringify(legacyConfigDir)};`,
"const lib=path.join(configDir,'gsd-core','bin','lib');",
"const surface=require(path.join(lib,'surface.cjs'));",
"const layoutModule=require(path.join(lib,'runtime-artifact-layout.cjs'));",
"const profiles=require(path.join(lib,'install-profiles.cjs'));",
"const clusters=require(path.join(lib,'clusters.cjs'));",
"const surfacePath=path.join(configDir,'.gsd-surface.json');",
"const agentPath=path.join(configDir,'agents','gsd-planner.md');",
"const beforeSurface=fs.existsSync(surfacePath)?fs.readFileSync(surfacePath):null;",
"const beforeAgent=fs.readFileSync(agentPath);",
"const layout=layoutModule.resolveRuntimeArtifactLayout('codex',configDir,'global');",
"let error=null;try{surface.applySurface(configDir,layout,new Map(),clusters.CLUSTERS,undefined,{surfaceState:{baseProfile:'core',disabledClusters:[],explicitAdds:[],explicitRemoves:[]}})}catch(value){error=value}",
"if(!error||!/install or upgrade gsd-core/.test(error.message))throw new Error(`expected actionable source failure, got ${error&&error.message}`);",
"const afterSurface=fs.existsSync(surfacePath)?fs.readFileSync(surfacePath):null;",
"if(!Buffer.isBuffer(beforeAgent)||!beforeAgent.equals(fs.readFileSync(agentPath)))throw new Error('legacy output changed');",
"if(beforeSurface===null?afterSurface!==null:!beforeSurface.equals(afterSurface))throw new Error('legacy surface state changed');",
].join('');
const legacyResult = spawnSync(process.execPath, ['-e', legacyChildScript], {
cwd: runtimeRoot,
env: { ...process.env, HOME: runtimeRoot, USERPROFILE: runtimeRoot, GSD_TEST_MODE: '' },
encoding: 'utf8',
timeout: CHILD_TIMEOUT_MS,
});
assert.equal(legacyResult.status, 0, `legacy source-less refusal failed:\n${legacyResult.stdout}\n${legacyResult.stderr}`);
for (const { runtime, configDir } of installs) {
const childScript = [
"const path=require('node:path');",
`const configDir=${JSON.stringify(configDir)};`,
`const runtime=${JSON.stringify(runtime)};`,
"const lib=path.join(configDir,'gsd-core','bin','lib');",
"const surface=require(path.join(lib,'surface.cjs'));",
"const layoutModule=require(path.join(lib,'runtime-artifact-layout.cjs'));",
"const profiles=require(path.join(lib,'install-profiles.cjs'));",
"const clusters=require(path.join(lib,'clusters.cjs'));",
"const corpus=path.join(configDir,'gsd-core','commands','gsd');",
"const manifest=profiles.loadSkillsManifest(corpus);",
"const layout=layoutModule.resolveRuntimeArtifactLayout(runtime,configDir,'global');",
"const before=layout.kinds.map(k=>{const root=path.join(k.home||configDir,k.destSubpath);try{return require('node:fs').readdirSync(root).length}catch{return 0}}).reduce((a,b)=>a+b,0);",
"const state={baseProfile:'core',disabledClusters:[],explicitAdds:[],explicitRemoves:[]};",
"surface.applySurface(configDir,layout,manifest,clusters.CLUSTERS,undefined,{surfaceState:state});",
"const after=layout.kinds.map(k=>{const root=path.join(k.home||configDir,k.destSubpath);try{return require('node:fs').readdirSync(root).length}catch{return 0}}).reduce((a,b)=>a+b,0);",
"if(!(after>0&&after<before))throw new Error(`surface did not materially shrink: ${before} -> ${after}`);",
"process.stdout.write(JSON.stringify({before,after}));",
].join('');
const result = spawnSync(process.execPath, ['-e', childScript], {
cwd: runtimeRoot,
env: { ...process.env, HOME: runtimeRoot, USERPROFILE: runtimeRoot, GSD_TEST_MODE: '' },
encoding: 'utf8',
timeout: CHILD_TIMEOUT_MS,
});
assert.equal(result.status, 0, `${runtime} offline materialization failed:\n${result.stdout}\n${result.stderr}`);
const counts = JSON.parse(result.stdout);
assert.ok(counts.after > 0 && counts.after < counts.before);
}
});
});
// ────────────────────────────────────────────────────────────────────────
// Folded from tests/bug-131-release-tarball-smoke-explicit-home.test.cjs — consolidation epic #1969 (B6 #1975)
// ────────────────────────────────────────────────────────────────────────
{
const { describe: __foldDescribe } = require('node:test');
__foldDescribe("folded:bug-131-release-tarball-smoke-explicit-home (consolidation epic #1969 B6 #1975)", () => {
// allow-test-rule: integration-test-input (see #131)
// Regression test for #131: runNpm() must not fail when HOME points at an
// unwritable directory. The before() hook in release-tarball-smoke.install.test.cjs
// calls runNpm(['pack', ...]) and runNpm(['install', '-g', ...]) — if those inherit
// an unwritable HOME from the environment (common in constrained Docker hosts),
// the entire hook fails and all 6 subtests are cancelled.
//
// Fix: runNpm() must inject an explicit HOME, npm_config_cache, and
// npm_config_userconfig that point into a temp directory it owns, so that npm
// never reads from or writes to the caller's HOME.
//
// Test 3 (added in the second fix pass) verifies that isolatedNpmEnv() — the
// companion export that lets runSmoke() apply the same isolation — also redirects
// HOME away from the caller's HOME. Without this, subtests A-F of
// release-tarball-smoke.install.test.cjs still fail because runSmoke() calls
// spawnSync('npm', ...) internally and was not covered by the runNpm() fix.
'use strict';
const { describe, test } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const { execFileSync } = require('node:child_process');
// The helpers under test.
const { isolatedNpmEnv, cleanup } = require('./helpers.cjs');
// Bounds the `node -e` npm-harness spawn pattern shared by the three
// execFileSync(process.execPath, ['-e', script], ...) sites in this file,
// each of which requires helpers.cjs and calls runNpm(...).
const NPM_HARNESS_SPAWN_TIMEOUT_MS = 30_000;
// Resolve a filesystem path to its canonical (symlink-free) form even if the
// leaf does not exist yet (e.g. ~/.npm before npm has written its cache).
// Walks up to the nearest existing ancestor, resolves that, then re-appends
// the trailing segments. This handles macOS /var → /private/var symlinks for
// paths created under os.tmpdir() where the leaf directory may not exist yet.
function safeRealpath(p) {
try {
return fs.realpathSync(p);
} catch (_) {
// Leaf does not exist — resolve the nearest existing ancestor then
// reconstruct the original suffix so the result is still canonical.
const segments = [];
let cur = p;
for (;;) {
const parent = path.dirname(cur);
if (parent === cur) {
// Reached filesystem root — return original path unchanged.
return p;
}
segments.unshift(path.basename(cur));
cur = parent;
try {
return path.join(fs.realpathSync(cur), ...segments);
} catch (__) {
// Keep walking up.
}
}
}
}
describe('bug-131: runNpm isolates HOME from the caller environment', () => {
// ── Test 1 — runNpm works with an unwritable HOME ────────────────────────
// Spawn a child Node process that sets HOME to an unwritable directory, then
// invokes runNpm(['cache', 'verify']). `npm --version` performs zero
// filesystem I/O against HOME/.npm or HOME/.npmrc on modern npm, and even
// `npm config get cache` only *resolves* the cache path as a string without
// touching disk — both stay green even without HOME isolation, making the
// assertion vacuous. `npm cache verify` genuinely creates/reads/writes the
// cache directory under HOME (mkdir _cacache, write logs), so without the
// fix it fails with ENOTDIR against the unwritable HOME, and with the fix
// runNpm's injected isolated HOME lets it succeed. (Proven empirically: with
// this exact probe, neutralising runNpm()'s isolation flips this test from
// green to red, whereas `npm config get cache` stayed green either way.)
test('runNpm succeeds even when process HOME is unwritable', () => {
// Simulate an unwritable HOME with a mechanism that holds for every uid,
// including root (as gsd-test Docker benches run). chmod 0o500 is
// insufficient because root bypasses mode bits entirely, silently making
// this assertion vacuous under root — see CLAUDE.md section 4. Instead,
// make the PARENT of "HOME" a regular file rather than a directory: any
// attempt to create or write an entry under a non-directory parent fails
// with ENOTDIR at the filesystem/VFS level, a property that has nothing
// to do with permission bits and therefore cannot be bypassed by root.
const poisonedHomeBlocker = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-bug131-poison-'));
const blockerFile = path.join(poisonedHomeBlocker, 'blocker');
fs.writeFileSync(blockerFile, ''); // regular file, not a directory
const poisonedHome = path.join(blockerFile, 'home'); // parent is a file → ENOTDIR
try {
// We exercise the real runNpm() path by running a tiny inline Node script
// that requires helpers.cjs and calls runNpm(['cache', 'verify']) with
// HOME set to the unwritable dir. The script exits 0 on success, non-zero
// on throw.
const script = `
process.env.HOME = ${JSON.stringify(poisonedHome)};
process.env.USERPROFILE = ${JSON.stringify(poisonedHome)};
const { runNpm } = require(${JSON.stringify(path.join(__dirname, 'helpers.cjs'))});
try {
const out = runNpm(['cache', 'verify']);
if (!out || out.trim() === '') process.exit(2); // vacuous success guard
process.stdout.write(out);
process.exit(0);
} catch (e) {
process.stderr.write(e.message + '\\n');
process.exit(1);
}
`;
let stdout = '';
let stderr = '';
let exitCode = 0;
try {
stdout = execFileSync(process.execPath, ['-e', script], {
encoding: 'utf-8',
timeout: NPM_HARNESS_SPAWN_TIMEOUT_MS,
});
} catch (err) {
stdout = err.stdout || '';
stderr = err.stderr || '';
exitCode = err.status ?? 1;
}
assert.equal(
exitCode,
0,
`runNpm should succeed with an unwritable HOME but exited ${exitCode}. stderr: ${stderr}`,
);
// npm cache verify reports what it found/fixed in the cache directory.
assert.match(
stdout,
/cache verified|content verified/i,
`expected npm cache verify output, got: ${stdout}`,
);
} finally {
// poisonedHome itself was never created (its parent is a file), so only
// the directory holding the blocker file needs cleanup.
cleanup(poisonedHomeBlocker);
}
});
// ── Test 2 — runNpm does not leak a caller-supplied HOME into npm ────────
// Even if the caller exports HOME=/some/real/path, the injected HOME must be
// a different (temp) path so npm writes never touch the caller's $HOME.
test('runNpm injects a HOME distinct from process.env.HOME', () => {
// Capture what HOME runNpm actually passes to npm by asking npm to print
// the value it sees for the $HOME env var. We do this via `npm config get
// cache` which reveals the cache path — if it's under process.env.HOME,
// the fix is absent; if it's under a tmp dir, the fix is present.
const script = `
const { runNpm } = require(${JSON.stringify(path.join(__dirname, 'helpers.cjs'))});
try {
// npm config get cache prints the effective cache directory.
const out = runNpm(['config', 'get', 'cache']);
process.stdout.write(out.trim());
process.exit(0);
} catch (e) {
process.stderr.write(e.message + '\\n');
process.exit(1);
}
`;
let stdout = '';
let stderr = '';
let exitCode = 0;
try {
stdout = execFileSync(process.execPath, ['-e', script], {
encoding: 'utf-8',
timeout: NPM_HARNESS_SPAWN_TIMEOUT_MS,
});
} catch (err) {
stdout = err.stdout || '';
stderr = err.stderr || '';
exitCode = err.status ?? 1;
}
assert.equal(
exitCode,
0,
`runNpm config get cache failed with exit ${exitCode}. stderr: ${stderr}`,
);
const effectiveCacheDir = stdout.trim();
// The effective npm cache must NOT be inside the calling process's HOME.
// If it is, the fix was not applied and the Docker regression can still occur.
const callerHome = os.homedir();
assert.ok(
!effectiveCacheDir.startsWith(callerHome),
`npm cache dir ${effectiveCacheDir} is still under caller HOME ${callerHome} — fix not applied`,
);
// It must be somewhere under the system tmp dir, confirming isolation.
// Use safeRealpath on both sides so that macOS /var→/private/var symlinks
// do not cause a false mismatch when os.tmpdir() and the resolved cache
// path differ only in symlink expansion. The cache sub-directory (.npm) may
// not exist yet; safeRealpath walks up to the nearest existing ancestor.
const sysTmp = safeRealpath(os.tmpdir());
const realCacheDir = safeRealpath(effectiveCacheDir);
assert.ok(
realCacheDir.startsWith(sysTmp),
`npm cache dir ${realCacheDir} should be under tmpdir ${sysTmp}`,
);
});
// ── Test 3 — isolatedNpmEnv() redirects HOME away from the caller's HOME ──
// runSmoke() calls spawnSync('npm', ...) with npmEnv from isolatedNpmEnv().
// If isolatedNpmEnv() didn't redirect HOME, subtests A-F would still fail on
// Docker hosts with an unwritable HOME (the original bug #131 root cause,
// manifesting via the sibling runSmoke() path). (#131)
test('isolatedNpmEnv() HOME is distinct from the caller HOME and lives under tmpdir', () => {
const env = isolatedNpmEnv();
// Must expose a HOME key.
assert.ok(
typeof env.HOME === 'string' && env.HOME.length > 0,
'isolatedNpmEnv() must set HOME',
);
// Must not be the caller's HOME.
const callerHome = os.homedir();
assert.notEqual(
env.HOME,
callerHome,
`isolatedNpmEnv() HOME must differ from caller HOME ${callerHome}`,
);
// Must live under the system tmpdir, confirming it is an isolated temp directory.
// Use safeRealpath on both sides so that macOS /var→/private/var symlinks
// do not cause a false mismatch.
const sysTmp = safeRealpath(os.tmpdir());
const realHome = safeRealpath(env.HOME);
assert.ok(
realHome.startsWith(sysTmp),
`isolatedNpmEnv() HOME ${realHome} should be under tmpdir ${sysTmp}`,
);
// npm_config_cache and npm_config_userconfig must also be set and under the isolated HOME.
assert.ok(
typeof env.npm_config_cache === 'string' && env.npm_config_cache.startsWith(env.HOME),
`npm_config_cache ${env.npm_config_cache} should be under isolated HOME ${env.HOME}`,
);
assert.ok(
typeof env.npm_config_userconfig === 'string' && env.npm_config_userconfig.startsWith(env.HOME),
`npm_config_userconfig ${env.npm_config_userconfig} should be under isolated HOME ${env.HOME}`,
);
assert.equal(
env.npm_config_loglevel,
'error',
'isolatedNpmEnv() should suppress npm notice/warn chatter in test gates',
);
assert.equal(
env.npm_config_update_notifier,
'false',
'isolatedNpmEnv() should disable npm update-notifier notices in test gates',
);
assert.equal(
env.NO_UPDATE_NOTIFIER,
'1',
'isolatedNpmEnv() should disable npm update-notifier notices for npm versions that honor NO_UPDATE_NOTIFIER',
);
});
// ── Test 4 — runNpm's 180000ms bound survives an explicit `timeout: undefined` ──
// (#3148 wave 4) runNpm() used to spread `...defaults` (which carries
// `timeout: 180000`) and then `...otherOptions` AFTER it, so a caller
// passing an own `timeout: undefined` key (not an omission) silently won
// the spread and erased the bound, leaving the underlying execFileSync call
// unbounded. The fix destructures `timeout` off `options` with a default
// and passes it explicitly after both spreads, so an own `undefined` key
// resolves to the default instead of erasing it.
//
// Proof is behavioral, not textual: a fresh child process monkeypatches
// `child_process.execFileSync` to capture the options object it actually
// receives — before `helpers.cjs` is required in that child, so its
// top-level `const { execFileSync } = require('child_process')` picks up
// the patched function — then calls `runNpm(['--version'], { timeout:
// undefined })` and reports back the captured `timeout` value. Reverting
// the destructure-with-default fix (restoring the plain `{ ...defaults,
// ...otherOptions, env: mergedEnv }` spread order) makes this test fail:
// the captured `timeout` becomes `undefined` instead of `180000`.
test('runNpm resolves an explicit `timeout: undefined` to the 180000ms bound, not unbounded', () => {
const script = `
const cp = require('node:child_process');
const seen = [];
cp.execFileSync = (cmd, args, options) => {
seen.push(options);
return '9.9.9';
};
const { runNpm } = require(${JSON.stringify(path.join(__dirname, 'helpers.cjs'))});
// An own \`timeout: undefined\` key — not an omitted key — is the exact
// hazard: a caller-controlled property that must not erase the bound.
runNpm(['--version'], { timeout: undefined });
process.stdout.write(JSON.stringify({ timeout: seen[0] && seen[0].timeout }));
`;
let stdout = '';
let stderr = '';
let exitCode = 0;
try {
stdout = execFileSync(process.execPath, ['-e', script], {
encoding: 'utf-8',
timeout: NPM_HARNESS_SPAWN_TIMEOUT_MS,
});
} catch (err) {
stdout = err.stdout || '';
stderr = err.stderr || '';
exitCode = err.status ?? 1;
}
assert.equal(
exitCode,
0,
`runNpm timeout-capture probe failed with exit ${exitCode}. stderr: ${stderr}`,
);
const captured = JSON.parse(stdout.trim());
assert.equal(
captured.timeout,
180000,
`runNpm must resolve an explicit timeout: undefined to the 180000ms bound; ` +
`captured options.timeout was ${JSON.stringify(captured.timeout)} — an unset bound ` +
`is not a bound (DEFECT.UNBOUNDED-SUBPROCESS)`,
);
});
});
});
}