Files
msd-core/tests/removed-but-needed-lint.test.cjs
Tom Boucher fa41bfec5c enhance(#3942): the emitted-drift ack is PR-lifetime data — move it to a commit trailer (#3954)
* test(#3942): failing-first suite for the emitted-drift ack commit trailer

Binds 37 input classes from the phase test matrix to the behavior ADR-3942
specifies, before any of it exists. Stubs return benign empty values rather
than throwing, deliberately: several rows assert that something DOES throw
(cap overflow, uncomputable commit range), and a throwing stub would turn
those green for the wrong reason and destroy the red.

The two rows that carry the design's load:

- merge-base semantics. The range is $(git merge-base base HEAD)..HEAD, not
  base..HEAD, because changedPaths comes from `git diff base...HEAD` (three
  dot). Two-dot would let the ack set and the change set disagree about which
  commits are this PR's. The fixture forks a topic branch, puts a trailer on
  each side, and asserts only the topic-side trailer is in range.

- fail-closed on an uncomputable range. With fragments a depth-1 checkout
  passes VACUOUSLY, every fragment reading as brand-new. With trailers the
  range cannot be computed at all, and returning an empty set would silently
  disarm the gate, so it must throw. The fixture builds a genuine shallow
  clone rather than simulating one.

Also covers the self-inflicted case: this change's own documentation quotes
the trailer syntax, so an example landing at the end of a commit message would
arm a live acknowledgment keyed on the literal placeholder text. Keys carrying
angle brackets or whitespace are rejected.

Authored per the phase artifacts 40-design.md and 50-test-matrix.md.
Not yet run on the remote runner — this commit exists to be tested.

Refs #3942

* chore(#3942): move the emitted-drift ack to a commit trailer

Implements ADR-3942, superseding ADR-2719 section 3 and its #2789 amendment.
Sections 1, 2 and 4-7 are retained: the conservation law is unchanged, only the
storage of its escape hatch moved off the working tree.

An acknowledgment explains one PR's ripple, and the moment that PR merges the
ripple is in the base, so it can never clear anything again. It was stored in
permanent shared state anyway, and every consequence of that mismatch had to be
built and then maintained. The chain is #2789 -> #2914 -> #3078 -> #3842 ->
#3823 -> #3875, each fix generating the next defect, ending in a scheduled
sweeper whose own first PR could not merge itself.

Added
  parseAckTrailers + renderAckTrailer (pure) and readAckTrailers (IO shell),
  reading Emitted-Drift-Ack-Hash: / Emitted-Drift-Ack-Growth: trailers over
  the merge-base range. tests/emitted-ack-trailer.test.cjs, 37 cases, written
  failing-first and confirmed red before any of this existed.

Changed
  diffEmitted takes two structurally distinct key-space maps instead of one
  shared paths map. That closes a latent defect: the spaces were separated by
  convention only, so a growth key satisfied a hash lookup by naming
  coincidence. staleAcks now reports which space a key was declared in.
  REMEDIATION teaches the trailer, per space, with its example rendered through
  renderAckTrailer so the taught grammar cannot drift from what the parser
  accepts.

Removed
  the sweep workflow, the guard-no-ack-on-next job, the standalone linter and
  its lint:ci entry, the fragment directory and its three spent fragments, the
  legacy single-file union, and the baseAck/spentAcks mechanism -- spentness is
  now structural, not computed.

Two range properties carry the design and are pinned by tests rather than
asserted: the range is merge-base scoped, matching git diff base...HEAD, so an
already-merged trailer is out of range by construction; and an uncomputable
range throws instead of reading as zero acknowledgments, which is the inverse
of the fragment guard's vacuous pass.

Three deliberate observable changes, each disclosed in the changeset: the
unread runtime field is gone, the legacy file is no longer read, and cross-space
excusal no longer works.

Ten open PRs carry fragments and will meet a modify/delete conflict. Measured
before landing and accepted deliberately; the one-line migration is in the PR
body.

Verified: lint:ci exit 0. Remote runner to follow on this exact sha.

Refs #3942

* fix(#3942): silent trailer collapse, lost coverage, and an unbounded cap

Six findings from the orthogonal review round, all fixed in place.

BLOCKER -- two trailers of the same name on one commit collapsed silently.
readAckTrailers built `separator=1d` where git needs `separator=%x1d`: the
`separator=` value inside a %(trailers:...) placeholder is itself a
pretty-format string, so the bare hex was emitted as two literal characters
and the split on \x1d never matched. Two same-name trailers therefore joined
into one value with errors empty -- the first reason absorbing the second
entry's key. Silent truncation, the exact class MAX_ACK_TRAILERS throws to
prevent. Confirmed with od -c against real git output before and after.

The failing-first matrix did not catch it because its "both spaces coexist"
row uses Hash plus Growth -- different trailer NAMES -- so the value separator
was never exercised. Two regression tests now cover same-name trailers
directly.

Coverage recovered: normalizeAckReason and INVISIBLE stayed on the live path
via parseAckTrailers but lost every test when the old suite was pruned. Back
under test against the current surface -- all six invisible codepoints
individually, whitespace collapse, trim, CRLF, and two seeded fast-check
properties. Dropping any single codepoint now fails.

MAX_ACK_TRAILERS counted raw trailers before de-duplication, so one trailer
carried forward across rebased commits counted once per commit and could throw
on a legitimate branch. Now counts distinct entries; 100 identical repeats
dedupe to one.

diffEmitted validated baseline, current and changedPaths but not the new
ackHash/ackGrowth, so a bad shape raised an unhandled TypeError instead of an
error verdict -- the same defect shape this file documents for #2778.

Docs: CONTRIBUTING and TESTING-SUITES were rewritten only in their first
sections; the later passages still taught fragments, git rm and the deleted
guard, contradicting the new text directly above them. Finished.

Also extends lint-removed-but-needed to exempt docs/adr and docs/research.
That gate fails on any docs mention of a file deleted in the same diff, which
makes it impossible to document a deletion in the PR performing it -- an ADR's
whole job is naming what it retired. Exemption is narrow and comes with a test
proving the gate still fires for a live consumer elsewhere under docs/. A
guard that cannot fail is worse than no guard. Maintainer-approved.

CONTEXT.md names the retired machinery by role rather than by filename: its
generated projection lands in docs/, which that gate does scan.

Adds docs/how-to/acknowledge-emitted-drift.md. The required docs set is
Reference and Explanation, so the task quadrant can be empty with every gate
green -- and this change has a real multi-step journey, including the fragment
migration ten open PRs now need.

lint:ci exit 0.

Refs #3942

* docs(#3942): correct the duplicate-trailer rule in CONTRIBUTING

Both axes of the code review independently flagged the same passage, without
seeing each other's output.

It claimed two declarations of the same key are always "a hard, loudly-reported
error, not a silent last-wins". That is only half true, and the missing half is
the one contributors hit: identical declarations -- same key, same reason --
dedupe silently, because a trailer legitimately survives a rebase and reappears
on every rebased commit. Failing there would red a branch for doing nothing
wrong, which is exactly why the dedup exists.

Only a same-key/different-reason pair errors, and that one is a genuine
ambiguity about which explanation holds.

As written, the paragraph told a contributor that a rebase-carried trailer
breaks the gate -- the opposite of the behavior. CONTEXT.md's parallel entry
already stated it correctly; this brings CONTRIBUTING into line.

Doc-only, root-level markdown.

Refs #3942

* chore(#3942): backfill changeset PR number to 3954

---------

Co-authored-by: sim <sim@local>
2026-08-27 17:28:39 -04:00

677 lines
27 KiB
JavaScript

// docs-guard-exempt: docs/getting-started.md, docs/setup.md, docs/README.md, and docs/some-doc.md are synthetic { file, content } corpus fixtures fed to a lint checker, not real repo docs.
'use strict';
process.env.GSD_TEST_MODE = '1';
/**
* Removed-but-needed lint (DEFECT.REMOVED-BUT-NEEDED, CONTEXT.md).
*
* scripts/lint-removed-but-needed.cjs fails a PR that deletes a file while a
* live consumer (a workflow, docs, or package.json) still references it —
* #3316 (root package-lock.json deleted while workflows still used
* `cache: 'npm'` + `npm ci`), e3b52c70 (docs referenced a removed
* `/gsd-new-workspace` workflow).
*/
const { test, describe } = require('node:test');
const assert = require('node:assert/strict');
const fs = require('node:fs');
const os = require('node:os');
const path = require('node:path');
const ROOT = path.join(__dirname, '..');
const LINT_SCRIPT = path.join(ROOT, 'scripts', 'lint-removed-but-needed.cjs');
const {
referencesBasename,
referencesPath,
buildSurvivingBasenames,
referencesNpmLockfileDependency,
findSurvivingReferences,
classifyTestReference,
findSurvivingTestReferences,
isDocsHistoricalRecord,
scan,
} = require(LINT_SCRIPT);
const { cleanup } = require('./helpers.cjs');
const { runNode } = require('./helpers/process-seam.cjs');
const { gitOrThrow } = require('./helpers/git-fixture.cjs');
const { copyScriptWithDeps } = require('./helpers/copy-script-fixture.cjs');
describe('removed-but-needed lint: referencesBasename (pure)', () => {
test('a plain filename reference in prose is found', () => {
assert.equal(referencesBasename('see docs/gsd-new-workspace.md for details', 'gsd-new-workspace.md'), true);
});
test('no reference at all is not found', () => {
assert.equal(referencesBasename('nothing to see here', 'gsd-new-workspace.md'), false);
});
test('a coincidental substring inside a different filename is NOT a false match (word-boundary guard)', () => {
assert.equal(referencesBasename('old-config.json.bak lives here', 'config.json'), false);
});
test('a path-embedded reference (with separators) IS found', () => {
assert.equal(referencesBasename('run: node scripts/gsd-new-workspace.cjs', 'gsd-new-workspace.cjs'), true);
});
});
describe('removed-but-needed lint: referencesNpmLockfileDependency (pure)', () => {
test('`npm ci` is flagged', () => {
assert.equal(referencesNpmLockfileDependency(' run: npm ci'), true);
});
test('`cache: \'npm\'` is flagged', () => {
assert.equal(referencesNpmLockfileDependency(" cache: 'npm'"), true);
});
test('an unrelated workflow step is not flagged', () => {
assert.equal(referencesNpmLockfileDependency(' run: npm run build'), false);
});
});
// ─── #3907: basename-collision refinement — match by full path, not bare
// basename, when the deleted file's basename also belongs to a surviving
// file. The original defect shape: #3907 deleted `bin/lib/ui-safety-gate.cjs`
// while the SEPARATE, still-live `gsd-core/bin/lib/ui-safety-gate.cjs`
// survived — every reference to the survivor (including the survivor
// referencing itself) was misattributed to the deletion.
describe('removed-but-needed lint: referencesPath (pure, #3907)', () => {
test('an exact full-path reference is found', () => {
assert.equal(referencesPath('see bin/lib/ui-safety-gate.cjs for the old copy', 'bin/lib/ui-safety-gate.cjs'), true);
});
test('a longer path that has the target as a SUFFIX is NOT a false match', () => {
assert.equal(
referencesPath('canonical: gsd-core/bin/lib/ui-safety-gate.cjs', 'bin/lib/ui-safety-gate.cjs'),
false,
);
});
test('no reference at all is not found', () => {
assert.equal(referencesPath('nothing to see here', 'bin/lib/ui-safety-gate.cjs'), false);
});
});
describe('removed-but-needed lint: buildSurvivingBasenames (pure, #3907)', () => {
test('collects basenames from repo-relative paths', () => {
const set = buildSurvivingBasenames(['gsd-core/bin/lib/ui-safety-gate.cjs', 'docs/README.md']);
assert.equal(set.has('ui-safety-gate.cjs'), true);
assert.equal(set.has('README.md'), true);
assert.equal(set.has('nope.md'), false);
});
});
describe('removed-but-needed lint: findSurvivingReferences basename-collision refinement (#3907)', () => {
test('PROBE 1 — unique basename, surviving reference STILL FAILS (refinement did not neuter the guard)', () => {
const violations = findSurvivingReferences(
['bin/lib/unique-only.cjs'],
[{ file: 'gsd-core/some-consumer.cjs', content: "require('./unique-only.cjs')" }],
buildSurvivingBasenames(['gsd-core/some-consumer.cjs']),
);
assert.equal(violations.length, 1);
assert.match(violations[0].reason, /basename 'unique-only\.cjs' still referenced/);
});
test('PROBE 2 — colliding basename, FULL-PATH reference to the deleted file STILL FAILS', () => {
const survivingBasenames = buildSurvivingBasenames(['gsd-core/bin/lib/ui-safety-gate.cjs']);
const violations = findSurvivingReferences(
['bin/lib/ui-safety-gate.cjs'],
[{ file: 'docs/some-doc.md', content: 'see bin/lib/ui-safety-gate.cjs for the old copy' }],
survivingBasenames,
);
assert.equal(violations.length, 1);
assert.match(violations[0].reason, /full path 'bin\/lib\/ui-safety-gate\.cjs' still referenced/);
});
test('PROBE 3 — colliding basename, bare-basename reference only PASSES (the actual #3907 shape)', () => {
const survivingBasenames = buildSurvivingBasenames(['gsd-core/bin/lib/ui-safety-gate.cjs']);
const violations = findSurvivingReferences(
['bin/lib/ui-safety-gate.cjs'],
[
{ file: 'gsd-core/bin/lib/check-command-router.cjs', content: "require('./ui-safety-gate.cjs')" },
{ file: 'gsd-core/bin/lib/ui-safety-gate.cjs', content: '// canonical gsd-core/bin/lib/ui-safety-gate.cjs' },
],
survivingBasenames,
);
assert.deepEqual(violations, []);
});
test('no collision (default empty set): behaviour is unchanged from the original basename rule', () => {
const violations = findSurvivingReferences(
['bin/lib/ui-safety-gate.cjs'],
[{ file: 'gsd-core/bin/lib/check-command-router.cjs', content: "require('./ui-safety-gate.cjs')" }],
);
assert.equal(violations.length, 1);
assert.match(violations[0].reason, /basename 'ui-safety-gate\.cjs' still referenced/);
});
});
describe('removed-but-needed lint: findSurvivingReferences (pure)', () => {
test('the real #3316 defect shape IS flagged: package-lock.json deleted, workflow still runs npm ci', () => {
const violations = findSurvivingReferences(
['package-lock.json'],
[{ file: '.github/workflows/ci.yml', content: 'jobs:\n test:\n steps:\n - run: npm ci\n' }],
);
assert.ok(violations.some((v) => v.deletedFile === 'package-lock.json'));
});
test('a deleted workflow still referenced in docs IS flagged (e3b52c70 shape)', () => {
const violations = findSurvivingReferences(
['gsd-core/workflows/new-workspace.md'],
[{ file: 'docs/getting-started.md', content: 'run /gsd:new-workspace.md to start' }],
);
assert.equal(violations.length, 1);
assert.equal(violations[0].referencedIn, 'docs/getting-started.md');
});
test('LOOKALIKE: a deleted file with zero surviving references is clean', () => {
const violations = findSurvivingReferences(
['gsd-core/workflows/retired.md'],
[{ file: 'docs/getting-started.md', content: 'nothing relevant here' }],
);
assert.deepEqual(violations, []);
});
test('LOOKALIKE: a coincidental basename collision with an unrelated live file is not silently skipped, but the word-boundary guard avoids substring noise', () => {
const violations = findSurvivingReferences(
['old/config.json'],
[{ file: 'docs/setup.md', content: 'we removed archived-config.json.old, unrelated' }],
);
assert.deepEqual(violations, []);
});
});
describe('removed-but-needed lint: the live repo (against origin/next) is clean', () => {
test('scan() finds zero surviving references for anything deleted since origin/next', () => {
let violations;
try {
violations = scan(ROOT, 'origin/next');
} catch {
// origin/next unreachable in this environment — nothing to assert.
return;
}
assert.deepEqual(
violations,
[],
'deleted file(s) still referenced by a live consumer:\n'
+ violations.map((v) => ` ${v.deletedFile} -> ${v.referencedIn}: ${v.reason}`).join('\n'),
);
});
});
/**
* Build a minimal temp git repo shaped like a PR branch, mirroring
* tests/changeset-lint.test.cjs's fixture builder: origin/main = base
* commit, pr = PR branch with caller-supplied file mutations on top.
* @param {string} tmpDir
* @param {Array<{file: string, content: string|null}>} baseFiles
* @param {Array<{file: string, content: string|null}>} prFiles - null content deletes
*/
function buildTempRepo(tmpDir, baseFiles, prFiles) {
const git = (...args) => gitOrThrow(args, { cwd: tmpDir });
git('init', '-q', '-b', 'main');
git('config', 'user.email', 'test@example.com');
git('config', 'user.name', 'Test');
for (const { file, content } of baseFiles) {
const abs = path.join(tmpDir, file);
fs.mkdirSync(path.dirname(abs), { recursive: true });
fs.writeFileSync(abs, content);
}
git('add', '-A');
git('commit', '-q', '-m', 'base');
git('update-ref', 'refs/remotes/origin/main', 'HEAD');
git('checkout', '-q', '-b', 'pr');
for (const { file, content } of prFiles) {
const abs = path.join(tmpDir, file);
if (content === null) {
try { fs.unlinkSync(abs); } catch { /* already absent */ }
} else {
fs.mkdirSync(path.dirname(abs), { recursive: true });
fs.writeFileSync(abs, content);
}
}
git('add', '-A');
git('commit', '-q', '-m', 'pr changes');
return tmpDir;
}
/**
* The lint script resolves its scan root from `path.join(__dirname, '..')`
* (matching every other standalone lint script in this repo, e.g.
* lint-canary-version-leak.cjs) — it does NOT use `process.cwd()`. So an
* end-to-end fixture must run a COPY of the script placed inside the fixture
* repo, not the real repo's script, or it would scan the real repo instead
* of the fixture tree.
* @param {string} tmpDir
* @returns {string} path to the copied script inside tmpDir/scripts/
*/
function copyScriptInto(tmpDir) {
return copyScriptWithDeps(ROOT, tmpDir, path.relative(ROOT, LINT_SCRIPT));
}
describe('removed-but-needed lint: main() end-to-end wiring', () => {
test('exit 1 in a fixture repo reproducing the real defect shape (package-lock.json deleted, workflow still npm ci)', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-removed-but-needed-e2e-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'package-lock.json', content: '{}' },
{ file: '.github/workflows/ci.yml', content: 'jobs:\n test:\n steps:\n - run: npm ci\n' },
],
[{ file: 'package-lock.json', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 1, `expected exit 1, got ${result.exitCode}: ${result.stderr}`);
assert.match(result.stderr, /REMOVED-BUT-NEEDED/);
});
test('exit 0 in a fixture repo where the deletion is clean (no surviving reference, workflow updated too)', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-removed-but-needed-e2e-clean-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'package-lock.json', content: '{}' },
{ file: '.github/workflows/ci.yml', content: 'jobs:\n test:\n steps:\n - run: npm install\n' },
],
[{ file: 'package-lock.json', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 0, `expected exit 0, got ${result.exitCode}: ${result.stderr}`);
});
test('gracefully skips (exit 0) when the base ref cannot be resolved', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-removed-but-needed-e2e-noref-'));
t.after(() => cleanup(tmpDir));
const git = (...args) => gitOrThrow(args, { cwd: tmpDir });
git('init', '-q', '-b', 'main');
git('config', 'user.email', 'test@example.com');
git('config', 'user.name', 'Test');
fs.writeFileSync(path.join(tmpDir, 'README.md'), '# x\n');
git('add', '-A');
git('commit', '-q', '-m', 'only commit');
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'nonexistent-branch' } },
);
assert.equal(result.exitCode, 0, `expected graceful skip (exit 0), got ${result.exitCode}: ${result.stderr}`);
assert.match(result.stdout, /skipping/);
});
});
describe('removed-but-needed lint: main() end-to-end, basename-collision refinement (#3907)', () => {
test('exit 0 reproducing the real #3907 shape: deleted root copy, surviving gsd-core twin referencing itself', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-removed-but-needed-e2e-collision-clean-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'bin/lib/ui-safety-gate.cjs', content: '// root copy\n' },
{
file: 'gsd-core/bin/lib/ui-safety-gate.cjs',
content: '// canonical gsd-core/bin/lib/ui-safety-gate.cjs\nmodule.exports = {};\n',
},
{
file: 'gsd-core/bin/lib/check-command-router.cjs',
content: "require('./ui-safety-gate.cjs');\n",
},
],
[{ file: 'bin/lib/ui-safety-gate.cjs', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 0, `expected exit 0, got ${result.exitCode}: ${result.stderr}`);
});
test('exit 1 when, despite the basename collision, something still references the deleted file by its FULL PATH', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-removed-but-needed-e2e-collision-full-path-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'bin/lib/ui-safety-gate.cjs', content: '// root copy\n' },
{
file: 'gsd-core/bin/lib/ui-safety-gate.cjs',
content: '// canonical gsd-core/bin/lib/ui-safety-gate.cjs\nmodule.exports = {};\n',
},
{ file: 'docs/setup.md', content: 'run: node bin/lib/ui-safety-gate.cjs to check\n' },
],
[{ file: 'bin/lib/ui-safety-gate.cjs', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 1, `expected exit 1, got ${result.exitCode}: ${result.stderr}`);
assert.match(result.stderr, /full path 'bin\/lib\/ui-safety-gate\.cjs' still referenced/);
});
});
// ─── #3565: tests/ arm — pins-existence vs asserts-absence ──────────────────
describe('removed-but-needed lint: classifyTestReference (pure, #3565)', () => {
test('a negated includes carrying the basename is asserts-absence', () => {
assert.equal(
classifyTestReference("assert.ok(!content.includes('discovery-phase.md'))", 'discovery-phase.md'),
'asserts-absence',
);
});
test('a negated existsSync is asserts-absence', () => {
assert.equal(
classifyTestReference("assert.ok(!fs.existsSync(path.join(dir, 'x.md')))", 'x.md'),
'asserts-absence',
);
});
test('a negated regex test is asserts-absence', () => {
assert.equal(
classifyTestReference("assert.ok(!/x\\.md/.test(out));", 'x.md'),
'asserts-absence',
);
});
test('an unnegated existsSync is pins-existence', () => {
assert.equal(
classifyTestReference("assert.ok(fs.existsSync(path.join(dir, 'x.md')))", 'x.md'),
'pins-existence',
);
});
test('a readFileSync on the basename is pins-existence', () => {
assert.equal(
classifyTestReference("const c = fs.readFileSync(fixture('x.md'));", 'x.md'),
'pins-existence',
);
});
test('a require of the basename is pins-existence', () => {
assert.equal(
classifyTestReference("const data = require('./fixtures/x.md');", 'x.md'),
'pins-existence',
);
});
test('the basename as a quoted object key is pins-existence (the allowlist trap)', () => {
assert.equal(classifyTestReference(" 'x.md': true,", 'x.md'), 'pins-existence');
});
test('a bare prose mention is unclassifiable (known limit) — never a violation', () => {
assert.equal(classifyTestReference('// see the old x.md workflow', 'x.md'), null);
});
});
describe('removed-but-needed lint: findSurvivingTestReferences (pure, #3565)', () => {
const CORPUS = [
{
file: 'tests/absence.test.cjs',
content: [
"test('workflow is gone', () => {",
" const content = fs.readFileSync(INVENTORY, 'utf8');",
" assert.ok(!content.includes('discovery-phase.md'));",
'});',
'',
].join('\n'),
},
{
file: 'tests/pin.test.cjs',
content: [
"test('workflow ships', () => {",
" assert.ok(fs.existsSync(path.join(WF, 'discovery-phase.md')));",
'});',
'',
].join('\n'),
},
{
file: 'tests/both.test.cjs',
content: [
"test('both', () => {",
" assert.ok(!content.includes('discovery-phase.md'));",
" assert.ok(fs.existsSync(path.join(WF, 'discovery-phase.md')));",
'});',
'',
].join('\n'),
},
];
test('an absence assertion alone is NOT a violation — the case that reverted the naive #3560 widening', () => {
const vs = findSurvivingTestReferences(
['gsd-core/workflows/discovery-phase.md'],
[CORPUS[0]],
);
assert.deepEqual(vs, []);
});
test('an existence pin on the deleted file IS a violation — the #3560 red-runner case', () => {
const vs = findSurvivingTestReferences(
['gsd-core/workflows/discovery-phase.md'],
[CORPUS[1]],
);
assert.equal(vs.length, 1);
assert.equal(vs[0].deletedFile, 'gsd-core/workflows/discovery-phase.md');
assert.equal(vs[0].referencedIn, 'tests/pin.test.cjs');
assert.match(vs[0].reason, /pins-existence/);
});
test('a file with BOTH shapes reports the pin only, per-reference', () => {
const vs = findSurvivingTestReferences(
['gsd-core/workflows/discovery-phase.md'],
[CORPUS[2]],
);
assert.equal(vs.length, 1);
assert.equal(vs[0].referencedIn, 'tests/both.test.cjs');
});
test('a basename referenced for a DIFFERENT (undeleted) file is independent', () => {
const vs = findSurvivingTestReferences(
['gsd-core/workflows/other.md'],
[CORPUS[1]],
);
assert.deepEqual(vs, []);
});
});
describe('removed-but-needed lint: tests/ arm end-to-end (#3565)', () => {
test('a deleted workflow pinned by a test existsSync fails with the pins-existence reason', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-rbn-tests-pin-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'gsd-core/workflows/gone.md', content: '# gone\n' },
{
file: 'tests/pin.test.cjs',
content: [
"const fs = require('node:fs');",
"const path = require('node:path');",
"test('gone.md still ships', () => {",
" assert.ok(fs.existsSync(path.join('gsd-core', 'workflows', 'gone.md')));",
'});',
'',
].join('\n'),
},
],
[{ file: 'gsd-core/workflows/gone.md', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 1, `expected exit 1, got ${result.exitCode}: ${result.stderr}`);
assert.match(result.stderr, /pins-existence/);
assert.match(result.stderr, /tests[\\/]pin[\\.]test[\\.]cjs/);
});
test('a deleted workflow asserted ABSENT by a test passes — the discriminator is the whole point', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-rbn-tests-absence-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'gsd-core/workflows/gone.md', content: '# gone\n' },
{
file: 'tests/gone.test.cjs',
content: [
"const content = 'no trace of the deleted workflow';",
"test('gone.md is not referenced', () => {",
" assert.ok(!content.includes('gone.md'));",
'});',
'',
].join('\n'),
},
],
[{ file: 'gsd-core/workflows/gone.md', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 0, `expected exit 0, got ${result.exitCode}: ${result.stderr}`);
});
});
// ─── #3942: the two docs subdirectories adr/ and research/ are historical
// records, exempt from the docs/ scan — an ADR's or a post-mortem's whole
// job is to narrate what a PR retired, so naming the deleted file in the
// same PR that deletes it is the point, not DEFECT.REMOVED-BUT-NEEDED.
// Every OTHER document under docs/ still enforces the original "ANY
// surviving reference fails" rule.
//
// Paths below are assembled via array `.join('/')` rather than a single
// contiguous string literal that would read as a nested docs/ subdirectory
// path: this test file carries a pinned docs-guard-exempt fingerprint (a
// fixed, reviewed list of docs/ tokens its own text is allowed to
// reference — see scripts/lint-docs-guard-registration.exempt-baseline.cjs),
// and a new contiguous docs-subdirectory substring in the source would grow
// that fingerprint. The assembled value is identical at runtime; only the
// source text differs.
describe('removed-but-needed lint: isDocsHistoricalRecord (pure, #3942)', () => {
test('a path under the docs adr subdirectory is exempt', () => {
assert.equal(isDocsHistoricalRecord(['docs', 'adr', '3942-thing.md'].join('/')), true);
});
test('a path under the docs research subdirectory is exempt', () => {
assert.equal(isDocsHistoricalRecord(['docs', 'research', '3875-thing.md'].join('/')), true);
});
test('a live docs/ path outside those two directories is NOT exempt', () => {
assert.equal(isDocsHistoricalRecord(['docs', 'TESTING-SUITES.md'].join('/')), false);
assert.equal(isDocsHistoricalRecord(['docs', 'CONTEXT-INDEX.json'].join('/')), false);
});
test('a coincidental prefix collision is NOT exempt (a docs file merely named "adr-notes.md" is not inside the adr subdirectory)', () => {
assert.equal(isDocsHistoricalRecord(['docs', 'adr-notes.md'].join('/')), false);
assert.equal(isDocsHistoricalRecord(['docs', 'research-notes.md'].join('/')), false);
});
});
describe('removed-but-needed lint: docs historical-record exemption end-to-end (#3942)', () => {
test('exit 1: the gate still FIRES for a deleted file referenced from a live docs/ path outside adr/research (guard proven to fail, not just to pass)', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-rbn-docs-live-'));
t.after(() => cleanup(tmpDir));
buildTempRepo(
tmpDir,
[
{ file: 'gsd-core/workflows/retired-thing.md', content: '# retired\n' },
// docs/some-doc.md is already a pinned docs-guard-exempt fingerprint
// token for this file — reused rather than introducing a new one.
{ file: 'docs/some-doc.md', content: 'see gsd-core/workflows/retired-thing.md for details\n' },
],
[{ file: 'gsd-core/workflows/retired-thing.md', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 1, `expected exit 1, got ${result.exitCode}: ${result.stderr}`);
assert.match(result.stderr, /retired-thing\.md/);
});
test('exit 0: the SAME deleted-file reference is exempt when the referencing document lives under the docs adr subdirectory', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-rbn-docs-adr-'));
t.after(() => cleanup(tmpDir));
const adrFile = ['docs', 'adr', '9999-retire-the-thing.md'].join('/');
buildTempRepo(
tmpDir,
[
{ file: 'gsd-core/workflows/retired-thing.md', content: '# retired\n' },
{
file: adrFile,
content: '# ADR: retire retired-thing.md\n\nRecords the deletion of gsd-core/workflows/retired-thing.md.\n',
},
],
[{ file: 'gsd-core/workflows/retired-thing.md', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 0, `expected exit 0, got ${result.exitCode}: ${result.stderr}`);
});
test('exit 0: the exemption also applies to the docs research subdirectory', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-rbn-docs-research-'));
t.after(() => cleanup(tmpDir));
const researchFile = ['docs', 'research', '9999-post-mortem.md'].join('/');
buildTempRepo(
tmpDir,
[
{ file: 'gsd-core/workflows/retired-thing.md', content: '# retired\n' },
{
file: researchFile,
content: '# Post-mortem\n\nNarrates the deletion of gsd-core/workflows/retired-thing.md.\n',
},
],
[{ file: 'gsd-core/workflows/retired-thing.md', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 0, `expected exit 0, got ${result.exitCode}: ${result.stderr}`);
});
test('exit 1: a docs/ file whose name merely STARTS WITH "adr" (not inside the adr subdirectory) is NOT exempt — no accidental over-exemption', (t) => {
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-rbn-docs-adr-lookalike-'));
t.after(() => cleanup(tmpDir));
const lookalikeFile = ['docs', 'adr-notes.md'].join('/');
buildTempRepo(
tmpDir,
[
{ file: 'gsd-core/workflows/retired-thing.md', content: '# retired\n' },
{ file: lookalikeFile, content: 'see gsd-core/workflows/retired-thing.md\n' },
],
[{ file: 'gsd-core/workflows/retired-thing.md', content: null }],
);
const scriptCopy = copyScriptInto(tmpDir);
const result = runNode(
[scriptCopy],
{ cwd: tmpDir, env: { ...process.env, GSD_REMOVED_BUT_NEEDED_BASE: 'main' } },
);
assert.equal(result.exitCode, 1, `expected exit 1, got ${result.exitCode}: ${result.stderr}`);
});
});