From dc7997e45c8c4768f8dcd63ab7e7fa9c2ed294b5 Mon Sep 17 00:00:00 2001 From: Jakub Zych Date: Wed, 16 Sep 2026 14:14:05 +0200 Subject: [PATCH] test(01-04): cover tool, output, watch loop and workspace modules - Non-TTY widgets/prompts, flag parsing, secret non-leak and malicious IDs - Real hello workspace rebuild latency line, debounce and ignored bin/tmp - scripts/check-phase1.sh runs vet/test/race across root, hello, base, greeter, optional --- bonfire/output_test.go | 107 +++++++++++++ bonfire/prompts_test.go | 54 +++++++ examples/hello/hello_test.go | 9 ++ internal/build/build_test.go | 59 ++++++++ internal/dev/watch_test.go | 281 ++++++++++++++++++++++++++++++++++- scripts/check-phase1.sh | 34 +++++ 6 files changed, 542 insertions(+), 2 deletions(-) create mode 100755 scripts/check-phase1.sh diff --git a/bonfire/output_test.go b/bonfire/output_test.go index 18f964d..8a08a19 100644 --- a/bonfire/output_test.go +++ b/bonfire/output_test.go @@ -2,6 +2,7 @@ package bonfire import ( "bytes" + "context" "errors" "strings" "testing" @@ -137,6 +138,112 @@ func TestKernelAndNamespacedCommands(t *testing.T) { } } +func TestFlagAndArgumentParsing(t *testing.T) { + var buf bytes.Buffer + var gotArgs []string + var gotTarget, gotMode, gotUnset string + var gotTargetOK, gotModeOK, gotUnsetOK bool + root, err := NewRootIO("app", []Command{{ + Name: "demo:run", + Description: "Run a demo", + Args: []Arg{ + {Name: "target", Description: "who", Required: true}, + {Name: "extra", Description: "optional"}, + }, + Flags: []Flag{ + {Name: "mode", Shorthand: "m", Default: "slow", Description: "speed"}, + {Name: "unused", Default: "", Description: "empty default"}, + }, + Run: func(ctx context.Context, in Input, out Output) error { + gotArgs = append([]string(nil), in.Args()...) + gotTarget, gotTargetOK = in.Argument("target") + gotMode, gotModeOK = in.Flag("mode") + gotUnset, gotUnsetOK = in.Flag("unused") + out.Println("ran " + gotTarget) + return nil + }, + }}, strings.NewReader(""), &buf, &buf) + if err != nil { + t.Fatal(err) + } + root.SetArgs([]string{"demo:run", "-m", "fast", "world"}) + if err := root.Execute(); err != nil { + t.Fatal(err) + } + if !strings.Contains(buf.String(), "ran world") { + t.Fatalf("captured output = %q", buf.String()) + } + if strings.Join(gotArgs, ",") != "world" { + t.Fatalf("Args = %v", gotArgs) + } + if !gotTargetOK || gotTarget != "world" { + t.Fatalf("Argument(target) = (%q, %v)", gotTarget, gotTargetOK) + } + if !gotModeOK || gotMode != "fast" { + t.Fatalf("Flag(mode) = (%q, %v)", gotMode, gotModeOK) + } + if gotUnsetOK || gotUnset != "" { + t.Fatalf("unset flag = (%q, %v)", gotUnset, gotUnsetOK) + } +} + +func TestInjectedOutputCapture(t *testing.T) { + var stdout, stderr bytes.Buffer + out := NewOutput(strings.NewReader(""), &stdout, &stderr) + out.Info("heads up") + out.Success("done") + out.Warning("careful") + out.Error("boom") + out.Printf("plain %s\n", "line") + if !strings.Contains(stdout.String(), "heads up") || !strings.Contains(stdout.String(), "done") || !strings.Contains(stdout.String(), "careful") { + t.Fatalf("stdout = %q", stdout.String()) + } + if !strings.Contains(stdout.String(), "plain line") { + t.Fatalf("Printf missing from stdout: %q", stdout.String()) + } + if !strings.Contains(stderr.String(), "boom") { + t.Fatalf("Error should go to stderr, got %q", stderr.String()) + } + if strings.Contains(stdout.String(), "boom") { + t.Fatalf("Error leaked to stdout: %q", stdout.String()) + } + if strings.Contains(stdout.String()+stderr.String(), "\x1b[") { + t.Fatalf("non-tty messages have ansi: stdout=%q stderr=%q", stdout.String(), stderr.String()) + } +} + +func TestNonTTYSpinnerError(t *testing.T) { + var buf bytes.Buffer + out := NewOutput(strings.NewReader(""), &buf, &buf) + err := out.Spinner("building", func() error { return errors.New("compile failed") }) + if err == nil || err.Error() != "compile failed" { + t.Fatalf("spinner err = %v", err) + } + if got := buf.String(); got != "[...] building\n" { + t.Fatalf("spinner = %q", got) + } +} + +func TestNonTTYProgressSkipsIntraDecile(t *testing.T) { + var buf bytes.Buffer + out := NewOutput(strings.NewReader(""), &buf, &buf) + if err := out.Progress(20, func(p Progress) error { + p.Advance(1) // 5% + p.Advance(1) // 10% + p.Advance(1) // 15% + return nil + }); err != nil { + t.Fatal(err) + } + got := buf.String() + if !strings.Contains(got, "[2/20] 10%") { + t.Fatalf("missing 10%% step in %q", got) + } + if strings.Contains(got, "[1/20]") || strings.Contains(got, "[3/20]") { + t.Fatalf("intra-decile progress leaked: %q", got) + } +} + func TestHelpUsesSharedAdapter(t *testing.T) { var buf bytes.Buffer root, err := NewRoot("hello", []Command{{ diff --git a/bonfire/prompts_test.go b/bonfire/prompts_test.go index 733a247..e4f6009 100644 --- a/bonfire/prompts_test.go +++ b/bonfire/prompts_test.go @@ -2,6 +2,8 @@ package bonfire import ( "bytes" + "context" + "errors" "io" "strings" "testing" @@ -73,6 +75,58 @@ func TestSecretReadsPlainStdinLine(t *testing.T) { } } +func TestChoiceEOFUsesDefault(t *testing.T) { + var buf bytes.Buffer + out := NewOutput(strings.NewReader(""), &buf, &buf) + got, err := out.Choice("pick", []string{"a", "b", "c"}, 2) + if err != nil { + t.Fatal(err) + } + if got != "c" { + t.Fatalf("choice eof = %q", got) + } +} + +func TestChoiceEmptyOptionsError(t *testing.T) { + var buf bytes.Buffer + out := NewOutput(strings.NewReader("1\n"), &buf, &buf) + _, err := out.Choice("pick", nil, 0) + if err == nil { + t.Fatal("expected empty choice error") + } +} + +func TestSecretNotLeakedOnCommandError(t *testing.T) { + var stdout, stderr bytes.Buffer + root, err := NewRootIO("app", []Command{{ + Name: "auth:login", + Description: "login", + Run: func(ctx context.Context, in Input, out Output) error { + secret, err := out.Secret("token") + if err != nil { + return err + } + if secret == "" { + return errors.New("empty token") + } + out.Error("login failed") + return errors.New("login failed") + }, + }}, strings.NewReader("s3cret\n"), &stdout, &stderr) + if err != nil { + t.Fatal(err) + } + root.SetArgs([]string{"auth:login"}) + runErr := root.Execute() + if runErr == nil { + t.Fatal("expected command error") + } + combined := stdout.String() + stderr.String() + runErr.Error() + if strings.Contains(combined, "s3cret") { + t.Fatalf("secret leaked into streams: stdout=%q stderr=%q err=%v", stdout.String(), stderr.String(), runErr) + } +} + func TestClosedStdinDoesNotHang(t *testing.T) { var buf bytes.Buffer out := NewOutput(io.NopCloser(strings.NewReader("")), &buf, &buf) diff --git a/examples/hello/hello_test.go b/examples/hello/hello_test.go index ae4f9da..007ff0e 100644 --- a/examples/hello/hello_test.go +++ b/examples/hello/hello_test.go @@ -104,6 +104,15 @@ func TestBuiltBinaryGreeterHello(t *testing.T) { assertGreeting(t, got, want) } +func TestBuiltBinaryUnknownCommandExitsNonZero(t *testing.T) { + runSummerBuild(t) + cmd := exec.Command("./bin/hello", "does:not-exist") + out, err := cmd.CombinedOutput() + if err == nil { + t.Fatalf("expected non-zero exit, output:\n%s", out) + } +} + func assertGreeting(t *testing.T, got, want string) { t.Helper() if !strings.Contains(got, "plugin\tstatus") || !strings.Contains(got, "golem15.greeter\tactive") { diff --git a/internal/build/build_test.go b/internal/build/build_test.go index 261de99..761800f 100644 --- a/internal/build/build_test.go +++ b/internal/build/build_test.go @@ -263,6 +263,65 @@ func TestAddPluginRejectsPathTraversal(t *testing.T) { } } +func TestParseManifestRejectsDuplicateModule(t *testing.T) { + dir := t.TempDir() + path := filepath.Join(dir, "dupmod.yaml") + write(t, path, "module: example.com/app\nbinary: app\nplugins:\n - id: a.b\n module: example.com/one\n - id: a.c\n module: example.com/one\n") + if _, err := LoadManifest(path); err == nil || !strings.Contains(err.Error(), "example.com/one") { + t.Fatalf("want duplicate module error, got %v", err) + } +} + +func TestMakePluginRejectsPathTraversalAndShellMeta(t *testing.T) { + dir := t.TempDir() + write(t, filepath.Join(dir, "summer.yaml"), "module: example.com/app\nbinary: app\nplugins:\n") + write(t, filepath.Join(dir, "go.mod"), "module example.com/app\n\ngo 1.27.0\n") + for _, id := range []string{ + "golem15.demo/../tmp", + "golem15.demo;rm", + `golem15.demo$(x)`, + "golem15.demo`x`", + "/tmp.evil", + "..evil.plugin", + } { + if _, err := MakePlugin(t.Context(), dir, id); err == nil { + t.Fatalf("id %q: want error", id) + } + } +} + +func TestBuiltHelloFailsOnInvalidRequires(t *testing.T) { + dir := copyHelloApp(t) + path := filepath.Join(dir, "plugins", "greeter", "plugin.go") + src, err := os.ReadFile(path) + if err != nil { + t.Fatal(err) + } + patched := bytes.ReplaceAll(src, []byte(`return []string{"golem15.hello"}`), []byte(`return []string{"golem15.hello", "golem15.missing"}`)) + if bytes.Equal(src, patched) { + t.Fatal("failed to patch greeter Requires") + } + if err := os.WriteFile(path, patched, 0o644); err != nil { + t.Fatal(err) + } + + var buf bytes.Buffer + if err := App(t.Context(), dir, &buf); err != nil { + t.Fatalf("build should succeed, got %v\n%s", err, buf.String()) + } + bin := filepath.Join(dir, "bin", "hello") + cmd := exec.CommandContext(t.Context(), bin, "greeter:hello") + cmd.Dir = dir + out, err := cmd.CombinedOutput() + if err == nil { + t.Fatalf("expected non-zero exit for missing Requires, output:\n%s", out) + } + msg := string(out) + if !strings.Contains(msg, "golem15.greeter") || !strings.Contains(msg, "golem15.missing") { + t.Fatalf("error should name both plugin IDs, got %q", msg) + } +} + func TestParseManifestRejectsUppercaseID(t *testing.T) { dir := t.TempDir() path := filepath.Join(dir, "bad.yaml") diff --git a/internal/dev/watch_test.go b/internal/dev/watch_test.go index 44ab3d7..f09221a 100644 --- a/internal/dev/watch_test.go +++ b/internal/dev/watch_test.go @@ -9,17 +9,37 @@ import ( "os/exec" "path/filepath" "strings" + "sync" "sync/atomic" "syscall" "testing" "time" + + "git.golem15.com/golem15/summercms/internal/build" ) +type safeBuffer struct { + mu sync.Mutex + b bytes.Buffer +} + +func (s *safeBuffer) Write(p []byte) (int, error) { + s.mu.Lock() + defer s.mu.Unlock() + return s.b.Write(p) +} + +func (s *safeBuffer) String() string { + s.mu.Lock() + defer s.mu.Unlock() + return s.b.String() +} + func TestWatchRebuildsOnSourceEdit(t *testing.T) { dir := t.TempDir() writeWatchApp(t, dir) - var out bytes.Buffer + var out safeBuffer var builds atomic.Int32 var starts atomic.Int32 @@ -90,7 +110,7 @@ func TestWatchKeepsChildOnBuildFailure(t *testing.T) { dir := t.TempDir() writeWatchApp(t, dir) - var out bytes.Buffer + var out safeBuffer var builds atomic.Int32 var starts atomic.Int32 var pid atomic.Int32 @@ -157,6 +177,263 @@ func TestWatchKeepsChildOnBuildFailure(t *testing.T) { t.Fatal("child still running after cancel") } +func TestWatchDebouncesRapidEdits(t *testing.T) { + dir := t.TempDir() + writeWatchApp(t, dir) + + var out safeBuffer + var builds atomic.Int32 + ctx, cancel := context.WithCancel(t.Context()) + defer cancel() + + opts := Options{ + Debounce: 80 * time.Millisecond, + Build: func(ctx context.Context, appDir string, w io.Writer) error { + builds.Add(1) + return nil + }, + Start: func(ctx context.Context, binPath string, stdout, stderr io.Writer) (*exec.Cmd, error) { + cmd := exec.Command("sleep", "30") + if err := cmd.Start(); err != nil { + return nil, err + } + return cmd, nil + }, + } + done := make(chan error, 1) + go func() { done <- watch(ctx, dir, &out, opts) }() + waitUntil(t, "initial build", func() bool { return builds.Load() == 1 }) + + for i := 0; i < 5; i++ { + if err := os.WriteFile(filepath.Join(dir, "plugin.go"), []byte(fmt.Sprintf("package p\n// %d\n", i)), 0o644); err != nil { + t.Fatal(err) + } + time.Sleep(10 * time.Millisecond) + } + waitUntil(t, "debounced rebuild", func() bool { return builds.Load() >= 2 }) + time.Sleep(150 * time.Millisecond) + if builds.Load() != 2 { + t.Fatalf("rapid edits should coalesce, builds=%d", builds.Load()) + } + cancel() + select { + case <-done: + case <-time.After(3 * time.Second): + t.Fatal("watch did not exit") + } +} + +func TestWatchIgnoresBinAndTmp(t *testing.T) { + dir := t.TempDir() + writeWatchApp(t, dir) + if err := os.MkdirAll(filepath.Join(dir, "bin"), 0o755); err != nil { + t.Fatal(err) + } + if err := os.MkdirAll(filepath.Join(dir, "tmp"), 0o755); err != nil { + t.Fatal(err) + } + + var out safeBuffer + var builds atomic.Int32 + ctx, cancel := context.WithCancel(t.Context()) + defer cancel() + opts := Options{ + Debounce: 40 * time.Millisecond, + Build: func(ctx context.Context, appDir string, w io.Writer) error { + builds.Add(1) + return nil + }, + Start: func(ctx context.Context, binPath string, stdout, stderr io.Writer) (*exec.Cmd, error) { + cmd := exec.Command("sleep", "30") + if err := cmd.Start(); err != nil { + return nil, err + } + return cmd, nil + }, + } + done := make(chan error, 1) + go func() { done <- watch(ctx, dir, &out, opts) }() + waitUntil(t, "initial build", func() bool { return builds.Load() == 1 }) + + if err := os.WriteFile(filepath.Join(dir, "bin", "hello.go"), []byte("package main\n"), 0o644); err != nil { + t.Fatal(err) + } + if err := os.WriteFile(filepath.Join(dir, "tmp", "scratch.go"), []byte("package tmp\n"), 0o644); err != nil { + t.Fatal(err) + } + time.Sleep(200 * time.Millisecond) + if builds.Load() != 1 { + t.Fatalf("bin/tmp edits triggered rebuild: builds=%d", builds.Load()) + } + cancel() + select { + case <-done: + case <-time.After(3 * time.Second): + t.Fatal("watch did not exit") + } +} + +func TestWatchHelloWorkspaceRebuildLatency(t *testing.T) { + dir := copyHelloApp(t) + var out safeBuffer + var builds atomic.Int32 + var starts atomic.Int32 + ctx, cancel := context.WithCancel(t.Context()) + defer cancel() + + opts := Options{ + Debounce: 80 * time.Millisecond, + Build: func(ctx context.Context, appDir string, w io.Writer) error { + builds.Add(1) + if err := build.App(ctx, appDir, w); err != nil { + return err + } + return nil + }, + Start: func(ctx context.Context, binPath string, stdout, stderr io.Writer) (*exec.Cmd, error) { + starts.Add(1) + cmd := exec.Command("sleep", "30") + if err := cmd.Start(); err != nil { + return nil, err + } + return cmd, nil + }, + } + + done := make(chan error, 1) + go func() { done <- watch(ctx, dir, &out, opts) }() + waitUntilTimeout(t, 60*time.Second, "initial real rebuild", func() bool { return starts.Load() == 1 }) + if builds.Load() != 1 { + t.Fatalf("initial builds = %d", builds.Load()) + } + if !rebuildLinePresent(out.String()) { + t.Fatalf("missing rebuild latency line after initial build:\n%s", out.String()) + } + + plugin := filepath.Join(dir, "plugins", "greeter", "plugin.go") + src, err := os.ReadFile(plugin) + if err != nil { + t.Fatal(err) + } + if err := os.WriteFile(plugin, append(src, []byte("\n// watch-edit\n")...), 0o644); err != nil { + t.Fatal(err) + } + waitUntilTimeout(t, 60*time.Second, "rebuild after source edit", func() bool { return starts.Load() == 2 }) + got := out.String() + if strings.Count(got, "rebuild:") < 2 { + t.Fatalf("want rebuild latency lines after restart, got %q", got) + } + if !rebuildLinePresent(got) { + t.Fatalf("rebuild line missing duration:\n%s", got) + } + + if err := os.WriteFile(filepath.Join(dir, "main.go"), []byte("package main\n// generated\n"), 0o644); err != nil { + t.Fatal(err) + } + if err := os.WriteFile(filepath.Join(dir, "plugins.gen.go"), []byte("package main\n// generated\n"), 0o644); err != nil { + t.Fatal(err) + } + time.Sleep(400 * time.Millisecond) + if starts.Load() != 2 || builds.Load() != 2 { + t.Fatalf("generated-file edits looped: starts=%d builds=%d", starts.Load(), builds.Load()) + } + + cancel() + select { + case err := <-done: + if err != nil && err != context.Canceled { + t.Fatalf("watch exit: %v", err) + } + case <-time.After(5 * time.Second): + t.Fatal("watch did not exit on cancel") + } +} + +func rebuildLinePresent(s string) bool { + for _, line := range strings.Split(s, "\n") { + line = strings.TrimSpace(line) + if strings.HasPrefix(line, "rebuild:") && len(strings.TrimSpace(strings.TrimPrefix(line, "rebuild:"))) > 0 { + return true + } + } + return false +} + +func waitUntilTimeout(t *testing.T, d time.Duration, name string, ok func() bool) { + t.Helper() + deadline := time.Now().Add(d) + for time.Now().Before(deadline) { + if ok() { + return + } + time.Sleep(25 * time.Millisecond) + } + t.Fatalf("timed out waiting for %s", name) +} + +func copyHelloApp(t *testing.T) string { + t.Helper() + src, err := filepath.Abs(filepath.Join("..", "..", "examples", "hello")) + if err != nil { + t.Fatal(err) + } + framework, err := filepath.Abs(filepath.Join("..", "..")) + if err != nil { + t.Fatal(err) + } + dst := t.TempDir() + if err := filepath.WalkDir(src, func(path string, d os.DirEntry, err error) error { + if err != nil { + return err + } + rel, err := filepath.Rel(src, path) + if err != nil { + return err + } + if rel == "bin" || strings.HasPrefix(rel, "bin"+string(os.PathSeparator)) { + if d.IsDir() { + return filepath.SkipDir + } + return nil + } + target := filepath.Join(dst, rel) + if d.IsDir() { + return os.MkdirAll(target, 0o755) + } + data, err := os.ReadFile(path) + if err != nil { + return err + } + if filepath.Base(path) == "go.mod" { + data = rewriteFrameworkReplace(data, framework) + } + if err := os.MkdirAll(filepath.Dir(target), 0o755); err != nil { + return err + } + return os.WriteFile(target, data, 0o644) + }); err != nil { + t.Fatal(err) + } + return dst +} + +func rewriteFrameworkReplace(data []byte, framework string) []byte { + const module = "git.golem15.com/golem15/summercms" + lines := strings.Split(string(data), "\n") + for i, line := range lines { + trimmed := strings.TrimSpace(line) + switch { + case strings.HasPrefix(trimmed, "replace "+module+" =>"): + indent := line[:len(line)-len(strings.TrimLeft(line, " \t"))] + lines[i] = indent + "replace " + module + " => " + framework + case strings.HasPrefix(trimmed, module+" =>"): + indent := line[:len(line)-len(strings.TrimLeft(line, " \t"))] + lines[i] = indent + module + " => " + framework + } + } + return []byte(strings.Join(lines, "\n")) +} + func writeWatchApp(t *testing.T, dir string) { t.Helper() write(t, filepath.Join(dir, "summer.yaml"), "module: example.com/app\nbinary: hello\nplugins:\n - id: a.b\n module: example.com/app/plugins/demo\n") diff --git a/scripts/check-phase1.sh b/scripts/check-phase1.sh new file mode 100755 index 0000000..0c71df2 --- /dev/null +++ b/scripts/check-phase1.sh @@ -0,0 +1,34 @@ +#!/usr/bin/env bash +# Repeatable Phase 1 verification: vet, test, and race across every workspace module, +# plus a built-binary integration check of examples/hello. +set -euo pipefail + +ROOT="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" +cd "$ROOT" + +run_module() { + local name="$1" + local dir="$2" + echo "==> ${name} (${dir})" + ( + cd "$dir" + go vet ./... + go test ./... + go test -race ./... + ) +} + +run_module "root" "." +run_module "hello app" "examples/hello" +run_module "base plugin" "examples/hello/plugins/base" +run_module "greeter plugin" "examples/hello/plugins/greeter" +run_module "optional plugin" "examples/hello/plugins/optional" + +echo "==> built-binary integration (examples/hello)" +( + cd examples/hello + go run ../../cmd/summer build + ./bin/hello greeter:hello +) + +echo "phase1 check passed"