mirror of
https://github.com/callstack/agent-device.git
synced 2026-09-14 20:06:34 +08:00
05a1d76f2e
* test: gate daemon RPC wire compatibility against the last released tag (#1432) ADR 0006 fixes exactly when DAEMON_RPC_PROTOCOL_VERSION must be bumped, and nothing checked that it was. The runtime guard (readRemoteDaemonHealth) refuses a mismatched peer, but only fires when someone remembered the bump — a wire change that skipped it left both sides advertising protocol 2 while parsing different payloads, which is the failure ADR 0006 exists to prevent. Local daemons cannot skew (isReusableDaemonInfo takes over on any package version mismatch). Cross-machine is skewed by design — proxy, cloud/limrun, a remote macOS host — and ADR 0006 explicitly rules package version out as the compatibility gate there, so the one boundary where skew is intended was the one boundary with no gate. test/wire-compat/surface.ts declares the wire surface grouped by the ADR bullet each group serves, quoting it, with an `uncovered` note where a bullet is only partly digestible (the /health and /rpc literals inside http-server.ts stay reviewer-owned: a moved route 404s at connect time rather than misparsing). ledger.json records what each declaration hashes to, at which protocol version. Two gates, split for the same reason the replay-compat corpus splits: - unit-core holds the ledger to its source and prints the digest to paste; - Released-Surface Compatibility reads the ledger at the last RELEASED tag and requires the drift since then to carry a bump or a compatibleChanges ack. From one commit a bumped ledger and an unbumped one are both just an edited file, so only a released baseline can tell them apart. Acks are keyed by the digest they cover, so one "added an optional field" cannot launder later changes. Digests ignore comments and formatting; the manifest's closure is derived from the AST, so a field typed by an unlisted sibling fails rather than sitting outside the gate. CI cost: one added job (checkout + toolchain + two node scripts, ~1 min), mirroring the existing full-history replay-compat job. * test: close wire-surface overclaim and make the closure fail closed (#1432) Addresses both review P1s on #1717. P1 — the manifest materially overclaimed ADR 0006 coverage. It quoted all four bullets while digesting only the payload TYPES, so the producer and consumer seams could break a skewed peer without moving a listed digest. Now listed on both sides of every boundary: JSON-RPC method sets and the projections that turn each method's params into a DaemonRequest, createRpcError/sendJson/ writeRpcResponseEnvelope, resolveToken and the auth-hook types, upload preflight/finalize/308 handlers and the resumable ticket shape, artifact route and download/inventory framing, REST error mapping, and the client's own payload builder, lease-method mapping, response parser and error projection. 57 -> 117 declarations. What stays out is now named rather than implied: createDaemonHttpServer's dispatch wiring and the /health and /rpc literals inside it. Everything it dispatches WITH is digested individually, and a moved route 404s at connect time rather than misparsing — the loud failure, not the silent one. P1 — imported and re-exported payload shapes escaped the closure. declarationHomes() scanned only the manifest's own files and the walk continued silently when a name could not be placed, so a listed type could gain foo?: ImportedShape from a new module and stay green. Resolution is now explicit and fails closed: relative imports, workspace specifiers (through the owning package's own exports map, so a re-pointed export cannot drop a type), and facade re-export chains. Every referenced name must land on a listed declaration, a waiver with a written reason, a declared external module, or the TS/Node global set. Fixed two extractor blind spots the walk exposed: a declaration's own generic parameters and `as const` were being reported as references. Planted-red proofs (wire-mutations.test.ts): 13 cases independently mutate method naming, response serialization, response parsing, auth projection, upload ticket shape, 308 framing, artifact framing, REST error mapping, and progress framing, each asserting the digest moves; 3 probes prove the closure really reaches across a package boundary, a facade re-export, and a plain relative import. Mutations apply inside the declaration's own span — a whole-file replace silently hit a sibling sharing the substring, which is how the first draft of one case passed vacuously. The largest waiver pair (InternalRequestOptions, CommandFlags) rests on ADR 0006's own additive rule: they reach the peer inside DaemonRequest's untyped flags/input bags, and the decision says a new flag needs no bump. Digesting them would fire the gate on every new CLI flag and train reviewers to rubber-stamp acks. * test: list the consumer half of the auxiliary HTTP boundaries (#1432) Addresses the remaining review P1 on #1717. The manifest claimed both sides of response/upload/artifact framing while listing nothing from upload-client.ts, daemon-artifacts.ts, or the health consumer in daemon-client-transport.ts, so those parsers could narrow without moving a listed digest or protocol 2. Now listed (117 -> 141 declarations): - /health consumer: RemoteDaemonHealth, readHealthPayload, readDaemonHttpHealth, readRemoteDaemonHealth. This is the sharpest of the three — narrowing the reader or the comparison disables the very refusal ADR 0006 exists to guarantee, and nothing else in the repo would notice. - /upload consumer: UploadResponse, UploadPreflightResponse, UploadPreflightResult, parseUploadPreflightResult, requestUploadPreflight, uploadDirectArtifact, tryDirectUploadWithResume, shouldRetryDirectUpload, finalizeDirectUpload, uploadLegacyArtifact, ARTIFACT_HASH_ALGORITHM, isStringRecord, and PreparedUploadArtifact — whose sha256/sizeBytes/fileName/artifactType/ contentType fields ARE the preflight body the daemon parses. - /artifacts/* consumer: DaemonArtifactEndpoint, buildDaemonArtifactUrl, isRemoteDaemon, DownloadRemoteArtifactParams, downloadRemoteArtifact, materializeRemoteArtifacts, resolveMaterializedArtifactPath. Running the closure fail-closed over the new files surfaced three more stops, each decided rather than skipped: PreparedUploadArtifact listed (it is payload), UploadProgressSink waived (client-local rendering, never leaves the process), and src/daemon/types.ts#DaemonArtifact waived as a re-export alias of the listed kernel type, matching its DaemonRequest/DaemonResponse siblings. 10 more planted-red mutations cover the new seams: health version-read and mismatch-refusal defeated, RemoteDaemonHealth field dropped, preflight parser narrowed, preflight/legacy response shapes narrowed, finalize body key renamed, ticket field renamed, artifact tenant header dropped, artifact URL moved. A fourth closure probe proves the upload-consumer files are genuinely reached by the walk rather than merely listed. 22 -> 33 tests. The README now states the coverage as a producer/consumer table per boundary, so the claim is checkable at a glance instead of asserted in prose. * test: list the client half of the resumable 308 contract (#1432) Addresses the third review P1 on #1717. Listing the daemon's handleResumableUpload proved it still PRODUCES 308; nothing proved the client still CONSUMES the released one. src/remote/upload-stream.ts owns that half and was entirely outside the manifest, so a newer client could stop accepting `upload-offset`, change how it reads `Range: bytes=0-N`, or emit a different resumed `Content-Range` without moving one of the 141 listed digests. Now listed (141 -> 151): UploadStreamResponse, streamFileToHttpRequest, streamFileToHttpRequestAttempt, buildUploadRequestHeaders, isUploadResumeStatus, isUploadRedirectStatus, parseUploadResumeOffset, parseNonNegativeIntegerHeader, firstHeaderValue, MAX_UPLOAD_REDIRECTS. streamFileToHttpRequestAttempt is listed despite its size, unlike createDaemonHttpServer which stays in `uncovered`. The distinction is stated at the declaration: the HTTP server only dispatches to handlers that are each digested, while the attempt loop IS the resume state machine — it decides whether a 308 continues the upload and what the next request carries, so its sequencing alone can break a released daemon while every helper keeps its digest. 6 new planted-red mutations prove the client half moves the ledger: a dropped `upload-offset` fallback, narrowed Range parsing, a changed resumed Content-Range, 308 no longer treated as continue, a narrowed UploadStreamResponse, and dropped header-value coercion. 33 -> 39 tests. Closure fail-closed surfaced two more stops: UploadStreamProgressOptions waived (local byte-progress rendering) and URL/URLSearchParams added to the global set. README now carries a `/upload` resume row in the producer/consumer table, and names the pattern behind three rounds of review: the coverage sentence kept getting written ahead of the coverage, so the table and the `uncovered` notes are the claims to trust — they are checkable against surface.ts, prose is not. --------- Co-authored-by: Claude <noreply@anthropic.com>
212 lines
7.9 KiB
TypeScript
212 lines
7.9 KiB
TypeScript
// Entrypoint regressions for `pnpm check:affected`: the model self-test covers
|
|
// classification, this covers the run.ts seams the model cannot — real git
|
|
// change discovery (committed/staged/unstaged/untracked + both rename paths)
|
|
// and `--run` propagation (order, GitHub-authoritative skips, stop-on-failure).
|
|
|
|
import assert from 'node:assert/strict';
|
|
import fs from 'node:fs';
|
|
import os from 'node:os';
|
|
import path from 'node:path';
|
|
import { test } from 'node:test';
|
|
import { runCmdSync } from '../../src/utils/exec.ts';
|
|
import { DEFAULT_VITEST_MAX_WORKERS } from '../lib/vitest-concurrency.ts';
|
|
import { selectChecks } from './model.ts';
|
|
import { type CommandExecutor, readChangedFiles, runChecks } from './run.ts';
|
|
|
|
function git(cwd: string, ...args: string[]): void {
|
|
runCmdSync('git', args, { cwd });
|
|
}
|
|
|
|
function makeRepo(): string {
|
|
const dir = fs.mkdtempSync(path.join(os.tmpdir(), 'check-affected-'));
|
|
git(dir, 'init', '-q', '-b', 'main');
|
|
git(dir, 'config', 'user.email', 'test@example.com');
|
|
git(dir, 'config', 'user.name', 'Test');
|
|
return dir;
|
|
}
|
|
|
|
test('readChangedFiles surfaces committed, staged, unstaged, untracked, and both rename paths', () => {
|
|
const dir = makeRepo();
|
|
try {
|
|
fs.writeFileSync(path.join(dir, 'committed.ts'), 'export const a = 1;\n');
|
|
fs.writeFileSync(path.join(dir, 'to-rename.ts'), 'export const b = 2;\n');
|
|
git(dir, 'add', '-A');
|
|
git(dir, 'commit', '-q', '-m', 'base');
|
|
const base = runCmdSync('git', ['rev-parse', 'HEAD'], { cwd: dir }).stdout.trim();
|
|
|
|
// Committed on top of base: an edit plus a rename (git records it as R100).
|
|
fs.writeFileSync(path.join(dir, 'committed.ts'), 'export const a = 2;\n');
|
|
git(dir, 'mv', 'to-rename.ts', 'renamed.ts');
|
|
git(dir, 'add', '-A');
|
|
git(dir, 'commit', '-q', '-m', 'work');
|
|
|
|
// Working-tree state the committed diff cannot see.
|
|
fs.writeFileSync(path.join(dir, 'staged.ts'), 'export const c = 3;\n');
|
|
git(dir, 'add', 'staged.ts');
|
|
fs.writeFileSync(path.join(dir, 'committed.ts'), 'export const a = 3;\n'); // unstaged edit
|
|
fs.writeFileSync(path.join(dir, 'untracked.ts'), 'export const d = 4;\n');
|
|
|
|
const files = readChangedFiles(base, 'HEAD', dir);
|
|
assert.ok(files.includes('committed.ts'));
|
|
assert.ok(files.includes('to-rename.ts'), 'rename source path must be preserved');
|
|
assert.ok(files.includes('renamed.ts'), 'rename destination path must be preserved');
|
|
assert.ok(files.includes('staged.ts'), 'staged working-tree file must be included');
|
|
assert.ok(files.includes('untracked.ts'), 'untracked file must be included');
|
|
} finally {
|
|
fs.rmSync(dir, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
test('readChangedFiles unions staged and unstaged so a net diff cannot hide a file', () => {
|
|
const dir = makeRepo();
|
|
try {
|
|
fs.writeFileSync(path.join(dir, 'seed.ts'), 'export const s = 0;\n');
|
|
git(dir, 'add', '-A');
|
|
git(dir, 'commit', '-q', '-m', 'base');
|
|
const base = runCmdSync('git', ['rev-parse', 'HEAD'], { cwd: dir }).stdout.trim();
|
|
|
|
// Stage a new file, then delete it in the working tree. `git diff HEAD`
|
|
// nets to nothing (absent in HEAD and in the working tree), so a net
|
|
// comparison would drop config.ts entirely.
|
|
fs.writeFileSync(path.join(dir, 'config.ts'), 'export const c = 1;\n');
|
|
git(dir, 'add', 'config.ts');
|
|
fs.rmSync(path.join(dir, 'config.ts'));
|
|
|
|
assert.deepEqual(
|
|
runCmdSync('git', ['diff', '--name-only', 'HEAD'], { cwd: dir })
|
|
.stdout.split('\n')
|
|
.filter(Boolean),
|
|
[],
|
|
'sanity: the net `git diff HEAD` really does hide config.ts',
|
|
);
|
|
assert.ok(
|
|
readChangedFiles(base, 'HEAD', dir).includes('config.ts'),
|
|
'staged add + unstaged delete must still surface config.ts',
|
|
);
|
|
} finally {
|
|
fs.rmSync(dir, { recursive: true, force: true });
|
|
}
|
|
});
|
|
|
|
const ALL_SCRIPTS: Record<string, string> = {
|
|
'format:check': 'x',
|
|
lint: 'x',
|
|
typecheck: 'x',
|
|
'test-app:typecheck': 'x',
|
|
'check:layering': 'x',
|
|
'check:fallow': 'x',
|
|
'check:mcp-metadata': 'x',
|
|
build: 'x',
|
|
'check:package': 'x',
|
|
'check:unit': 'x',
|
|
'check:coverage-changed': 'x',
|
|
'test:integration:provider': 'x',
|
|
'test:integration:node': 'x',
|
|
'test:integration:progress:check': 'x',
|
|
'check:replay-compat': 'x',
|
|
'check:daemon-wire-compat': 'x',
|
|
};
|
|
|
|
const ARGS = { base: 'origin/main', head: 'HEAD', json: false, run: true };
|
|
|
|
test('runChecks runs local checks in order and stops on the first failure', async () => {
|
|
const executed: string[][] = [];
|
|
const execute: CommandExecutor = async (command) => {
|
|
executed.push(command);
|
|
return command.includes('lint') ? 1 : 0;
|
|
};
|
|
const plan = selectChecks({
|
|
changedFiles: ['packages/selectors/src/index.ts'],
|
|
packageEntryFiles: [],
|
|
});
|
|
const code = await runChecks(plan, { scripts: ALL_SCRIPTS }, ARGS, { execute, cwd: '.' });
|
|
assert.equal(code, 1);
|
|
// format then lint, then it stops — nothing after the failing check runs.
|
|
assert.deepEqual(
|
|
executed.map((command) => command[command.length - 1]),
|
|
['format:check', 'lint'],
|
|
);
|
|
});
|
|
|
|
test('runChecks passes the selector change set to Vitest related', async () => {
|
|
const executed: string[][] = [];
|
|
const execute: CommandExecutor = async (command) => {
|
|
executed.push(command);
|
|
return 0;
|
|
};
|
|
const changedFiles = ['packages/selectors/src/index.ts', 'packages/selectors/src/index.test.ts'];
|
|
const plan = selectChecks({ changedFiles, packageEntryFiles: [] });
|
|
const code = await runChecks(plan, { scripts: ALL_SCRIPTS }, ARGS, {
|
|
execute,
|
|
cwd: '.',
|
|
changedFiles,
|
|
});
|
|
assert.equal(code, 0);
|
|
assert.deepEqual(
|
|
executed.find((command) => command.includes('related')),
|
|
['pnpm', 'exec', 'vitest', 'related', '--run', '--passWithNoTests', ...changedFiles],
|
|
);
|
|
});
|
|
|
|
test('runChecks skips GitHub-authoritative checks and passes when locals succeed', async () => {
|
|
const executed: string[][] = [];
|
|
const execute: CommandExecutor = async (command) => {
|
|
executed.push(command);
|
|
return 0;
|
|
};
|
|
// A fail-open plan selects every check, including the non-local build lanes.
|
|
const plan = selectChecks({
|
|
changedFiles: ['unknown/path.xyz'],
|
|
packageEntryFiles: [],
|
|
});
|
|
assert.equal(plan.failOpen, true);
|
|
const code = await runChecks(plan, { scripts: ALL_SCRIPTS }, ARGS, { execute, cwd: '.' });
|
|
assert.equal(code, 0);
|
|
const ran = executed.map((command) => command[command.length - 1]);
|
|
for (const skipped of ['build:xcuitest', 'build:android-snapshot-helper', 'test:smoke:web']) {
|
|
assert.ok(
|
|
!ran.includes(skipped),
|
|
`${skipped} is GitHub-authoritative and must not run locally`,
|
|
);
|
|
}
|
|
});
|
|
|
|
test('runChecks combines related tests with lightweight changed-line coverage', async () => {
|
|
const executed: string[][] = [];
|
|
const execute: CommandExecutor = async (command) => {
|
|
executed.push(command);
|
|
return 0;
|
|
};
|
|
const plan = selectChecks({ changedFiles: ['unknown/path.xyz'], packageEntryFiles: [] });
|
|
|
|
const code = await runChecks(plan, { scripts: ALL_SCRIPTS }, ARGS, { execute, cwd: '.' });
|
|
|
|
assert.equal(code, 0);
|
|
const related = executed.filter((command) => command.includes('related'));
|
|
assert.equal(related.length, 1);
|
|
assert.ok(related[0]?.includes('--coverage'));
|
|
assert.ok(related[0]?.includes('--coverage.reporter=lcov'));
|
|
assert.ok(related[0]?.includes(`--maxWorkers=${DEFAULT_VITEST_MAX_WORKERS}`));
|
|
assert.ok(
|
|
executed.findIndex((command) => command.includes('test:integration:node')) <
|
|
executed.findIndex((command) => command.includes('related')),
|
|
'process-lifecycle integration must run before high-parallelism affected coverage',
|
|
);
|
|
assert.equal(
|
|
executed.some((command) => command.includes('test:coverage')),
|
|
false,
|
|
);
|
|
assert.equal(
|
|
executed.some((command) => command.includes('check:unit')),
|
|
false,
|
|
);
|
|
assert.equal(
|
|
executed.some((command) => command.includes('test:integration:provider')),
|
|
false,
|
|
);
|
|
assert.equal(
|
|
executed.some((command) => command.includes('check:coverage-changed')),
|
|
true,
|
|
);
|
|
});
|