mirror of
https://github.com/garrytan/gstack.git
synced 2026-10-02 17:40:02 +02:00
* feat: add surface-aware exploratory QA and ship documentation gates * test: preserve delegated QA setup authority after main integration * fix(qa): clarify exploration order and preserve report artifacts * test(qa): follow the shared setup reference directly * refactor(ship): make verification and recovery routes explicit * test(ship): align evidence and review guards with explicit routes * fix(workflows): clarify ship recovery and functional QA evidence * fix(workflows): clarify approval recovery and full QA coverage * refactor(workflows): order review transactions and clarify ship state * fix(ship): clarify final verification and fail closed at publication * fix(evals): attribute native atomic documentation writes * fix(ship): clarify recovery and documentation lifecycle guidance * fix(test): preserve observed native placeholder styling in CI * fix(codex): report watchdog timeouts without a process-exit race * Checkpoint functional QA implementation and workflow validation repairs * Fix documentation and shared-review fixture contracts * docs: clarify judge reuse and evaluation supervision * test: align review evidence and selected case contracts * test: verify append-only documentation checkpoints and recovery * fix: qualify QA workflows and CI validation repairs * fix: launch shared-libs fixture scripts on Windows * fix: qualify QA deadlines, fixture isolation, and shard cleanup * fix: preserve qualified QA and cancellation repairs * fix: enforce functional fixture authority and share strict event decoding * fix: retain free-test evidence and explain recovery * fix: reject malformed native evidence after decoder consolidation * test: use reliable capture for telemetry privacy filters * test: refresh measured quick coverage and document validation costs * Fix native fixture receipts and preserve VM validation evidence * Align negative judge controls with upstream clarity policy * Fix report-only QA preparation and public evidence handling * Clarify QA-only preparation and current-report preservation * Stream Ship quality judgments with an explicit 64k response contract * Validate compact judge reasoning locally with supported wire schema * Align functional QA fixture instructions with evidence acceptance * Bind native browser diagnostics to execution evidence and align review verdicts * Preserve native diagnostic line boundaries * Serialize functional QA evidence from native captures * Keep large QA evidence fixture payload out of Windows argv
79 lines
3.1 KiB
TypeScript
79 lines
3.1 KiB
TypeScript
/**
|
|
* scratch-repo — shared test fixture for throwaway git repos.
|
|
*
|
|
* One copy of the hermetic git incantation: identity pinned AND signing
|
|
* disabled (`commit.gpgsign=false tag.gpgsign=false`). Fixture commits must
|
|
* never invoke the operator's gpg — gpg-agent fails with "Cannot allocate
|
|
* memory" under parallel shard load and breaks test SETUP, not the code under
|
|
* test. Three suites duplicated this incantation before extraction (and one
|
|
* copy had already drifted).
|
|
*/
|
|
|
|
import { execSync, spawnSync } from 'child_process';
|
|
import * as fs from 'fs';
|
|
import * as path from 'path';
|
|
import * as os from 'os';
|
|
|
|
const GIT_HERMETIC_ARGS = [
|
|
'-c', 'user.email=t@test',
|
|
'-c', 'user.name=t',
|
|
'-c', 'commit.gpgsign=false',
|
|
'-c', 'tag.gpgsign=false',
|
|
] as const;
|
|
|
|
const GIT_HERMETIC_FLAGS = GIT_HERMETIC_ARGS.join(' ');
|
|
|
|
/** Run a git command string in a scratch repo (hermetic identity, no gpg). */
|
|
export function gitIn(repoDir: string, args: string): string {
|
|
return execSync(`git ${GIT_HERMETIC_FLAGS} ${args}`, { cwd: repoDir, encoding: 'utf-8', timeout: 10000 });
|
|
}
|
|
|
|
/** Argv-array variant for callers that avoid shell quoting. */
|
|
export function gitArgvIn(repoDir: string, args: string[], timeout = 5000, env?: NodeJS.ProcessEnv) {
|
|
return spawnSync('git', [...GIT_HERMETIC_ARGS, ...args], { cwd: repoDir, timeout, env });
|
|
}
|
|
|
|
/** Create a scratch repo (mkdtemp) with an initial commit; caller cleans up. */
|
|
export function makeScratchRepo(prefix: string, files: Record<string, string> = { 'src.txt': 'v1\n' }): string {
|
|
const repoDir = fs.mkdtempSync(path.join(os.tmpdir(), prefix));
|
|
gitIn(repoDir, 'init -q -b main');
|
|
for (const [name, content] of Object.entries(files)) {
|
|
fs.writeFileSync(path.join(repoDir, name), content);
|
|
}
|
|
gitIn(repoDir, `add ${Object.keys(files).join(' ')}`);
|
|
gitIn(repoDir, 'commit -q -m init');
|
|
return repoDir;
|
|
}
|
|
|
|
/** Recursively find files with a given suffix under a directory. */
|
|
export function findFilesBySuffix(root: string, suffix: string): string[] {
|
|
const found: string[] = [];
|
|
const walk = (d: string) => {
|
|
if (!fs.existsSync(d)) return;
|
|
for (const e of fs.readdirSync(d, { withFileTypes: true })) {
|
|
const p = path.join(d, e.name);
|
|
if (e.isDirectory()) walk(p);
|
|
else if (e.name.endsWith(suffix)) found.push(p);
|
|
}
|
|
};
|
|
walk(root);
|
|
return found;
|
|
}
|
|
|
|
/**
|
|
* Create a fake `gh` on PATH that behaves per `mode`, keeping bun/git/etc
|
|
* resolvable. Returns the PATH value to pass into env. Used to exercise the
|
|
* post-spawn gh branches (success, failure, garbage JSON) without network.
|
|
*/
|
|
export function makeGhShimPath(mode: 'fail' | 'json' | 'garbage', jsonPayload = '{}'): { pathEnv: string; shimDir: string } {
|
|
const shimDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gstack-gh-shim-'));
|
|
const body =
|
|
mode === 'fail'
|
|
? '#!/bin/sh\necho "shim: gh failed" >&2\nexit 1\n'
|
|
: mode === 'garbage'
|
|
? '#!/bin/sh\necho "this is not json"\nexit 0\n'
|
|
: `#!/bin/sh\ncat <<'SHIM_JSON'\n${jsonPayload}\nSHIM_JSON\nexit 0\n`;
|
|
fs.writeFileSync(path.join(shimDir, 'gh'), body, { mode: 0o755 });
|
|
return { pathEnv: `${shimDir}:${process.env.PATH ?? ''}`, shimDir };
|
|
}
|