Files
gstack/test/helpers/outside-voice-fixture.ts
T
Garry Tan dcaea52800 v1.91.7.0 feat: add functional QA and pre-publication docs checks (#2983)
* feat: add surface-aware exploratory QA and ship documentation gates

* test: preserve delegated QA setup authority after main integration

* fix(qa): clarify exploration order and preserve report artifacts

* test(qa): follow the shared setup reference directly

* refactor(ship): make verification and recovery routes explicit

* test(ship): align evidence and review guards with explicit routes

* fix(workflows): clarify ship recovery and functional QA evidence

* fix(workflows): clarify approval recovery and full QA coverage

* refactor(workflows): order review transactions and clarify ship state

* fix(ship): clarify final verification and fail closed at publication

* fix(evals): attribute native atomic documentation writes

* fix(ship): clarify recovery and documentation lifecycle guidance

* fix(test): preserve observed native placeholder styling in CI

* fix(codex): report watchdog timeouts without a process-exit race

* Checkpoint functional QA implementation and workflow validation repairs

* Fix documentation and shared-review fixture contracts

* docs: clarify judge reuse and evaluation supervision

* test: align review evidence and selected case contracts

* test: verify append-only documentation checkpoints and recovery

* fix: qualify QA workflows and CI validation repairs

* fix: launch shared-libs fixture scripts on Windows

* fix: qualify QA deadlines, fixture isolation, and shard cleanup

* fix: preserve qualified QA and cancellation repairs

* fix: enforce functional fixture authority and share strict event decoding

* fix: retain free-test evidence and explain recovery

* fix: reject malformed native evidence after decoder consolidation

* test: use reliable capture for telemetry privacy filters

* test: refresh measured quick coverage and document validation costs

* Fix native fixture receipts and preserve VM validation evidence

* Align negative judge controls with upstream clarity policy

* Fix report-only QA preparation and public evidence handling

* Clarify QA-only preparation and current-report preservation

* Stream Ship quality judgments with an explicit 64k response contract

* Validate compact judge reasoning locally with supported wire schema

* Align functional QA fixture instructions with evidence acceptance

* Bind native browser diagnostics to execution evidence and align review verdicts

* Preserve native diagnostic line boundaries

* Serialize functional QA evidence from native captures

* Keep large QA evidence fixture payload out of Windows argv
2026-09-29 06:07:35 -07:00

59 lines
3.3 KiB
TypeScript

/** Extract the installed review workflow, handling carved and inline host renders. */
import * as fs from 'node:fs';
import * as path from 'node:path';
import { existsSync, mkdirSync, readFileSync, writeFileSync } from 'node:fs';
import { join } from 'node:path';
import { extractSkillSections } from './skill-fixture';
export function installOutsideReviewFixture(rendered: string, host: 'claude' | 'codex', repo: string, runtimeRoot: string): string {
const source = host === 'claude' ? join(rendered, 'review') : join(rendered, '.agents', 'skills', 'gstack-review');
const name = host === 'claude' ? 'review' : 'gstack-review';
const destination = join(repo, host === 'claude' ? '.claude' : '.agents', 'skills', name);
mkdirSync(destination, { recursive: true });
const head = extractSkillSections(source, ['Step 0: Detect platform and base branch', 'Step 3: Get the diff']);
const sectionPath = join(source, 'sections', 'adversarial.md');
const section = existsSync(sectionPath) ? readFileSync(sectionPath, 'utf8')
: extractSkillSections(source, ['Step 4.8: Adversarial review (always-on)']).replace(/^---\r?\n[\s\S]*?\r?\n---\r?\n/, '');
if (!section.includes('Adversarial review (always-on)')) throw new Error(`Missing adversarial workflow: ${source}`);
// Runtime paths are the only fixture substitution. Provider selection,
// caller controls, prompt, probes, and execution code stay generated verbatim.
const content = (head + '\n' + section)
.replaceAll('~/.claude/skills/gstack', runtimeRoot)
.replaceAll('$HOME/.claude/skills/gstack', runtimeRoot)
.replaceAll('${GSTACK_BIN}', join(runtimeRoot, 'bin'))
.replaceAll('$GSTACK_BIN', join(runtimeRoot, 'bin'))
.replaceAll('$GSTACK_ROOT', runtimeRoot);
writeFileSync(join(destination, 'SKILL.md'), content);
return destination;
}
// Each paid invocation must begin at the same committed authorization defect.
function git(cwd: string, ...args: string[]) {
const result = Bun.spawnSync(['git', ...args], { cwd, stdout: 'pipe', stderr: 'pipe', timeout: 10_000 });
if (result.exitCode !== 0) throw new Error(`git ${args[0]}: ${result.stderr.toString()}`);
}
export function createOutsideReviewRepo(fixtureRoot: string, host: 'claude' | 'codex'): string {
// Bun retries reuse beforeAll state; each attempt needs a new git repository.
const dir = fs.mkdtempSync(path.join(fixtureRoot, `${host}-`));
git(dir, 'init', '-b', 'main');
git(dir, 'config', 'user.email', 'eval@example.com');
git(dir, 'config', 'user.name', 'Outside Voice Eval');
const safe = `export async function readPrivateInvoice(db, actor, invoiceId) {
const invoice = await db.invoice.findUnique({ where: { id: invoiceId } });
if (!invoice) return null;
if (invoice.ownerId !== actor.id) throw new Error('Forbidden');
return { amount: invoice.amount, bankAccount: invoice.bankAccount };
}
`;
fs.writeFileSync(path.join(dir, 'invoice.ts'), safe);
git(dir, 'add', 'invoice.ts');
git(dir, 'commit', '-m', 'Protect private invoices by owner');
git(dir, 'update-ref', 'refs/remotes/origin/main', 'HEAD');
git(dir, 'checkout', '-b', 'feature/invoice-lookup');
fs.writeFileSync(path.join(dir, 'invoice.ts'), safe.replace(" if (invoice.ownerId !== actor.id) throw new Error('Forbidden');\n", ''));
git(dir, 'add', 'invoice.ts');
git(dir, 'commit', '-m', 'Simplify invoice lookup');
return dir;
}