fix: stop test fixtures from deleting the repository's dependencies
Four fixtures linked the installed dependencies into a throwaway root with a single directory symlink at <fixture>/node_modules, then ran pnpm inside that root. pnpm does not recognise the modules directory it finds there and purges it; with CI=true it does so without a prompt. The purge followed the symlink and deleted the repository's own node_modules mid-run, so a test suite uninstalled the workspace it was running in. That is what produced the cascading, file-unrelated failures a full test:unit run reported, and it happened twice while running the suites for the adapter re-review. scripts/lib/fixture-node-modules.ts replaces all four sites: node_modules is a real directory whose entries are individual symlinks, so a recursive delete unlinks the fixture's own links instead of walking through one link into the shared tree. Resolution is unchanged. tests/unit/fixture-node-modules.test.ts performs the exact recursive delete pnpm performs and asserts the source tree survives, and check:adapter-inventory now fails on any reintroduction of the directory-symlink form — verified by putting the old line back and watching the gate reject it. A full tests/unit + tests/integration run now leaves the dependencies intact. removal-fixture, supply-chain and security-followup-archive, the three suites that had to be excluded before, pass in that run. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
af7f35058b
commit
250531aa43
@@ -19,6 +19,7 @@ import {
|
||||
validateCiArtifact,
|
||||
} from "../../scripts/lib/ci-artifact-validator.ts";
|
||||
import { writeCiGateLogAtomic } from "../../scripts/lib/ci-gate-log.ts";
|
||||
import { linkFixtureNodeModules } from "../../scripts/lib/fixture-node-modules.ts";
|
||||
import { captureCiCandidateArchive, verifyCiCandidateArchive } from "../../scripts/lib/ci-candidate-archive.ts";
|
||||
import {
|
||||
CANDIDATE_ARCHIVE_USAGE,
|
||||
@@ -2131,7 +2132,7 @@ async function ensureProviderBaseFixture(): Promise<string> {
|
||||
recursive: true,
|
||||
});
|
||||
await rm(path.join(root, "artifacts/release"), { recursive: true, force: true });
|
||||
await symlink(path.join(sourceRoot, "node_modules"), path.join(root, "node_modules"), "dir");
|
||||
await linkFixtureNodeModules(root, sourceRoot);
|
||||
const git = spawnSync("git", ["show", "-s", "--format=%H%n%ct", "HEAD"], {
|
||||
cwd: sourceRoot,
|
||||
encoding: "utf8",
|
||||
|
||||
@@ -0,0 +1,89 @@
|
||||
import { mkdtemp, mkdir, readdir, readFile, rm, stat, writeFile } from "node:fs/promises";
|
||||
import { tmpdir } from "node:os";
|
||||
import path from "node:path";
|
||||
|
||||
import { describe, expect, it } from "vitest";
|
||||
|
||||
import { linkFixtureNodeModules } from "../../scripts/lib/fixture-node-modules.ts";
|
||||
|
||||
/**
|
||||
* A removal or provider fixture runs `pnpm` inside a throwaway copy of the
|
||||
* repository. pnpm does not recognise the modules directory it finds there and
|
||||
* purges it, and with `CI=true` it does so without a prompt. When
|
||||
* `<fixture>/node_modules` was a single directory symlink, that purge followed
|
||||
* the link and deleted the repository's own installed dependencies mid-run —
|
||||
* a test suite uninstalling the workspace it was running in.
|
||||
*/
|
||||
describe("fixture node_modules linking", () => {
|
||||
async function sourceTree() {
|
||||
const source = await mkdtemp(path.join(tmpdir(), "fixture-source-"));
|
||||
const modules = path.join(source, "node_modules");
|
||||
await mkdir(path.join(modules, "left", "lib"), { recursive: true });
|
||||
await mkdir(path.join(modules, "@scope", "right"), { recursive: true });
|
||||
await mkdir(path.join(modules, ".bin"), { recursive: true });
|
||||
await writeFile(path.join(modules, "left", "lib", "index.js"), "export default 1;\n");
|
||||
await writeFile(path.join(modules, "@scope", "right", "package.json"), "{}\n");
|
||||
await writeFile(path.join(modules, ".modules.yaml"), "{}\n");
|
||||
return source;
|
||||
}
|
||||
|
||||
it("survives a recursive delete of the fixture's node_modules", async () => {
|
||||
const source = await sourceTree();
|
||||
const fixture = await mkdtemp(path.join(tmpdir(), "fixture-root-"));
|
||||
try {
|
||||
await linkFixtureNodeModules(fixture, source);
|
||||
|
||||
// The fixture resolves the same packages...
|
||||
expect(
|
||||
await readFile(
|
||||
path.join(fixture, "node_modules/left/lib/index.js"),
|
||||
"utf8",
|
||||
),
|
||||
).toContain("export default 1;");
|
||||
expect(
|
||||
(await readdir(path.join(fixture, "node_modules"))).sort(),
|
||||
).toEqual([".bin", ".modules.yaml", "@scope", "left"]);
|
||||
|
||||
// ...and this is exactly what pnpm's purge does.
|
||||
await rm(path.join(fixture, "node_modules"), {
|
||||
recursive: true,
|
||||
force: true,
|
||||
});
|
||||
|
||||
// The repository's real dependencies are untouched.
|
||||
expect(
|
||||
await readFile(
|
||||
path.join(source, "node_modules/left/lib/index.js"),
|
||||
"utf8",
|
||||
),
|
||||
).toContain("export default 1;");
|
||||
expect(
|
||||
await stat(path.join(source, "node_modules/@scope/right/package.json")),
|
||||
).toBeDefined();
|
||||
expect(
|
||||
(await readdir(path.join(source, "node_modules"))).sort(),
|
||||
).toEqual([".bin", ".modules.yaml", "@scope", "left"]);
|
||||
} finally {
|
||||
await rm(source, { recursive: true, force: true });
|
||||
await rm(fixture, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
|
||||
it("creates node_modules as a real directory, never a symlink", async () => {
|
||||
const source = await sourceTree();
|
||||
const fixture = await mkdtemp(path.join(tmpdir(), "fixture-root-"));
|
||||
try {
|
||||
await linkFixtureNodeModules(fixture, source);
|
||||
const { lstat } = await import("node:fs/promises");
|
||||
const entry = await lstat(path.join(fixture, "node_modules"));
|
||||
expect(entry.isSymbolicLink()).toBe(false);
|
||||
expect(entry.isDirectory()).toBe(true);
|
||||
expect(
|
||||
(await lstat(path.join(fixture, "node_modules/left"))).isSymbolicLink(),
|
||||
).toBe(true);
|
||||
} finally {
|
||||
await rm(source, { recursive: true, force: true });
|
||||
await rm(fixture, { recursive: true, force: true });
|
||||
}
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user