GitNexus/gitnexus/test/unit/fts-policy.test.ts
Gergő Magyar 21a52af1d4
fix(lbug): ship FTS per-platform and recover in-place native aborts (#3274)
* fix(lbug): pin Ladybug core so Dependabot cannot ship a skewed FTS artifact

The extension version is a separate upstream constant. Ignore daily core bumps and fail the pairing gate when the committed manifest does not name the installed core.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): make doctor and CI FTS gates resolve the packaged artifact

Doctor and the REQUIRE_FTS file gates still treated an empty ~/.lbdb as
unavailable, which would turn three CI jobs red once analyze stops
installing into that tree.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): name native-abort and tuple-missing so analyze cannot mis-advise

The CLI summary's trailing else treated every unknown skip reason as a
missing extension. New crash and platform causes must get their own
remedies, not a network-install hint.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): delete the dead read-path FTS index create

ensureFTSIndex had no production callers and swallowed read-only
CREATE_FTS_INDEX failures, which hid the only signal that a reader
tried to write.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): vendor per-platform FTS artifacts so analyze needs no host install

Keyword search depended on a CDN fetch into ~/.lbdb. Shipping the five
published tuples inside the package makes air-gapped and ignore-scripts
installs load the same artifact the publish gate checksums.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): load the packaged FTS artifact before any network install

Analyze still required a CDN fetch into ~/.lbdb even when the package
already shipped the file. FTS now path-loads the vendored tuple first
and records source labels so a later truncated home copy cannot steal
the diagnosis.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): diagnose a core/extension version skew instead of a missing runtime

A structurally valid FTS artifact whose path version disagrees with the
packaged pin must name both versions, not prescribe VC++ or OpenSSL.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): stamp an FTS phase so repair stays usable after an in-place abort

A native CREATE_FTS_INDEX abort leaves no skip reason; the next run infers
it from the dirty flag, and --repair-fts must not treat that phase as a
half-written graph.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): park an in-place FTS crash WAL without wiping the graph

An FTS abort after a successful checkpoint must reopen the live index on
macOS, Windows, and Linux. Staging never parks the live WAL; readers keep
today's large-WAL refusal.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): refuse read-only opens of an FTS-poisoned WAL

MCP and serve cannot repair a leftover in-place abort. Fail before the
native open and name --repair-fts, on macOS, Windows, and Linux.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): name a vendor-neutral Windows OpenSSL prerequisite

OQ1 is unanswered here so GitNexus does not ship OpenSSL DLLs. Windows
FTS now asks for a system OpenSSL 3 runtime instead of Git Bash PATH.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(lbug): inject the FTS vendor root and redact it on HTTP and MCP

Path-loaded artifacts no longer vary with HOME. Tests pass an injected
vendor tree and assert search warnings never leak a filesystem path.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(lbug): document load-only as the global FTS install default

Analyze still overrides to auto. Packaged per-platform artifacts load
before any network install on macOS, Windows, and Linux.

Co-authored-by: Cursor <cursoragent@cursor.com>

* docs(lbug): format the FTS install-policy README table

Prettier does not run on Markdown in pre-commit, so the U10 table wrap
needs its own formatting commit.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): skip FTS CREATE after a persisted native abort

A recovered analyze run was retrying CREATE_FTS_INDEX from skipReason
alone. Keep that skip until --repair-fts, fail closed on unsupported
tuples, and honor the checkpoint warrant for park/repair.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): honor checkpoint flushed warrant and align FTS tests with packaged vendor

A no-op CHECKPOINT must not satisfy the FTS park warrant, and CI still asserted HOME-only FTS isolation after analyze started path-LOADing the packaged artifact.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(lbug): accept a nonempty incremental write set in the #2790 recovery check

FTS-phase recovery can incremental-add files (changed=0, added=1). That is not the #2790 empty-diff wipe skip.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): compare FTS home versions to the core pin and tighten the publish filename gate

Ladybug's ~/.lbdb/extension directory is the runtime/core version; treating it as the artifact version false-diagnosed skew. The publish guard now rejects a path-escaping filename the same way the fetch script does.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(lbug): seed FTS e2e fixtures from the packaged vendor artifact

A machine with no ~/.lbdb copy should still run the vendor-survivorship cases; the seed no longer depends on HOME or a network install.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3274)

Keep in-place FTS abort evidence after persist so a second CREATE abort
cannot fail-open readers, and close the CLI, loader, embed, and e2e gaps
the review called out.

Note: full npm test hit Ladybug worker-pool startup failures under memory
pressure; tsc and 180 targeted unit tests passed.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3274)

Run the vendored-path symlink guard on the OS matrix, put e2e HOME
fixtures on Ladybug's real extension layout, pin the embed crash-WAL
gate before the writable open, and let analyze writers park through
missing-shadow recovery.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(lbug): keep --repair-fts CI green after vendored-first FTS

Never-installed warning fixtures must not inspect a packaged vendor binary, and a failed dirty restamp must not abort an otherwise successful --repair-fts run.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(cli): give the #1169 analyze e2e the same 90s Windows budget as its sibling

The first #1169 persist-meta case was still on a 60s spawn/it budget and was killed banner-only on windows-latest after the FTS warning fixture no longer failed the shard first.

Co-authored-by: Cursor <cursoragent@cursor.com>

* test(ci): reweight Windows shards after the FTS e2e grew

Vendored-first HOME fixtures pushed fts-extension-e2e to ~6 minutes on windows-latest, so the old 146s weight packed it with skills-e2e and blew the 20-minute watchdog.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-14 08:52:24 +01:00

259 lines
9.9 KiB
TypeScript

import { afterEach, describe, expect, it, vi } from 'vitest';
import fs from 'node:fs/promises';
import os from 'node:os';
import path from 'node:path';
import {
FTS_DISABLED_MESSAGE,
FTS_SKIP_REASONS,
formatAnalyzeFtsSkipSummary,
getFtsDisabledReason,
isExplicitFtsDisablement,
resolveFtsDisableReason,
withExplicitFtsDisablement,
type FtsSkipReason,
} from '../../src/core/search/fts-policy.js';
import type { PersistedFtsSkipReason, RepoMeta } from '../../src/storage/repo-meta.js';
import { classifyFtsBuildError, ftsDegradedWarning } from '../../src/core/search/fts-indexes.js';
import { searchFTSFromLbug } from '../../src/core/search/bm25-index.js';
import { hybridSearch } from '../../src/core/search/hybrid-search.js';
import { extensionManager, resetExtensionState } from '../../src/core/lbug/extension-loader.js';
afterEach(() => {
vi.unstubAllEnvs();
resetExtensionState();
});
describe('explicit FTS opt-out', () => {
it('is off by default and accepts only the exact environment value 1', () => {
vi.stubEnv('GITNEXUS_SKIP_FTS', undefined);
expect(resolveFtsDisableReason()).toBeUndefined();
for (const value of ['', '0', 'true', 'yes', ' 1', '1 ']) {
expect(resolveFtsDisableReason(false, value)).toBeUndefined();
}
expect(resolveFtsDisableReason(false, '1')).toBe('disabled-by-env');
expect(resolveFtsDisableReason(true, '1')).toBe('disabled-by-flag');
expect(resolveFtsDisableReason(true, '0')).toBe('disabled-by-flag');
expect(isExplicitFtsDisablement('disabled-by-flag')).toBe(true);
expect(isExplicitFtsDisablement('disabled-by-env')).toBe(true);
expect(isExplicitFtsDisablement('build-failed')).toBe(false);
expect(isExplicitFtsDisablement('native-abort')).toBe(false);
expect(isExplicitFtsDisablement('tuple-missing')).toBe(false);
});
it('does not infer intent from a failed or legacy index', () => {
expect(getFtsDisabledReason(undefined)).toBeUndefined();
for (const skipReason of [
undefined,
'build-failed',
'extension-unavailable',
'native-abort',
'tuple-missing',
] as const) {
expect(
getFtsDisabledReason({ provider: 'ladybugdb-fts', status: 'unavailable', skipReason }),
).toBeUndefined();
}
expect(
getFtsDisabledReason({
provider: 'ladybugdb-fts',
status: 'available',
skipReason: 'disabled-by-flag',
}),
).toBeUndefined();
expect(
getFtsDisabledReason({
provider: 'ladybugdb-fts',
status: 'unavailable',
skipReason: 'disabled-by-env',
}),
).toBe('disabled-by-env');
});
it('stamps explicit disablement without rewriting freshness or sibling capabilities', () => {
const indexedAt = '2026-01-01T00:00:00.000Z';
const meta = {
indexedAt,
lastCommit: 'abc',
capabilities: {
graph: { provider: 'ladybugdb', status: 'available' },
fts: { provider: 'ladybugdb-fts', status: 'available' },
vectorSearch: {
provider: 'ladybugdb-vector',
status: 'vector-index',
exactScanLimit: 10,
},
},
} as RepoMeta;
const stamped = withExplicitFtsDisablement(meta, 'disabled-by-flag');
expect(stamped.indexedAt).toBe(indexedAt);
expect(stamped.lastCommit).toBe('abc');
expect(stamped.capabilities?.graph).toEqual(meta.capabilities?.graph);
expect(stamped.capabilities?.vectorSearch).toEqual(meta.capabilities?.vectorSearch);
expect(stamped.capabilities?.fts).toEqual({
provider: 'ladybugdb-fts',
status: 'unavailable',
skipReason: 'disabled-by-flag',
});
expect(withExplicitFtsDisablement(meta, undefined)).toBe(meta);
expect(withExplicitFtsDisablement(stamped, 'disabled-by-flag')).toBe(stamped);
expect(
withExplicitFtsDisablement(stamped, 'disabled-by-env').capabilities?.fts?.skipReason,
).toBe('disabled-by-env');
});
it('reports intent even when another database has an extension failure', async () => {
await extensionManager.ensure(
vi.fn().mockRejectedValue(new Error('invalid ELF header')),
'fts',
'FTS',
{ policy: 'load-only' },
);
expect(ftsDegradedWarning(undefined, 'disabled-by-flag')).toBe(FTS_DISABLED_MESSAGE);
expect(ftsDegradedWarning()).toContain('FTS extension failed to load');
});
it('returns no keyword results without a database or extension load', async () => {
await expect(
searchFTSFromLbug('createHandler', 10, undefined, 'disabled-by-env'),
).resolves.toEqual({ results: [], ftsAvailable: false });
});
it.each([
{ skipFts: true, env: undefined },
{ skipFts: false, env: '1' },
{ skipFts: true, env: '1' },
])('rejects FTS repair while explicitly disabled (%j)', async ({ skipFts, env }) => {
const home = await fs.mkdtemp(path.join(os.tmpdir(), 'gitnexus-fts-policy-'));
vi.stubEnv('GITNEXUS_HOME', home);
vi.stubEnv('GITNEXUS_SKIP_FTS', env);
try {
const { runFullAnalysis } = await import('../../src/core/run-analyze.js');
await expect(
runFullAnalysis(path.join(home, 'repo'), { skipFts, repairFts: true }, { onProgress() {} }),
).rejects.toThrow('--repair-fts cannot be used with --skip-fts or GITNEXUS_SKIP_FTS=1');
expect(await fs.readdir(home)).toEqual([]);
} finally {
await fs.rm(home, { recursive: true, force: true });
}
});
it('keeps semantic results when keyword search is explicitly disabled', async () => {
const executeQuery = vi.fn();
const semantic = vi.fn().mockResolvedValue([
{
nodeId: 'Function:handler',
filePath: 'src/handler.ts',
name: 'handler',
label: 'Function',
startLine: 1,
endLine: 3,
distance: 0.1,
},
]);
const result = await hybridSearch('handler', 10, executeQuery, semantic, 'disabled-by-flag');
expect(result).toHaveLength(1);
expect(result[0]).toMatchObject({
name: 'handler',
sources: ['semantic'],
filePath: 'src/handler.ts',
});
expect(semantic).toHaveBeenCalledWith(executeQuery, 'handler', 10);
expect(executeQuery).not.toHaveBeenCalled();
});
});
describe('FTS skip-reason members (U6)', () => {
type SameSkipReason = FtsSkipReason extends PersistedFtsSkipReason
? PersistedFtsSkipReason extends FtsSkipReason
? true
: never
: never;
const _storageMirrorsCore: SameSkipReason = true;
void _storageMirrorsCore;
it('round-trips native-abort and tuple-missing through the capability stamp', () => {
const base = {
indexedAt: '2026-01-01T00:00:00.000Z',
lastCommit: 'abc',
capabilities: {
graph: { provider: 'ladybugdb', status: 'available' as const },
fts: { provider: 'ladybugdb-fts', status: 'available' as const },
vectorSearch: {
provider: 'ladybugdb-vector',
status: 'vector-index' as const,
exactScanLimit: 10,
},
},
} as RepoMeta;
for (const reason of ['native-abort', 'tuple-missing'] as const) {
const stamped: RepoMeta = {
...base,
capabilities: {
...base.capabilities!,
fts: { provider: 'ladybugdb-fts', status: 'unavailable', skipReason: reason },
},
};
expect(stamped.capabilities?.fts?.skipReason).toBe(reason);
expect(isExplicitFtsDisablement(stamped.capabilities?.fts?.skipReason)).toBe(false);
}
});
it('lets the storage union accept every core-side member', () => {
for (const reason of FTS_SKIP_REASONS) {
const persisted: PersistedFtsSkipReason = reason;
const core: FtsSkipReason = persisted;
expect(core).toBe(reason);
}
});
it('keeps explicit disablement ahead of the new failure members', () => {
expect(resolveFtsDisableReason(true, '1')).toBe('disabled-by-flag');
expect(isExplicitFtsDisablement(resolveFtsDisableReason(true))).toBe(true);
expect(formatAnalyzeFtsSkipSummary('disabled-by-flag')).toBe(FTS_DISABLED_MESSAGE);
expect(formatAnalyzeFtsSkipSummary('native-abort')).not.toContain(
'GITNEXUS_LBUG_EXTENSION_INSTALL=auto',
);
expect(formatAnalyzeFtsSkipSummary('tuple-missing')).not.toContain(
'GITNEXUS_LBUG_EXTENSION_INSTALL=auto',
);
});
it('still classifies a message-bearing tokenizer failure as capability', () => {
expect(classifyFtsBuildError('Runtime exception: Failed calling LOWER: Invalid UTF-8.')).toBe(
'capability',
);
});
it('names each skip reason instead of falling through to the network-install remedy', () => {
const nativeAbort = formatAnalyzeFtsSkipSummary('native-abort');
expect(nativeAbort).toMatch(/aborted while building/);
expect(nativeAbort.replaceAll('gitnexus analyze --repair-fts', '')).not.toContain(
'gitnexus analyze',
);
expect(formatAnalyzeFtsSkipSummary('tuple-missing')).toMatch(/no packaged FTS artifact/);
expect(formatAnalyzeFtsSkipSummary('build-failed')).toMatch(/search index build failed/);
expect(formatAnalyzeFtsSkipSummary('extension-unavailable')).toContain(
'GITNEXUS_LBUG_EXTENSION_INSTALL=auto',
);
expect(formatAnalyzeFtsSkipSummary(undefined)).toContain(
'GITNEXUS_LBUG_EXTENSION_INSTALL=auto',
);
});
it('prints the skip summary on the already-up-to-date CLI path whenever FTS was skipped', async () => {
const { readFile } = await import('node:fs/promises');
const { fileURLToPath } = await import('node:url');
const analyzeSrc = await readFile(
fileURLToPath(new URL('../../src/cli/analyze.ts', import.meta.url)),
'utf8',
);
const alreadyUpToDate = analyzeSrc.match(
/Already up to date[\s\S]{0,400}if \(runOptions\.registryName\)/,
);
expect(alreadyUpToDate).not.toBeNull();
expect(alreadyUpToDate![0]).toContain('if (result.ftsSkipped)');
expect(alreadyUpToDate![0]).toContain('formatAnalyzeFtsSkipSummary(result.ftsSkipReason)');
expect(alreadyUpToDate![0]).not.toContain('isExplicitFtsDisablement');
});
});