mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-03 02:21:44 +00:00
* fix(lbug): pin Ladybug core so Dependabot cannot ship a skewed FTS artifact The extension version is a separate upstream constant. Ignore daily core bumps and fail the pairing gate when the committed manifest does not name the installed core. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): make doctor and CI FTS gates resolve the packaged artifact Doctor and the REQUIRE_FTS file gates still treated an empty ~/.lbdb as unavailable, which would turn three CI jobs red once analyze stops installing into that tree. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): name native-abort and tuple-missing so analyze cannot mis-advise The CLI summary's trailing else treated every unknown skip reason as a missing extension. New crash and platform causes must get their own remedies, not a network-install hint. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): delete the dead read-path FTS index create ensureFTSIndex had no production callers and swallowed read-only CREATE_FTS_INDEX failures, which hid the only signal that a reader tried to write. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): vendor per-platform FTS artifacts so analyze needs no host install Keyword search depended on a CDN fetch into ~/.lbdb. Shipping the five published tuples inside the package makes air-gapped and ignore-scripts installs load the same artifact the publish gate checksums. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): load the packaged FTS artifact before any network install Analyze still required a CDN fetch into ~/.lbdb even when the package already shipped the file. FTS now path-loads the vendored tuple first and records source labels so a later truncated home copy cannot steal the diagnosis. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): diagnose a core/extension version skew instead of a missing runtime A structurally valid FTS artifact whose path version disagrees with the packaged pin must name both versions, not prescribe VC++ or OpenSSL. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): stamp an FTS phase so repair stays usable after an in-place abort A native CREATE_FTS_INDEX abort leaves no skip reason; the next run infers it from the dirty flag, and --repair-fts must not treat that phase as a half-written graph. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): park an in-place FTS crash WAL without wiping the graph An FTS abort after a successful checkpoint must reopen the live index on macOS, Windows, and Linux. Staging never parks the live WAL; readers keep today's large-WAL refusal. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): refuse read-only opens of an FTS-poisoned WAL MCP and serve cannot repair a leftover in-place abort. Fail before the native open and name --repair-fts, on macOS, Windows, and Linux. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): name a vendor-neutral Windows OpenSSL prerequisite OQ1 is unanswered here so GitNexus does not ship OpenSSL DLLs. Windows FTS now asks for a system OpenSSL 3 runtime instead of Git Bash PATH. Co-authored-by: Cursor <cursoragent@cursor.com> * test(lbug): inject the FTS vendor root and redact it on HTTP and MCP Path-loaded artifacts no longer vary with HOME. Tests pass an injected vendor tree and assert search warnings never leak a filesystem path. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(lbug): document load-only as the global FTS install default Analyze still overrides to auto. Packaged per-platform artifacts load before any network install on macOS, Windows, and Linux. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(lbug): format the FTS install-policy README table Prettier does not run on Markdown in pre-commit, so the U10 table wrap needs its own formatting commit. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): skip FTS CREATE after a persisted native abort A recovered analyze run was retrying CREATE_FTS_INDEX from skipReason alone. Keep that skip until --repair-fts, fail closed on unsupported tuples, and honor the checkpoint warrant for park/repair. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): honor checkpoint flushed warrant and align FTS tests with packaged vendor A no-op CHECKPOINT must not satisfy the FTS park warrant, and CI still asserted HOME-only FTS isolation after analyze started path-LOADing the packaged artifact. Co-authored-by: Cursor <cursoragent@cursor.com> * test(lbug): accept a nonempty incremental write set in the #2790 recovery check FTS-phase recovery can incremental-add files (changed=0, added=1). That is not the #2790 empty-diff wipe skip. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): compare FTS home versions to the core pin and tighten the publish filename gate Ladybug's ~/.lbdb/extension directory is the runtime/core version; treating it as the artifact version false-diagnosed skew. The publish guard now rejects a path-escaping filename the same way the fetch script does. Co-authored-by: Cursor <cursoragent@cursor.com> * test(lbug): seed FTS e2e fixtures from the packaged vendor artifact A machine with no ~/.lbdb copy should still run the vendor-survivorship cases; the seed no longer depends on HOME or a network install. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3274) Keep in-place FTS abort evidence after persist so a second CREATE abort cannot fail-open readers, and close the CLI, loader, embed, and e2e gaps the review called out. Note: full npm test hit Ladybug worker-pool startup failures under memory pressure; tsc and 180 targeted unit tests passed. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3274) Run the vendored-path symlink guard on the OS matrix, put e2e HOME fixtures on Ladybug's real extension layout, pin the embed crash-WAL gate before the writable open, and let analyze writers park through missing-shadow recovery. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): keep --repair-fts CI green after vendored-first FTS Never-installed warning fixtures must not inspect a packaged vendor binary, and a failed dirty restamp must not abort an otherwise successful --repair-fts run. Co-authored-by: Cursor <cursoragent@cursor.com> * test(cli): give the #1169 analyze e2e the same 90s Windows budget as its sibling The first #1169 persist-meta case was still on a 60s spawn/it budget and was killed banner-only on windows-latest after the FTS warning fixture no longer failed the shard first. Co-authored-by: Cursor <cursoragent@cursor.com> * test(ci): reweight Windows shards after the FTS e2e grew Vendored-first HOME fixtures pushed fts-extension-e2e to ~6 minutes on windows-latest, so the old 146s weight packed it with skills-e2e and blew the 20-minute watchdog. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
262 lines
10 KiB
TypeScript
262 lines
10 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
|
|
import * as os from 'node:os';
|
|
import * as path from 'node:path';
|
|
import { mkdtempSync, writeFileSync, mkdirSync, rmSync } from 'node:fs';
|
|
import type { GroupConfig, GroupManifestLink } from '../../../src/core/group/types.js';
|
|
|
|
// Two test surfaces for the windowed manifest resolution (issue #2189 / PR #2191
|
|
// review, Finding 3 — bound peak pool residency to MAX_POOL_SIZE regardless of
|
|
// group size):
|
|
//
|
|
// 1. partitionManifestWindows — a pure function; the bounded-residency logic
|
|
// lives here (every window references <= maxResident repos, every link in
|
|
// exactly one window). Tested directly, no pool.
|
|
// 2. A real-pool integration test that drives syncGroup through the actual
|
|
// pool (native LadybugDB layer mocked, as in lbug-pool-pinning.test.ts) and
|
|
// asserts the count of concurrently-open Databases never exceeds the
|
|
// resident cap — the end-to-end residency bound the review flagged as
|
|
// missing.
|
|
|
|
// ── Surface 1: pure partition function ──────────────────────────────────────
|
|
|
|
describe('partitionManifestWindows (issue #2189 windowed resolution)', () => {
|
|
const link = (from: string, to: string): GroupManifestLink => ({
|
|
from,
|
|
to,
|
|
type: 'http',
|
|
contract: `GET::/${from}-${to}`,
|
|
role: 'consumer',
|
|
});
|
|
|
|
it('keeps every window within maxResident repos and places every link exactly once', async () => {
|
|
const { partitionManifestWindows } = await import('../../../src/core/group/sync.js');
|
|
const repos = ['r1', 'r2', 'r3', 'r4', 'r5', 'r6', 'r7', 'r8'];
|
|
const known = new Set(repos);
|
|
// A star: every leaf links to the hub r1, plus a few leaf-leaf links.
|
|
const links = [
|
|
link('r1', 'r2'),
|
|
link('r1', 'r3'),
|
|
link('r1', 'r4'),
|
|
link('r1', 'r5'),
|
|
link('r1', 'r6'),
|
|
link('r7', 'r8'),
|
|
link('r2', 'r3'),
|
|
];
|
|
const maxResident = 5;
|
|
const windows = partitionManifestWindows(links, known, maxResident);
|
|
|
|
// Bounded residency: no window references more than maxResident repos.
|
|
for (const w of windows) expect(w.repos.size).toBeLessThanOrEqual(maxResident);
|
|
|
|
// True partition: every link appears in exactly one window.
|
|
const placed = windows.flatMap((w) => w.links);
|
|
expect(placed).toHaveLength(links.length);
|
|
const placedKeys = placed.map((l) => `${l.from}->${l.to}`).sort();
|
|
const inputKeys = links.map((l) => `${l.from}->${l.to}`).sort();
|
|
expect(placedKeys).toEqual(inputKeys);
|
|
// No link appears twice (the contract-dedup invariant — KTD-4).
|
|
expect(new Set(placedKeys).size).toBe(placedKeys.length);
|
|
});
|
|
|
|
it('counts only in-group repos toward a window; dangling links consume no budget', async () => {
|
|
const { partitionManifestWindows } = await import('../../../src/core/group/sync.js');
|
|
const known = new Set(['r1']);
|
|
const links = [
|
|
link('r1', 'external-a'), // 1 in-group repo
|
|
link('external-b', 'external-c'), // 0 in-group repos (fully dangling)
|
|
];
|
|
const windows = partitionManifestWindows(links, known, 5);
|
|
// Both links are still placed (so they yield synthetic-UID contracts)...
|
|
expect(windows.flatMap((w) => w.links)).toHaveLength(2);
|
|
// ...but the only repo counted is r1.
|
|
const allRepos = new Set(windows.flatMap((w) => [...w.repos]));
|
|
expect(allRepos).toEqual(new Set(['r1']));
|
|
});
|
|
|
|
it('returns no windows for an empty link set', async () => {
|
|
const { partitionManifestWindows } = await import('../../../src/core/group/sync.js');
|
|
expect(partitionManifestWindows([], new Set(['r1']), 5)).toEqual([]);
|
|
});
|
|
|
|
it('splits links across multiple windows when referenced repos exceed maxResident', async () => {
|
|
const { partitionManifestWindows } = await import('../../../src/core/group/sync.js');
|
|
const known = new Set(['r1', 'r2', 'r3', 'r4', 'r5', 'r6']);
|
|
// 3 disjoint repo-pairs = 6 distinct repos; maxResident 2 forces ≥3 windows.
|
|
const links = [link('r1', 'r2'), link('r3', 'r4'), link('r5', 'r6')];
|
|
const windows = partitionManifestWindows(links, known, 2);
|
|
expect(windows.length).toBeGreaterThanOrEqual(3);
|
|
for (const w of windows) expect(w.repos.size).toBeLessThanOrEqual(2);
|
|
expect(windows.flatMap((w) => w.links)).toHaveLength(3);
|
|
});
|
|
});
|
|
|
|
// ── Surface 2: real-pool residency bound through syncGroup ───────────────────
|
|
|
|
const { loadFTSExtensionMock, loadVectorExtensionMock, openCounter } = vi.hoisted(() => ({
|
|
loadFTSExtensionMock: vi.fn(),
|
|
loadVectorExtensionMock: vi.fn().mockResolvedValue(false),
|
|
openCounter: { live: 0, peak: 0 },
|
|
}));
|
|
|
|
vi.mock('@ladybugdb/core', () => ({
|
|
default: {
|
|
Database: vi.fn(),
|
|
Connection: vi.fn(function (this: any) {
|
|
this.query = vi.fn().mockResolvedValue({
|
|
getAll: vi.fn().mockResolvedValue([]),
|
|
close: vi.fn(),
|
|
});
|
|
// executeParameterized's prepare/execute path (manifest resolveSymbol).
|
|
this.prepare = vi.fn().mockResolvedValue({
|
|
isSuccess: () => true,
|
|
getErrorMessage: vi.fn().mockResolvedValue(''),
|
|
});
|
|
this.execute = vi.fn().mockResolvedValue({
|
|
getAll: vi.fn().mockResolvedValue([]),
|
|
close: vi.fn(),
|
|
});
|
|
this.close = vi.fn().mockResolvedValue(undefined);
|
|
}),
|
|
},
|
|
}));
|
|
|
|
vi.mock('../../../src/core/lbug/lbug-adapter.js', () => ({
|
|
isReadOnlyDbError: vi.fn(() => false),
|
|
loadFTSExtension: loadFTSExtensionMock,
|
|
loadVectorExtension: loadVectorExtensionMock,
|
|
}));
|
|
|
|
vi.mock('../../../src/core/lbug/lbug-config.js', () => ({
|
|
// Track concurrently-open Databases: a fresh fake per open, decrement on close.
|
|
createLbugDatabase: vi.fn(() => {
|
|
openCounter.live += 1;
|
|
openCounter.peak = Math.max(openCounter.peak, openCounter.live);
|
|
return {
|
|
init: vi.fn().mockResolvedValue(undefined),
|
|
close: vi.fn().mockImplementation(async () => {
|
|
openCounter.live -= 1;
|
|
}),
|
|
};
|
|
}),
|
|
toNativeSafePath: vi.fn((p: string) => p),
|
|
isWalCorruptionError: vi.fn(() => false),
|
|
WAL_RECOVERY_SUGGESTION: '',
|
|
isStorageVersionMismatchError: vi.fn(() => false),
|
|
throwIfStorageVersionMismatch: vi.fn(),
|
|
sleep: vi.fn(async () => {}),
|
|
STORAGE_VERSION_MISMATCH_SUGGESTION: '',
|
|
}));
|
|
|
|
vi.mock('../../../src/core/lbug/sidecar-recovery.js', () => ({
|
|
preflightLbugSidecars: vi.fn().mockResolvedValue(undefined),
|
|
guardWalQuarantine: vi.fn().mockResolvedValue(undefined),
|
|
isMissingFsError: vi.fn(() => false),
|
|
isMissingShadowSidecarError: vi.fn(() => false),
|
|
isReadOnlyShadowReplayError: vi.fn(() => false),
|
|
quarantineWalForMissingShadow: vi.fn().mockResolvedValue(''),
|
|
renameFailureMessage: vi.fn((p: string) => `rename failed for ${p}`),
|
|
statIfExists: vi.fn().mockResolvedValue(null),
|
|
assertReadOnlyFtsCrashSafe: vi.fn().mockResolvedValue(undefined),
|
|
FtsReaderUnrepairableError: class FtsReaderUnrepairableError extends Error {
|
|
readonly code = 'FTS_READER_UNREPAIRABLE' as const;
|
|
constructor(dbPath = '') {
|
|
super(dbPath);
|
|
this.name = 'FtsReaderUnrepairableError';
|
|
}
|
|
},
|
|
}));
|
|
|
|
// The registry read happens in syncGroup's else branch; resolveRepoHandle is
|
|
// supplied, so an empty registry is fine (only the meta.json fallback reads it).
|
|
vi.mock('../../../src/storage/repo-manager.js', async (importOriginal) => {
|
|
const actual = await importOriginal<typeof import('../../../src/storage/repo-manager.js')>();
|
|
return {
|
|
...actual,
|
|
readRegistry: vi.fn().mockResolvedValue([]),
|
|
readRegistryStrict: vi.fn().mockResolvedValue([]),
|
|
};
|
|
});
|
|
|
|
const { syncGroup } = await import('../../../src/core/group/sync.js');
|
|
const { closeLbug, getMaxResidentRepos } = await import('../../../src/core/lbug/pool-adapter.js');
|
|
|
|
describe('syncGroup windowed resolution bounds pool residency (real pool, #2189)', () => {
|
|
let tmpRoot: string;
|
|
|
|
beforeEach(() => {
|
|
tmpRoot = mkdtempSync(path.join(os.tmpdir(), 'gn-window-resid-'));
|
|
loadFTSExtensionMock.mockResolvedValue(true);
|
|
openCounter.live = 0;
|
|
openCounter.peak = 0;
|
|
});
|
|
|
|
afterEach(async () => {
|
|
await closeLbug().catch(() => {});
|
|
rmSync(tmpRoot, { recursive: true, force: true });
|
|
});
|
|
|
|
it('never holds more than getMaxResidentRepos() Databases open for a large group', async () => {
|
|
const maxResident = getMaxResidentRepos();
|
|
const repoCount = maxResident + 4; // exceed the cap so windowing must split
|
|
|
|
const repos: Record<string, string> = {};
|
|
const links: GroupManifestLink[] = [];
|
|
for (let i = 1; i <= repoCount; i++) {
|
|
const gp = `app/repo-${i}`;
|
|
repos[gp] = `repo-${i}`;
|
|
// Star topology: every repo links to repo-1 → many windows reference repo-1.
|
|
if (i > 1) {
|
|
links.push({
|
|
from: gp,
|
|
to: 'app/repo-1',
|
|
type: 'http',
|
|
contract: `GET::/api/${i}`,
|
|
role: 'consumer',
|
|
});
|
|
}
|
|
}
|
|
|
|
const config: GroupConfig = {
|
|
version: 1,
|
|
name: 'test',
|
|
description: '',
|
|
repos,
|
|
links,
|
|
packages: {},
|
|
// All detection off → init loop just opens pools (no extractor file reads).
|
|
detect: {
|
|
http: false,
|
|
grpc: false,
|
|
thrift: false,
|
|
topics: false,
|
|
includes: false,
|
|
workspace_deps: false,
|
|
},
|
|
matching: {},
|
|
};
|
|
|
|
await syncGroup(config, {
|
|
resolveRepoHandle: async (_name, groupPath) => {
|
|
// Each repo gets a real storage dir with a fake lbug file so fs.stat in
|
|
// doInitLbug succeeds; distinct paths → distinct Databases.
|
|
const storagePath = path.join(tmpRoot, groupPath);
|
|
mkdirSync(storagePath, { recursive: true });
|
|
writeFileSync(path.join(storagePath, 'lbug'), '');
|
|
return {
|
|
id: groupPath.replace(/\//g, '-'),
|
|
path: groupPath,
|
|
repoPath: storagePath,
|
|
storagePath,
|
|
};
|
|
},
|
|
skipWrite: true,
|
|
});
|
|
|
|
// The init loop (no pin) keeps the pool at the LRU cap; windowed resolution
|
|
// leases <= maxResident repos per window and releases them. Peak concurrent
|
|
// open Databases must stay within the resident cap (+ at most one transient
|
|
// overshoot at an init boundary — the pool's documented soft cap).
|
|
expect(openCounter.peak).toBeGreaterThan(0);
|
|
expect(openCounter.peak).toBeLessThanOrEqual(maxResident + 1);
|
|
});
|
|
});
|