mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-02 02:11:29 +00:00
* fix(lbug): pin Ladybug core so Dependabot cannot ship a skewed FTS artifact The extension version is a separate upstream constant. Ignore daily core bumps and fail the pairing gate when the committed manifest does not name the installed core. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): make doctor and CI FTS gates resolve the packaged artifact Doctor and the REQUIRE_FTS file gates still treated an empty ~/.lbdb as unavailable, which would turn three CI jobs red once analyze stops installing into that tree. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): name native-abort and tuple-missing so analyze cannot mis-advise The CLI summary's trailing else treated every unknown skip reason as a missing extension. New crash and platform causes must get their own remedies, not a network-install hint. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): delete the dead read-path FTS index create ensureFTSIndex had no production callers and swallowed read-only CREATE_FTS_INDEX failures, which hid the only signal that a reader tried to write. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): vendor per-platform FTS artifacts so analyze needs no host install Keyword search depended on a CDN fetch into ~/.lbdb. Shipping the five published tuples inside the package makes air-gapped and ignore-scripts installs load the same artifact the publish gate checksums. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): load the packaged FTS artifact before any network install Analyze still required a CDN fetch into ~/.lbdb even when the package already shipped the file. FTS now path-loads the vendored tuple first and records source labels so a later truncated home copy cannot steal the diagnosis. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): diagnose a core/extension version skew instead of a missing runtime A structurally valid FTS artifact whose path version disagrees with the packaged pin must name both versions, not prescribe VC++ or OpenSSL. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): stamp an FTS phase so repair stays usable after an in-place abort A native CREATE_FTS_INDEX abort leaves no skip reason; the next run infers it from the dirty flag, and --repair-fts must not treat that phase as a half-written graph. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): park an in-place FTS crash WAL without wiping the graph An FTS abort after a successful checkpoint must reopen the live index on macOS, Windows, and Linux. Staging never parks the live WAL; readers keep today's large-WAL refusal. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): refuse read-only opens of an FTS-poisoned WAL MCP and serve cannot repair a leftover in-place abort. Fail before the native open and name --repair-fts, on macOS, Windows, and Linux. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): name a vendor-neutral Windows OpenSSL prerequisite OQ1 is unanswered here so GitNexus does not ship OpenSSL DLLs. Windows FTS now asks for a system OpenSSL 3 runtime instead of Git Bash PATH. Co-authored-by: Cursor <cursoragent@cursor.com> * test(lbug): inject the FTS vendor root and redact it on HTTP and MCP Path-loaded artifacts no longer vary with HOME. Tests pass an injected vendor tree and assert search warnings never leak a filesystem path. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(lbug): document load-only as the global FTS install default Analyze still overrides to auto. Packaged per-platform artifacts load before any network install on macOS, Windows, and Linux. Co-authored-by: Cursor <cursoragent@cursor.com> * docs(lbug): format the FTS install-policy README table Prettier does not run on Markdown in pre-commit, so the U10 table wrap needs its own formatting commit. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): skip FTS CREATE after a persisted native abort A recovered analyze run was retrying CREATE_FTS_INDEX from skipReason alone. Keep that skip until --repair-fts, fail closed on unsupported tuples, and honor the checkpoint warrant for park/repair. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): honor checkpoint flushed warrant and align FTS tests with packaged vendor A no-op CHECKPOINT must not satisfy the FTS park warrant, and CI still asserted HOME-only FTS isolation after analyze started path-LOADing the packaged artifact. Co-authored-by: Cursor <cursoragent@cursor.com> * test(lbug): accept a nonempty incremental write set in the #2790 recovery check FTS-phase recovery can incremental-add files (changed=0, added=1). That is not the #2790 empty-diff wipe skip. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): compare FTS home versions to the core pin and tighten the publish filename gate Ladybug's ~/.lbdb/extension directory is the runtime/core version; treating it as the artifact version false-diagnosed skew. The publish guard now rejects a path-escaping filename the same way the fetch script does. Co-authored-by: Cursor <cursoragent@cursor.com> * test(lbug): seed FTS e2e fixtures from the packaged vendor artifact A machine with no ~/.lbdb copy should still run the vendor-survivorship cases; the seed no longer depends on HOME or a network install. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3274) Keep in-place FTS abort evidence after persist so a second CREATE abort cannot fail-open readers, and close the CLI, loader, embed, and e2e gaps the review called out. Note: full npm test hit Ladybug worker-pool startup failures under memory pressure; tsc and 180 targeted unit tests passed. Co-authored-by: Cursor <cursoragent@cursor.com> * Address PR review feedback (#3274) Run the vendored-path symlink guard on the OS matrix, put e2e HOME fixtures on Ladybug's real extension layout, pin the embed crash-WAL gate before the writable open, and let analyze writers park through missing-shadow recovery. Co-authored-by: Cursor <cursoragent@cursor.com> * fix(lbug): keep --repair-fts CI green after vendored-first FTS Never-installed warning fixtures must not inspect a packaged vendor binary, and a failed dirty restamp must not abort an otherwise successful --repair-fts run. Co-authored-by: Cursor <cursoragent@cursor.com> * test(cli): give the #1169 analyze e2e the same 90s Windows budget as its sibling The first #1169 persist-meta case was still on a 60s spawn/it budget and was killed banner-only on windows-latest after the FTS warning fixture no longer failed the shard first. Co-authored-by: Cursor <cursoragent@cursor.com> * test(ci): reweight Windows shards after the FTS e2e grew Vendored-first HOME fixtures pushed fts-extension-e2e to ~6 minutes on windows-latest, so the old 146s weight packed it with skills-e2e and blew the 20-minute watchdog. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com> Co-authored-by: Cursor <cursoragent@cursor.com>
308 lines
11 KiB
TypeScript
308 lines
11 KiB
TypeScript
import { afterEach, beforeEach, describe, expect, it, vi } from 'vitest';
|
|
import * as os from 'node:os';
|
|
import * as path from 'node:path';
|
|
import { mkdtempSync, writeFileSync, rmSync } from 'node:fs';
|
|
|
|
// Drive the REAL initLbug path (which calls evictLRU) rather than
|
|
// initLbugWithDb (which bypasses eviction entirely). The native LadybugDB
|
|
// open/connect/FTS stack is mocked exactly as in lbug-pool-fts-load.test.ts,
|
|
// plus sidecar-recovery so openReadOnlyDatabase's preflight is a no-op. fs is
|
|
// NOT mocked — each repo uses a real temp file so the fs.stat existence check
|
|
// in doInitLbug succeeds naturally.
|
|
//
|
|
// Covers issue #2189: a group sync larger than MAX_POOL_SIZE must keep every
|
|
// repo resident through deferred manifest/workspace resolution. Pinning makes
|
|
// that resident set survive automatic (LRU + idle) eviction.
|
|
|
|
const { loadFTSExtensionMock, loadVectorExtensionMock } = vi.hoisted(() => ({
|
|
loadFTSExtensionMock: vi.fn(),
|
|
loadVectorExtensionMock: vi.fn().mockResolvedValue(false),
|
|
}));
|
|
|
|
vi.mock('@ladybugdb/core', () => ({
|
|
default: {
|
|
Database: vi.fn(),
|
|
Connection: vi.fn(function (this: any) {
|
|
// probeDatabaseForShadowReplay() runs a probe query during the
|
|
// read-only open; the result must expose getAll()/close().
|
|
this.query = vi.fn().mockResolvedValue({
|
|
getAll: vi.fn().mockResolvedValue([]),
|
|
close: vi.fn(),
|
|
});
|
|
this.close = vi.fn().mockResolvedValue(undefined);
|
|
}),
|
|
},
|
|
}));
|
|
|
|
vi.mock('../../src/core/lbug/lbug-adapter.js', () => ({
|
|
isReadOnlyDbError: vi.fn(() => false),
|
|
loadFTSExtension: loadFTSExtensionMock,
|
|
loadVectorExtension: loadVectorExtensionMock,
|
|
}));
|
|
|
|
vi.mock('../../src/core/lbug/lbug-config.js', () => ({
|
|
// A fresh fake Database per call so distinct dbPaths get distinct entries
|
|
// and closeOne's db.close() resolves per repo.
|
|
createLbugDatabase: vi.fn(() => ({
|
|
init: vi.fn().mockResolvedValue(undefined),
|
|
close: vi.fn().mockResolvedValue(undefined),
|
|
})),
|
|
toNativeSafePath: vi.fn((p: string) => p),
|
|
isWalCorruptionError: vi.fn(() => false),
|
|
WAL_RECOVERY_SUGGESTION: '',
|
|
isStorageVersionMismatchError: vi.fn(() => false),
|
|
throwIfStorageVersionMismatch: vi.fn(),
|
|
sleep: vi.fn(async () => {}),
|
|
STORAGE_VERSION_MISMATCH_SUGGESTION: '',
|
|
}));
|
|
|
|
vi.mock('../../src/core/lbug/sidecar-recovery.js', () => ({
|
|
preflightLbugSidecars: vi.fn().mockResolvedValue(undefined),
|
|
guardWalQuarantine: vi.fn().mockResolvedValue(undefined),
|
|
isMissingFsError: vi.fn(() => false),
|
|
isMissingShadowSidecarError: vi.fn(() => false),
|
|
isReadOnlyShadowReplayError: vi.fn(() => false),
|
|
quarantineWalForMissingShadow: vi.fn().mockResolvedValue(''),
|
|
// Not consumed by pool-adapter today; listed so this wholesale mock can't
|
|
// become a TypeError trap if the pool ever routes through dirty recovery
|
|
// (#2409, tri-review 4669518496 mock-hygiene sweep).
|
|
quarantineSidecarsForDirtyRecovery: vi
|
|
.fn()
|
|
.mockResolvedValue({ moved: [], removed: [], failed: [] }),
|
|
renameFailureMessage: vi.fn((p: string) => `rename failed for ${p}`),
|
|
statIfExists: vi.fn().mockResolvedValue(null),
|
|
assertReadOnlyFtsCrashSafe: vi.fn().mockResolvedValue(undefined),
|
|
FtsReaderUnrepairableError: class FtsReaderUnrepairableError extends Error {
|
|
readonly code = 'FTS_READER_UNREPAIRABLE' as const;
|
|
constructor(dbPath = '') {
|
|
super(dbPath);
|
|
this.name = 'FtsReaderUnrepairableError';
|
|
}
|
|
},
|
|
}));
|
|
|
|
const { initLbug, initLbugWithDb, closeLbug, isLbugReady, pinRepo, unpinRepo } =
|
|
await import('../../src/core/lbug/pool-adapter.js');
|
|
const { createLbugDatabase } = await import('../../src/core/lbug/lbug-config.js');
|
|
const { initWikiDb, closeWikiDb, pinWikiDb } = await import('../../src/core/wiki/graph-queries.js');
|
|
|
|
describe('pool-adapter repo pinning (issue #2189)', () => {
|
|
let tmpDir: string;
|
|
// Track every repoId touched so afterEach can fully reset module-global state.
|
|
const touched = new Set<string>();
|
|
|
|
const dbPathFor = (repoId: string): string => {
|
|
const p = path.join(tmpDir, `${repoId}.lbug`);
|
|
writeFileSync(p, ''); // real file so fs.stat() in doInitLbug succeeds
|
|
return p;
|
|
};
|
|
|
|
const init = async (repoId: string): Promise<void> => {
|
|
touched.add(repoId);
|
|
await initLbug(repoId, dbPathFor(repoId));
|
|
};
|
|
|
|
beforeEach(() => {
|
|
tmpDir = mkdtempSync(path.join(os.tmpdir(), 'gn-pin-test-'));
|
|
loadFTSExtensionMock.mockResolvedValue(true);
|
|
});
|
|
|
|
afterEach(async () => {
|
|
vi.useRealTimers();
|
|
await closeLbug().catch(() => {});
|
|
for (const id of touched) unpinRepo(id);
|
|
touched.clear();
|
|
loadFTSExtensionMock.mockReset();
|
|
rmSync(tmpDir, { recursive: true, force: true });
|
|
});
|
|
|
|
// MAX_POOL_SIZE is 5; the 6th init triggers evictLRU.
|
|
it('characterization: WITHOUT pinning, the earliest repo is LRU-evicted past the cap', async () => {
|
|
for (let i = 1; i <= 6; i++) await init(`repo-${i}`);
|
|
|
|
// repo-1 had the oldest lastUsed and nothing was checked out, so it is the
|
|
// eviction victim — exactly the stale-executor scenario from #2189.
|
|
expect(isLbugReady('repo-1')).toBe(false);
|
|
// The most recently initialized repo survives.
|
|
expect(isLbugReady('repo-6')).toBe(true);
|
|
});
|
|
|
|
it('FIX: pinning each repo keeps all of them resident past the cap', async () => {
|
|
for (let i = 1; i <= 6; i++) {
|
|
await init(`repo-${i}`);
|
|
pinRepo(`repo-${i}`);
|
|
}
|
|
|
|
for (let i = 1; i <= 6; i++) {
|
|
expect(isLbugReady(`repo-${i}`)).toBe(true);
|
|
}
|
|
});
|
|
|
|
it('explicit close beats the pin AND clears it (no cross-operation leak)', async () => {
|
|
pinRepo('repo-x');
|
|
await init('repo-x');
|
|
expect(isLbugReady('repo-x')).toBe(true);
|
|
|
|
// Explicit teardown closes a pinned repo without needing an unpin first.
|
|
await closeLbug('repo-x');
|
|
expect(isLbugReady('repo-x')).toBe(false);
|
|
|
|
// The pin must have been cleared on close: re-init repo-x FIRST (oldest
|
|
// lastUsed) and fill past the cap. If the pin had leaked, repo-x would be
|
|
// un-evictable; instead it is evicted as the LRU victim.
|
|
await init('repo-x');
|
|
for (let i = 1; i <= 5; i++) await init(`fresh-${i}`);
|
|
expect(isLbugReady('repo-x')).toBe(false);
|
|
});
|
|
|
|
it('idle-timeout sweep skips pinned repos but still evicts idle unpinned ones', async () => {
|
|
vi.useFakeTimers();
|
|
|
|
await init('pinned-idle');
|
|
pinRepo('pinned-idle');
|
|
await init('unpinned-idle');
|
|
|
|
expect(isLbugReady('pinned-idle')).toBe(true);
|
|
expect(isLbugReady('unpinned-idle')).toBe(true);
|
|
|
|
// The idle timer runs every 60s and closes entries idle past
|
|
// IDLE_TIMEOUT_MS (5 min) with no checked-out connections. advance past
|
|
// both thresholds, flushing microtasks between fires.
|
|
await vi.advanceTimersByTimeAsync(5 * 60 * 1000 + 60 * 1000);
|
|
|
|
expect(isLbugReady('pinned-idle')).toBe(true);
|
|
expect(isLbugReady('unpinned-idle')).toBe(false);
|
|
});
|
|
|
|
it('wiki DB pin wrapper keeps __wiki__ resident past idle cleanup', async () => {
|
|
vi.useFakeTimers();
|
|
|
|
const releaseWikiPin = pinWikiDb();
|
|
await initWikiDb(dbPathFor('wiki-wrapper'));
|
|
expect(isLbugReady('__wiki__')).toBe(true);
|
|
|
|
await vi.advanceTimersByTimeAsync(5 * 60 * 1000 + 60 * 1000);
|
|
expect(isLbugReady('__wiki__')).toBe(true);
|
|
|
|
releaseWikiPin();
|
|
await vi.advanceTimersByTimeAsync(5 * 60 * 1000 + 60 * 1000);
|
|
expect(isLbugReady('__wiki__')).toBe(false);
|
|
|
|
await closeWikiDb();
|
|
});
|
|
|
|
it('unpinRepo re-enables eviction for that repo', async () => {
|
|
// Pin five repos and fill the pool; a sixth init evicts nothing (all pinned).
|
|
for (let i = 1; i <= 5; i++) {
|
|
await init(`p-${i}`);
|
|
pinRepo(`p-${i}`);
|
|
}
|
|
await init('p-6'); // unpinned; pool now holds 6 (soft-cap exceeded)
|
|
for (let i = 1; i <= 6; i++) expect(isLbugReady(`p-${i}`)).toBe(true);
|
|
|
|
// Unpin the oldest, then init a 7th repo — the now-unpinned p-1 is the LRU
|
|
// victim.
|
|
unpinRepo('p-1');
|
|
await init('p-7');
|
|
expect(isLbugReady('p-1')).toBe(false);
|
|
expect(isLbugReady('p-7')).toBe(true);
|
|
});
|
|
|
|
it('reference-counts leases: two pins need two unpins before eviction (Finding 1)', async () => {
|
|
// Fill the pool to capacity, all leased.
|
|
for (let i = 1; i <= 4; i++) {
|
|
await init(`rc-${i}`);
|
|
pinRepo(`rc-${i}`);
|
|
}
|
|
await init('rc-shared');
|
|
pinRepo('rc-shared'); // lease 1
|
|
pinRepo('rc-shared'); // lease 2 (two holders)
|
|
|
|
// Release ONE lease — a holder remains, so rc-shared stays exempt even
|
|
// under eviction pressure.
|
|
unpinRepo('rc-shared');
|
|
await init('rc-extra'); // evictLRU finds no unpinned victim → pool grows
|
|
expect(isLbugReady('rc-shared')).toBe(true);
|
|
|
|
// Release the LAST lease — now rc-shared (oldest unpinned) is evictable.
|
|
unpinRepo('rc-shared');
|
|
await init('rc-extra2');
|
|
expect(isLbugReady('rc-shared')).toBe(false);
|
|
});
|
|
|
|
it('unpinRepo floors at zero and tolerates unknown repoIds', () => {
|
|
expect(() => {
|
|
unpinRepo('never-touched'); // unknown repoId → no-op
|
|
pinRepo('floor-x');
|
|
unpinRepo('floor-x'); // count 0 → key deleted
|
|
unpinRepo('floor-x'); // already gone → no-op, never a negative count
|
|
}).not.toThrow();
|
|
});
|
|
|
|
it('pinRepo returns a disposer that releases exactly once and composes with refcount', async () => {
|
|
for (let i = 1; i <= 4; i++) {
|
|
await init(`d-${i}`);
|
|
pinRepo(`d-${i}`);
|
|
}
|
|
await init('d-shared');
|
|
const release1 = pinRepo('d-shared'); // lease 1
|
|
const release2 = pinRepo('d-shared'); // lease 2
|
|
|
|
release1();
|
|
release1(); // double-call is a no-op — must NOT decrement lease 2
|
|
|
|
// lease 2 still held → d-shared survives eviction pressure.
|
|
await init('d-extra');
|
|
expect(isLbugReady('d-shared')).toBe(true);
|
|
|
|
// Release the last lease via its own disposer → now evictable.
|
|
release2();
|
|
await init('d-extra2');
|
|
expect(isLbugReady('d-shared')).toBe(false);
|
|
});
|
|
|
|
it('a pin acquired while closeOne awaits db.close() does not survive teardown', async () => {
|
|
vi.mocked(createLbugDatabase).mockImplementationOnce(() => ({
|
|
init: vi.fn().mockResolvedValue(undefined),
|
|
close: vi.fn().mockImplementation(async () => {
|
|
await new Promise((resolve) => setTimeout(resolve, 20));
|
|
}),
|
|
}));
|
|
|
|
await init('late-pin');
|
|
const closing = closeLbug('late-pin');
|
|
await Promise.resolve();
|
|
pinRepo('late-pin');
|
|
await closing;
|
|
expect(isLbugReady('late-pin')).toBe(false);
|
|
|
|
await init('late-pin');
|
|
for (let i = 1; i <= 5; i++) await init(`late-fresh-${i}`);
|
|
expect(isLbugReady('late-pin')).toBe(false);
|
|
});
|
|
|
|
it('initLbugWithDb waits for an in-flight closeOne before registering', async () => {
|
|
vi.mocked(createLbugDatabase).mockImplementationOnce(() => ({
|
|
init: vi.fn().mockResolvedValue(undefined),
|
|
close: vi.fn().mockImplementation(async () => {
|
|
await new Promise((resolve) => setTimeout(resolve, 20));
|
|
}),
|
|
}));
|
|
|
|
await init('injected-overlap');
|
|
const closing = closeLbug('injected-overlap');
|
|
await Promise.resolve();
|
|
const injected = {
|
|
init: vi.fn().mockResolvedValue(undefined),
|
|
close: vi.fn().mockResolvedValue(undefined),
|
|
};
|
|
const injecting = initLbugWithDb(
|
|
'injected-overlap',
|
|
injected as never,
|
|
dbPathFor('injected-overlap'),
|
|
);
|
|
await closing;
|
|
await injecting;
|
|
expect(isLbugReady('injected-overlap')).toBe(true);
|
|
});
|
|
});
|