GitNexus/gitnexus/test/unit/pdg-mode-flip.test.ts
Gergő Magyar 0261982d9a
Some checks are pending
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Publish / Classify release event (push) Waiting to run
Publish / RC guard (marker + release-PR skip) (push) Blocked by required conditions
Publish / ci (push) Blocked by required conditions
Publish / Publish to npm (push) Blocked by required conditions
Publish / Build & Push RC Docker images (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
fix(analyze): make --memory-budget set the real heap and report rebuild reasons once (#3386)
* feat(analyze): --memory-budget flag with heap-limit override and worker-pool degradation (#3137)

Adds an explicit `--memory-budget <mb>` CLI flag that overrides the
RAM/cgroup auto-sized main-thread heap ceiling for the parse phase:

- CLI validation (integer >= 200 MB) before bar.start(), matching the
  --workers pattern
- Threaded CLI → runFullAnalysis → PipelineOptions → parse-impl as
  memoryBudgetBytes
- parse-impl resolves the heap limit as budget ?? v8.heap_size_limit, so
  both the preflight projection warning and the #2649 mid-loop abort
  probe honor the budget
- Graceful degradation: when the projected heap need exceeds the budget
  at the computed pool size, the pool shrinks (never below 1, never
  above the operator's --workers) before sub-batch math and pool
  construction, so all downstream consumers see the degraded size

Omitting the flag keeps the auto-sizer path byte-identical.

Refs #3137

* feat(analyze): collapse rebuild-gate log into one summary + persist needsFullRebuild verdict (#3137)

The nine meta-mismatch rebuild gates (pdg mode, content retention,
schema fingerprint, graph-write collapse, analysis features, Spring
vendor prefixes, runner identity, FTS CJK mode, embedding dims) each
logged individually and set force:true independently. An upgrade that
trips several at once printed a scattered wall of near-identical
warnings.

- Gates now collect into rebuildReasons[]; a single summary block
  prints them (inline for one, numbered for many) and sets force once.
  Per-gate Tip text is preserved verbatim inside the entries.
- The verdict persists to meta (needsFullRebuild: {reasons, recordedAt})
  BEFORE the rebuild starts. If the rebuild is interrupted, the next
  run announces the recorded reasons up front instead of quietly
  attempting an incremental write on a half-rebuilt index — the gates
  may not all re-fire against a wiped DB.
- The verdict is cleared on the next successful completion (the final
  meta does not carry the field forward).

Semantics unchanged: every gate was already evaluated (none
early-returns), force is idempotent, and a rebuild happens iff at
least one reason fired.

Refs #3137

* refactor(cli): share one integer flag parser across analyze, watch, and wiki

Replace the duplicated Number.isInteger checks for --workers, --embeddings,
the positive env-backed analyze flags, the watch interval flags, and wiki's
--timeout/--retries with parseIntegerOption (per-flag minimum, optional
scale for the safe-integer bound). User-facing messages are unchanged.

* fix(analyze): make --memory-budget set the real V8 heap through the respawn

The budget now drives ensureHeap's existing respawn instead of a parse-phase
override, so the #2649 preflight, mid-loop abort, remedy text, and GC pacing
all see one heap limit. The respawn sizes old space plus three semi-spaces to
equal the budget, the child resolves as already at the budget (no second
respawn), and GITNEXUS_HEAP_LIMIT_SOURCE drives budget-aware OOM advice.
Budget validation moves to the preAction hook so analyze and watch reject a
bad value before any respawn. Removes the pool-shrink block and the
memoryBudgetBytes plumbing through PipelineOptions and run-analyze.

* docs(analyze): describe --memory-budget accurately and translate its help

The help text claimed graceful worker-pool degradation, which no longer
exists; it now says the flag sets the main-thread V8 heap and that parse
workers keep their own caps. Wires the option through the help i18n map
with en and zh-CN strings, and documents it in both READMEs and the
out-of-memory troubleshooting section.

* feat(analyze): add a pure rebuild-reason collector

One collector per run holds keyed rebuild reasons, merges by key, flattens
reasons stored by an interrupted rebuild into one recovery entry, validates
stored reasons on read, and formats the single up-front summary plus one
follow-up line for reasons added after the pipeline.

* fix(analyze): route every forced rebuild through one reason collector

Every path that forces a full rebuild (the nine meta gates, --force,
--skills, --no-parse-cache, --drop-embeddings, --repair-fts retention,
Spring Actuator, AsyncAPI, shared-store graph gaps, dirty-flag recovery,
the post-pipeline capability gate, and the #2409 escalation) now adds a
keyed reason to one collector. The rebuild decision is applied from the
collector at fixed checkpoints, one summary prints right before the
pipeline, and late reasons print one follow-up line. The escalation stays
non-forcing. runFullAnalysis returns the collected keys, which replaces the
runner-identity source-regex test with a behavior test. Removes the separate
needsFullRebuild field and its announcement, and stops folding --skills and
--no-parse-cache into --force.

* fix(analyze): persist rebuild reasons on the existing crash marker

Every incrementalInProgress writer (the full-rebuild stamp before the wipe,
the incremental pre-write, saveIncrementalDirtyState including the #2409
escalation, and buildFtsDirtyStamp) now carries the collected reasons into
the active slot's metaDir, so an interrupted rebuild explains itself on the
next run through one merged recovery entry. A successful run still clears
the marker and its reasons; the FTS-park recovery clears them without
forcing.

* test(analyze): cover every rebuild-reason key through runFullAnalysis

Add a coverage table that the typechecker keeps complete: every
RebuildReasonKey maps to a test file that drives it through
runFullAnalysis and asserts the returned key. Adds the missing
graph-write-collapse and drop-embeddings drivers, asserts the key in the
existing pdg-mode, spring-vendor-prefixes, cjk-segmentation, and
embedding-dims tests, and removes plan-local IDs from test names and
comments.

* fix(review): apply review findings

- A --max-old-space-size pin equal to --memory-budget no longer counts as
  the exact budget heap (V8 adds the young generation on top); only the
  budget-respawned child skips the respawn, so the limit really equals the
  budget.
- Snapshot the analyze env before ensureHeap and restore
  GITNEXUS_HEAP_LIMIT_SOURCE, so a kept process does not leak its heap
  source into a later programmatic analyzeCommand call.
- --skills and --no-parse-cache keep the forced storage requirements they
  had before force stopped being folded from them.
- Merge the duplicated follow-up announcement into one helper and fix a
  stale --drop-embeddings comment.
- The rebuild-reason coverage table no longer greps driver files for the
  key string; add tests for a programmatic invalid budget and the
  multi-cause interrupted-rebuild text.

* fix(review): don't announce the escalated write as a full rebuild

The #2409 escalation is a non-forcing reason, but its follow-up line used
the 'Full rebuild also required' lead. A follow-up that carries only
non-forcing reasons now leads with 'Write plan changed'.

* docs(analyze): document GITNEXUS_HEAP_LIMIT_SOURCE in the env table

CONTRIBUTING requires every new GITNEXUS_* variable to have a row; this one
is internal (set by analyze itself) and exists so OOM advice points at
--memory-budget.

* fix(review): address GitNexus review threads on #3386

- heapPressureRemedy measures pressure against the real auto-sized cap
  (heapCapMbFor) instead of a flat 0.75 x RAM, and no longer tells a
  GITNEXUS_MEMORY=off run with no pin to drop a pin that does not exist.
- toStored() persists the interrupted rebuild's reasons first, as documented.
- ensureHeap's doc names which paths leave GITNEXUS_HEAP_LIMIT_SOURCE unset.
- The heap-respawn suite restores the caller's GITNEXUS_MEMORY.
- The non-forcing follow-up test rejects any 'full rebuild' wording.

* fix(review): require both budget flags and check key coverage at runtime

- A budget-respawned child is recognized only when the inherited heap-source
  marker comes with both the budget's old-space and semi-space flags; the
  marker alone is an inherited env var, not proof. The old-space parser is
  generalized to any V8 size flag instead of copying its regex.
- REBUILD_REASON_KEYS is exported and RebuildReasonKey derives from it, so the
  coverage table is checked at runtime (CI does not type-check test files).

* fix(review): don't claim a full rebuild in a non-forcing summary

formatSummary and formatFollowUp now share one leadFor helper, so a block
of only non-forcing reasons reads 'Write plan changed' in both.

---------

Co-authored-by: ChunxueLi <mecoloud@users.noreply.gitee.com>
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
2026-09-26 18:14:36 +01:00

427 lines
20 KiB
TypeScript
Raw Permalink Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

/**
* Integration coverage for the pdg-mode flip → forced-full-writeback wiring
* (#2099 F1). Sibling of incremental-orchestration.test.ts: real on-disk git
* repo, real LadybugDB, real `runFullAnalysis`.
*
* The P1 these tests pin: the incremental DB writeback persists only
* changed-file nodes, so before the fix a `--pdg` run against an
* already-indexed repo silently persisted ZERO BasicBlock rows
* (`Incremental: changed=0`), and a plain run after a `--pdg` index left
* zombie blocks. The primary assertion is a direct count over the BasicBlock
* table — `meta.stats.nodes` aggregates Community/Process rows that are
* re-derived nondeterministically every run, so it is only used as a
* secondary signal here, never with exact equality.
*/
import { describe, it, expect } from 'vitest';
import { getStoragePaths, loadMeta, saveMeta } from '../../src/storage/repo-manager.js';
import { taintModelVersion } from '../../src/core/ingestion/taint/typescript-model.js';
import { setupMiniRepo as setupSharedMiniRepo } from '../helpers/mini-repo.js';
const setupMiniRepo = () => setupSharedMiniRepo('gitnexus-pdg-flip-');
/** Direct count over the BasicBlock table — the primary truth signal. */
async function countBasicBlocks(repoPath: string): Promise<number> {
const adapter = await import('../../src/core/lbug/lbug-adapter.js');
const { lbugPath } = getStoragePaths(repoPath);
await adapter.initLbug(lbugPath);
try {
const rows = (await adapter.executeQuery(
'MATCH (n:BasicBlock) RETURN count(n) AS c',
)) as Array<{ c: number | bigint }>;
return Number(rows[0]?.c ?? 0);
} finally {
await adapter.closeLbug();
}
}
describe('pdgModeMismatch — M1→M2 stamp upgrade (#2082 M2, pure)', () => {
it('an M1-era stamp (no REACHING_DEF cap) mismatches an M2 request — upgrade forces full writeback', async () => {
const { pdgModeMismatch } = await import('../../src/core/run-analyze.js');
const m1Stamp = { maxFunctionLines: 2000, maxEdgesPerFunction: 5000 };
// default M2 request resolves maxReachingDefEdgesPerFunction=4000 ≠ undefined
expect(pdgModeMismatch(m1Stamp, { pdg: true })).toBe(true);
});
it('an identical resolved M2 config compares equal (steady state keeps incremental)', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true })).toBe(false);
});
it('a REACHING_DEF cap change alone trips the mismatch', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxReachingDefEdgesPerFunction: 100 })).toBe(
true,
);
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxReachingDefEdgesPerFunction: 4000 })).toBe(
false, // explicit default ≡ default (resolution before comparison)
);
});
});
describe('pdgModeMismatch — M2→M3 stamp upgrade (#2083 M3 U5, pure)', () => {
it('an M2-era stamp (no taint keys) mismatches an M3 request — upgrade forces full writeback', async () => {
const { pdgModeMismatch } = await import('../../src/core/run-analyze.js');
// Exactly what an M2 run wrote: the three pre-taint resolved caps, no
// maxTaintFindingsPerFunction / maxTaintHops / taintModelVersion. The
// key-union comparator sees e.g. 200 !== undefined and trips the full
// writeback that populates TAINTED/SANITIZES rows without --force (R7).
const m2Stamp = {
maxFunctionLines: 2000,
maxEdgesPerFunction: 5000,
maxReachingDefEdgesPerFunction: 4000,
};
expect(pdgModeMismatch(m2Stamp, { pdg: true })).toBe(true);
});
it('an identical resolved M3 config compares equal (steady state keeps incremental)', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true })).toBe(false);
});
it('a taint cap change alone trips the mismatch', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxTaintFindingsPerFunction: 10 })).toBe(true);
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxTaintHops: 4 })).toBe(true);
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxTaintFindingsPerFunction: 200 })).toBe(
false, // explicit default ≡ default (resolution before comparison)
);
});
it('a model-version change ALONE trips the mismatch (the R7 repopulation guarantee)', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
// A stamp written by a hypothetical older binary whose built-in model
// differed — every cap identical, only the digest moved. Persisted
// findings must never outlive the model that produced them.
const stamp = resolvePdgConfig({ pdg: true });
const oldModelStamp = { ...stamp, taintModelVersion: '000000000000' };
expect(stamp?.taintModelVersion).not.toBe('000000000000'); // guard the premise
expect(pdgModeMismatch(oldModelStamp, { pdg: true })).toBe(true);
});
});
describe('pdgModeMismatch — M3→M4 interproc-cap stamp upgrade (#2084 review P1-3, pure)', () => {
it('resolvePdgConfig stamps the three resolved interproc caps', async () => {
const { resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(stamp?.maxInterprocFindings).toBe(2000);
expect(stamp?.maxInterprocHops).toBe(32);
expect(stamp?.maxInterprocEdges).toBe(1000);
});
it('an M3-era stamp (no interproc keys) mismatches a post-fix request — upgrade forces full writeback', async () => {
const { pdgModeMismatch } = await import('../../src/core/run-analyze.js');
// What an M3 run wrote: every taint cap + model digest, but none of the
// interproc caps. The key-union comparator sees 2000 !== undefined and
// trips the full writeback that re-materialises TAINT_PATH within bounds.
const m3Stamp = {
maxFunctionLines: 2000,
maxEdgesPerFunction: 5000,
maxReachingDefEdgesPerFunction: 4000,
maxTaintFindingsPerFunction: 200,
maxTaintHops: 32,
taintModelVersion: 'deadbeefcafe',
};
expect(pdgModeMismatch(m3Stamp, { pdg: true })).toBe(true);
});
it('an interproc cap change alone trips the mismatch', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxInterprocFindings: 10 })).toBe(true);
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxInterprocEdges: 50 })).toBe(true);
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxInterprocHops: 8 })).toBe(true);
// explicit default ≡ default (resolution before comparison)
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxInterprocFindings: 2000 })).toBe(false);
});
});
describe('pdgModeMismatch — pre-M5→M5 CDG-cap stamp upgrade (#2085 M5, pure)', () => {
it('resolvePdgConfig stamps the resolved CDG cap', async () => {
const { resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(stamp?.maxCdgEdgesPerFunction).toBe(5000);
});
it('a pre-M5 stamp (no CDG key) mismatches a CDG-aware request — upgrade forces full writeback', async () => {
const { pdgModeMismatch } = await import('../../src/core/run-analyze.js');
// What an M4-era run wrote: every cap through the interproc set + model
// digest, but NO maxCdgEdgesPerFunction. The key-union comparator sees
// 5000 !== undefined and trips the full writeback that materialises CDG
// edges for every file without --force.
const m4Stamp = {
maxFunctionLines: 2000,
maxEdgesPerFunction: 5000,
maxReachingDefEdgesPerFunction: 4000,
maxTaintFindingsPerFunction: 200,
maxTaintHops: 32,
maxInterprocFindings: 2000,
maxInterprocHops: 32,
maxInterprocEdges: 1000,
taintModelVersion,
};
expect(pdgModeMismatch(m4Stamp, { pdg: true })).toBe(true);
});
it('a CDG cap change alone trips the mismatch', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxCdgEdgesPerFunction: 10 })).toBe(true);
// explicit default ≡ default (resolution before comparison)
expect(pdgModeMismatch(stamp, { pdg: true, pdgMaxCdgEdgesPerFunction: 5000 })).toBe(false);
});
});
describe('pdgModeMismatch — pre-#2201→SSA reaching-defs solver upgrade (#2201 review R3, pure)', () => {
it('resolvePdgConfig stamps the reaching-defs solver identity', async () => {
const { resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(stamp?.reachingDefSolver).toBe('ssa-sparse-v1');
});
it('a pre-#2201 stamp (no solver key) mismatches the SSA request — upgrade recomputes truncated deep-loop facts', async () => {
const { pdgModeMismatch } = await import('../../src/core/run-analyze.js');
// What a pre-#2201 (M5-era) run wrote: every cap + model digest, but NO
// reachingDefSolver. The key-union comparator sees 'ssa-sparse-v1' !==
// undefined and trips the full writeback that recomputes the now-fuller
// REACHING_DEF coverage — the deep-loop functions the dense worklist
// truncated to empty at the blocks×64 ceiling now compute full facts.
const m5Stamp = {
maxFunctionLines: 2000,
maxEdgesPerFunction: 5000,
maxReachingDefEdgesPerFunction: 4000,
maxCdgEdgesPerFunction: 5000,
maxTaintFindingsPerFunction: 200,
maxTaintHops: 32,
maxInterprocFindings: 2000,
maxInterprocHops: 32,
maxInterprocEdges: 1000,
taintModelVersion,
};
expect(pdgModeMismatch(m5Stamp, { pdg: true })).toBe(true);
});
it('an identical post-#2201 stamp compares equal (no spurious re-analysis churn)', async () => {
const { pdgModeMismatch, resolvePdgConfig } = await import('../../src/core/run-analyze.js');
const stamp = resolvePdgConfig({ pdg: true });
expect(pdgModeMismatch(stamp, { pdg: true })).toBe(false);
});
});
describe('detect_changes BasicBlock exclusion (#2082 U7)', () => {
it('the symbol-overlap id-prefix filter excludes exactly the BasicBlock rows', async () => {
const repo = await setupMiniRepo();
try {
const { runFullAnalysis } = await import('../../src/core/run-analyze.js');
const cb = { onProgress: () => {}, onLog: () => {} };
await runFullAnalysis(repo.dbPath, { skipAgentsMd: true, pdg: true }, cb);
const adapter = await import('../../src/core/lbug/lbug-adapter.js');
const { lbugPath } = getStoragePaths(repo.dbPath);
await adapter.initLbug(lbugPath);
try {
// Counterfactual: WITHOUT the U7 filter, line-bearing BasicBlock rows
// exist on a pdg index (the noise detect_changes used to report).
const blocks = (await adapter.executeQuery(
`MATCH (n) WHERE n.id STARTS WITH 'BasicBlock:'
AND n.startLine IS NOT NULL AND n.endLine IS NOT NULL
RETURN n.id AS id`,
)) as Array<{ id: string }>;
expect(blocks.length).toBeGreaterThan(0);
// With the U7 filter (the exact predicate detectChanges now runs —
// also validates STARTS WITH against the real engine): no BasicBlocks,
// real symbols intact.
const symbols = (await adapter.executeQuery(
`MATCH (n) WHERE NOT n.id STARTS WITH 'BasicBlock:'
AND n.startLine IS NOT NULL AND n.endLine IS NOT NULL
RETURN n.id AS id`,
)) as Array<{ id: string }>;
expect(symbols.length).toBeGreaterThan(0);
for (const row of symbols) {
expect(String(row.id)).not.toMatch(/^BasicBlock:/);
}
// DB-level smoke for the M2 projection itself: REACHING_DEF rows
// persisted with the variable name in `reason` (plan Validation).
const rd = (await adapter.executeQuery(
`MATCH (:BasicBlock)-[r:CodeRelation {type: 'REACHING_DEF'}]->(:BasicBlock)
RETURN count(r) AS c`,
)) as Array<{ c: number | bigint }>;
expect(Number(rd[0]?.c ?? 0)).toBeGreaterThan(0);
} finally {
await adapter.closeLbug();
}
} finally {
await repo.cleanup();
}
}, 600_000);
});
describe('runFullAnalysis — pdg-mode flip (#2099 F1)', () => {
it('resolves preserveExistingPdg from metadata after entering the locked analysis path', async () => {
const repo = await setupMiniRepo();
try {
const { runFullAnalysis } = await import('../../src/core/run-analyze.js');
const { storagePath } = getStoragePaths(repo.dbPath);
const cb = { onProgress: () => {}, onLog: () => {} };
await runFullAnalysis(repo.dbPath, { skipAgentsMd: true, pdg: true }, cb);
const blocks = await countBasicBlocks(repo.dbPath);
expect(blocks).toBeGreaterThan(0);
const preserved = await runFullAnalysis(
repo.dbPath,
{ skipAgentsMd: true, preserveExistingPdg: true },
cb,
);
expect(preserved.alreadyUpToDate).toBe(true);
expect((await loadMeta(storagePath))!.pdg).toBeDefined();
expect(await countBasicBlocks(repo.dbPath)).toBe(blocks);
} finally {
await repo.cleanup();
}
}, 600_000);
it('off→on flip forces a full writeback that persists the CFG layer; on→off removes it', async () => {
const repo = await setupMiniRepo();
try {
const { runFullAnalysis } = await import('../../src/core/run-analyze.js');
const { storagePath } = getStoragePaths(repo.dbPath);
const logs: string[] = [];
const cb = { onProgress: () => {}, onLog: (m: string) => logs.push(m) };
// 1. Plain index — no CFG layer, no stamp.
await runFullAnalysis(repo.dbPath, { skipAgentsMd: true }, cb);
expect(await countBasicBlocks(repo.dbPath)).toBe(0);
expect((await loadMeta(storagePath))!.pdg).toBeUndefined();
// 2. The P1 trigger: --pdg with NO file changes. Pre-fix this hit the
// alreadyUpToDate fast path (or the incremental path with changed=0)
// and persisted nothing. The flip check must force a full rebuild.
logs.length = 0;
const flipOn = await runFullAnalysis(repo.dbPath, { skipAgentsMd: true, pdg: true }, cb);
expect(flipOn.alreadyUpToDate).toBeUndefined();
expect(flipOn.rebuildReasons).toContain('pdg-mode');
expect(logs.some((m) => m.includes('pdg mode changed'))).toBe(true);
expect(await countBasicBlocks(repo.dbPath)).toBeGreaterThan(0);
const stamped = await loadMeta(storagePath);
expect(stamped!.pdg).toEqual({
maxFunctionLines: 2000,
maxEdgesPerFunction: 5000,
maxReachingDefEdgesPerFunction: 4000,
maxCdgEdgesPerFunction: 5000,
maxTaintFindingsPerFunction: 200,
maxTaintHops: 32,
maxInterprocFindings: 2000,
maxInterprocHops: 32,
maxInterprocEdges: 1000,
taintModelVersion,
reachingDefSolver: 'ssa-sparse-v1',
hasCallSummary: true,
});
expect(stamped!.incrementalInProgress).toBeUndefined(); // cleared on success
// 3. Steady state: a second identical --pdg run takes the fast path —
// the flip check must compare equal (KTD5 default resolution).
logs.length = 0;
const steady = await runFullAnalysis(repo.dbPath, { skipAgentsMd: true, pdg: true }, cb);
expect(steady.alreadyUpToDate).toBe(true);
expect(logs.some((m) => m.includes('pdg mode changed'))).toBe(false);
// 4. Flip back: a plain run must fully remove the CFG layer (no
// zombie BasicBlocks) and clear the stamp.
logs.length = 0;
const flipOff = await runFullAnalysis(repo.dbPath, { skipAgentsMd: true }, cb);
expect(flipOff.alreadyUpToDate).toBeUndefined();
expect(flipOff.rebuildReasons).toContain('pdg-mode');
expect(logs.some((m) => m.includes('pdg mode changed'))).toBe(true);
expect(await countBasicBlocks(repo.dbPath)).toBe(0);
expect((await loadMeta(storagePath))!.pdg).toBeUndefined();
} finally {
await repo.cleanup();
}
}, 600_000);
it('a cap change while pdg stays on forces a rebuild; matching modes keep incremental eligibility', async () => {
const repo = await setupMiniRepo();
try {
const { runFullAnalysis } = await import('../../src/core/run-analyze.js');
const { storagePath } = getStoragePaths(repo.dbPath);
const logs: string[] = [];
const cb = { onProgress: () => {}, onLog: (m: string) => logs.push(m) };
await runFullAnalysis(repo.dbPath, { skipAgentsMd: true, pdg: true }, cb);
const blocks = await countBasicBlocks(repo.dbPath);
expect(blocks).toBeGreaterThan(0);
// Cap change with no file changes → mismatch → full rebuild (the
// emit-time cap shapes the persisted edge set; meta must re-stamp).
logs.length = 0;
const capChange = await runFullAnalysis(
repo.dbPath,
{ skipAgentsMd: true, pdg: true, pdgMaxEdgesPerFunction: 1 },
cb,
);
expect(capChange.alreadyUpToDate).toBeUndefined();
expect(capChange.rebuildReasons).toContain('pdg-mode');
expect(logs.some((m) => m.includes('different caps'))).toBe(true);
expect((await loadMeta(storagePath))!.pdg).toEqual({
maxFunctionLines: 2000,
maxEdgesPerFunction: 1,
maxReachingDefEdgesPerFunction: 4000,
maxCdgEdgesPerFunction: 5000,
maxTaintFindingsPerFunction: 200,
maxTaintHops: 32,
maxInterprocFindings: 2000,
maxInterprocHops: 32,
maxInterprocEdges: 1000,
taintModelVersion,
reachingDefSolver: 'ssa-sparse-v1',
hasCallSummary: true,
});
// The CFG layer survives a rebuild under a tighter edge cap (blocks are
// never capped, only edges).
expect(await countBasicBlocks(repo.dbPath)).toBe(blocks);
} finally {
await repo.cleanup();
}
}, 600_000);
it('a dirty flag from a crashed full rebuild composes with the flip check: one rebuild, flag cleared', async () => {
const repo = await setupMiniRepo();
try {
const { runFullAnalysis } = await import('../../src/core/run-analyze.js');
const { storagePath } = getStoragePaths(repo.dbPath);
const logs: string[] = [];
const cb = { onProgress: () => {}, onLog: (m: string) => logs.push(m) };
await runFullAnalysis(repo.dbPath, { skipAgentsMd: true, pdg: true }, cb);
// Simulate a full rebuild that died between the pre-wipe dirty-flag
// write (KTD2b: toWriteCount 0 sentinel) and the end-of-run saveMeta.
const meta = (await loadMeta(storagePath))!;
await saveMeta(storagePath, {
...meta,
incrementalInProgress: { startedAt: Date.now(), toWriteCount: 0 },
});
// Next plain run: crash recovery fires (force), the flip ALSO logs its
// notice (decoupled from the force gate), and exactly one rebuild runs.
logs.length = 0;
const recovered = await runFullAnalysis(repo.dbPath, { skipAgentsMd: true }, cb);
expect(recovered.alreadyUpToDate).toBeUndefined();
expect(logs.some((m) => m.includes('did not complete cleanly'))).toBe(true);
expect(logs.some((m) => m.includes('pdg mode changed'))).toBe(true);
const after = await loadMeta(storagePath);
expect(after!.incrementalInProgress).toBeUndefined();
expect(after!.pdg).toBeUndefined();
expect(await countBasicBlocks(repo.dbPath)).toBe(0);
} finally {
await repo.cleanup();
}
}, 600_000);
});