mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-03 02:21:44 +00:00
Some checks failed
CodeQL / Analyze (javascript-typescript) (push) Waiting to run
CodeQL / Analyze (python) (push) Waiting to run
Gitleaks / gitleaks (push) Waiting to run
Publish / Classify release event (push) Waiting to run
Publish / RC guard (marker + release-PR skip) (push) Blocked by required conditions
Publish / ci (push) Blocked by required conditions
Publish / Publish to npm (push) Blocked by required conditions
Publish / Build & Push RC Docker images (push) Blocked by required conditions
Scorecard / Scorecard analysis (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-cli) (push) Waiting to run
Trivy Image Scan / Trivy (gitnexus-web) (push) Waiting to run
Skill copy sync / shipped skills drift guard (push) Has been cancelled
* feat(cli): add a bunx lane to the runner ladder
The ladder assumed a Node toolchain: global gitnexus, then pnpm dlx or
npx in some order, with npx as the last resort. On a bun-only machine
npm, npx and pnpm are all absent, so every rung fell through to npx and
both the emitted hint and the generated .gitnexus/run.cjs produced a
command the machine could not run at all.
Add bun as a fourth mode, invoked as an install-free bunx one-shot, on
two rungs:
- npm 11+ with no pnpm to fall back on — bunx dodges the same arborist
install crash the pnpm rung exists for (#1939);
- npm and pnpm both absent — previously the dead end described above.
Every pre-existing outcome is preserved: pnpm still wins on npm 11+, npx
still wins on npm < 11, and pnpm still wins over bunx when npm is absent.
Regression tests pin each of those. The bun PATH probe is lazy, so a
machine with a Node toolchain pays no extra scan and the stale-index hook
budget is unchanged.
bunx takes no allow-build equivalent: bun's --trust is a bun add/install
flag that writes trustedDependencies into a project package.json, which a
one-shot has none of, so the argv stays flag-free.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016R9psS9gJ73MRyquoBoPKg
* fix(lbug): restore the prebuilt native binary when install scripts were skipped
Without this the new bunx lane resolves to a command that still fails:
bun skips lifecycle scripts for a bunx fetch, so @ladybugdb/core's
install script never copies lbugjs.node up from its per-platform
sub-package and every native command dead-ends on 'LadybugDB native
binary (lbugjs.node) is missing'.
The existing guidance cannot rescue that case. It offers pnpm
--allow-build, a global install, or adding trustedDependencies to a
project package.json — bunx has no project package.json to add to, no
per-invocation opt-in, and re-extracts the package on every run, so an
out-of-band repair is wiped before the next invocation. In-process
recovery is the only thing that can work.
Recovery is cheap because nothing is actually absent: the binary is
already on disk in @ladybugdb/core-<platform>-<arch>, and the skipped
script only copied it up. Redo that copy (prebuilt only — never a source
build, never a network fetch) before reporting failure. Best-effort by
construction: read-only node_modules, an absent sub-package or an
unsupported platform all fall through to the existing diagnostics
unchanged, which a test pins.
Also covers pnpm dlx without --allow-build and npm --ignore-scripts.
Declare trustedDependencies so a plain `bun install` in this repo
produces a working native binary too — the remedy the error message
already prescribes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016R9psS9gJ73MRyquoBoPKg
* fix(ai-context): name every install-free runner in the generated bootstrap note
The emitted gitnexus:start block told a reader with no runner yet to run
`npx gitnexus analyze`, falling back to a global npm install. Both name
binaries a bun-only machine does not have, so the generated AGENTS.md and
CLAUDE.md offered it no reachable bootstrap path.
List npx, bunx and pnpm dlx instead of resolving one. The block is
committed, so emitting the command this machine happens to resolve would
make two contributors on different package managers rewrite it at each
other on every analyze — the per-machine churn #1706 removed. Naming all
three keeps the note machine-independent and correct everywhere.
Regenerates this repo's own committed block to match.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_016R9psS9gJ73MRyquoBoPKg
* fix(cli): address PR #2765 review — bunx liveness, restore diagnostics, docs
Addresses all five review comments on #2765.
P1 — `hasBun()` was a PATH-existence check only, so a present-but-broken
`bunx` shim (partial uninstall, failed `bun upgrade`) was selected with no
functional validation. Because selecting `bun` also suppresses the npm-11
npx-crash warning, the result was a silent dead end: no diagnostic, and a
`bunx gitnexus@latest analyze` command that only fails at execution time.
Add `probeRuns()` — a real `bunx --version` liveness probe, gated behind the
cheap spawn-free PATH scan so machines with npm/pnpm still pay nothing. It
ignores the output on purpose (a banner or unparseable version still counts
as alive); only a spawn failure, non-zero exit, or timeout rejects. Injectable
via a new `bunRuns` dep so the mode tests stay host-independent.
P2 — the `gitnexus-cli` skill (and both shipped mirrors) still described the
pre-bunx ladder, stranding exactly this PR's audience: a bun-only machine
whose agent bootstraps from that file was told to use npx/npm/pnpm, none of
which exist there. All three copies now name `bunx` in the ladder and the
bootstrap fallback, with a `shipped-skills-sync` fragment assertion so the
gap is CI-caught (these copies are not byte-compared, only the engineering
family is).
P2 — `restorePrebuiltNativeBinary` collapsed every failure into `false`, so an
EACCES/EROFS from `copyFileSync` was indistinguishable from "no prebuilt
sub-package exists". Users on a read-only `node_modules` layer (a baked
container image mounted read-only — a common CI pattern) got the generic
lifecycle-script advice, which cannot fix a non-writable filesystem. Return a
`RestoreOutcome` instead and route `copy-failed` to its own message.
P2 — document that `trustedDependencies` only takes effect for `bun install` /
`pnpm install` run inside this repo: it does nothing for a `bunx` one-shot or
for a consumer's `bun add gitnexus`. The note sits on
`restorePrebuiltNativeBinary` so a future maintainer cannot mistake that
function for redundant and delete the thing the bunx path actually relies on.
P3 — the `binary_missing` bun advice told `bunx` one-shot users to edit a
package.json they do not have, and listed 1 of the 3 packages this package
now trusts. Both repair messages now share one `BUN_REPAIR_LINES` const with
the full package list and a `bun install -g gitnexus` alternative.
Also: shortened the bootstrap note and raised the CLAUDE.md block budget
2900 -> 2950. The note has to name every install-free runner (that is the
point of the bun lane), and main's own growth since this PR's last green CI
had already pushed the generated block over the old ceiling.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015epfxkEMsmHFNVSFQqAkB4
* refactor(cli): simplify the #2765 review fixes
Cleanup pass over the previous commit — no intended behavior change except
the doctor status line noted below.
Reuse: `probeRuns()` duplicated `probeVersion()`'s entire spawn setup — same
argv, timeout, `windowsHide`, and the CVE-2024-27980 Windows-shim workaround —
in a file with two byte-identical committed copies, so the shim rule lived at
four sites. Its docstring's own objection was to the RETURN SHAPE, not to
reuse, so `probeVersion` now returns `{ ran, major, minor }` and `hasBun` reads
`.ran`. Existing callers only read `major`/`minor`, so nothing else changes.
Also dropped a pointless `const runs = () => …` thunk (`&&` already
short-circuits), and deleted a new test that was a character-for-character
duplicate of `falls back to npx when npm is null-absent and pnpm is also
absent` — its cheapest-first-gate rationale moved into that test's comment.
Correctness in the budget comment: the claim that the bun rung is free because
"pnpm is absent there, so its probe never ran" was wrong. `formatAnalyzeCommand`
spawns `pnpm --version` unconditionally when no global `gitnexus` is on PATH —
that spawn IS how pnpm presence is discovered. Real worst case is 5 subprocesses
/ ~8s, and the 8s needs Windows (`shell: true` spawns cmd.exe for an absent
pnpm); on POSIX an absent pnpm ENOENTs in ~1ms. Comment now says that. Likewise
"a machine with npm or pnpm never pays" was wrong for npm 11+ without pnpm —
that IS the rung that pays.
Altitude: `copy-failed` changed only the message text while still returning
`kind: 'binary_missing'`, so `doctor` would have printed "✗ lbugjs.node missing"
directly above a message saying the binary IS present — exactly the
contradiction #2672 removed. Added a `binary_unwritable` kind, a doctor case,
and a `nativeStatusCases` row. The binary-missing message construction moved
out of `checkLbugNative` into `unrestorableBinaryFailure`, typed
`Exclude<RestoreOutcome, 'restored'>` so a new outcome forces a decision
instead of silently inheriting the lifecycle-script advice.
Drift: the trusted-package list was hand-spelled in five places in
native-check.ts, with "matches gitnexus/package.json" asserted only in a
comment. All five now render from one `NATIVE_BUILD_PACKAGES` const (rendered
output is byte-identical), and the test reads the list out of package.json
instead of restating it, so a fourth native package fails the test rather than
silently shipping stale advice.
Finally, replaced the absolute CLAUDE.md block cap with the ratio the two prior
justifications actually appealed to (`< 5465 * 0.55`). Raising 2700 -> 2900 ->
2950 was a ratchet with no ratchet: an absolute cap can only fail on the PR
that adds the character, and the fix is always to nudge the number. Also fixed
a stale runner ladder in skills-steering.test.ts that still omitted bunx.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015epfxkEMsmHFNVSFQqAkB4
---------
Co-authored-by: drdave-flexnteos <revenaugh.david@gmail.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Gergő Magyar <gergomagyar@icloud.com>
Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
198 lines
8.5 KiB
TypeScript
198 lines
8.5 KiB
TypeScript
import { describe, it, expect } from 'vitest';
|
||
import { readFileSync, readdirSync, existsSync } from 'node:fs';
|
||
import path from 'node:path';
|
||
import { STANDARD_SKILL_CATALOG } from '../../src/cli/standard-skills.js';
|
||
|
||
// Steering policy (#1939, #1945): the committed skill files route gitnexus
|
||
// commands through the project-local runner `gitnexus analyze` drops next to the
|
||
// index (`node .gitnexus/run.cjs <command>`). That one CLI-neutral command
|
||
// resolves the available runner (global `gitnexus` → `pnpm dlx` → `bunx` → `npx`)
|
||
// at call time, so the docs make no package-manager assumption. The runner only exists
|
||
// after the first analyze, so the cli skill documents a bootstrap path (and the
|
||
// npm-11 `node.target is null` npx install-crash escape hatch). When the pnpm
|
||
// fallback is shown it must use the pre-`dlx` `--allow-build` position (honored
|
||
// since pnpm 10.2); the post-`dlx` position is rejected as a package spec on
|
||
// pnpm 10.2–10.13.x.
|
||
//
|
||
// Pure file reads resolved via path.resolve — deterministic, no host-PATH or
|
||
// glob-CWD dependence, so this needs no cross-platform-tests.ts registration.
|
||
|
||
const GITNEXUS_ROOT = path.resolve(__dirname, '..', '..'); // gitnexus/test/unit -> gitnexus/
|
||
const REPO_ROOT = path.resolve(__dirname, '..', '..', '..'); // -> monorepo root
|
||
|
||
function collectSkillFiles(): string[] {
|
||
const files: string[] = [];
|
||
const projectSkillsRoot = path.join(REPO_ROOT, '.claude', 'skills');
|
||
|
||
// Bundled ship source: flat *.md files installSkills() copies to new users.
|
||
const bundled = path.join(GITNEXUS_ROOT, 'skills');
|
||
if (existsSync(bundled)) {
|
||
for (const f of readdirSync(bundled)) {
|
||
if (f.endsWith('.md')) files.push(path.join(bundled, f));
|
||
}
|
||
}
|
||
|
||
// Per-skill <name>/SKILL.md copies across the other distribution locations.
|
||
const skillRoots = [
|
||
projectSkillsRoot,
|
||
path.join(projectSkillsRoot, 'gitnexus'),
|
||
path.join(REPO_ROOT, 'gitnexus-claude-plugin', 'skills'),
|
||
path.join(REPO_ROOT, 'gitnexus-cursor-integration', 'skills'),
|
||
];
|
||
for (const root of skillRoots) {
|
||
if (!existsSync(root)) continue;
|
||
for (const dir of readdirSync(root)) {
|
||
if (root === projectSkillsRoot && !dir.startsWith('gitnexus-')) {
|
||
continue;
|
||
}
|
||
const skillMd = path.join(root, dir, 'SKILL.md');
|
||
if (existsSync(skillMd)) files.push(skillMd);
|
||
}
|
||
}
|
||
|
||
return files;
|
||
}
|
||
|
||
function cliSkillFiles(files: string[]): string[] {
|
||
return files.filter(
|
||
(f) =>
|
||
/gitnexus-cli/.test(path.basename(path.dirname(f))) || path.basename(f) === 'gitnexus-cli.md',
|
||
);
|
||
}
|
||
|
||
function standardSkillTargets(skill: (typeof STANDARD_SKILL_CATALOG)[number]): string[] {
|
||
const targets: string[] = [];
|
||
if (skill.distributions.project) {
|
||
targets.push(path.join('.claude', 'skills', skill.name, 'SKILL.md'));
|
||
}
|
||
if (skill.distributions.npm) {
|
||
targets.push(path.join('gitnexus', 'skills', `${skill.name}.md`));
|
||
}
|
||
if (skill.distributions.claudePlugin) {
|
||
targets.push(path.join('gitnexus-claude-plugin', 'skills', skill.name, 'SKILL.md'));
|
||
}
|
||
if (skill.distributions.cursor) {
|
||
targets.push(path.join('gitnexus-cursor-integration', 'skills', skill.name, 'SKILL.md'));
|
||
}
|
||
return targets;
|
||
}
|
||
|
||
describe('skill-file steering (#1939, #1945)', () => {
|
||
const files = collectSkillFiles();
|
||
|
||
it('collects skill files from all committed locations (guard is not vacuous)', () => {
|
||
const rels = files.map((f) => path.relative(REPO_ROOT, f));
|
||
expect(rels.some((r) => r.startsWith(`gitnexus${path.sep}skills${path.sep}`))).toBe(true);
|
||
expect(
|
||
rels.some((r) => r.startsWith(path.join('.claude', 'skills', 'gitnexus-cli') + path.sep)),
|
||
).toBe(true);
|
||
expect(
|
||
rels.some((r) =>
|
||
r.startsWith(path.join('.claude', 'skills', 'gitnexus', 'gitnexus-pdg-query') + path.sep),
|
||
),
|
||
).toBe(true);
|
||
expect(
|
||
rels.some((r) => r.startsWith(path.join('gitnexus-claude-plugin', 'skills') + path.sep)),
|
||
).toBe(true);
|
||
expect(
|
||
rels.some((r) => r.startsWith(path.join('gitnexus-cursor-integration', 'skills') + path.sep)),
|
||
).toBe(true);
|
||
});
|
||
|
||
it('scans the complete standard-skill distribution without nested duplicates', () => {
|
||
const rels = files.map((f) => path.relative(REPO_ROOT, f));
|
||
const relSet = new Set(rels);
|
||
const discoveredStandardNames = rels
|
||
.filter((rel) => path.dirname(rel) === path.join('gitnexus', 'skills') && rel.endsWith('.md'))
|
||
.map((rel) => path.basename(rel, '.md'))
|
||
.filter(
|
||
(name) =>
|
||
relSet.has(path.join('.claude', 'skills', name, 'SKILL.md')) &&
|
||
relSet.has(path.join('gitnexus-claude-plugin', 'skills', name, 'SKILL.md')),
|
||
)
|
||
.sort();
|
||
expect(STANDARD_SKILL_CATALOG.map((skill) => skill.name).sort()).toEqual(
|
||
discoveredStandardNames,
|
||
);
|
||
|
||
const discoveredCursorNames = discoveredStandardNames.filter((name) =>
|
||
relSet.has(path.join('gitnexus-cursor-integration', 'skills', name, 'SKILL.md')),
|
||
);
|
||
expect(
|
||
STANDARD_SKILL_CATALOG.filter((skill) => skill.distributions.cursor)
|
||
.map((skill) => skill.name)
|
||
.sort(),
|
||
).toEqual(discoveredCursorNames);
|
||
|
||
for (const skill of STANDARD_SKILL_CATALOG) {
|
||
for (const target of standardSkillTargets(skill)) expect(rels).toContain(target);
|
||
expect(rels).not.toContain(
|
||
path.join('.claude', 'skills', 'gitnexus', skill.name, 'SKILL.md'),
|
||
);
|
||
}
|
||
});
|
||
|
||
it('routes EVERY cli skill subcommand through the project-local runner (#1945)', () => {
|
||
// The cli skill demonstrates every subcommand. Each must invoke the
|
||
// CLI-neutral runner `gitnexus analyze` drops next to the index — not a
|
||
// hardcoded package manager — so the docs make no pnpm/npx assumption.
|
||
// Checking each subcommand (not just `analyze`) guards against a regression
|
||
// where status/clean/wiki/list silently revert to `npx gitnexus <sub>`.
|
||
const cli = cliSkillFiles(files);
|
||
expect(cli.length).toBeGreaterThan(0); // guard is not vacuous
|
||
const SUBCOMMANDS = ['analyze', 'status', 'clean', 'wiki', 'list'];
|
||
const offenders: string[] = [];
|
||
for (const f of cli) {
|
||
const text = readFileSync(f, 'utf-8');
|
||
for (const sub of SUBCOMMANDS) {
|
||
if (!new RegExp(`node\\s+\\.gitnexus/run\\.cjs\\s+${sub}\\b`).test(text)) {
|
||
offenders.push(`${path.relative(REPO_ROOT, f)}:${sub}`);
|
||
}
|
||
}
|
||
}
|
||
expect(offenders).toEqual([]);
|
||
});
|
||
|
||
it('documents the not-analyzed-yet / npm-11 bootstrap fallback in the cli skill (#1939)', () => {
|
||
// The runner only exists after the first analyze, so the cli skill must
|
||
// document the bootstrap path (and the npm-11 npx install crash escape
|
||
// hatch): the issue reference plus at least one fallback mechanism.
|
||
const cli = cliSkillFiles(files);
|
||
const offenders = cli.filter((f) => {
|
||
const text = readFileSync(f, 'utf-8');
|
||
const refsIssue = /1939/.test(text);
|
||
const hasFallback =
|
||
/install -g gitnexus/.test(text) || /--allow-build.*dlx gitnexus/.test(text);
|
||
return !(refsIssue && hasFallback);
|
||
});
|
||
expect(offenders.map((f) => path.relative(REPO_ROOT, f))).toEqual([]);
|
||
|
||
// Positive vacuity guard: at least one cli skill must still carry the pnpm
|
||
// pre-`dlx` fallback form, so the npm-11 pnpm path can't silently vanish
|
||
// from every skill while the OR above is satisfied by `install -g` alone.
|
||
const withPnpmFallback = cli.filter((f) =>
|
||
/--allow-build.*dlx gitnexus/.test(readFileSync(f, 'utf-8')),
|
||
);
|
||
expect(withPnpmFallback.length).toBeGreaterThan(0);
|
||
});
|
||
|
||
it('routes every stale-index reanalyze hint through the runner, not a raw package manager', () => {
|
||
// Skills that tell the agent to reanalyze a stale index must point at the
|
||
// runner so the package-manager choice is resolved at call time.
|
||
const offenders = files.filter((f) => {
|
||
const text = readFileSync(f, 'utf-8');
|
||
if (!/[Ss]tale/.test(text)) return false; // only skills with a reanalyze hint
|
||
return !/node\s+\.gitnexus\/run\.cjs\s+analyze/.test(text);
|
||
});
|
||
expect(offenders.map((f) => path.relative(REPO_ROOT, f))).toEqual([]);
|
||
});
|
||
|
||
it('any pnpm fallback uses the pre-`dlx` --allow-build form, never the broken post-`dlx` position', () => {
|
||
// `pnpm dlx --allow-build=…` (flags after `dlx`) is parsed as a package spec
|
||
// and rejected on pnpm 10.2–10.13.x; the flags must precede `dlx` (#1939).
|
||
const postDlxOffenders = files.filter((f) =>
|
||
/pnpm dlx --allow-build/.test(readFileSync(f, 'utf-8')),
|
||
);
|
||
expect(postDlxOffenders.map((f) => path.relative(REPO_ROOT, f))).toEqual([]);
|
||
});
|
||
});
|