mirror of
https://github.com/abhigyanpatwari/GitNexus.git
synced 2026-10-05 02:43:32 +00:00
* feat(taint): harvest occurrence-tagged call/member sites on StatementFacts (#2083 U1) Worker-side site harvest in TsHarvester: call/new/member-read records with dotted callee paths, receiver slots, per-argument occurrence tagging with nested-site links, per-declarator resultDefs, spread/template/require-literal markers. hasTaintSafeSites validation seam. The pdg parse-cache chunk-key namespace is versioned (pdg:1 -> pdg:2) instead of a global SCHEMA_BUMP so flag-off users keep warm caches; bench fingerprints re-baselined for the three call-bearing scenarios (straight-line/dense-bindings byte-unchanged). * feat(taint): built-in TS/JS source/sink/sanitizer model + site matcher (#2083 U2) Typed spec (kind taxonomy; sanitizers carry neutralizes-kinds), the canonical Express/Node model, and matchFunctionSites: ESM alias/namespace + require- literal callee resolution, bare-name fallback restricted to true globals, sanitizers module-or-global only (never user-shadowable by name), spread/ template arg-position rules, deterministic taintModelVersion. * feat(taint): pure intra-procedural taint propagation engine (#2083 U3) Two-rule model (statement-local + du-fact worklist) with per-taint neutralized-kind exclusion sets: sanitizers exclude only the sink kinds they neutralize (escape(req.body) suppresses res.send but still fires db.query; exec(path.basename(t)) fires), intersection-over-paths so a bypass occurrence keeps the taint live, kill locality on resultDefs, propagate-through args+receiver with viaCall hops, one path per finding, deterministic caps, coverage-gap statuses. Test-first: 38 scenarios on real harvested CFGs. * feat(taint): thread taint caps + model version through pdg config/meta (#2083 U5) resolvePdgConfig gains maxTaintFindingsPerFunction (200), maxTaintHops (32), and the taintModelVersion digest; RepoMeta.pdg + RunScopeResolutionInput surfaces added. The key-union comparator trips full writeback on M2->M3 upgrade and on model-version change without --force (mode-flip tested). No CLI flags or rc keys (programmatic parity with the other caps). * feat(taint): in-phase taint emit with sparse TAINTED/SANITIZES edges (#2083 U4) run.ts pdg window: match-first fast path (solver only when a function has both a matched source and sink) -> computeReachingDefs with the shared RD fact derivation -> computeTaintFlows -> per-finding TAINTED (versioned hop-encoded reason via the shared path codec, statement-level occurrence identity) + per-kill SANITIZES, dedup-before-budget, truncate-and-warn. All emit counters surfaced (aggregate warn for gaps/drops, debug for volume); PROF gains taint=. Flag-off golden untouched. * feat(mcp): explain tool for persisted taint findings (#2083 U6) Anchorless calls enumerate the sparse TAINTED table (bounded, deterministic, limit-clamped); anchored calls (file or symbol via resolveSymbolCandidates) return full decoded hop detail. sinkKind rides a version-1 codec header (1;<kind>|hops — no other persisted channel exists; U4/U6 ship together). RepoMeta.pdg probe yields a no-taint-layer note instead of an error. TAINTED/SANITIZES pinned OUT of VALID_RELATION_TYPES (KTD9a negative- membership tests); generators + canonical skill docs + mirrors updated. * test(taint): acceptance fixture battery, snapshots, and bench gates (#2083 U7) pdg-repo taint-cases fixtures complete the six plan shapes; committed findings/kills snapshot via a shared pure-path harness that also feeds the AE2 exact-equality assertion (stored TAINTED == pure-path findings, the no-explosion gate). New taint-dense bench scenario with four --check gates: per-function findings pinned AT the cap, absolute reason-byte + site-bytes disk ceilings (the load-bearing R10 gate), zero-match pass < 0.5x match- dense, N-linearity. Pre-existing scenario baselines untouched. * refactor(taint): share one pointKey helper across propagate + emit (#2083 review) Extract pointKey(ProgramPoint) to cfg/reaching-defs.ts (colon-separated, matching the codebase block:stmt id convention) and import it in both propagate.ts and emit.ts, replacing the two divergent locals (':' vs '.'). Edge-id material now uses the colon form; ids are in-memory only and no test asserts the pointKey segment shape. * fix(taint): discriminate taint state by source occurrence (#2083 review) Two distinct sources flowing into one variable at one def point no longer collapse to a single TAINTED edge: the taint-state key gains a root source-occurrence discriminator ({point, siteIndex} — the same fields recordFinding's identity uses, excluding kind). Def->use fact lookup keys on the source-independent (binding, def-point) portion. Same-source multi-path flows still share one state so their exclusion sets intersect (the raw arm soundly wins); termination holds (finite keys, monotone shrink, no cross-source ping-pong). Restores the KTD6 identity contract. * fix(mcp): route dotted symbol names in explain to symbol resolution (#2083 review) The fileish classifier matched any dotted name (UserController.create) as a file via its extension-like suffix, so symbol resolution never ran and the tool returned a silent empty file-anchored result. Tighten the classifier to require a path separator or a real source extension (derived from the resolver's EXTENSIONS list, multi-language), so dotted/bare names route to resolveSymbolCandidates (found / ambiguous / not-found). * fix(mcp): gate explain no-taint-layer note on taintModelVersion (#2083 review) An M1/M2-era --pdg index has meta.pdg defined (BasicBlock/REACHING_DEF recorded) but no taintModelVersion and zero TAINTED rows. The probe keyed on generic meta.pdg presence, so explain returned the generic empty note instead of the actionable 'no taint layer — run analyze' hint. Gate on meta.pdg?.taintModelVersion (the field M3 stamps) so an M2-era index gets the layer hint; a taint-stamped index with no findings still gets the generic note. * fix(taint): sequence-expression value flows only the final operand (#2083 review) A comma expression in value position (exec((log(x), 'safe'))) default- descended, fanning every operand's occurrences into the enclosing sink argument — over-tainting exec's arg 0 with x. Add an explicit walkValue case that records earlier operands' uses with occurrence fan-out suppressed (new FactAccumulator.suppressOccurrences) and routes only the last operand through the value path. Sites-layer only; defs/uses/mayDefs byte-identical (cfg + reaching-defs snapshots unchanged). * perf(taint): FIFO head-cursor worklist + dedup before chainHops (#2083 review) Replace queue.shift() (O(N) dequeue) with a strict-FIFO head cursor plus order-preserving prefix reclamation; FIFO is load-bearing because chainHops reads the live taints map whose parent/source/viaCall are rewritten order-sensitively on monotone shrink, so hop determinism is dequeue-order contingent. Extract findingKey() and dedup-check before chainHops in the justify branch — already-recorded identities discard their hop chain (first write wins), so the ancestry walk was pure waste. The else kill branch is untouched. Findings + hops byte-identical (snapshot unchanged). * perf(taint): O(1) member-read dedup via composite-key set (#2083 review) addMemberRead rescanned the whole per-statement sites array per call to dedup by (object, property, parent) — O(n^2) on member-read-dense statements. Track a composite-key Set alongside sites for O(1) dedup. (The require-literal join is already O(sites) with a no-op body on non-require sites, so no early-exit is needed there.) Behavior identical: harvest + model-match + taint snapshots unchanged. * refactor(taint): drop test-only export; source taint caps via emit.ts (#2083 review) Remove the sanitizerNeutralizes export (its only consumers were two test assertions — inlined to entry.neutralizes membership). Re-export the DEFAULT_PDG_MAX_TAINT_* caps from emit.ts and point run.ts at emit.ts, so the pipeline's taint dependency surface is the single orchestration module rather than reaching into propagate.ts. * test(taint): extract the shared TS CFG/taint test harness (#2083 review) The parse/collectFunctions/cfgOf/cfgsOf/importsFor harness was copied byte-for-byte across four suites (harvest, model-match, propagate, taint-emit). Promote it to test/helpers/ts-cfg-harness.ts and import it. site-safety/reaching-defs carry a structurally different inlined builder and are left as-is. Pure extraction, no assertion changes. * test(mcp): harden explain limit-rejection battery (#2083 review) Add NaN, Infinity, -Infinity, and a numeric string to the out-of-bounds limit cases — a regression fence over the interpolated LIMIT, confirming the Number.isInteger guard rejects every non-integer/non-finite/string input before it reaches the query.
281 lines
12 KiB
TypeScript
281 lines
12 KiB
TypeScript
/**
|
|
* Unit Tests: MCP Tool Definitions
|
|
*
|
|
* Tests: GITNEXUS_TOOLS from tools.ts
|
|
* - All 13 tools are defined (per-repo + group_list/group_sync)
|
|
* - Each tool has valid name, description, inputSchema
|
|
* - Required fields are correct
|
|
* - Optional repo parameter is present on tools that need it
|
|
*/
|
|
import { describe, it, expect } from 'vitest';
|
|
import {
|
|
GITNEXUS_TOOLS,
|
|
LIST_REPOS_DEFAULT_LIMIT,
|
|
LIST_REPOS_MAX_LIMIT,
|
|
} from '../../src/mcp/tools.js';
|
|
|
|
const GROUP_TOOLS = new Set(['group_list', 'group_sync']);
|
|
const MUTATING_TOOLS = new Set(['rename', 'group_sync']);
|
|
// Read-only tools that legitimately reach external systems. Add a tool name
|
|
// here when introducing a read-only tool that needs openWorldHint: true.
|
|
const OPEN_WORLD_READ_ONLY_TOOLS = new Set(['query']);
|
|
|
|
describe('GITNEXUS_TOOLS', () => {
|
|
it('exports all tools (8 base + 1 explain + 3 route/tool/shape + 1 api_impact + 2 group)', () => {
|
|
expect(GITNEXUS_TOOLS).toHaveLength(15);
|
|
});
|
|
|
|
it('contains all expected tool names', () => {
|
|
const names = GITNEXUS_TOOLS.map((t) => t.name);
|
|
expect(names).toEqual(
|
|
expect.arrayContaining([
|
|
'list_repos',
|
|
'query',
|
|
'cypher',
|
|
'context',
|
|
'detect_changes',
|
|
'check',
|
|
'rename',
|
|
'impact',
|
|
'explain',
|
|
'api_impact',
|
|
]),
|
|
);
|
|
});
|
|
|
|
it('each tool has name, description, and inputSchema', () => {
|
|
for (const tool of GITNEXUS_TOOLS) {
|
|
expect(tool.name).toBeTruthy();
|
|
expect(typeof tool.name).toBe('string');
|
|
expect(tool.description).toBeTruthy();
|
|
expect(typeof tool.description).toBe('string');
|
|
expect(tool.annotations).toBeDefined();
|
|
expect(tool.inputSchema).toBeDefined();
|
|
expect(tool.inputSchema.type).toBe('object');
|
|
expect(tool.inputSchema.properties).toBeDefined();
|
|
expect(Array.isArray(tool.inputSchema.required)).toBe(true);
|
|
}
|
|
});
|
|
|
|
it('each tool exposes all MCP safety annotations', () => {
|
|
for (const tool of GITNEXUS_TOOLS) {
|
|
expect(typeof tool.annotations.readOnlyHint).toBe('boolean');
|
|
expect(typeof tool.annotations.destructiveHint).toBe('boolean');
|
|
expect(typeof tool.annotations.idempotentHint).toBe('boolean');
|
|
expect(typeof tool.annotations.openWorldHint).toBe('boolean');
|
|
}
|
|
});
|
|
|
|
it('read-only tools are marked non-destructive and idempotent', () => {
|
|
for (const tool of GITNEXUS_TOOLS) {
|
|
if (MUTATING_TOOLS.has(tool.name)) continue;
|
|
|
|
expect(tool.annotations.readOnlyHint).toBe(true);
|
|
expect(tool.annotations.destructiveHint).toBe(false);
|
|
expect(tool.annotations.idempotentHint).toBe(true);
|
|
expect(tool.annotations.openWorldHint).toBe(OPEN_WORLD_READ_ONLY_TOOLS.has(tool.name));
|
|
}
|
|
});
|
|
|
|
it('query is marked open-world because it may use external embeddings', () => {
|
|
const queryTool = GITNEXUS_TOOLS.find((t) => t.name === 'query')!;
|
|
expect(queryTool.annotations).toEqual({
|
|
readOnlyHint: true,
|
|
destructiveHint: false,
|
|
idempotentHint: true,
|
|
openWorldHint: true,
|
|
});
|
|
});
|
|
|
|
it('rename and group_sync are marked mutating and non-idempotent', () => {
|
|
for (const name of ['rename', 'group_sync'] as const) {
|
|
const tool = GITNEXUS_TOOLS.find((t) => t.name === name)!;
|
|
expect(tool.annotations).toEqual({
|
|
readOnlyHint: false,
|
|
destructiveHint: true,
|
|
idempotentHint: false,
|
|
openWorldHint: false,
|
|
});
|
|
}
|
|
});
|
|
|
|
it('query tool requires "query" parameter', () => {
|
|
const queryTool = GITNEXUS_TOOLS.find((t) => t.name === 'query')!;
|
|
expect(queryTool.inputSchema.required).toContain('query');
|
|
expect(queryTool.inputSchema.properties.query).toBeDefined();
|
|
expect(queryTool.inputSchema.properties.query.type).toBe('string');
|
|
});
|
|
|
|
it('cypher tool requires "query" parameter', () => {
|
|
const cypherTool = GITNEXUS_TOOLS.find((t) => t.name === 'cypher')!;
|
|
expect(cypherTool.inputSchema.required).toContain('query');
|
|
expect(cypherTool.inputSchema.properties.params).toBeDefined();
|
|
expect(cypherTool.inputSchema.properties.params.type).toBe('object');
|
|
expect(cypherTool.inputSchema.properties.params.description).toContain('prepared statement');
|
|
});
|
|
|
|
it('context tool has no required parameters', () => {
|
|
const contextTool = GITNEXUS_TOOLS.find((t) => t.name === 'context')!;
|
|
expect(contextTool.inputSchema.required).toEqual([]);
|
|
});
|
|
|
|
it('impact tool requires target and direction', () => {
|
|
const impactTool = GITNEXUS_TOOLS.find((t) => t.name === 'impact')!;
|
|
expect(impactTool.inputSchema.required).toContain('target');
|
|
expect(impactTool.inputSchema.required).toContain('direction');
|
|
});
|
|
|
|
it('rename tool requires new_name', () => {
|
|
const renameTool = GITNEXUS_TOOLS.find((t) => t.name === 'rename')!;
|
|
expect(renameTool.inputSchema.required).toContain('new_name');
|
|
});
|
|
|
|
it('detect_changes tool has no required parameters', () => {
|
|
const detectTool = GITNEXUS_TOOLS.find((t) => t.name === 'detect_changes')!;
|
|
expect(detectTool.inputSchema.required).toEqual([]);
|
|
});
|
|
|
|
it('list_repos tool exposes optional limit/offset pagination params', () => {
|
|
const listTool = GITNEXUS_TOOLS.find((t) => t.name === 'list_repos')!;
|
|
const props = listTool.inputSchema.properties;
|
|
expect(props.limit).toBeDefined();
|
|
expect(props.limit.type).toBe('integer');
|
|
expect(props.offset).toBeDefined();
|
|
expect(props.offset.type).toBe('integer');
|
|
// Pagination is opt-in: zero-arg callers must still be valid.
|
|
expect(listTool.inputSchema.required).toEqual([]);
|
|
// No `repo` param on list_repos (it lists all repos).
|
|
expect(props.repo).toBeUndefined();
|
|
// Description must teach an LLM to page through every repository.
|
|
expect(listTool.description.toLowerCase()).toContain('paginat');
|
|
expect(listTool.description).toContain('nextOffset');
|
|
expect(listTool.description).toContain('hasMore');
|
|
});
|
|
|
|
it('list_repos schema bounds match the exported pagination constants', () => {
|
|
const listTool = GITNEXUS_TOOLS.find((t) => t.name === 'list_repos')!;
|
|
const { limit, offset } = listTool.inputSchema.properties;
|
|
expect(limit.minimum).toBe(1);
|
|
expect(limit.maximum).toBe(LIST_REPOS_MAX_LIMIT);
|
|
expect(limit.default).toBe(LIST_REPOS_DEFAULT_LIMIT);
|
|
expect(offset.minimum).toBe(0);
|
|
expect(offset.default).toBe(0);
|
|
// Sane, documented bounds (guards against accidental constant drift).
|
|
expect(LIST_REPOS_DEFAULT_LIMIT).toBeLessThanOrEqual(LIST_REPOS_MAX_LIMIT);
|
|
expect(LIST_REPOS_DEFAULT_LIMIT).toBeGreaterThan(0);
|
|
});
|
|
|
|
it('per-repo tools have optional repo parameter for backend selection', () => {
|
|
for (const tool of GITNEXUS_TOOLS) {
|
|
if (tool.name === 'list_repos') continue;
|
|
if (GROUP_TOOLS.has(tool.name)) continue;
|
|
expect(tool.inputSchema.properties.repo).toBeDefined();
|
|
expect(tool.inputSchema.properties.repo.type).toBe('string');
|
|
expect(tool.inputSchema.required).not.toContain('repo');
|
|
}
|
|
});
|
|
|
|
it('per-repo tools have an optional branch scope param (#2106); group/list tools do not', () => {
|
|
for (const tool of GITNEXUS_TOOLS) {
|
|
if (tool.name === 'list_repos' || GROUP_TOOLS.has(tool.name)) {
|
|
expect(tool.inputSchema.properties.branch).toBeUndefined();
|
|
continue;
|
|
}
|
|
expect(tool.inputSchema.properties.branch, tool.name).toBeDefined();
|
|
expect(tool.inputSchema.properties.branch.type).toBe('string');
|
|
// Optional — omitting it keeps the default/primary-branch behavior.
|
|
expect(tool.inputSchema.required).not.toContain('branch');
|
|
}
|
|
});
|
|
|
|
it('group tools without backend repo param omit repo property', () => {
|
|
for (const name of ['group_list', 'group_sync'] as const) {
|
|
const tool = GITNEXUS_TOOLS.find((t) => t.name === name)!;
|
|
expect(tool.inputSchema.properties).not.toHaveProperty('repo');
|
|
}
|
|
});
|
|
|
|
it('impact, query, and context expose optional service with minLength', () => {
|
|
for (const n of ['impact', 'query', 'context'] as const) {
|
|
const tool = GITNEXUS_TOOLS.find((t) => t.name === n)!;
|
|
const svc = tool.inputSchema.properties.service;
|
|
expect(svc, n).toBeDefined();
|
|
expect(svc!.minLength).toBe(1);
|
|
}
|
|
});
|
|
|
|
it('impact schema bounds match cross-impact validation ranges', () => {
|
|
const impact = GITNEXUS_TOOLS.find((t) => t.name === 'impact')!;
|
|
expect(impact.inputSchema.properties.maxDepth.minimum).toBe(1);
|
|
expect(impact.inputSchema.properties.maxDepth.maximum).toBe(32);
|
|
expect(impact.inputSchema.properties.minConfidence.minimum).toBe(0);
|
|
expect(impact.inputSchema.properties.minConfidence.maximum).toBe(1);
|
|
expect(impact.inputSchema.properties.timeoutMs.maximum).toBe(3600000);
|
|
});
|
|
|
|
it('detect_changes scope has correct enum values', () => {
|
|
const detectTool = GITNEXUS_TOOLS.find((t) => t.name === 'detect_changes')!;
|
|
const scopeProp = detectTool.inputSchema.properties.scope;
|
|
expect(scopeProp.enum).toEqual(['unstaged', 'staged', 'all', 'compare']);
|
|
});
|
|
|
|
// ─── explain (#2083 M3 U6) ─────────────────────────────────────────
|
|
|
|
it('explain tool is anchorless-optional with a bounded limit and a branch scope', () => {
|
|
const explainTool = GITNEXUS_TOOLS.find((t) => t.name === 'explain')!;
|
|
expect(explainTool).toBeDefined();
|
|
// Anchorless calls (enumerate all findings) must be valid.
|
|
expect(explainTool.inputSchema.required).toEqual([]);
|
|
expect(explainTool.inputSchema.properties.target).toBeDefined();
|
|
expect(explainTool.inputSchema.properties.target.type).toBe('string');
|
|
const limit = explainTool.inputSchema.properties.limit;
|
|
expect(limit).toBeDefined();
|
|
expect(limit.type).toBe('integer');
|
|
expect(limit.minimum).toBe(1);
|
|
expect(limit.maximum).toBeGreaterThan(0);
|
|
// Branch-scoped per #2106 (injected via BRANCH_SCOPED_TOOLS).
|
|
expect(explainTool.inputSchema.properties.branch).toBeDefined();
|
|
});
|
|
|
|
it('explain description names the --pdg requirement and the KTD10 contract caveats', () => {
|
|
const explainTool = GITNEXUS_TOOLS.find((t) => t.name === 'explain')!;
|
|
const d = explainTool.description;
|
|
expect(d).toContain('--pdg');
|
|
expect(d).toContain('intra-procedural');
|
|
// The named blind-spot classes (plan KTD10) must reach the consumer.
|
|
expect(d.toLowerCase()).toContain('closure/callback');
|
|
expect(d.toLowerCase()).toContain('property/field');
|
|
expect(d.toLowerCase()).toContain('guard-style');
|
|
expect(d.toLowerCase()).toContain('cross-function');
|
|
expect(d.toLowerCase()).toContain('commonjs');
|
|
expect(d.toLowerCase()).toContain('exception');
|
|
});
|
|
|
|
it('api_impact tool has no required parameters', () => {
|
|
const apiImpactTool = GITNEXUS_TOOLS.find((t) => t.name === 'api_impact')!;
|
|
expect(apiImpactTool).toBeDefined();
|
|
expect(apiImpactTool.inputSchema.required).toEqual([]);
|
|
expect(apiImpactTool.inputSchema.properties.route).toBeDefined();
|
|
expect(apiImpactTool.inputSchema.properties.file).toBeDefined();
|
|
expect(apiImpactTool.inputSchema.properties.repo).toBeDefined();
|
|
});
|
|
|
|
it('impact relationTypes is array of strings', () => {
|
|
const impactTool = GITNEXUS_TOOLS.find((t) => t.name === 'impact')!;
|
|
const relProp = impactTool.inputSchema.properties.relationTypes;
|
|
expect(relProp.type).toBe('array');
|
|
expect(relProp.items).toEqual({ type: 'string' });
|
|
});
|
|
|
|
it('route_map description defers to api_impact for pre-change analysis', () => {
|
|
const routeMapTool = GITNEXUS_TOOLS.find((t) => t.name === 'route_map')!;
|
|
expect(routeMapTool.description).toContain('api_impact');
|
|
expect(routeMapTool.description).toContain('pre-change analysis');
|
|
});
|
|
|
|
it('shape_check description defers to api_impact for pre-change analysis', () => {
|
|
const shapeCheckTool = GITNEXUS_TOOLS.find((t) => t.name === 'shape_check')!;
|
|
expect(shapeCheckTool.description).toContain('api_impact');
|
|
expect(shapeCheckTool.description).toContain('pre-change analysis');
|
|
});
|
|
});
|