GitNexus/gitnexus/test/unit/analyze-worker-ipc.test.ts
mengkaka 79543c8f83
feat(storage): add configurable index storage and content retention tiers (#3060)
* feat(storage): add configurable index storage and content retention tiers

Rebase #3060 onto current origin/main. Keep GITNEXUS_STORAGE_PATH,
GITNEXUS_STORAGE_ROOT, and GITNEXUS_CONTENT_RETENTION, and fold in
main's FTS skip, embed-session, and help-text updates.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3060)

Keep legacy registry rows on the local storage fallback, resolve
symlinks before the destructive-path guard, and align hook lookup
with CLI branch slugs, branch-slot metadata, and longest-path match.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3060)

Only list swept upload directories after a successful removal so
callers cannot treat a permission or transient rm failure as gone.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3060)

Document that getStoragePath may consult registered storage while
this module still does not mutate the global registry.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(storage): close review findings for external indexes and retention

Re-inspect ownership under the analyze lock, fail-closed when the
registry file is missing, and keep skip-git hook discovery plus
retention fields on HTTP/MCP list surfaces. /api/file stays 410
unless contentRetention is full.

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore(autofix): apply prettier + eslint fixes via /autofix command

* Address PR review feedback (#3060)

Treat lock-only index dirs as empty, honor HTTP --force storage policy, and prefer registered plus branch-aware slots in hooks and augment.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Address PR review feedback (#3060)

Keep hook fallbacks inside the current worktree, compare foreign-local slots canonically, and make storage fixtures survive ownership validation.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix macOS hook test expecting realpath'd registry paths.

resolveHookRepo returns the written registry path, not a filesystem realpath, so the assertion must match that.

* Address gitnexus-check warnings on hook install docs and slot tests.

The Cursor troubleshooting list omitted registry-query.cjs, and the writable-slot test only checked that isDirectory exists instead of that the path is a directory.

* Align the HTTP catalog source-scan with skippable resolveRepo validation.

resolveRepo lists fresh repos with validate: options.validateStorage !== false so DELETE can skip prune; the test still required a literal validate: true.

* Harden storage path sinks so CodeQL path-injection and ReDoS alerts clear.

Contain every filesystem probe inside the resolved storage slot with the inline path.relative idiom, reject filesystem-root slots, and trim slot basenames in linear time.

* Settle bridge stamps before writing so CI size/mtime matches stay stable.

LadybugDB can still flush into bridge.lbug after close+rename; persist whole-millisecond mtimes and wait for consecutive stats to agree so a freshly written pair matches.

* Type the settled bridge stat as fs.Stats so tsc does not see bigint.

Awaited<ReturnType<typeof fsp.stat>> collapsed the bigint overload and broke prepare/typecheck on CI.

* Keep the bridge mtime stamp exact so same-size swaps still fail the pair check.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Wrap the bridge stamp predicate so prettier --check stays green.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Require a quiet interval before stamping a settled bridge file.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Reuse shared storage and settle helpers instead of local copies.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Gergo Magyar <gergomagyar0@gmail.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
2026-09-12 20:31:55 +00:00

109 lines
4.5 KiB
TypeScript

/**
* #2112 boundary audit — the analyze-worker → parent IPC projection.
*
* The forked analyze worker reports completion over default-JSON child_process
* IPC. `AnalyzeResult.pipelineResult` carries the live `KnowledgeGraph` (closure
* methods, getter-materialized arrays) and can transitively hold a BigInt or a
* circular reference — all of which break `JSON.stringify` (the IPC serializer):
* methods drop silently, BigInt/circular THROW. `projectAnalyzeResultForIpc`
* strips `pipelineResult` to an explicit JSON-safe allowlist so the boundary is
* safe by construction. These tests pin that contract.
*/
import { describe, it, expect } from 'vitest';
import { projectAnalyzeResultForIpc } from '../../src/server/analyze-worker-ipc.js';
import type { AnalyzeResult } from '../../src/core/run-analyze.js';
import { createKnowledgeGraph } from '../../src/core/graph/graph.js';
/**
* An `AnalyzeResult` whose `pipelineResult` is hostile to JSON in all three
* ways the real `KnowledgeGraph` can be: a method (dropped), a circular ref
* (throws), and a BigInt (throws).
*/
function hostileResult(): AnalyzeResult {
const graph: Record<string, unknown> = {
nodes: [{ id: 'a', label: 'Function', properties: { name: 'a' } }],
relationships: [],
forEachNode: () => {}, // own function property — JSON drops it silently
bigCount: 10n, // BigInt — JSON.stringify throws
};
graph.self = graph; // circular — JSON.stringify throws
return {
repoName: 'demo',
repoPath: '/repos/demo',
storagePath: '/repos/demo/.gitnexus',
stats: { files: 3, nodes: 1, edges: 0 },
alreadyUpToDate: false,
ftsSkipped: true,
pipelineResult: { graph, repoPath: '/repos/demo', totalFileCount: 3 },
};
}
describe('#2112: analyze-worker IPC projection', () => {
it('drops pipelineResult and preserves the scalar fields the parent consumes', () => {
const projected = projectAnalyzeResultForIpc(hostileResult());
expect(projected).toEqual({
repoName: 'demo',
repoPath: '/repos/demo',
stats: { files: 3, nodes: 1, edges: 0 },
alreadyUpToDate: false,
ftsRepairedOnly: undefined,
ftsSkipped: true,
});
expect('pipelineResult' in projected).toBe(false);
});
it('the projection is JSON-serializable (survives the default child_process IPC channel)', () => {
const projected = projectAnalyzeResultForIpc(hostileResult());
// The real failure mode: process.send runs JSON.stringify under the hood.
expect(() => JSON.stringify(projected)).not.toThrow();
const roundTripped = JSON.parse(JSON.stringify(projected));
expect(roundTripped.repoName).toBe('demo');
expect(roundTripped.stats.nodes).toBe(1);
});
it('anchors the hazard: serializing the RAW result throws (the bug the projection prevents)', () => {
// Without the projection, `send({type:'complete', result})` would throw a
// TypeError in the worker, get caught, and mis-report this success as a
// failure. This assertion documents why the projection exists.
expect(() => JSON.stringify(hostileResult())).toThrow(TypeError);
});
it('drops a REAL KnowledgeGraph from pipelineResult — the payload stays tiny (graph not materialized)', () => {
// The synthetic cases above use a hand-built hostile object; this uses the
// real createKnowledgeGraph the server path actually puts in pipelineResult,
// whose nodes/relationships getters would materialize the whole graph into
// arrays under JSON.stringify. The projection must drop it entirely.
const graph = createKnowledgeGraph();
for (let i = 0; i < 50; i++) {
graph.addNode({
id: `n${i}`,
label: 'Function',
properties: { name: `n${i}`, filePath: 'x.ts' },
});
}
graph.addRelationship({ id: 'n0->n1', source: 'n0', target: 'n1', type: 'CALLS' });
const result: AnalyzeResult = {
repoName: 'demo',
repoPath: '/r',
storagePath: '/r/.gitnexus',
stats: { nodes: 50, edges: 1 },
pipelineResult: {
graph,
repoPath: '/r',
totalFileCount: 50,
resolutionOutcomes: [],
usedWorkerPool: true,
},
};
const projected = projectAnalyzeResultForIpc(result);
expect('pipelineResult' in projected).toBe(false);
const json = JSON.stringify(projected);
// A materialized 50-node graph would be thousands of bytes; the projection
// is just the scalar fields, so this stays small.
expect(json.length).toBeLessThan(300);
const rt = JSON.parse(json);
expect(rt.repoName).toBe('demo');
expect(rt.stats.nodes).toBe(50);
});
});