Files
OmniRoute/tests/unit/sonar-quality-gate-fixes.test.ts
Diego Rodrigues de Sa e Souza 7ee5bbc64d fix(build): v3.8.48 hotfix — npm tarball head-response-guard (#7065), electron win spawn, Sonar gate zeroed (#7055)
* fix(build): spawn npx.cmd through a shell in the electron better-sqlite3 rebuild

Node's CVE-2024-27980 hardening makes spawnSync of .cmd/.bat shims fail with
status null unless shell:true — the v3.8.47 tag build died on the Windows job
with 'better-sqlite3 rebuild against electron 43.1.0 failed (exit null)'.
Extracted the spawn plan into electronRebuildPlan.mjs (pure, import-safe) with
a regression test; args are fixed literals, no untrusted input reaches the shell.

* fix(build): ship head-response-guard.cjs in the npm tarball (#7065)

The prepublish prune allowlist (pack-artifact-policy.ts) lacked
head-response-guard.cjs, so assembleStandalone copied it and the prune
deleted it — every boot of the published 3.8.47 crashed with
ERR_MODULE_NOT_FOUND (3rd occurrence of this class; tls-options/3.8.41).
Also added to PACK_ARTIFACT_REQUIRED_PATHS so check:pack-artifact fails
loudly, plus a closure test that derives every server-ws.mjs sibling
import and asserts both lists cover it.

* fix(ci): zero the Sonar quality-gate findings on new code

- ci.yml sonarqube job: download the coverage artifact into coverage/ so
  lcov.info lands where sonar.javascript.lcov.reportPaths points — the
  upload strips the common coverage/ prefix, so 'path: .' left new-code
  coverage at 0% on every scan
- kiro auto-import: await the async isCloudEnabled() gate (S6544 — a bare
  truthiness check on the Promise made syncToCloud run even with cloud
  sync disabled)
- stream.ts: real JSON fallback in the reasoning-split clone (S3923 — both
  ternary branches called structuredClone, the promised fallback was dead)
- codex executor: handle the async reader.cancel() rejection (S4822)
- deterministic localeCompare sorts (S2871 x2)
- classify-pr-changes.mjs: confine the argv list file to the workspace
  (jssecurity:S8707 path-traversal guard) + behavioral tests
- Dockerfile: rebuild better-sqlite3 with npm's bundled node-gyp instead
  of npx --yes (docker:S6505 — no on-demand registry install)

* chore(ci): make the Sonar quality gate informational (wait=false)

The org's SonarCloud FREE plan cannot associate a custom quality gate — only
the built-in Sonar way (80% new coverage) applies, which no full-cycle release
PR can realistically meet. The scan still uploads (dashboard, PR decoration);
the CI job just no longer fails on the gate. A tuned 'OmniRoute way' gate
(coverage >=60, duplication <=5) is already configured in the org for the day
the plan is upgraded — re-enable wait=true then.

* chore(release): v3.8.48 hotfix bump + changelog (npm 3.8.47 unbootable, #7065)

* test: align pack-artifact + dockerfile guards to the corrected contracts

pack-artifact-policy.test.ts encoded the pre-#7065 REQUIRED list (without
head-response-guard.cjs) and dockerfile-better-sqlite3-node-gyp-6700.test.ts
asserted the npx invocation the Sonar fix replaced with npm's bundled
node-gyp — both now assert the corrected behavior.
2026-07-13 18:18:54 -03:00

62 lines
2.6 KiB
TypeScript

import { test } from "node:test";
import assert from "node:assert/strict";
import { spawnSync } from "node:child_process";
import fs from "node:fs";
import os from "node:os";
import path from "node:path";
import { fileURLToPath } from "node:url";
// Regression guards for the Sonar quality-gate fixes (release PR #6569 findings).
// Two classes of real defect are locked down here:
// 1. jssecurity:S8707 — classify-pr-changes.mjs read any path handed on argv;
// the CLI now confines the list file to the working directory.
// 2. typescript:S6544 — `isCloudEnabled()` is async; a bare `if (isCloudEnabled())`
// is always truthy, so cloud sync ran even with cloud disabled.
const ROOT = path.resolve(path.dirname(fileURLToPath(import.meta.url)), "../..");
const CLASSIFY = path.join(ROOT, "scripts", "quality", "classify-pr-changes.mjs");
test("classify-pr-changes rejects a list path that escapes the workspace", () => {
const cwd = fs.mkdtempSync(path.join(os.tmpdir(), "classify-guard-"));
try {
const outside = path.join(os.tmpdir(), "classify-outside.txt");
fs.writeFileSync(outside, "src/lib/db/core.ts\n");
const res = spawnSync(process.execPath, [CLASSIFY, outside], {
cwd,
encoding: "utf8",
});
assert.equal(res.status, 1, `expected exit 1, got ${res.status}\n${res.stdout}${res.stderr}`);
assert.match(res.stderr, /escapes the workspace/);
fs.rmSync(outside, { force: true });
} finally {
fs.rmSync(cwd, { recursive: true, force: true });
}
});
test("classify-pr-changes still accepts a workspace-relative list file", () => {
const cwd = fs.mkdtempSync(path.join(os.tmpdir(), "classify-ok-"));
try {
fs.writeFileSync(path.join(cwd, "changed-files.txt"), "docs/README.md\n");
const res = spawnSync(process.execPath, [CLASSIFY, "changed-files.txt"], {
cwd,
encoding: "utf8",
});
assert.equal(res.status, 0, `expected exit 0, got ${res.status}\n${res.stderr}`);
assert.match(res.stdout, /docs=true/);
assert.match(res.stdout, /code=false/);
} finally {
fs.rmSync(cwd, { recursive: true, force: true });
}
});
test("kiro auto-import awaits the async isCloudEnabled() gate (S6544)", () => {
const src = fs.readFileSync(
path.join(ROOT, "src", "app", "api", "oauth", "kiro", "auto-import", "route.ts"),
"utf8"
);
// `isCloudEnabled()` returns a Promise — a bare truthiness check is always true,
// which made syncToCloud() run even when cloud sync is disabled.
assert.doesNotMatch(src, /if\s*\(\s*isCloudEnabled\(\)/, "bare `if (isCloudEnabled())` found");
assert.match(src, /if\s*\(\s*await isCloudEnabled\(\)/);
});