test: isolate HOME in all CLI-spawning tests (close leak class)
Follow-up to the posture-grade-stability fix in 66433fe. Audited every
test that spawns a CLI and found more of the same class: tests running
HOME-scoped scanners (SKL/COL) or the CLAUDE.md cascade against the
developer's real ~/.claude instead of an isolated HOME.
Fixed (env: hermeticEnv()):
- posture.test.mjs — runs full posture (SKL/COL/cascade); twin of
the posture-grade-stability leak, masked only
because its asserts are structural/relative
- drift-cli.test.mjs — ACTIVE bug: the CLI wrote baselines into the
real ~/.claude during the run (pollution); now
isolated, and afterEach cleanup wrapped in
withHermeticHome so it looks in the same HOME
- token-hotspots-cli.test.mjs — scan-orchestrator run executes SKL/COL on
real HOME; TOK reads the HOME cascade
- accurate-tokens.test.mjs — TOK reads the HOME cascade (kept the
ANTHROPIC_API_KEY deletion)
Proven safe, left as-is (no HOME-scoped scan affecting assertions, no
HOME writes): post-edit-verify.test.mjs (fast-path early-returns only),
fix-cli.test.mjs (output byte-identical real vs empty HOME — fixable
findings are project-local HKV/RUL/SET, never SKL/COL),
lint-default-output (caller already uses withHermeticHome).
Suite 875/875, no snapshot drift. No test regressed under isolation,
confirming none had a hidden real-HOME dependency.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Ter3E2JSi1Khgmuf2kady8
This commit is contained in:
parent
66433fee48
commit
325182ddc9
4 changed files with 34 additions and 34 deletions
|
|
@ -5,6 +5,7 @@ import { fileURLToPath } from 'node:url';
|
|||
import { execFile } from 'node:child_process';
|
||||
import { promisify } from 'node:util';
|
||||
import { readFile, unlink } from 'node:fs/promises';
|
||||
import { hermeticEnv } from '../helpers/hermetic-home.mjs';
|
||||
|
||||
const exec = promisify(execFile);
|
||||
const __dirname = fileURLToPath(new URL('.', import.meta.url));
|
||||
|
|
@ -12,12 +13,16 @@ const REPO = resolve(__dirname, '../..');
|
|||
const CLI = resolve(REPO, 'scanners/token-hotspots-cli.mjs');
|
||||
const ORCH = resolve(REPO, 'scanners/scan-orchestrator.mjs');
|
||||
const FIXTURE = resolve(REPO, 'tests/fixtures/marketplace-large');
|
||||
// Isolate HOME: the scan-orchestrator run executes HOME-scoped SKL/COL, and
|
||||
// TOK reads the CLAUDE.md cascade (which includes ~/.claude). See hermetic-home.mjs.
|
||||
const ENV = hermeticEnv();
|
||||
|
||||
describe('token-hotspots-cli', () => {
|
||||
it('returns valid JSON with hotspots.length >= 3', async () => {
|
||||
const { stdout } = await exec('node', [CLI, FIXTURE, '--json'], {
|
||||
timeout: 30000,
|
||||
cwd: REPO,
|
||||
env: ENV,
|
||||
});
|
||||
const json = JSON.parse(stdout);
|
||||
assert.equal(json.scanner, 'TOK');
|
||||
|
|
@ -33,6 +38,7 @@ describe('token-hotspots-cli', () => {
|
|||
await exec('node', [CLI, FIXTURE, '--output-file', out], {
|
||||
timeout: 30000,
|
||||
cwd: REPO,
|
||||
env: ENV,
|
||||
});
|
||||
const written = await readFile(out, 'utf-8');
|
||||
const json = JSON.parse(written);
|
||||
|
|
@ -47,6 +53,7 @@ describe('token-hotspots-cli', () => {
|
|||
const { stdout } = await exec('node', [CLI, FIXTURE, '--json'], {
|
||||
timeout: 30000,
|
||||
cwd: REPO,
|
||||
env: ENV,
|
||||
});
|
||||
const json = JSON.parse(stdout);
|
||||
assert.equal(json.telemetry_recipe_path, undefined,
|
||||
|
|
@ -57,6 +64,7 @@ describe('token-hotspots-cli', () => {
|
|||
const { stdout } = await exec('node', [CLI, FIXTURE, '--json', '--with-telemetry-recipe'], {
|
||||
timeout: 30000,
|
||||
cwd: REPO,
|
||||
env: ENV,
|
||||
});
|
||||
const json = JSON.parse(stdout);
|
||||
assert.equal(typeof json.telemetry_recipe_path, 'string');
|
||||
|
|
@ -75,6 +83,7 @@ describe('scan-orchestrator integration — TOK hotspots survive envelope', () =
|
|||
await exec('node', [ORCH, FIXTURE, '--output-file', out], {
|
||||
timeout: 60000,
|
||||
cwd: REPO,
|
||||
env: ENV,
|
||||
});
|
||||
const written = await readFile(out, 'utf-8');
|
||||
const envelope = JSON.parse(written);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue