mirror of
https://github.com/garrytan/gbrain.git
synced 2026-07-27 22:15:33 +00:00
* fix(bootstrap): extend probes for files/oauth_clients/sources.archived* + add MIGRATIONS introspection guard Adds 7 new forward-reference probes to applyForwardReferenceBootstrap on both engines, closes the column-only forward-ref class via a new MIGRATIONS-source introspection contract test. New probes: - files.source_id + files.page_id (v18 forward refs) - oauth_clients.source_id + oauth_clients.federated_read (v60+v61+v65) - sources.archived + archived_at + archive_expires_at (v34 promoted from JSONB) The sources.archived* columns are the codex-flagged class: they're added inline in v34's CREATE TABLE definition but `CREATE TABLE IF NOT EXISTS sources` is a no-op on pre-v34 brains, so downstream visibility filters (search/list_pages) trip on old brains. needsPagesBootstrap now folds archive columns into its CREATE TABLE so pre-v0.18 brains get a v34-shape sources in one go; needsSourcesArchive then only fires on the pre-v34 case (sources exists, archive cols don't). Closes the structural bug class via test/helpers/extract-added-columns.ts: reads src/core/migrate.ts as text and extracts every ALTER TABLE ADD COLUMN. The new contract test asserts every (table, column) pair is covered by EITHER the bootstrap's ALTER TABLE statements, the bootstrap's CREATE TABLE definitions, OR the schema blob's CREATE TABLE bodies. The column-only class (no index, no FK; just an inline CREATE TABLE column the schema blob can't add to existing tables) is now caught at PR time. Source-text introspection catches all three migration shapes uniformly: - top-level `sql:` field - `sqlFor.postgres` / `sqlFor.pglite` overrides - handler-body `engine.runMigration(N, \`ALTER TABLE ...\`)` (v34 shape) Pre-existing parseBaseTableColumns parser bug fixed: now strips `--` line comments and `/* ... */` blocks before identifying column names. Without this, a column preceded by a comment was silently dropped. Catches pages.page_kind and others that were silently uncovered. 13 columns added by migrations but not in PGLITE_SCHEMA_SQL are exempted with a unified rationale: they have no schema-blob forward reference; migration handles all upgrade paths cleanly. Refreshing the schema blob is a separate concern. Issues closed: #1018 (v60 oauth_clients), #974 (files.source_id/page_id), #820 (v0.13.0 migration files.page_id cascade); pre-empts the sources.archived class before any pre-v34 brain trips on it. Tests: - 9 cases in test/schema-bootstrap-coverage.test.ts (5 existing + 4 new) - helper-level unit tests cover SQL shape variants (IF NOT EXISTS, quoted identifiers, ALTER TABLE IF EXISTS ONLY, multi-statement) - planted-bug regression verifies the gate actually catches new uncovered columns Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(orphans): filter soft-deleted pages on both candidate and link-source sides Closes #1021. The v0.26.5 soft-delete invariant requires that findOrphanPages exclude both: 1. Candidate pages that are themselves soft-deleted 2. Inbound links from soft-deleted source pages Pre-fix, findOrphanPages had no deleted_at filter at all. Soft-deleted pages with no inbound links were counted as orphans (inflating counts). Pre-codex-tension-D11, only the candidate-side filter was planned. Codex C11 caught the second case: a live page that has ONE inbound link from a soft-deleted source page was hidden from orphan results — the link still existed in the links table, the EXISTS subquery saw it, the page looked "linked." Now the inner JOIN on pages enforces src.deleted_at IS NULL. Three regression tests pin the contract: - soft-deleted page with no inbound → NOT orphan - live page with ONLY inbound link from soft-deleted source → IS orphan - live page with live inbound → NOT orphan (smoke check that the new filters don't break unchanged behavior) Engine parity: same SQL shape on both Postgres and PGLite engines. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(think): route runThink through gateway.chat adapter (closes #952) Pre-fix, runThink instantiated `new Anthropic()` directly and read ANTHROPIC_API_KEY from process.env. Claude Desktop's stdio MCP launch doesn't inherit shell env, so `gbrain config set anthropic_api_key sk-...` (writes to ~/.gbrain/config.json) never reached the SDK and every MCP think call degraded to "no LLM available." The adapter routes through gateway.chat() — the canonical seam per CLAUDE.md. Gateway reads the API key from gbrain config OR env, picks up prompt caching, rate-leases, retry, and the test seam (__setChatTransportForTests) that v0.31.12 established. Per plan-eng-review D10 (cross-model tension with codex C7+C8+C9+C10), four spec points landed: 1. Drop `new Anthropic()` direct path entirely. Every non-stub LLM call from runThink routes through gateway. 2. Real availability check (NOT a false-positive `getChatModel()` truthy). `tryBuildGatewayClient` probes both the recipe (resolveRecipe throws AIConfigError on unknown providers) AND the API key (reads process.env + loadConfig at the gbrain config layer for parity with gateway's own auth resolution). Returns null on miss; runThink takes the graceful "no LLM available" early-return preserving the legacy NO_ANTHROPIC_API_KEY warning signal. 3. Model-id normalization. resolveModel returns bare anthropic ids (claude-opus-4-7); gateway.chat needs provider:model. Adapter auto-prefixes anthropic: when the id is bare. Provider:model strings pass through unchanged. 4. Response-shape conversion. ChatResult → Anthropic.Message via chatResultToMessage. mapStopReason translates gateway's provider-neutral stop reasons (end / length / tool_calls / refusal / content_filter / other) to Anthropic's stop_reason ('end_turn' / 'max_tokens' / 'tool_use'); refusal/content_filter/other fall through to end_turn (no Anthropic equivalent). Usage tokens pass through. `opts.client` injection preserved (test seam — see ThinkLLMClient). `opts.stubResponse` preserved (pure-test escape). Tests: - test/think-gateway-adapter.test.ts (9 cases): response shape, stop reason mapping, model-id normalization (bare + prefixed), provider unknown returns null, ANTHROPIC_API_KEY absent returns null (regression for legacy graceful degradation), hasAnthropicKey reads process.env correctly. Uses withEnv per the test-isolation contract. - test/think-pipeline.serial.test.ts (17 existing cases): unchanged; the graceful-degradation case at line 213 still produces the NO_ANTHROPIC_API_KEY warning because tryBuildGatewayClient returns null when no key is configured, taking the legacy early-return path. Closes #952. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(sync): distinguish git worktree from submodule via path-segment match (closes #889) Pre-fix, `manageGitignore` treated every `.git`-as-file as a submodule and skipped gitignore management. Both submodules AND worktrees use `.git` as a file (not a directory), so the legacy `statSync.isFile()` check couldn't discriminate. Worktrees got misclassified as submodules and their .gitignore wasn't managed. Per plan-eng-review D4 (chose path-segment match over absolute-vs- relative path heuristic): the gitdir path contains: - `/modules/<name>` for submodules (skip — managed by parent repo) - `/worktrees/<name>` for worktrees (MANAGE — first-class repo) Both are documented Git internal layouts, stable across all 4 {relative, absolute} × {modules, worktrees} combinations including the absorbed-submodule edge case from `git submodule absorbgitdirs` (where the submodule's gitdir flips to an absolute path). Malformed `.git` file (no `gitdir:` prefix, IO error) → MANAGE, preserving the pre-#889 catch{} fail-closed-toward-managing semantics. Tests (5 new + 1 regression renamed): - REGRESSION: submodule relative gitdir/modules/ → skip (D49 contract) - absorbed submodule absolute gitdir/modules/ → skip (edge case) - CRITICAL: worktree absolute gitdir/worktrees/ → MANAGE (closes #889) - worktree relative gitdir/worktrees/ → MANAGE - malformed .git file → MANAGE (preserves catch behavior) - regular .git directory → MANAGE (existing smoke) Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(walkers): pruneDir helper + descent-time exclusion + transcript predicate (closes #923, #202) Per plan-eng-review D12 (cross-model tension with codex C12+C13), three structural changes: 1. Extract `pruneDir(name)` helper in src/core/sync.ts. Returns false for directory names walkers must NEVER descend into: `node_modules` (latent bug — no leading dot), dot-prefix dirs (`.git`, `.obsidian`, `.raw`, `.cache`, etc.), `ops`, and `*.raw` sidecar dirs (gbrain convention — `people/pedro.raw/` holds raw source for pedro.md). Walkers consult it at descent time BEFORE recursion, saving the IO cost of walking entire vendor / hidden / sidecar subtrees only to filter them at file-emit time. 2. `isSyncable` itself gains the same exclusion set (via pruneDir on each path segment). Closes the latent bug where node_modules markdown files slipped through: `node_modules/some-pkg/README.md` returned true pre-fix because the legacy dot-prefix check only blocked `.node_modules` (with a leading dot), not the actual `node_modules`. CRITICAL regression test in test/sync.test.ts pins the contract per IRON RULE. 3. Two walkers rewritten to use pruneDir at descent + per-walker file predicate at emit: - `walkMarkdownFiles` (src/commands/extract.ts): pruneDir + isSyncable ({strategy:'markdown'}). Pre-fix this walker had ONLY an ad-hoc dot-prefix exclusion and didn't call isSyncable at all — descended into node_modules, emitted markdown files from there, ignored README/ ops/.raw filters. - `listTextFiles` (src/core/cycle/transcript-discovery.ts): pruneDir + own .txt/.md predicate. DOES NOT use isSyncable({strategy:'markdown'}) because transcripts accept .txt and don't share markdown sync's README/ops exclusions (codex C12). Also made RECURSIVE — pre-fix it walked only the top dir, so transcripts in `corpus/2026/` were invisible (codex C14 — descent-time pruning is the right shape but the test would have passed vacuously on a non-recursive walker). Verified blast radius before adding node_modules: every existing isSyncable caller (sync.ts:558-561 sync filter, frontmatter.ts:264 validate, brain-writer.ts:305 reverse-write, import.ts:454 import filter) wants node_modules excluded — this is a latent-bug fix, not a behavior change for any legitimate caller. Tests: - 7 new isSyncable cases including the node_modules CRITICAL regression - 6 new pruneDir cases (node_modules, dot-prefix, ops, *.raw, content dirs that should pass, empty-string default) - Existing extract.test.ts + extract-fs.test.ts unchanged and passing Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs(todos): file v0.36.x follow-ups for runThink rewrite + Supabase bootstrap parity Two follow-up TODOs filed during the v0.36 dreamy-thompson wave: 1. runThink full rewrite (D5+D7 from plan-eng-review): drop the ThinkLLMClient indirection now that v0.36 routes through gateway.chat. 12+ tests need migration to __setChatTransportForTests. Blocked by this wave landing. 2. Supabase parity test for applyForwardReferenceBootstrap (codex C6 residual): real Docker Postgres E2E catches schema correctness but not Supabase pooler/direct-pool routing. The probe uses this.sql but PostgresEngine.initSchema chooses a DDL connection; the divergence has caused multiple historical wedges (#699, #820 lineage). Both entries include full context per the CLAUDE.md TODOS-format spec (what, why, pros, cons, blocked-by, plan reference). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * fix(bootstrap): thread DDL connection through applyForwardReferenceBootstrap Codex adversarial review during /ship caught a P1: initSchema selected a DDL connection, took pg_advisory_lock(42) on it, but applyForwardReferenceBootstrap used `this.sql` (the instance pool) inside. Bootstrap probes ran outside the lock scope on a different connection. Failure mode: two concurrent gbrain instances could BOTH enter the bootstrap block on Supabase transaction-pooler setups because the advisory lock was held on a different connection than the one running ALTER TABLE. The pooler's statement_timeout could also kill the probes mid-flight without affecting the lock-holder, leaving an inconsistent schema state. Fix: applyForwardReferenceBootstrap now accepts an optional connection parameter. initSchema passes the DDL conn (the one holding the lock). this.sql remains the fallback for any unit-test path that calls bootstrap directly. PGLite engine doesn't need this change — single connection, no pooler. This was pre-existing (every prior probe used this.sql), but the v0.36 wave is explicitly about fixing the Supabase upgrade-wedge class. Codex's position was correct: don't ship the wave with the underlying connection mismatch still there. The Supabase parity TEST FIXTURE follow-up remains on TODOS.md (test infra needed to PROVE the fix works under real pooler topology), but the bug itself is closed. 15/15 bootstrap tests pass. Typecheck clean. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * chore: bump version and changelog (v0.35.5.0) Six-correctness-fix wave: bootstrap forward-ref class (4 issues + 1 pre-empt), orphans soft-delete leak (both sides), runThink → gateway.chat adapter, git worktree vs submodule discriminator, walker pruneDir + descent-time exclusion, plus a Codex-P1 catch during /ship that threaded the DDL connection through applyForwardReferenceBootstrap. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> * docs: update CLAUDE.md for v0.35.5.0 backend correctness wave Fold v0.35.5.0 file-level annotations into CLAUDE.md: - postgres-engine.ts + pglite-engine.ts: 7 new applyForwardReferenceBootstrap probes (files.source_id/page_id, oauth_clients.source_id/federated_read, sources.archived/archived_at/archive_expires_at) + DDL connection threading - test/schema-bootstrap-coverage.test.ts: new MIGRATIONS-source introspection guard + parseBaseTableColumns comment-stripping fix - src/core/sync.ts: new pruneDir helper + manageGitignore worktree discriminator - src/core/think/index.ts (new entry): runThink gateway adapter for MCP stdio key resolution - src/core/operations.ts (new entry): findOrphanPages soft-delete filter Regenerate llms-full.txt via bun run build:llms. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
191 lines
7.0 KiB
TypeScript
191 lines
7.0 KiB
TypeScript
/**
|
|
* Tests for sync.ts manageGitignore() — step 8 of v0.22.3 storage tiering.
|
|
*
|
|
* Issue #2: function was defined but never invoked. Now wired into runSync
|
|
* after a successful sync (skips on dry_run / blocked_by_failures / failure).
|
|
*
|
|
* Tests cover: happy path, idempotency, GBRAIN_NO_GITIGNORE escape hatch,
|
|
* submodule detection, write-error graceful degradation, and the "no
|
|
* config — no-op" path.
|
|
*/
|
|
|
|
import { describe, test, expect, beforeEach, afterEach } from 'bun:test';
|
|
import { mkdtempSync, mkdirSync, rmSync, writeFileSync, readFileSync, existsSync, chmodSync, symlinkSync } from 'fs';
|
|
import { join } from 'path';
|
|
import { tmpdir } from 'os';
|
|
import { manageGitignore } from '../src/commands/sync.ts';
|
|
import { __resetMissingStorageWarning } from '../src/core/storage-config.ts';
|
|
|
|
let tmp: string;
|
|
let warnings: string[];
|
|
let originalWarn: typeof console.warn;
|
|
let originalEnv: string | undefined;
|
|
|
|
beforeEach(() => {
|
|
tmp = mkdtempSync(join(tmpdir(), 'gbrain-mgi-test-'));
|
|
__resetMissingStorageWarning();
|
|
warnings = [];
|
|
originalWarn = console.warn;
|
|
console.warn = (...args: unknown[]) => {
|
|
warnings.push(args.map(String).join(' '));
|
|
};
|
|
originalEnv = process.env.GBRAIN_NO_GITIGNORE;
|
|
delete process.env.GBRAIN_NO_GITIGNORE;
|
|
});
|
|
|
|
afterEach(() => {
|
|
console.warn = originalWarn;
|
|
if (originalEnv === undefined) delete process.env.GBRAIN_NO_GITIGNORE;
|
|
else process.env.GBRAIN_NO_GITIGNORE = originalEnv;
|
|
// Restore permissions for cleanup.
|
|
try {
|
|
chmodSync(tmp, 0o755);
|
|
} catch {
|
|
/* ignore */
|
|
}
|
|
rmSync(tmp, { recursive: true, force: true });
|
|
});
|
|
|
|
function writeStorageConfig(): void {
|
|
writeFileSync(
|
|
join(tmp, 'gbrain.yml'),
|
|
`storage:
|
|
db_tracked:
|
|
- people/
|
|
db_only:
|
|
- media/x/
|
|
- media/articles/
|
|
`,
|
|
);
|
|
}
|
|
|
|
describe('manageGitignore', () => {
|
|
test('no-op when gbrain.yml is absent', () => {
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(false);
|
|
expect(warnings).toEqual([]);
|
|
});
|
|
|
|
test('no-op when storage config has empty db_only', () => {
|
|
writeFileSync(
|
|
join(tmp, 'gbrain.yml'),
|
|
`storage:
|
|
db_tracked:
|
|
- people/
|
|
db_only: []
|
|
`,
|
|
);
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(false);
|
|
});
|
|
|
|
test('appends db_only directories to .gitignore — happy path', () => {
|
|
writeStorageConfig();
|
|
manageGitignore(tmp);
|
|
const content = readFileSync(join(tmp, '.gitignore'), 'utf-8');
|
|
expect(content).toContain('# Auto-managed by gbrain');
|
|
expect(content).toContain('media/x/');
|
|
expect(content).toContain('media/articles/');
|
|
});
|
|
|
|
test('idempotent — running twice does NOT duplicate entries', () => {
|
|
writeStorageConfig();
|
|
manageGitignore(tmp);
|
|
manageGitignore(tmp);
|
|
const content = readFileSync(join(tmp, '.gitignore'), 'utf-8');
|
|
const xCount = (content.match(/^media\/x\/$/gm) || []).length;
|
|
const articlesCount = (content.match(/^media\/articles\/$/gm) || []).length;
|
|
expect(xCount).toBe(1);
|
|
expect(articlesCount).toBe(1);
|
|
});
|
|
|
|
test('preserves user-written .gitignore entries', () => {
|
|
writeStorageConfig();
|
|
writeFileSync(join(tmp, '.gitignore'), '# my own rules\n*.swp\nnode_modules/\n');
|
|
manageGitignore(tmp);
|
|
const content = readFileSync(join(tmp, '.gitignore'), 'utf-8');
|
|
expect(content).toContain('# my own rules');
|
|
expect(content).toContain('*.swp');
|
|
expect(content).toContain('node_modules/');
|
|
expect(content).toContain('media/x/');
|
|
});
|
|
|
|
test('GBRAIN_NO_GITIGNORE=1 skips entirely', () => {
|
|
writeStorageConfig();
|
|
process.env.GBRAIN_NO_GITIGNORE = '1';
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(false);
|
|
});
|
|
|
|
test('skips with actionable warning when repo is a git submodule', () => {
|
|
writeStorageConfig();
|
|
// Submodule: .git is a file containing `gitdir: ...` instead of a directory.
|
|
writeFileSync(join(tmp, '.git'), 'gitdir: ../.git/modules/sub\n');
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(false);
|
|
expect(warnings.some((w) => /submodule/.test(w))).toBe(true);
|
|
});
|
|
|
|
test('proceeds when .git is a directory (regular repo)', () => {
|
|
writeStorageConfig();
|
|
mkdirSync(join(tmp, '.git'));
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(true);
|
|
expect(warnings.filter((w) => /submodule/.test(w))).toEqual([]);
|
|
});
|
|
|
|
test('warns and skips when .gitignore write fails (read-only filesystem simulation)', () => {
|
|
writeStorageConfig();
|
|
// Create a .gitignore as a directory — write to that path will fail with EISDIR.
|
|
mkdirSync(join(tmp, '.gitignore'));
|
|
manageGitignore(tmp);
|
|
expect(warnings.some((w) => /Could not (read|update)/.test(w))).toBe(true);
|
|
});
|
|
|
|
// ────────────────────────────────────────────────────────────────
|
|
// Worktree vs submodule discrimination (closes #889)
|
|
// ────────────────────────────────────────────────────────────────
|
|
|
|
test('REGRESSION: submodule with relative gitdir/modules/ → skip (D49 contract)', () => {
|
|
writeStorageConfig();
|
|
writeFileSync(join(tmp, '.git'), 'gitdir: ../.git/modules/sub\n');
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(false);
|
|
expect(warnings.some((w) => /submodule/.test(w))).toBe(true);
|
|
});
|
|
|
|
test('absorbed submodule with absolute gitdir/modules/ → skip (closes edge case)', () => {
|
|
writeStorageConfig();
|
|
// After `git submodule absorbgitdirs`, the gitdir path becomes absolute.
|
|
writeFileSync(join(tmp, '.git'), 'gitdir: /home/user/parent/.git/modules/sub\n');
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(false);
|
|
expect(warnings.some((w) => /submodule/.test(w))).toBe(true);
|
|
});
|
|
|
|
test('CRITICAL: worktree with absolute gitdir/worktrees/ → MANAGE (closes #889)', () => {
|
|
writeStorageConfig();
|
|
writeFileSync(join(tmp, '.git'), 'gitdir: /home/user/repo/.git/worktrees/feature-branch\n');
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(true);
|
|
expect(warnings.filter((w) => /submodule/.test(w))).toEqual([]);
|
|
});
|
|
|
|
test('worktree with relative gitdir/worktrees/ → MANAGE', () => {
|
|
writeStorageConfig();
|
|
writeFileSync(join(tmp, '.git'), 'gitdir: ../.git/worktrees/feature-branch\n');
|
|
manageGitignore(tmp);
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(true);
|
|
expect(warnings.filter((w) => /submodule/.test(w))).toEqual([]);
|
|
});
|
|
|
|
test('malformed .git file (no gitdir: prefix) → MANAGE (preserves catch behavior)', () => {
|
|
writeStorageConfig();
|
|
writeFileSync(join(tmp, '.git'), 'garbage content\n');
|
|
manageGitignore(tmp);
|
|
// No gitdir prefix → not a submodule → MANAGE.
|
|
expect(existsSync(join(tmp, '.gitignore'))).toBe(true);
|
|
expect(warnings.filter((w) => /submodule/.test(w))).toEqual([]);
|
|
});
|
|
});
|