Skip to content

hardening: fault-inject CLI generation and filesystem updates #159

Description

@smiggleworth

Goal

Run a deeper, contract-driven edge-case pass for 0.5.0. The cases below are probes, not claims that defects are currently present.

Probe targets

Probe interrupted generation/update, failed directory swaps and rollback, pre-existing destinations, symlink and path traversal boundaries, malformed package/config input, and subprocess failures/timeouts. Verify the tool never leaves a partial project or deletes unrelated files when a staged operation fails.

Required outcome

  • Inspect current implementation and tests before adding cases; extend existing coverage instead of duplicating it.
  • Exercise relevant malformed/boundary inputs, ordering and repeated operations, failure/recovery, cancellation/cleanup, and cross-runtime or cross-package parity.
  • For each confirmed bug, keep a minimal reproducer and regression test with the fix. If the fix is too large or needs a product decision, file/link a separate bug issue with impact and release disposition.
  • Refactor only where the probes expose a fragile boundary, repeated work, or unclear ownership. The 0.5.0 API contraction is not a substitute for behavioral hardening.
  • Record the scenarios exercised, outcomes, changed tests/fixes, coverage evidence for the affected branches, and the repository's relevant validation commands. If the probe finds no bug, record the evidence and tested matrix.

A broad checklist without executed tests or source-backed findings does not complete this issue.

Initial invariant and test-gap assessment (2026-10-02)

Baseline: static inventory of test paths, scripts, and named cases on origin/develop. No suites were run and not every assertion body was inspected. Named tests are evidence signals, not proof of coverage; candidate gaps must be checked against assertions before being called missing.

Invariants and evidence

  • Check mode is observational and generated output changes atomically. Existing tests assert check-mode immutability, preservation of the old generated tree when backup rename fails, and a complete result under concurrent generation.
  • A failed multi-file update restores the prior state and path pivots are rejected. Tests inject a replacement failure and assert rollback, and reject symlink/remote-to-file pivots. These are strong existing signals; suite execution remains outstanding.

Candidate gaps to verify

Abrupt process termination between backup and publish, and failures during rollback/temporary-file cleanup. Probe platform-specific rename/permission behavior only where supported; do not repeat the current injected replacement and symlink cases.

Closure evidence: inspect and run the relevant assertions, then mark each invariant covered, partial, not evidenced, or not run. Add a minimal regression reproducer for every confirmed defect; record the exact command and outcome for a no-defect probe.

Activity

  1. added this to the 0.5.0 milestone on Oct 2, 2026
  2. smiggleworth commented on Oct 10, 2026

    @smiggleworth
    ContributorAuthor

    The implemented failure matrix is documented at the merged hardening review, with links to the actual assertions and recovery workers. Delivery spans #176, #177, #178, #179, #180, #181 and #182. Every confirmed defect retains its reproducer/regression; the immutable pre-fix evidence is archived in the consolidated 0.5.0 review packet.

    • Covered: failed multi-file writes/replacement/rollback/cleanup with original-byte preservation and retained recovery copies; directory publication recovery at three actual process-termination checkpoints; generator/create destination ownership and concurrent publication.
    • Covered: stale-owner/reaper/release races, ambiguous records, legacy recovery, junctions, preparation/cleanup failures, bounded Windows read observations and 200 contended publications. Native Windows failures on earlier merged commits remain recorded and are resolved by the later fixes.
    • Covered: malformed manifest/config/workspace inputs with exact-tree preservation and zero registry calls; local/remote path pivots, source limits, redirects, status/encoding errors, aborts and body deadlines. Five real local HTTPS rejection probes now close their sockets without further body writes.
    • Covered: real local installer processes for missing command, exit 23, external installer termination, CLI termination and success. Injected ETIMEDOUT result handling is also exercised. No automatic installer timeout exists or is claimed.
    • Partial, explicit recovery boundary: abrupt file-update termination retains originals for manual restoration; killing the CLI during installation retains unpublished private preparation for manual cleanup. Process checkpoints do not establish power-loss durability or cooperation with older recursive-lock implementations.

    Final source has 455 unit cases (450 plus five POSIX skips on Windows), normal packed imports under actual TypeScript 6.0.3/7.0.2, five normally installed starters, the peer floor, production audit, and all 22 unchanged performance gates. Parent-process coverage is 86.02% statements, 78.89% branches and 87.79% lines; lock-helper lines are 98.76%. Child-process fault assertions are separate from those coverage percentages. Initial #182 Windows fixture-cleanup EBUSY was corrected by awaiting inherited process handles; production source was unchanged by that correction.

    Closing this package hardening pass after exact PR and merged CI/CodeQL acceptance. The complete 0.5.0 package graph, examples/site, version/changelog preparation and maintainer full review remain separate release gates. No release tags or npm publication are authorized before that review.

    Exact acceptance: PR CI 38025715612, merged CI 38025888482, and merged CodeQL. PR and merge source trees are identical.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestpriority-p1Required for the 0.5.0 milestone

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions