A review of the group-E fixes found 13 further defects; ten were introduced by
those fixes, two pre-existed and were merely relocated, one is deferred.
Services / transport
E-10 retireWorker synthesized no bg/exit frame, so sharedspice's s_bgRunning
mirror stayed latched true after a mid-run worker death: Run stayed
disabled and the promised fresh-worker restart was unreachable for the
whole session. Retirement now dispatches a synthetic controlled-exit
straight to the installed handler (never through dispatchEvt — a
fabricated frame must not touch the credit ledger). Driving the repro
exposed two further defects, both fixed here: a replacement worker
trapped on pre-init engine reads, and the rerun's cm_input_path/circ hit
that uninitialized engine before KiCad's validate() re-init (the native
flow assumes a crashed engine survives in-process — true for the dll,
false for a dead worker). Reads now answer their empty shapes pre-init,
writes lazy-init, and init is idempotent per worker engine.
E-19 dispatchEvt acked only AFTER handler(evt) returned, and the sharedspice
client deliberately rethrows non-trap errors — so each throw leaked one
unit of the 64-frame credit window until the stream died with a
misattributed "transport exceeded". The ack moves to a finally in both
service copies; the throw still propagates (the trap machinery needs it).
E-20 the oversize-line path promises to transfer the accepted prefix, but
with the window full that flush only DEFERS, and stopEventStream wiped
the deferred queue — losing the diagnostics that explain the failure.
The terminal notice now carries them as pendingEvents; both hosts
deliver them in order, unacked (the fatal frame is outside the credit
protocol).
E-21 the 30s prefetch deadline discarded every model already collected and
reported nothing. A caller-owned progress sink ships the partials and
the omission reaches the export report. (Awaiting the aborted collection
was rejected: an in-flight source fetch is not abortable — E-4's
original disease.) Plus a serving-candidate memo, so a .wrl ref served
by its .step fallback stops re-probing the miss on every export.
Scheduler
E-14 _terminalizeNativeTrap classified by message substring, so any plain JS
error QUOTING 'Aborted(' or 'out of bounds' permanently bricked a
healthy instance. Now structural only: instanceof RuntimeError plus a
duck-typed name check (verified in this build's glue that abort() throws
a genuine RuntimeError both pre- and post-runtime-init). Module.onAbort
now latches the gate — the authoritative notification, previously
ignored.
E-15 the shim half: _pumpResume gates on terminal (catching wakes already
queued at latch time) and resolveWait refuses on terminal WITHOUT
consuming the entry, so a frame stays visibly parked rather than
resuming inside a trapped module.
E-16 the E-5 handler read the realm-global scheduler at dispatch instead of
its installing module's; also frees the per-line buffer on the non-trap
rethrow path.
E-11 get_vec trusted the worker's res.length over the transferred arrays.
Observed death shape: a 4 GiB std::vector threw an unhandled
std::length_error that exited the editor's main loop. Now clamped, with
the buffers freed on every failure path.
Guardrails (replacing two deferred refactors: e2e→production-code injection and
collapsing the four copies of the worker-lifecycle machinery)
E-18 the source contract asserted comment-string counts — rewording failed
CI while moving a guard outside its #ifdef passed. It now parses the
#ifdef regions and asserts on code.
service-stub-parity.ts pins what the four lifecycle copies must share:
credit-window equality parsed from source, the finally-ack, boot
deadlines, terminal-notice consumption. The transport numbers are now
single-sourced from the worker.
CI actually runs the gates: the web/standalone vitest suites (which had
NEVER run in CI), the reducer, the source contract and the parity tool —
with a NON_PLAYWRIGHT_GATES check so deleting a step re-fails the lint.
E-22 the e2e occ stub's 60s boot watchdog, deleted in a66e109, is restored in
the ngspice-stub shape with a wedgeNextBoot() repro hook.
Every behavioral fix has red-then-green evidence (the reds were captured first).
E-17 (a stale RUNNING cross-stamping the next run's generation under E-6's
transport deferral) is DEFERRED with its analysis recorded — a real fix needs
run identity on the bg frames.
Test hygiene: the dwell lint now requires the mandated ": <why>" and all 47 bare
markers carry their reason; three export-report dwells became modal-lease polls;
exact-ledger assertions became relative deltas; the dead data-wx-dom-id branch,
an unused fault hook and unused receipt plumbing are gone; abort scans, wx
dialog drivers, the sim harness and the vitest FakeWorker are each one copy now.
Bumps kicad and wxwidgets to their findings-group-e tips.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
109 lines
4.7 KiB
TypeScript
109 lines
4.7 KiB
TypeScript
/**
|
|
* Determinism guard for the e2e/kicad specs. Fails (exit 1) if a spec reintroduces a banned
|
|
* anti-pattern, so the flake we removed can't creep back. Run locally or in CI:
|
|
*
|
|
* npx tsx tools/lint-determinism.ts # gate (exit 1 on any violation)
|
|
* npm run lint:determinism
|
|
*
|
|
* Rules (scoped to *.spec.ts files):
|
|
* - no blind `waitForTimeout` — use waitUntil / expect.poll / a web-first assertion. A genuine
|
|
* interaction dwell (canvas/keyboard commit with no observable) is allowed IF the line or the
|
|
* line above carries a marker: `eslint-disable-line`, `documented`, or `dwell`.
|
|
* - no `toHaveScreenshot` — Playwright's inline pixel compare is retired; capture via stableShot()
|
|
* and let the offline tools/screenshots gate compare against tests/baseline-screenshots.
|
|
* - no `retries` in specs — retries live in the playwright config (and are 0).
|
|
* - no swallowed `.catch(() => {})` — let failures throw.
|
|
*/
|
|
import * as fs from 'fs';
|
|
import * as path from 'path';
|
|
|
|
const TESTS_ROOT = path.resolve(__dirname, '..');
|
|
const SPEC_DIRS = ['kicad', 'e2e', 'jspi', 'web'];
|
|
|
|
type Rule = {
|
|
name: string;
|
|
message: string;
|
|
hit: (line: string, prev: string) => boolean;
|
|
};
|
|
|
|
const marker = (s: string) => /eslint-disable|documented|dwell/i.test(s);
|
|
|
|
// The canonical dwell marker (tests/TESTING.md) is
|
|
// `// eslint-disable-line -- documented interaction dwell: <why>`
|
|
// — a marker without the `: <why>` is a blind sleep wearing the uniform.
|
|
const DWELL_MARKER = /documented interaction dwell/;
|
|
const DWELL_MARKER_WITH_WHY = /documented interaction dwell:\s*\S/;
|
|
const bareDwellMarker = (s: string) => DWELL_MARKER.test(s) && !DWELL_MARKER_WITH_WHY.test(s);
|
|
|
|
const RULES: Rule[] = [
|
|
{
|
|
name: 'no-blind-waitForTimeout',
|
|
message: 'blind waitForTimeout — use waitUntil/expect.poll/web-first assertion, or annotate a documented interaction dwell',
|
|
hit: (line, prev) => /\.waitForTimeout\s*\(/.test(line) && !marker(line) && !marker(prev),
|
|
},
|
|
{
|
|
name: 'dwell-marker-needs-why',
|
|
message: 'dwell marker without its reason — the mandated form is `// eslint-disable-line -- documented interaction dwell: <why>` (tests/TESTING.md)',
|
|
hit: (line, prev) => /\.waitForTimeout\s*\(/.test(line)
|
|
&& (bareDwellMarker(line) || (!DWELL_MARKER.test(line) && bareDwellMarker(prev))),
|
|
},
|
|
{
|
|
name: 'no-toHaveScreenshot',
|
|
message: 'toHaveScreenshot does inline pixel comparison — use stableShot() (offline gate)',
|
|
hit: (line) => /toHaveScreenshot/.test(line),
|
|
},
|
|
{
|
|
name: 'no-inline-retries',
|
|
message: 'retries belong in the playwright config (kept at 0), not in specs',
|
|
hit: (line) => /\bretries\s*:/.test(line) && !line.trimStart().startsWith('//') && !line.trimStart().startsWith('*'),
|
|
},
|
|
{
|
|
name: 'no-swallowed-catch',
|
|
message: 'swallowed .catch(() => {}) hides failures — let it throw, assert the tolerated outcome, or annotate why it is best-effort',
|
|
hit: (line, prev) => /\.catch\(\s*\(\s*\)\s*=>\s*\{\s*\}\s*\)/.test(line) && !marker(line) && !marker(prev),
|
|
},
|
|
];
|
|
|
|
function specFiles(dir: string): string[] {
|
|
const abs = path.join(TESTS_ROOT, dir);
|
|
if (!fs.existsSync(abs)) return [];
|
|
const out: string[] = [];
|
|
for (const entry of fs.readdirSync(abs, { withFileTypes: true })) {
|
|
const p = path.join(abs, entry.name);
|
|
if (entry.isDirectory()) out.push(...specFiles(path.join(dir, entry.name)));
|
|
else if (entry.name.endsWith('.spec.ts')) out.push(p);
|
|
}
|
|
return out;
|
|
}
|
|
|
|
const violations: { file: string; line: number; rule: string; message: string; text: string }[] = [];
|
|
const files = SPEC_DIRS.flatMap(specFiles);
|
|
|
|
for (const file of files) {
|
|
const lines = fs.readFileSync(file, 'utf8').split('\n');
|
|
lines.forEach((line, i) => {
|
|
const trimmed = line.trimStart();
|
|
// Skip pure-comment lines — they describe, they don't execute. (Markers on a real code
|
|
// line are still seen because rule.hit receives the full line, comment included.)
|
|
if (trimmed.startsWith('//') || trimmed.startsWith('*') || trimmed.startsWith('/*')) return;
|
|
const prev = i > 0 ? lines[i - 1] : '';
|
|
for (const rule of RULES) {
|
|
if (rule.hit(line, prev)) {
|
|
violations.push({ file: path.relative(TESTS_ROOT, file), line: i + 1, rule: rule.name, message: rule.message, text: line.trim() });
|
|
}
|
|
}
|
|
});
|
|
}
|
|
|
|
if (violations.length === 0) {
|
|
console.log(`✓ determinism guard: ${files.length} spec files clean`);
|
|
process.exit(0);
|
|
}
|
|
|
|
console.error(`✗ determinism guard: ${violations.length} violation(s) across ${files.length} spec files\n`);
|
|
for (const v of violations) {
|
|
console.error(` ${v.file}:${v.line} [${v.rule}]`);
|
|
console.error(` ${v.text}`);
|
|
console.error(` → ${v.message}\n`);
|
|
}
|
|
process.exit(1);
|