run-gates.ts 67 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610
  1. /**
  2. * Run local and CI quality gates with bounded in-process scheduling.
  3. *
  4. * Package scripts own public aggregate names; this runner owns their validated
  5. * dependency graphs, scheduler environment, and process diagnostics.
  6. * @see ../.agents/notes/implemented/process/2026-07-06-parallel-pre-push-gates.md
  7. */
  8. import { spawn, spawnSync } from 'node:child_process'
  9. import { readdirSync, readFileSync } from 'node:fs'
  10. import { availableParallelism } from 'node:os'
  11. import { resolve } from 'node:path'
  12. import { performance } from 'node:perf_hooks'
  13. import { CLIENT_BUILD_PROFILE_SELECTOR } from './client-build-environment.ts'
  14. import { COVERAGE_EXEMPT_ENV, coverageExemptHeavySuites } from './coverage-exempt.ts'
  15. import {
  16. COVERAGE_PARTITIONS_ENV,
  17. COVERAGE_TEST_TIMEOUT_ENV,
  18. coverageTestTimeoutArgs,
  19. parseCoveragePartitionCount,
  20. } from './coverage-partitions.ts'
  21. import { pnpmInvocation } from './pnpm-invocation.ts'
  22. /** A named aggregate exposed by the gate runner. */
  23. export type Mode =
  24. | 'ci-primary'
  25. | 'ci-linux-primary'
  26. | 'ci-static'
  27. | 'ci-lint-contracts-ready'
  28. | 'ci-coverage'
  29. | 'ci-bench'
  30. | 'ci-snapshot'
  31. | 'ci-artifacts'
  32. | 'ci-consumers'
  33. | 'ci-windows-blocking'
  34. | 'ci-windows-complete'
  35. | 'ci-windows-observational'
  36. | 'node-compat'
  37. | 'check-all'
  38. | 'hygiene'
  39. | 'doc-sync'
  40. | 'doc-quick'
  41. type GateResultStatus = 'passed' | 'failed' | 'skipped'
  42. type GateState = 'pending' | 'running' | GateResultStatus
  43. /** A command and its dependency metadata inside one aggregate. */
  44. export interface Gate {
  45. id: string
  46. label: string
  47. displayCommand: string
  48. command: string
  49. args: string[]
  50. needs?: string[]
  51. /** Gate ids that must settle, regardless of outcome, before this gate starts. */
  52. after?: string[]
  53. env?: Record<string, string | undefined>
  54. /** Include this leaf in the build-free documentation aggregate. */
  55. quick?: boolean
  56. /** Keep a failure visible without failing the aggregate. */
  57. allowFailure?: boolean
  58. /** Write child output as it arrives instead of buffering it until completion. */
  59. streamOutput?: boolean
  60. }
  61. /** The observed outcome of one gate process. */
  62. export interface GateResult {
  63. gate: Gate
  64. status: GateResultStatus
  65. durationMs: number
  66. output: GateOutputChunk[]
  67. exitCode: number | null
  68. signalCode: NodeJS.Signals | null
  69. error?: string
  70. /** True when the shared abort signal terminated this gate before its outcome
  71. * was observed; such a result must not be reported as passed, even if the
  72. * child trapped the signal and exited zero. */
  73. aborted?: boolean
  74. }
  75. interface GateOutputChunk {
  76. stream: 'stdout' | 'stderr'
  77. text: string
  78. }
  79. interface RunningGate {
  80. gate: Gate
  81. promise: Promise<GateResult>
  82. }
  83. interface ConcurrencyDefault {
  84. workers: number
  85. source: string
  86. }
  87. type GateExecutor = (gate: Gate, signal?: AbortSignal) => Promise<GateResult>
  88. type ResultObserver = (result: GateResult) => void
  89. const root = resolve(import.meta.dirname, '..')
  90. if (import.meta.main) {
  91. process.exitCode = await main(process.argv.slice(2))
  92. }
  93. async function main(args: string[]): Promise<number> {
  94. const mode = parseMode(args[0])
  95. const gates = gatesForMode(mode)
  96. const concurrencyDefault = defaultConcurrency(mode, gates.length)
  97. const concurrencyOverride = process.env.DSH_GATE_CONCURRENCY
  98. const maxConcurrency = concurrencyFromEnv('DSH_GATE_CONCURRENCY', concurrencyDefault.workers)
  99. const concurrencySource = concurrencyOverride === undefined || concurrencyOverride === ''
  100. ? concurrencyDefault.source
  101. : '$DSH_GATE_CONCURRENCY'
  102. const failFast = flagEnabled('DSH_GATE_FAIL_FAST')
  103. const startedAt = performance.now()
  104. console.log(`run-gates: ${mode} running ${gates.length} gate(s) with ${maxConcurrency} worker(s) from ${concurrencySource}${failFast ? ', fail-fast after first blocking failure' : ''}.`)
  105. const results = await runGates(gates, maxConcurrency, runGate, printResult, cliGateOptions(failFast))
  106. printSummary(results, performance.now() - startedAt)
  107. return results.some(result => result.gate.allowFailure !== true && (result.status === 'failed' || result.status === 'skipped'))
  108. ? 1
  109. : 0
  110. }
  111. /**
  112. * The options the CLI entrypoint hands to the scheduler. Host signal
  113. * forwarding always follows fail-fast: children are detached only then, so
  114. * without it the forwarding would have no tree to drain.
  115. * @param failFast - whether `DSH_GATE_FAIL_FAST` is enabled.
  116. * @returns the scheduler options for the entrypoint.
  117. */
  118. export function cliGateOptions(failFast: boolean): RunGatesOptions {
  119. return { failFast, forwardProcessSignals: failFast }
  120. }
  121. function parseMode(raw: string | undefined): Mode {
  122. switch (raw) {
  123. case 'ci-primary':
  124. case 'ci-linux-primary':
  125. case 'ci-static':
  126. case 'ci-lint-contracts-ready':
  127. case 'ci-coverage':
  128. case 'ci-bench':
  129. case 'ci-snapshot':
  130. case 'ci-artifacts':
  131. case 'ci-consumers':
  132. case 'ci-windows-blocking':
  133. case 'ci-windows-complete':
  134. case 'ci-windows-observational':
  135. case 'node-compat':
  136. case 'check-all':
  137. case 'hygiene':
  138. case 'doc-sync':
  139. case 'doc-quick':
  140. return raw
  141. default:
  142. throw new Error(
  143. `run-gates: expected mode ci-primary | ci-linux-primary | ci-static | ci-lint-contracts-ready | ci-coverage | ci-bench | ci-snapshot | ci-artifacts | ci-consumers | ci-windows-blocking | ci-windows-complete | ci-windows-observational | node-compat | check-all | hygiene | doc-sync | doc-quick, got ${JSON.stringify(raw)}.`,
  144. )
  145. }
  146. }
  147. /**
  148. * Resolve the default worker count for one aggregate.
  149. * @param selectedMode - aggregate whose resource posture applies.
  150. * @param total - number of gates in the aggregate.
  151. * @param available - host CPU availability for ordinary modes.
  152. * @returns the default worker count and its diagnostic source.
  153. */
  154. export function defaultConcurrency(
  155. selectedMode: Mode,
  156. total: number,
  157. available = availableParallelism(),
  158. ): ConcurrencyDefault {
  159. if (selectedMode === 'ci-consumers') return { workers: total, source: 'ci-consumers gate count' }
  160. // Local modes cap workers: several doc gates each build a full ts.Program,
  161. // so an uncapped default on a large host trades wall clock for memory blowups.
  162. const localCap = selectedMode === 'check-all'
  163. || selectedMode === 'hygiene'
  164. || selectedMode === 'doc-sync'
  165. || selectedMode === 'doc-quick'
  166. const modeLimit = localCap ? Math.min(4, available) : available
  167. return {
  168. workers: Math.min(total, modeLimit),
  169. source: localCap
  170. ? `${available} available CPU(s), ${selectedMode} cap 4`
  171. : `${available} available CPU(s)`,
  172. }
  173. }
  174. function concurrencyFromEnv(name: string, fallback: number): number {
  175. const raw = process.env[name]
  176. if (raw === undefined || raw === '') return fallback
  177. const parsed = Number.parseInt(raw, 10)
  178. if (!Number.isSafeInteger(parsed) || parsed < 1) {
  179. throw new Error(`run-gates: ${name} must be a positive integer, got ${JSON.stringify(raw)}.`)
  180. }
  181. return parsed
  182. }
  183. function pnpmScript(id: string, script: string, options: Partial<Gate> = {}): Gate {
  184. return {
  185. id,
  186. label: options.label ?? script,
  187. displayCommand: `pnpm run ${script}`,
  188. ...pnpmInvocation(['run', script]),
  189. ...options,
  190. }
  191. }
  192. /** Build official client artifacts inside a CI aggregate without changing sibling gate environments. */
  193. function ciBuildGate(id = 'build', options: Partial<Gate> = {}): Gate {
  194. return pnpmScript(id, 'build', {
  195. ...options,
  196. env: { ...options.env, [CLIENT_BUILD_PROFILE_SELECTOR]: 'official' },
  197. })
  198. }
  199. function pnpmExec(id: string, args: string[], options: Partial<Gate> = {}): Gate {
  200. return {
  201. id,
  202. label: options.label ?? `pnpm exec ${args.join(' ')}`,
  203. displayCommand: `pnpm exec ${args.join(' ')}`,
  204. ...pnpmInvocation(['exec', ...args]),
  205. ...options,
  206. }
  207. }
  208. /**
  209. * Construct the complete gate list for a named aggregate.
  210. * @param selected - aggregate mode to construct.
  211. * @returns the aggregate's gate graph.
  212. */
  213. export function gatesForMode(selected: Mode): Gate[] {
  214. switch (selected) {
  215. case 'ci-primary':
  216. return ciPrimaryGates()
  217. case 'ci-linux-primary':
  218. return [...ciPrimaryGates(), webSnapshotGate(['built-package-invariants'])]
  219. case 'ci-static':
  220. return ciStaticGates({ ownsBuild: false })
  221. case 'ci-lint-contracts-ready':
  222. return [
  223. lintGate(),
  224. pnpmScript('duplication', 'duplication'),
  225. ]
  226. case 'ci-coverage':
  227. return coverageGates()
  228. case 'ci-bench':
  229. return [pnpmScript('bench', 'test:bench', { label: 'performance benchmarks' })]
  230. case 'ci-snapshot':
  231. return [ciBuildGate(), snapshotGate()]
  232. case 'ci-artifacts':
  233. return ciArtifactGates()
  234. case 'ci-consumers':
  235. return ciConsumerGates()
  236. case 'ci-windows-blocking':
  237. return ciWindowsBlockingGates()
  238. case 'ci-windows-complete':
  239. return ciWindowsCompleteGates()
  240. case 'ci-windows-observational':
  241. return ciWindowsObservationalGates()
  242. case 'node-compat':
  243. return nodeCompatGates()
  244. case 'check-all':
  245. return [
  246. pnpmScript('runtime-closure', 'verify-runtime-closure', { label: 'runtime closure' }),
  247. pnpmScript('cordis-config', 'verify-cordis-config', { label: 'Cordis config' }),
  248. pnpmScript('client-domain-graph', 'verify-client-domain-graph', { label: 'client domain graph' }),
  249. pnpmScript('test', 'test'),
  250. pnpmScript('approval-policy', 'test:approval-policy', { label: 'Weighted approval policy' }),
  251. pnpmScript('issue-management', 'test:issue-management', { label: 'Issue management policy' }),
  252. pnpmScript('duplication', 'duplication'),
  253. snapshotGate(),
  254. expectedOutputGate(),
  255. pnpmScript('build', 'build'),
  256. pnpmScript('build:web', 'build:web'),
  257. ...hygieneLeafGates({ artifactNeeds: ['build'] }),
  258. ...docSyncLeafGates({
  259. docTypecheckNeeds: ['build'],
  260. docTypecheckEnv: { DSH_DOC_TYPECHECK_USE_BUILD_OUTPUT: '1' },
  261. docTypecheckScript: 'doc-typecheck:contracts-ready',
  262. }),
  263. pnpmScript('module-graph', 'verify-module-graph', { label: 'module graph' }),
  264. ]
  265. case 'hygiene':
  266. return [
  267. ...hygieneLeafGates(),
  268. pnpmScript('cordis-config', 'verify-cordis-config', { label: 'Cordis config' }),
  269. pnpmScript('runtime-closure', 'verify-runtime-closure', { label: 'runtime closure' }),
  270. ]
  271. case 'doc-sync':
  272. return docSyncLeafGates()
  273. case 'doc-quick':
  274. return docQuickLeafGates()
  275. }
  276. }
  277. function ciSharedStaticGates(): Gate[] {
  278. return [
  279. pnpmScript('runtime-closure', 'verify-runtime-closure', { label: 'runtime closure' }),
  280. pnpmScript('default-product-isolation', 'verify-default-product-isolation', { label: 'default product isolation' }),
  281. pnpmScript('application-entrypoints', 'verify-application-entrypoints', { label: 'application entrypoints' }),
  282. pnpmScript('constraints', 'constraints'),
  283. pnpmScript('package-dependencies', 'verify-package-dependencies', { label: 'package dependencies' }),
  284. pnpmScript('dsh-package-licenses', 'verify-dsh-package-licenses', { label: 'DSH package licenses' }),
  285. pnpmScript('package-invariants', 'verify-package-invariants', { label: 'package invariants' }),
  286. pnpmScript('cordis-config', 'verify-cordis-config', { label: 'Cordis config' }),
  287. pnpmScript('optional-dependency-imports', 'verify-optional-dependency-imports', {
  288. label: 'optional dependency imports',
  289. }),
  290. pnpmScript('client-packages', 'verify-client-packages', { label: 'client packages' }),
  291. pnpmScript('client-ui-i18n', 'verify-client-ui-i18n', { label: 'client UI i18n' }),
  292. pnpmScript('no-bare-dispatcher', 'verify-no-bare-dispatcher', { label: 'proxy-aware dispatchers' }),
  293. pnpmScript('approval-policy', 'test:approval-policy', { label: 'Weighted approval policy' }),
  294. pnpmScript('issue-management', 'test:issue-management', { label: 'Issue management policy' }),
  295. ]
  296. }
  297. function ciPrimaryGates(): Gate[] {
  298. return [
  299. ...ciSharedStaticGates(),
  300. typertContractsGate(),
  301. pnpmScript('typecheck', 'typecheck:contracts-ready', { needs: ['typert-contracts'] }),
  302. lintGate({ needs: ['typert-contracts'] }),
  303. pnpmScript('duplication', 'duplication'),
  304. ...coverageGates(),
  305. ...nodeCompatSmokeGates(),
  306. snapshotGate(),
  307. ...docSyncLeafGates({
  308. docTypecheckNeeds: ['typert-contracts'],
  309. docTypecheckScript: 'doc-typecheck:contracts-ready',
  310. }),
  311. pnpmScript('module-graph', 'verify-module-graph', { label: 'module graph' }),
  312. // The prepared typecheck and build both drive Client tsc, while build also
  313. // repeats the Host contract pass. Wait for all three consumers so build
  314. // neither races tsbuildinfo nor replaces declarations while they are read.
  315. ciBuildGate('build', { needs: ['typecheck', 'lint', 'doc-typecheck'] }),
  316. pnpmScript('publint', 'publint', { needs: ['build'] }),
  317. pnpmScript('node-next-types', 'verify-node-next-types', {
  318. label: 'node-next types',
  319. needs: ['build'],
  320. }),
  321. builtPackageInvariantsGate(['build']),
  322. builtBinSmokeGate(),
  323. ]
  324. }
  325. function nodeCompatGates(): Gate[] {
  326. const typecheck = flagEnabled('DSH_NODE_COMPAT_SKIP_TYPECHECK')
  327. ? []
  328. : [pnpmScript('typecheck', 'typecheck')]
  329. if (runningNodeMajor() !== 22) {
  330. return [...typecheck, ...nodeCompatSmokeGates()]
  331. }
  332. return [
  333. ...typecheck,
  334. pnpmScript('build', 'build', {
  335. ...typecheck.length === 0 ? {} : { needs: ['typecheck'] },
  336. }),
  337. pnpmScript('build:web', 'build:web', {
  338. label: 'Web frontend build',
  339. needs: ['build'],
  340. }),
  341. ...nodeCompatSmokeGates({ cliSmoke: true }),
  342. ]
  343. }
  344. function nodeCompatSmokeGates(options: { cliSmoke?: boolean } = {}): Gate[] {
  345. const gates: Gate[] = [
  346. pnpmExec('source-worker-smoke', [
  347. 'vitest',
  348. 'run',
  349. 'packages/workflow/workflow-ptc/tests/source-runtime.compat.spec.ts',
  350. ], { label: 'source worker smoke' }),
  351. pnpmExec('jsonl-zstd-smoke', [
  352. 'vitest',
  353. 'run',
  354. 'packages/session/session-persistence-jsonl/tests/zstd.compat.spec.ts',
  355. ], { label: 'JSONL Zstandard smoke' }),
  356. pnpmExec('dsh-source-launch-smoke', [
  357. 'vitest',
  358. 'run',
  359. 'apps/cli/tests/source-launch.compat.spec.ts',
  360. ], { label: 'dsh source-launch smoke' }),
  361. pnpmExec('vitest-jsdom-smoke', [
  362. 'vitest',
  363. 'run',
  364. 'scripts/vitest-environment.compat.spec.ts',
  365. ], { label: 'Vitest jsdom smoke' }),
  366. pnpmExec('profile-resolution-smoke', [
  367. 'vitest',
  368. 'run',
  369. 'packages/boot/app-boot/tests/profile-resolution.spec.ts',
  370. 'packages/boot/app-boot/tests/profile-resolution-service.spec.ts',
  371. 'packages/boot/app-boot/tests/profile-resolution-worker-bootstrap.spec.ts',
  372. ], { label: 'profile resolution smoke' }),
  373. ]
  374. if (options.cliSmoke) {
  375. gates.push(
  376. pnpmExec('cli-lazy-search-startup-smoke', [
  377. 'vitest',
  378. 'run',
  379. 'apps/cli/tests/lazy-search-startup.compat.spec.ts',
  380. ], {
  381. label: 'CLI lazy-search startup smoke',
  382. env: { DSH_REQUIRE_BUILT_CLI_SMOKE: '1' },
  383. needs: ['build:web'],
  384. }),
  385. )
  386. }
  387. return gates
  388. }
  389. /** Active Node major used to select version-specific compatibility checks. */
  390. function runningNodeMajor(): number {
  391. const major = Number.parseInt(process.versions.node.split('.')[0] ?? '', 10)
  392. if (!Number.isSafeInteger(major)) {
  393. throw new Error(`run-gates: cannot parse Node version ${JSON.stringify(process.versions.node)}.`)
  394. }
  395. return major
  396. }
  397. function ciStaticGates(options: { ownsBuild: boolean }): Gate[] {
  398. return [
  399. ...ciSharedStaticGates(),
  400. ...options.ownsBuild ? [ciBuildGate()] : [],
  401. ...docSyncLeafGates({
  402. includeDocTypecheck: options.ownsBuild,
  403. ...options.ownsBuild
  404. ? {
  405. docTypecheckNeeds: ['build'],
  406. docTypecheckEnv: { DSH_DOC_TYPECHECK_USE_BUILD_OUTPUT: '1' },
  407. docTypecheckScript: 'doc-typecheck:contracts-ready',
  408. }
  409. : {},
  410. docsBuildScript: 'docs:build:mpa',
  411. }),
  412. pnpmScript('module-graph', 'verify-module-graph', { label: 'module graph' }),
  413. ]
  414. }
  415. function ciArtifactGates(): Gate[] {
  416. return [
  417. ciBuildGate(),
  418. pnpmScript('publint', 'publint', { needs: ['build'] }),
  419. pnpmScript('node-next-types', 'verify-node-next-types', {
  420. label: 'node-next types',
  421. needs: ['build'],
  422. }),
  423. builtPackageInvariantsGate(['build']),
  424. builtBinSmokeGate(),
  425. ]
  426. }
  427. function ciConsumerGates(): Gate[] {
  428. const builtTree = ['build']
  429. const validatedBuild = ['built-package-invariants']
  430. // The HMR web test starts `dev:web`, which rewrites the shared `lib/` and
  431. // `apps/web/dist/` trees. Let every build-artifact reader settle before that
  432. // writer starts; `after` preserves the web diagnostic even if a reader fails.
  433. const buildArtifactReaders = [
  434. 'publint',
  435. 'lint-and-duplication',
  436. 'snapshot',
  437. 'expected-output',
  438. 'doc-typecheck',
  439. 'node-next-types',
  440. 'built-bin-smoke',
  441. ]
  442. return [
  443. ciBuildGate(),
  444. pnpmScript('node-compat', 'check:node-compat', {
  445. label: 'Node compatibility',
  446. env: { [CLIENT_BUILD_PROFILE_SELECTOR]: 'official' },
  447. }),
  448. pnpmScript('publint', 'publint', { needs: builtTree }),
  449. builtPackageInvariantsGate(builtTree),
  450. pnpmScript('lint-and-duplication', 'check:ci:lint:contracts-ready', {
  451. label: 'lint and duplication',
  452. needs: validatedBuild,
  453. }),
  454. snapshotGate(validatedBuild),
  455. expectedOutputGate(validatedBuild),
  456. webSnapshotGate(validatedBuild, buildArtifactReaders),
  457. pnpmScript('doc-typecheck', 'doc-typecheck:contracts-ready', {
  458. needs: validatedBuild,
  459. env: { DSH_DOC_TYPECHECK_USE_BUILD_OUTPUT: '1' },
  460. }),
  461. pnpmScript('node-next-types', 'verify-node-next-types', {
  462. label: 'node-next types',
  463. needs: validatedBuild,
  464. }),
  465. builtBinSmokeGate(validatedBuild),
  466. ]
  467. }
  468. function webSnapshotGate(needs: string[], after?: string[]): Gate {
  469. const order = after === undefined ? { needs } : { needs, after }
  470. const workerRaw = process.env.DSH_WEB_SNAPSHOT_WORKERS
  471. if (workerRaw !== undefined && workerRaw !== '') {
  472. const workers = Number.parseInt(workerRaw, 10)
  473. if (!Number.isSafeInteger(workers) || workers < 2 || String(workers) !== workerRaw) {
  474. throw new Error(`run-gates: DSH_WEB_SNAPSHOT_WORKERS must be an integer greater than 1, got ${JSON.stringify(workerRaw)}.`)
  475. }
  476. return pnpmScript('web-snapshot', 'test:web:ci', {
  477. label: 'web browser snapshot',
  478. displayCommand: `DSH_SNAPSHOT=replay DSH_WEB_SNAPSHOT_WORKERS=${workers} pnpm run test:web:ci`,
  479. env: { DSH_SNAPSHOT: 'replay' },
  480. ...order,
  481. streamOutput: true,
  482. })
  483. }
  484. return pnpmScript('web-snapshot', 'test:web:built', {
  485. label: 'web browser snapshot',
  486. displayCommand: 'DSH_SNAPSHOT=replay pnpm run test:web:built',
  487. env: { DSH_SNAPSHOT: 'replay' },
  488. ...order,
  489. })
  490. }
  491. function ciWindowsBlockingGates(): Gate[] {
  492. return [
  493. ciBuildGate('windows-build', { label: 'build' }),
  494. pnpmScript('windows-site', 'docs:build', { label: 'production site' }),
  495. ]
  496. }
  497. function ciWindowsCompleteGates(): Gate[] {
  498. const coverage = coverageGates().map(gate => ({
  499. ...gate,
  500. needs: [...new Set(['build', ...(gate.needs ?? [])])],
  501. }))
  502. const coverageAfter = coverage.map(gate => gate.id)
  503. const observational = ciWindowsObservationalGates()
  504. // The required production site replaces the observational MPA build; both
  505. // VitePress modes write the same output directory and cannot overlap.
  506. .filter(gate => gate.id !== 'build' && gate.id !== 'docs-site-build')
  507. .map(gate => ({
  508. ...gate,
  509. allowFailure: true,
  510. after: [...new Set([
  511. ...coverageAfter,
  512. ...(gate.after ?? []).map(id => id === 'docs-site-build' ? 'windows-site' : id),
  513. ])],
  514. }))
  515. return [
  516. ciBuildGate(),
  517. pnpmScript('windows-site', 'docs:build', { label: 'production site' }),
  518. ...coverage,
  519. ...observational,
  520. ]
  521. }
  522. function ciWindowsObservationalGates(): Gate[] {
  523. const predecessors = [
  524. ...ciStaticGates({ ownsBuild: true }),
  525. // Linux owns required lint and snapshots; Windows omits those duplicates.
  526. pnpmScript('duplication', 'duplication'),
  527. pnpmScript('publint', 'publint', { needs: ['build'] }),
  528. pnpmScript('node-next-types', 'verify-node-next-types', {
  529. label: 'node-next types',
  530. needs: ['build'],
  531. }),
  532. builtPackageInvariantsGate(['build']),
  533. ]
  534. return [
  535. ...predecessors,
  536. {
  537. ...builtBinSmokeGate(),
  538. // This smoke starts real application children with bounded startup
  539. // deadlines. Let other Windows processes settle before measuring startup.
  540. after: predecessors.map(gate => gate.id),
  541. },
  542. ]
  543. }
  544. function typertContractsGate(): Gate {
  545. return pnpmScript('typert-contracts', 'build:lib:host', { label: 'Typert contracts' })
  546. }
  547. function lintGate(options: { needs?: string[] } = {}): Gate {
  548. const raw = process.env.DSH_OXLINT_THREADS
  549. const script = 'lint:contracts-ready'
  550. return pnpmScript('lint', script, {
  551. ...raw === undefined || raw === ''
  552. ? {}
  553. : { displayCommand: `DSH_OXLINT_THREADS=${raw} pnpm run ${script}` },
  554. ...options.needs === undefined ? {} : { needs: options.needs },
  555. })
  556. }
  557. // The heavy suites run uninstrumented beside the thresholded gate: their
  558. // compiler- and subprocess-bound fixtures pay a multiple of their runtime
  559. // under v8 instrumentation while contributing nothing the thresholds need
  560. // (membership rules in scripts/coverage-exempt.ts).
  561. //
  562. // DSH_COVERAGE_MAX_WORKERS is the ordinary lane's worker budget, so the two
  563. // parallel gates split it instead of each claiming it whole. When
  564. // DSH_COVERAGE_PARTITIONS is set, its single-worker processes replace the
  565. // instrumented share while this budget still sizes the exempt gate. The exempt
  566. // gate's wall clock is dominated by its longest single file, so it takes the
  567. // small share. A budget of 1 gives each gate 1 worker; lanes that need a strict
  568. // total of one (the serial reference jobs) also set DSH_GATE_CONCURRENCY=1,
  569. // which keeps the gates from overlapping at all.
  570. // DSH_COVERAGE_TEST_TIMEOUT_MS raises Vitest's per-test, expect.poll, and hook
  571. // defaults together for instrumented lanes whose scheduling overhead exceeds
  572. // those defaults. Explicit fixture timeouts remain authoritative.
  573. function coverageWorkerArgs(): { instrumented: string[]; exempt: string[] } {
  574. const [flag] = positiveIntArg('DSH_COVERAGE_MAX_WORKERS', '--maxWorkers')
  575. if (flag === undefined) return { instrumented: [], exempt: [] }
  576. const total = Number.parseInt(flag.split('=')[1] ?? '', 10)
  577. const exempt = Math.max(1, Math.floor(total / 3))
  578. const instrumented = Math.max(1, total - exempt)
  579. return {
  580. instrumented: [`--maxWorkers=${String(instrumented)}`],
  581. exempt: [`--maxWorkers=${String(exempt)}`],
  582. }
  583. }
  584. function coverageGates(): Gate[] {
  585. const workers = coverageWorkerArgs()
  586. const timeouts = coverageTestTimeoutArgs(process.env[COVERAGE_TEST_TIMEOUT_ENV])
  587. const partitions = parseCoveragePartitionCount(process.env[COVERAGE_PARTITIONS_ENV])
  588. const instrumented = partitions === undefined
  589. ? pnpmExec('coverage', [
  590. 'vitest',
  591. 'run',
  592. '--coverage',
  593. ...workers.instrumented,
  594. ...timeouts,
  595. ], {
  596. label: 'test:coverage',
  597. env: { [COVERAGE_EXEMPT_ENV]: '1' },
  598. })
  599. : pnpmScript('coverage', 'test:coverage:partitioned', {
  600. label: 'test:coverage',
  601. displayCommand: `${COVERAGE_PARTITIONS_ENV}=${partitions} pnpm run test:coverage:partitioned`,
  602. env: { [COVERAGE_EXEMPT_ENV]: '1' },
  603. streamOutput: true,
  604. })
  605. return [
  606. pnpmScript('native-system', 'build:native-system'),
  607. { ...instrumented, needs: ['native-system'] },
  608. pnpmExec('coverage-exempt-heavy', [
  609. 'vitest',
  610. 'run',
  611. ...coverageExemptHeavySuites.map(suite => suite.filter),
  612. ...workers.exempt,
  613. ...timeouts,
  614. ], {
  615. label: 'test:coverage-exempt-heavy',
  616. needs: ['native-system'],
  617. }),
  618. ]
  619. }
  620. // Recorded-session adapters boot process scenarios in `lib` mode. Callers wait
  621. // either on `build` or on a validation gate that transitively owns that build.
  622. function snapshotGate(needs: string[] = ['build']): Gate {
  623. return pnpmScript('snapshot', 'test:snapshot', {
  624. env: { DSH_EXAMPLE_MODE: 'lib' },
  625. needs,
  626. })
  627. }
  628. // Owner-local process expectations consume built package exports without entering
  629. // the recorded-session corpus or the credentialed provider lane.
  630. function expectedOutputGate(needs: string[] = ['build']): Gate {
  631. return pnpmScript('expected-output', 'test:expected', {
  632. env: { DSH_EXAMPLE_MODE: 'lib' },
  633. needs,
  634. })
  635. }
  636. function builtPackageInvariantsGate(needs?: string[]): Gate {
  637. return pnpmScript('built-package-invariants', 'verify-built-package-invariants', {
  638. label: 'built package invariants',
  639. ...needs === undefined ? {} : { needs },
  640. })
  641. }
  642. function positiveIntArg(envName: string, flag: string): string[] {
  643. const raw = process.env[envName]
  644. if (raw === undefined || raw === '') return []
  645. const parsed = Number.parseInt(raw, 10)
  646. if (!Number.isSafeInteger(parsed) || parsed < 1 || String(parsed) !== raw) {
  647. throw new Error(`run-gates: ${envName} must be a positive integer, got ${JSON.stringify(raw)}.`)
  648. }
  649. return [`${flag}=${raw}`]
  650. }
  651. function flagEnabled(envName: string): boolean {
  652. const raw = process.env[envName]
  653. if (raw === undefined || raw === '') return false
  654. if (raw !== '1') throw new Error(`run-gates: ${envName} must be 1 when set, got ${JSON.stringify(raw)}.`)
  655. return true
  656. }
  657. function hygieneLeafGates(options: { artifactNeeds?: string[] } = {}): Gate[] {
  658. const artifactOptions = options.artifactNeeds === undefined ? {} : { needs: options.artifactNeeds }
  659. return [
  660. pnpmScript('rescope-vendor', 'rescope-vendor:check', { label: 'vendor rescope' }),
  661. pnpmScript('publint', 'publint', artifactOptions),
  662. pnpmScript('constraints', 'constraints'),
  663. pnpmScript('default-product-isolation', 'verify-default-product-isolation', { label: 'default product isolation' }),
  664. pnpmScript('package-dependencies', 'verify-package-dependencies', { label: 'package dependencies' }),
  665. pnpmScript('application-entrypoints', 'verify-application-entrypoints', { label: 'application entrypoints' }),
  666. pnpmScript('dsh-package-licenses', 'verify-dsh-package-licenses', { label: 'DSH package licenses' }),
  667. pnpmScript('package-invariants', 'verify-package-invariants', { label: 'package invariants' }),
  668. builtPackageInvariantsGate(options.artifactNeeds),
  669. pnpmScript('node-next-types', 'verify-node-next-types', {
  670. label: 'node-next types',
  671. ...artifactOptions,
  672. }),
  673. pnpmScript('optional-dependency-imports', 'verify-optional-dependency-imports', {
  674. label: 'optional dependency imports',
  675. }),
  676. pnpmScript('client-packages', 'verify-client-packages', { label: 'client packages' }),
  677. pnpmScript('client-ui-i18n', 'verify-client-ui-i18n', { label: 'client UI i18n' }),
  678. pnpmScript('no-bare-dispatcher', 'verify-no-bare-dispatcher', { label: 'proxy-aware dispatchers' }),
  679. ]
  680. }
  681. function docSyncLeafGates(options: {
  682. includeDocTypecheck?: boolean
  683. docTypecheckNeeds?: string[]
  684. docTypecheckEnv?: Record<string, string | undefined>
  685. docTypecheckScript?: 'doc-typecheck' | 'doc-typecheck:contracts-ready'
  686. docsBuildScript?: 'docs:build' | 'docs:build:mpa'
  687. } = {}): Gate[] {
  688. const docTypecheckOptions: Partial<Gate> = {}
  689. if (options.docTypecheckNeeds !== undefined) docTypecheckOptions.needs = options.docTypecheckNeeds
  690. if (options.docTypecheckEnv !== undefined) docTypecheckOptions.env = options.docTypecheckEnv
  691. return [
  692. // Stable FIFO starts the longest leaves first; only docs-site-build writes website/.generated.
  693. ...options.includeDocTypecheck === false
  694. ? []
  695. : [pnpmScript('doc-typecheck', options.docTypecheckScript ?? 'doc-typecheck', docTypecheckOptions)],
  696. pnpmScript('docs-site-build', options.docsBuildScript ?? 'docs:build', { label: 'documentation build' }),
  697. pnpmScript('doc-graphs', 'verify-doc-graphs', { label: 'doc graphs' }),
  698. pnpmScript('markdown-links', 'verify-md-links', { label: 'markdown links', quick: true }),
  699. pnpmScript('type-equivalence', 'verify-type-equiv', { label: 'type equivalence', quick: true }),
  700. pnpmScript('cordis-catalog', 'verify-cordis-catalog', { label: 'cordis catalog' }),
  701. pnpmScript('cordis-inspect-catalog', 'verify-cordis-inspect-catalog', { label: 'Cordis inspect catalog' }),
  702. pnpmScript('workflow-guest', 'verify-workflow-guest', { label: 'workflow guest source' }),
  703. pnpmScript('mermaid', 'verify-mermaid'),
  704. pnpmScript('scoped-events', 'verify-scoped-events', { label: 'scoped events' }),
  705. pnpmScript('translation-pairing', 'verify-translation-pairing', { label: 'translation pairing', quick: true }),
  706. pnpmScript('markdown-wrap', 'verify-md-wrap', { label: 'markdown wrap', quick: true }),
  707. pnpmScript('client-catalog', 'verify-client-catalog', { label: 'client catalog' }),
  708. pnpmScript('export-jsdoc', 'verify-export-jsdoc', { label: 'export jsdoc' }),
  709. pnpmScript('tool-catalog', 'verify-tool-catalog', { label: 'tool catalog' }),
  710. pnpmScript('config-catalog', 'verify-config-catalog', { label: 'config catalog' }),
  711. pnpmScript('dependency-catalog', 'verify-dependency-catalog', { label: 'npm dependency catalog', quick: true }),
  712. pnpmScript('persistence-catalog', 'verify-persistence-catalog', { label: 'persistence catalog' }),
  713. pnpmScript('persistence-changes', 'verify-persistence-changes', { label: 'persistence type history' }),
  714. pnpmScript('persistence-releases', 'verify-persistence-releases', { label: 'released persistence history' }),
  715. pnpmScript('persistence-formats', 'verify-persistence-formats', { label: 'Session format references', quick: true }),
  716. pnpmScript('session-format-catalog', 'verify-session-format-catalog', { label: 'Session format catalog' }),
  717. pnpmScript('public-repository-links', 'verify-public-repository-links', { label: 'public repository links', quick: true }),
  718. pnpmScript('repository-references', 'verify-repository-references', { label: 'repository references', quick: true }),
  719. pnpmScript('concrete-terms', 'verify-concrete-terms', { label: 'concrete terms', quick: true }),
  720. pnpmScript('doc-refs', 'verify-doc-refs', { label: 'doc refs', quick: true }),
  721. pnpmScript('subsystem-pages', 'verify-subsystem-pages', { label: 'subsystem pages' }),
  722. pnpmScript('package-paths', 'verify-package-paths', { label: 'package paths' }),
  723. pnpmScript('tsconfig-paths', 'verify-tsconfig-paths', { label: 'tsconfig paths' }),
  724. pnpmScript('config-source-ownership', 'verify-config-source-ownership', { label: 'config source ownership' }),
  725. pnpmScript('package-readme-summaries', 'verify-package-readme-summaries', { label: 'package README Summaries', quick: true }),
  726. pnpmScript('package-readme-model-experience', 'verify-package-readme-model-experience', { label: 'package README model experience', quick: true }),
  727. pnpmScript('agent-note-classification', 'verify-agent-note-classification', { label: 'agent note classification', quick: true }),
  728. pnpmScript('agent-note-format', 'verify-agent-note-format', { label: 'agent note format', quick: true }),
  729. pnpmScript('archived-agent-notes', 'verify-archived-agent-notes', { label: 'archived agent notes', quick: true }),
  730. pnpmScript('skill-invocation-metadata', 'verify-skill-invocation-metadata', { label: 'skill invocation metadata', quick: true }),
  731. pnpmScript('translation-prompt', 'verify-translation-prompt', { label: 'translation prompt', quick: true }),
  732. pnpmScript('doc-budgets', 'verify-doc-budgets', { label: 'doc budgets', quick: true }),
  733. pnpmExec('doc-standard-tests', ['vitest', 'run', 'scripts/doc-standard.spec.ts'], {
  734. label: 'documentation standard tests',
  735. quick: true,
  736. }),
  737. pnpmExec('docs-site-projection', [
  738. 'vitest', 'run', 'scripts/project-doc-site.spec.ts', 'scripts/verify-doc-site-fragments.spec.ts',
  739. 'website/tests/mermaid-viewer.spec.ts',
  740. 'website/tests/code-groups.spec.ts',
  741. 'website/tests/page-markdown-actions.spec.ts', 'website/tests/raw-markdown.spec.ts',
  742. ], {
  743. label: 'documentation site checks',
  744. }),
  745. pnpmScript('package-readme-limitations', 'verify-package-readme-limitations', { label: 'package README limitations', quick: true }),
  746. ]
  747. }
  748. /**
  749. * The quick comprehensive documentation-standard aggregate for `test:docs`.
  750. * It covers the prose, pairing, README, budget, and Agent Note gates
  751. * without builds, generator regeneration, or the VitePress site build.
  752. */
  753. function docQuickLeafGates(): Gate[] {
  754. return docSyncLeafGates({ includeDocTypecheck: false }).filter(gate => gate.quick === true)
  755. }
  756. function builtBinSmokeGate(needs: string[] = ['build']): Gate {
  757. return pnpmExec('built-bin-smoke', [
  758. 'vitest',
  759. 'run',
  760. '--config',
  761. 'vitest.e2e.config.ts',
  762. 'apps/cli/tests/profiles/headless/tests/keyless-smoke.e2e.ts',
  763. 'apps/cli/tests/built-bin.e2e.ts',
  764. 'packages/host/directory-picker-native/tests/built-worker.e2e.ts',
  765. 'packages/sdk/server/tests/built-scope-carrier.e2e.ts',
  766. 'packages/deliverables/tool-present/tests/built-errors.e2e.ts',
  767. 'packages/subprocess/subprocess-local/tests/spawn-runner-built.e2e.ts',
  768. 'packages/subagent/subagent-codex/tests/loader-composition.e2e.ts',
  769. 'packages/subagent/subagent-claude-code/tests/loader-composition.e2e.ts',
  770. 'packages/api/remotes/tests/built-lib.e2e.ts',
  771. 'packages/experimental/agent-team/tests/built-lib.e2e.ts',
  772. // Built execution consumers: the only automated proof that package-name
  773. // imports reach their lib/ entrypoints under plain Node. The e2e lane runs
  774. // unbuilt, so these files self-skip there.
  775. 'packages/workflow/workflow-ptc/tests/built-runtime.e2e.ts',
  776. 'packages/ptc-runtime/ptc-runtime-node/tests/built-lib.e2e.ts',
  777. 'packages/session/session-persistence-jsonl/tests/built-migration-worker.e2e.ts',
  778. 'packages/lsp/lsp-stdio/tests/built-lib.e2e.ts',
  779. ], {
  780. label: 'built-bin smoke',
  781. needs,
  782. env: { DSH_EXAMPLE_MODE: 'lib' },
  783. })
  784. }
  785. /**
  786. * Reject a gate list whose graph cannot be executed unambiguously.
  787. * @param gates - complete aggregate to validate.
  788. */
  789. function validateGateGraph(gates: readonly Gate[]): void {
  790. if (gates.length === 0) throw new Error('run-gates: gate graph has no gates.')
  791. const ids = new Set<string>()
  792. for (const gate of gates) {
  793. if (ids.has(gate.id)) throw new Error(`run-gates: duplicate gate id ${JSON.stringify(gate.id)}.`)
  794. ids.add(gate.id)
  795. }
  796. for (const gate of gates) {
  797. for (const dependency of gate.needs ?? []) {
  798. if (!ids.has(dependency)) {
  799. throw new Error(`run-gates: gate ${JSON.stringify(gate.id)} depends on unknown gate ${JSON.stringify(dependency)}.`)
  800. }
  801. }
  802. for (const predecessor of gate.after ?? []) {
  803. if (!ids.has(predecessor)) {
  804. throw new Error(`run-gates: gate ${JSON.stringify(gate.id)} waits for unknown gate ${JSON.stringify(predecessor)}.`)
  805. }
  806. }
  807. }
  808. const cycle = findDependencyCycle(gates)
  809. if (cycle !== undefined) throw new Error(`run-gates: dependency cycle: ${cycle.join(' -> ')}.`)
  810. }
  811. function findDependencyCycle(gates: readonly Gate[]): string[] | undefined {
  812. const byId = new Map(gates.map(gate => [gate.id, gate]))
  813. const complete = new Set<string>()
  814. const active = new Map<string, number>()
  815. const path: string[] = []
  816. const visit = (id: string): string[] | undefined => {
  817. if (complete.has(id)) return undefined
  818. const cycleStart = active.get(id)
  819. if (cycleStart !== undefined) return [...path.slice(cycleStart), id]
  820. const gate = byId.get(id)
  821. if (gate === undefined) return undefined
  822. active.set(id, path.length)
  823. path.push(id)
  824. for (const predecessor of [...(gate.needs ?? []), ...(gate.after ?? [])]) {
  825. const cycle = visit(predecessor)
  826. if (cycle !== undefined) return cycle
  827. }
  828. path.pop()
  829. active.delete(id)
  830. complete.add(id)
  831. return undefined
  832. }
  833. for (const gate of gates) {
  834. const cycle = visit(gate.id)
  835. if (cycle !== undefined) return cycle
  836. }
  837. return undefined
  838. }
  839. /**
  840. * Scheduling options for one aggregate.
  841. */
  842. export interface RunGatesOptions {
  843. /** Stop the aggregate at the first blocking gate failure. */
  844. failFast?: boolean
  845. /** Forward host SIGINT/SIGTERM to the abort path so detached gate trees are
  846. * terminated when the run itself is interrupted or the runner cancels it.
  847. * Tree termination additionally requires failFast, because only then is the
  848. * abort signal passed to the executor and children detached. */
  849. forwardProcessSignals?: boolean
  850. }
  851. /**
  852. * Validate and run one aggregate before the injected executor can start a child.
  853. * @param gates - complete aggregate to execute.
  854. * @param maxActive - maximum concurrent child count.
  855. * @param execute - child-process executor; receives the abort signal only when
  856. * fail-fast is enabled, so ordinary runs keep their children in the host
  857. * process group.
  858. * @param observe - result observer invoked when each gate settles.
  859. * @param options - scheduling options; fail-fast aborts the aggregate at the
  860. * first blocking gate failure by killing running children and skipping every
  861. * not-yet-run gate.
  862. * @returns results in aggregate order.
  863. */
  864. export async function runGates(
  865. gates: Gate[],
  866. maxActive: number,
  867. execute: GateExecutor,
  868. observe: ResultObserver = () => {},
  869. options: RunGatesOptions = {},
  870. ): Promise<GateResult[]> {
  871. validateGateGraph(gates)
  872. if (!Number.isSafeInteger(maxActive) || maxActive < 1) {
  873. throw new Error(`run-gates: max concurrency must be a positive integer, got ${JSON.stringify(maxActive)}.`)
  874. }
  875. if (options.forwardProcessSignals === true && options.failFast !== true) {
  876. throw new Error('run-gates: forwardProcessSignals requires failFast, otherwise no child is detached or killed.')
  877. }
  878. const states = new Map<string, GateState>(gates.map(gate => [gate.id, 'pending']))
  879. const results = new Map<string, GateResult>()
  880. const running: RunningGate[] = []
  881. const abort = new AbortController()
  882. let abortCause: string | undefined
  883. // Host interruption (terminal Ctrl+C, runner cancellation) drains through
  884. // the same abort path as a gate failure, so detached trees are killed and
  885. // never orphaned. Handlers are removed before returning.
  886. const hostSignals = options.forwardProcessSignals === true ? ['SIGINT', 'SIGTERM'] as const : []
  887. const hostHandlers = hostSignals.map((name) => {
  888. const handler = () => {
  889. abortCause = abortCause ?? 'host interruption'
  890. abort.abort()
  891. }
  892. process.on(name, handler)
  893. return { name, handler }
  894. })
  895. const failFastSignal = options.failFast === true ? abort.signal : undefined
  896. try {
  897. for (;;) {
  898. let madeProgress = false
  899. if (abortCause === undefined) {
  900. while (running.length < maxActive) {
  901. const ready = gates.find(gate => states.get(gate.id) === 'pending' && predecessorsReady(gate, states))
  902. if (ready === undefined) break
  903. states.set(ready.id, 'running')
  904. running.push({ gate: ready, promise: execute(ready, failFastSignal) })
  905. console.log(`run-gates: start ${ready.label}`)
  906. madeProgress = true
  907. }
  908. }
  909. if (running.length === 0) {
  910. if (abortCause !== undefined) {
  911. for (const gate of gates) {
  912. if (states.get(gate.id) !== 'pending') continue
  913. const skipped = skippedByFailFast(gate, abortCause)
  914. states.set(gate.id, 'skipped')
  915. results.set(gate.id, skipped)
  916. observe(skipped)
  917. }
  918. break
  919. }
  920. const pending = gates.filter(gate => states.get(gate.id) === 'pending')
  921. if (pending.length === 0) break
  922. const gate = pending.find(item => (item.needs ?? []).some(id => gateFailed(states.get(id))))
  923. if (gate === undefined) throw new Error('run-gates: validated graph stalled without a failed dependency.')
  924. const failedDeps = (gate.needs ?? []).filter(id => gateFailed(states.get(id)))
  925. const result: GateResult = {
  926. gate,
  927. status: 'skipped',
  928. durationMs: 0,
  929. output: [],
  930. exitCode: null,
  931. signalCode: null,
  932. error: `dependency failed or skipped: ${failedDeps.join(', ')}`,
  933. }
  934. states.set(gate.id, 'skipped')
  935. results.set(gate.id, result)
  936. observe(result)
  937. continue
  938. }
  939. if (!madeProgress) {
  940. const settled = await Promise.race(running.map(async item => ({ item, result: await item.promise })))
  941. running.splice(running.indexOf(settled.item), 1)
  942. const observed = abortCause === undefined || settled.result.aborted !== true
  943. ? settled.result
  944. : skippedByFailFast(settled.item.gate, abortCause)
  945. states.set(settled.item.gate.id, observed.status)
  946. results.set(settled.item.gate.id, observed)
  947. observe(observed)
  948. if (abortCause === undefined && options.failFast === true
  949. && observed.status === 'failed' && settled.item.gate.allowFailure !== true) {
  950. abortCause = `${observed.gate.label} failed`
  951. abort.abort()
  952. console.error(`run-gates: fail-fast aborting: ${abortCause}.`)
  953. for (const gate of gates) {
  954. if (states.get(gate.id) !== 'pending') continue
  955. const skipped = skippedByFailFast(gate, abortCause)
  956. states.set(gate.id, 'skipped')
  957. results.set(gate.id, skipped)
  958. observe(skipped)
  959. }
  960. }
  961. }
  962. }
  963. } finally {
  964. for (const { name, handler } of hostHandlers) process.removeListener(name, handler)
  965. }
  966. return gates.map((gate) => {
  967. const result = results.get(gate.id)
  968. if (result === undefined) throw new Error(`run-gates: missing result for ${gate.id}.`)
  969. return result
  970. })
  971. }
  972. /**
  973. * The result of a gate that produced no evidence because fail-fast aborted.
  974. * A gate whose process settled before the abort took effect keeps its real
  975. * result instead: it did produce evidence, and the summary must say so. Any
  976. * result settling after the abort — including a genuine independent failure
  977. * in the race window, and a child that trapped the signal and exited zero —
  978. * is recorded skipped with its partial output discarded, because on Windows a
  979. * killed process is indistinguishable from a failed one by exit code alone.
  980. * @param gate - the gate that produced no evidence.
  981. * @param cause - the full clause naming what aborted the aggregate, e.g.
  982. * `typecheck failed` or `host interruption`.
  983. * @returns the skipped record with the fail-fast error.
  984. */
  985. function skippedByFailFast(gate: Gate, cause: string): GateResult {
  986. return {
  987. gate,
  988. status: 'skipped',
  989. durationMs: 0,
  990. output: [],
  991. exitCode: null,
  992. signalCode: null,
  993. error: `aborted by fail-fast: ${cause}`,
  994. }
  995. }
  996. function predecessorsReady(gate: Gate, states: Map<string, GateState>): boolean {
  997. return (gate.needs ?? []).every(id => states.get(id) === 'passed')
  998. && (gate.after ?? []).every(id => gateSettled(states.get(id)))
  999. }
  1000. function gateSettled(state: GateState | undefined): boolean {
  1001. return state === 'passed' || state === 'failed' || state === 'skipped'
  1002. }
  1003. function gateFailed(state: GateState | undefined): boolean {
  1004. return state === 'failed' || state === 'skipped'
  1005. }
  1006. /**
  1007. * Execute one gate through the real shell-free child-process boundary.
  1008. * @param gate - command and scheduler environment to execute.
  1009. * @param signal - abort signal that terminates the whole gate process tree when
  1010. * the aggregate fails fast; an already-aborted signal terminates it
  1011. * immediately. A provided signal spawns the child detached so POSIX can signal
  1012. * its process group and Windows can reach its tree through taskkill.
  1013. * @returns the complete process outcome.
  1014. */
  1015. export async function runGate(gate: Gate, signal?: AbortSignal): Promise<GateResult> {
  1016. const started = performance.now()
  1017. const output: GateOutputChunk[] = []
  1018. let spawnError: string | undefined
  1019. let aborted = false
  1020. const outcome = await new Promise<{
  1021. exitCode: number | null
  1022. signalCode: NodeJS.Signals | null
  1023. }>((resolveExit) => {
  1024. const child = spawn(gate.command, gate.args, {
  1025. cwd: root,
  1026. env: { ...process.env, ...gate.env },
  1027. stdio: ['pipe', 'pipe', 'pipe'],
  1028. detached: signal !== undefined && process.platform !== 'win32',
  1029. })
  1030. child.stdout.setEncoding('utf8')
  1031. child.stderr.setEncoding('utf8')
  1032. child.stdout.on('data', (chunk: string) => {
  1033. if (gate.streamOutput === true) process.stdout.write(chunk)
  1034. else output.push({ stream: 'stdout', text: chunk })
  1035. })
  1036. child.stderr.on('data', (chunk: string) => {
  1037. if (gate.streamOutput === true) process.stderr.write(chunk)
  1038. else output.push({ stream: 'stderr', text: chunk })
  1039. })
  1040. // Deliver one signal to the entire gate tree: the negative pid targets the
  1041. // POSIX process group the detached child leads; Windows has no groups, so
  1042. // taskkill walks the tree rooted at the child and force-terminates (a
  1043. // taskkill without `/F` does not terminate console processes, which is
  1044. // what gate commands are). Outcomes are deliberately unchecked because
  1045. // delivery races tree exit, and a missing taskkill binary is as tolerable
  1046. // as ESRCH. Mirrors the subprocess package's teardown contract
  1047. // (packages/subprocess/subprocess-local/src/spawn.ts).
  1048. const treeKill = (signalToSend: 'SIGTERM' | 'SIGKILL') => {
  1049. const pid = child.pid
  1050. if (pid === undefined) return
  1051. if (process.platform === 'win32') {
  1052. for (const args of taskkillArgs(pid, descendants)) {
  1053. spawnSync('taskkill', args, { stdio: 'ignore' })
  1054. }
  1055. return
  1056. }
  1057. try {
  1058. process.kill(-pid, signalToSend)
  1059. } catch {
  1060. // The group is gone; the direct child may still be alive alone.
  1061. child.kill(signalToSend)
  1062. }
  1063. // The captured list stays valid after the group kill reparents the
  1064. // detached descendants of a nested run-gates (the `check:node-compat`
  1065. // and `check:ci:lint:contracts-ready` gates in ci-consumers): pids do
  1066. // not change on reparenting, so the escalation reaches leaves that
  1067. // ignored SIGTERM without re-enumerating.
  1068. for (const descendantPid of descendants) {
  1069. try {
  1070. process.kill(descendantPid, signalToSend)
  1071. } catch {
  1072. // The descendant exited between the enumeration and the signal.
  1073. }
  1074. }
  1075. }
  1076. let escalation: ReturnType<typeof setTimeout> | undefined
  1077. let terminatedAt = 0
  1078. // Captured once at terminate and re-signalled on escalation: the group
  1079. // kill reaps the direct child, after which its detached descendants are
  1080. // reparented and unreachable by parent id, so the escalation cannot
  1081. // re-enumerate them.
  1082. let descendants: number[] = []
  1083. let pipeDrain: ReturnType<typeof setTimeout> | undefined
  1084. const terminate = () => {
  1085. aborted = true
  1086. const pid = child.pid
  1087. // Merge while the child is still alive: re-enumerating alone would drop
  1088. // a descendant that an exited intermediate reparented out of the parent
  1089. // chain, and replacing the list entirely would lose the sampler's
  1090. // last-known entries when the child already exited. Union preserves both.
  1091. // The sampler runs on every platform (including Windows, where an
  1092. // exited intermediate's table record vanishes and a fresh enumeration
  1093. // cannot cross the gap), so the cache is the source of truth once the
  1094. // child is gone.
  1095. if (pid !== undefined && child.exitCode === null && child.signalCode === null) {
  1096. descendants = [...new Set([...descendants, ...descendantPids(pid)])]
  1097. }
  1098. treeKill('SIGTERM')
  1099. if (escalation === undefined) {
  1100. terminatedAt = Date.now()
  1101. // Force-kill at the deadline regardless of the direct child's exit
  1102. // state: when the wrapper dies but a grandchild ignores SIGTERM and
  1103. // still holds the stdio pipes, `close` has not fired and the tree must
  1104. // still be killed. treeKill swallows an already-absent group.
  1105. escalation = setTimeout(() => { treeKill('SIGKILL') }, 5000)
  1106. }
  1107. if (pipeDrain === undefined) {
  1108. // `close` can stay pending past the direct child's exit when a
  1109. // descendant holds the stdio write ends (escaped process group, or
  1110. // uninterruptible I/O that keeps the SIGKILL pending). Bound the wait
  1111. // past the 5-second SIGKILL grace and force the streams closed so
  1112. // fail-fast settles instead of hanging to the job timeout. Only the
  1113. // abort path arms it: on an ordinary run a gate that outlives its
  1114. // descendants must keep waiting rather than report passed over a live
  1115. // leak. Armed in terminate (not only at `exit`) so the window where
  1116. // the child already exited before the abort is covered too.
  1117. pipeDrain = setTimeout(() => {
  1118. child.stdout.destroy()
  1119. child.stderr.destroy()
  1120. child.stdin.destroy()
  1121. }, 10000)
  1122. }
  1123. }
  1124. if (signal !== undefined) {
  1125. if (signal.aborted) terminate()
  1126. else signal.addEventListener('abort', terminate, { once: true })
  1127. }
  1128. // Refresh the descendant cache while the child runs, so an abort that
  1129. // arrives after the child already exited can still reach a detached
  1130. // descendant the child left behind: once the child is gone, its
  1131. // descendants are reparented (POSIX) or their intermediate's table record
  1132. // is gone (Windows), so a fresh enumeration cannot cross the gap. The
  1133. // cache is primed at spawn and refreshed every 5 seconds, so a descendant
  1134. // is captured once it appears in any enumeration whose parent chain is
  1135. // still fully present in the table; the residual window is a descendant
  1136. // that never appears in such a snapshot — created after one enumeration
  1137. // and orphaned before the next. Enumeration is asynchronous (a slow
  1138. // WMI/CIM call is bounded by its own 10-second timeout), so a gate's
  1139. // output draining and exit handling are never blocked while the sampler
  1140. // reads the process table. Fail-fast runs only; ordinary runs never
  1141. // abort.
  1142. let descendantSampler: ReturnType<typeof setInterval> | undefined
  1143. if (signal !== undefined) {
  1144. let enumerationInFlight: { cancel: () => void } | undefined
  1145. const refreshDescendants = () => {
  1146. const pid = child.pid
  1147. if (pid === undefined || child.exitCode !== null || child.signalCode !== null) return
  1148. if (enumerationInFlight !== undefined) return
  1149. const handle = descendantPidsAsync(pid, process.platform)
  1150. enumerationInFlight = handle
  1151. void handle.promise.then((fresh) => {
  1152. if (enumerationInFlight === handle) enumerationInFlight = undefined
  1153. // Merge regardless of the child's exit state: the enumeration
  1154. // started while the child was alive, so its snapshot is the last
  1155. // reliable view of the tree. The child may exit (its intermediate
  1156. // gone, its table record vanished) before the promise settles while
  1157. // a grandchild still holds the stdio write ends and keeps `close`
  1158. // pending — exactly when terminate needs this list.
  1159. // Merge instead of replacing, like terminate: an intermediate that
  1160. // exited since the last tick reparented its detached descendants
  1161. // out of the parent chain, so a fresh enumeration alone would drop
  1162. // them. Filter the cache to the still-executing so a long gate
  1163. // does not accumulate stale pids; while sampler ticks still run the
  1164. // live filter also keeps the escalation from signalling a reused
  1165. // pid, but once ticks stop (child exited) the cache can go stale,
  1166. // and a pid reused after that is the accepted sampling window.
  1167. descendants = [...new Set([...descendants.filter(processAlive), ...fresh])]
  1168. })
  1169. }
  1170. const cancelInFlightEnumeration = () => {
  1171. if (enumerationInFlight !== undefined) enumerationInFlight.cancel()
  1172. enumerationInFlight = undefined
  1173. }
  1174. refreshDescendants()
  1175. descendantSampler = setInterval(refreshDescendants, 5000)
  1176. // A gate that settles while an enumeration is still running must not
  1177. // leave the PowerShell subprocess holding stdio handles until its own
  1178. // timeout: stop it as soon as the child's outcome is known.
  1179. child.once('close', cancelInFlightEnumeration)
  1180. child.once('error', cancelInFlightEnumeration)
  1181. }
  1182. child.on('error', (error) => {
  1183. if (escalation !== undefined) clearTimeout(escalation)
  1184. if (pipeDrain !== undefined) clearTimeout(pipeDrain)
  1185. if (descendantSampler !== undefined) clearInterval(descendantSampler)
  1186. if (signal !== undefined) signal.removeEventListener('abort', terminate)
  1187. spawnError = `failed to start command: ${error.message}`
  1188. resolveExit({ exitCode: null, signalCode: null })
  1189. })
  1190. child.on('close', (exitCode, signalCode) => {
  1191. if (pipeDrain !== undefined) clearTimeout(pipeDrain)
  1192. if (descendantSampler !== undefined) clearInterval(descendantSampler)
  1193. if (signal !== undefined) signal.removeEventListener('abort', terminate)
  1194. if (escalation !== undefined && process.platform !== 'win32') {
  1195. // `close` only means the direct child's stdio closed; a grandchild
  1196. // that ignored SIGTERM and redirected its stdio can outlive it. Do
  1197. // not settle until the process group and the captured descendants are
  1198. // confirmed gone — the deadline SIGKILL covers members still alive at
  1199. // the grace end — so runGate returns only once the tree is quiescent.
  1200. const confirmGroupGone = () => {
  1201. if (!groupAlive(child.pid) && descendants.every(descendantPid => !processAlive(descendantPid))) {
  1202. clearTimeout(escalation)
  1203. resolveExit({ exitCode, signalCode })
  1204. return
  1205. }
  1206. if (Date.now() - terminatedAt < 8000) {
  1207. setTimeout(confirmGroupGone, 50)
  1208. return
  1209. }
  1210. // The grace ended with members still alive (e.g. uninterruptible
  1211. // I/O that even SIGKILL cannot cut). Fail loud instead of reporting
  1212. // a quiescent tree: the gate is recorded failed either way.
  1213. console.error(`run-gates: gate tree not quiescent after 8s (${gate.label}).`)
  1214. clearTimeout(escalation)
  1215. resolveExit({ exitCode, signalCode })
  1216. }
  1217. confirmGroupGone()
  1218. return
  1219. }
  1220. if (escalation !== undefined) clearTimeout(escalation)
  1221. resolveExit({ exitCode, signalCode })
  1222. })
  1223. child.stdin.end()
  1224. })
  1225. const { exitCode, signalCode } = outcome
  1226. const status: GateResultStatus = exitCode === 0 && signalCode === null && spawnError === undefined ? 'passed' : 'failed'
  1227. const result: GateResult = {
  1228. gate,
  1229. status,
  1230. durationMs: performance.now() - started,
  1231. output,
  1232. exitCode,
  1233. signalCode,
  1234. }
  1235. result.aborted = aborted
  1236. if (spawnError !== undefined) result.error = spawnError
  1237. return result
  1238. }
  1239. /**
  1240. * Parse the state, parent, and process-group fields from a `/proc/<pid>/stat`
  1241. * line. The comm field may contain spaces and parentheses, so the state starts
  1242. * after the last closing parenthesis.
  1243. * @param stat - one `/proc/<pid>/stat` line.
  1244. * @returns state, parent pid, and process-group pid; undefined when truncated.
  1245. */
  1246. function procStatFields(stat: string): { state: string; ppid: number; pgrp: number } | undefined {
  1247. const fields = stat.slice(stat.lastIndexOf(')') + 2).split(' ')
  1248. const state = fields[0]
  1249. const ppid = fields[1]
  1250. const pgrp = fields[2]
  1251. if (state === undefined || ppid === undefined || pgrp === undefined) return undefined
  1252. return { state, ppid: Number(ppid), pgrp: Number(pgrp) }
  1253. }
  1254. /**
  1255. * Whether one process is still executing. Zombies (state `Z`) do not count:
  1256. * they are dead records awaiting reaping, and kill(pid, 0) would report them
  1257. * as alive. Linux reads /proc/<pid>/stat to distinguish; other platforms fall
  1258. * back to the signal probe.
  1259. * @param pid - the process to probe.
  1260. */
  1261. function processAlive(pid: number): boolean {
  1262. if (process.platform === 'linux') {
  1263. try {
  1264. const parsed = procStatFields(readFileSync(`/proc/${pid}/stat`, 'utf8'))
  1265. return parsed !== undefined && parsed.state !== 'Z'
  1266. } catch {
  1267. return false
  1268. }
  1269. }
  1270. try {
  1271. process.kill(pid, 0)
  1272. return true
  1273. } catch {
  1274. return false
  1275. }
  1276. }
  1277. /**
  1278. * Whether any member of the child's POSIX process group is still executing.
  1279. * Zombie entries (state `Z`) do not count: they are dead records awaiting
  1280. * reaping, and the kill(-pid, 0) group probe would report them as alive.
  1281. * Linux enumerates /proc to distinguish after a fast-path group probe; other
  1282. * POSIX platforms fall back to the probe alone.
  1283. * @param pid - the group leader's pid; undefined or non-positive means the
  1284. * spawn failed and nothing is alive.
  1285. */
  1286. function groupAlive(pid: number | undefined): boolean {
  1287. if (pid === undefined || pid <= 0) return false
  1288. if (process.platform === 'linux') {
  1289. try {
  1290. process.kill(-pid, 0)
  1291. } catch {
  1292. // ESRCH: the group has no entries at all.
  1293. return false
  1294. }
  1295. try {
  1296. for (const entry of readdirSync('/proc')) {
  1297. if (!/^\d+$/.test(entry)) continue
  1298. try {
  1299. const parsed = procStatFields(readFileSync(`/proc/${entry}/stat`, 'utf8'))
  1300. if (parsed !== undefined && parsed.pgrp === pid && parsed.state !== 'Z') return true
  1301. } catch {
  1302. // The process exited mid-scan; it is not a live member.
  1303. }
  1304. }
  1305. return false
  1306. } catch {
  1307. return false
  1308. }
  1309. }
  1310. try {
  1311. process.kill(-pid, 0)
  1312. return true
  1313. } catch {
  1314. return false
  1315. }
  1316. }
  1317. /**
  1318. * The pids of every transitive descendant of `root`, read from the live
  1319. * process table. Linux walks /proc/<pid>/stat parent fields; other platforms
  1320. * parse `ps` (POSIX) or the CIM process table (Windows) output. This is one
  1321. * snapshot, not the full tree-ownership mechanism: terminate and the sampler
  1322. * rely on the 5-second cache to cross an intermediate that exited between
  1323. * ticks (reparented on POSIX, table record gone on Windows), so a single
  1324. * enumeration reaches only the descendants whose parent chain is still fully
  1325. * present in the table.
  1326. * @param root - the pid whose descendants are wanted.
  1327. * @returns descendant pids in breadth-first order; empty on enumeration failure.
  1328. */
  1329. function descendantPids(root: number): number[] {
  1330. if (root <= 0) return []
  1331. if (process.platform === 'linux') {
  1332. const rows: Array<[number, number]> = []
  1333. try {
  1334. for (const entry of readdirSync('/proc')) {
  1335. if (!/^\d+$/.test(entry)) continue
  1336. try {
  1337. const parsed = procStatFields(readFileSync(`/proc/${entry}/stat`, 'utf8'))
  1338. if (parsed !== undefined) rows.push([Number(entry), parsed.ppid])
  1339. } catch {
  1340. // The process exited mid-scan; skip it.
  1341. }
  1342. }
  1343. } catch {
  1344. return []
  1345. }
  1346. return collectDescendants(root, rows)
  1347. }
  1348. let ps: { error?: Error; stdout: string }
  1349. if (process.platform === 'win32') {
  1350. // taskkill /T covers the tree only while the root is alive; once the
  1351. // direct child exits (a descendant still holding the stdio write ends
  1352. // keeps `close` pending), abort must reach the survivors from a fresh
  1353. // enumeration. Windows keeps the exited parent's pid in its descendants'
  1354. // parent column, so this walk still finds the whole tree. A hung
  1355. // PowerShell (WMI/CIM service trouble) must not stall the abort path
  1356. // indefinitely, so the enumeration is bounded.
  1357. ps = spawnSync('powershell', processTableArgs('win32'), { encoding: 'utf8', timeout: 10000 })
  1358. } else {
  1359. ps = spawnSync('ps', processTableArgs('posix'), { encoding: 'utf8' })
  1360. }
  1361. if (ps.error !== undefined) return []
  1362. return collectDescendants(root, parsePidPpidLines(ps.stdout))
  1363. }
  1364. /**
  1365. * The process-table enumeration command for one platform. Windows queries the
  1366. * CIM provider through PowerShell (each line `pid ppid`); other platforms use
  1367. * `ps -axo pid=,ppid=`.
  1368. * @param platform - the target platform.
  1369. * @returns the command arguments to enumerate every live process's pid/ppid.
  1370. */
  1371. function processTableArgs(platform: 'win32' | 'posix'): string[] {
  1372. if (platform === 'win32') {
  1373. return ['-NoProfile', '-NonInteractive', '-Command', 'Get-CimInstance Win32_Process | ForEach-Object { "$($_.ProcessId) $($_.ParentProcessId)" }']
  1374. }
  1375. return ['-axo', 'pid=,ppid=']
  1376. }
  1377. /**
  1378. * Asynchronous descendant enumeration, so a slow WMI/CIM call (bounded by a
  1379. * 10-second timeout) cannot block the event loop: the sampler runs it while
  1380. * the gate's output streams and exit handling must keep flowing. Returns the
  1381. * same descendant list as {@link descendantPids}; used by the fail-fast
  1382. * sampler only, never on the abort path (which needs the synchronous walk to
  1383. * capture the tree before any member exits).
  1384. * @param root - the pid whose descendants are wanted.
  1385. * @param platform - the platform whose table the enumeration reads.
  1386. * @returns a promise of descendant pids in breadth-first order; empty on
  1387. * enumeration failure.
  1388. */
  1389. function descendantPidsAsync(root: number, platform: NodeJS.Platform): { promise: Promise<number[]>; cancel: () => void } {
  1390. if (root <= 0 || platform === 'linux') {
  1391. // The /proc walk is synchronous inside the async wrapper so the sampler
  1392. // keeps the same contract on every platform; /proc reads are fast and
  1393. // need no subprocess, and a completed enumeration needs no cancellation.
  1394. return { promise: Promise.resolve(descendantPids(root)), cancel: () => {} }
  1395. }
  1396. const [command, args] = platform === 'win32'
  1397. ? ['powershell', processTableArgs('win32')]
  1398. : ['ps', processTableArgs('posix')]
  1399. const child = spawn(command, args, {
  1400. stdio: ['ignore', 'pipe', 'ignore'],
  1401. timeout: platform === 'win32' ? 10000 : undefined,
  1402. })
  1403. child.stdout.setEncoding('utf8')
  1404. let stdout = ''
  1405. let settled = false
  1406. let settle!: (value: number[]) => void
  1407. const promise = new Promise<number[]>((resolve) => { settle = resolve })
  1408. const finish = (value: number[]) => {
  1409. if (settled) return
  1410. settled = true
  1411. // The enumeration completed (or was cancelled): stop the subprocess so
  1412. // the gate does not wait on its stdio handles.
  1413. child.kill('SIGTERM')
  1414. settle(value)
  1415. }
  1416. child.stdout.on('data', (chunk: string) => { stdout += chunk })
  1417. child.on('error', () => { finish([]) })
  1418. child.on('close', () => { finish(collectDescendants(root, parsePidPpidLines(stdout))) })
  1419. return {
  1420. promise,
  1421. cancel: () => { finish([]) },
  1422. }
  1423. }
  1424. /** Parse `pid ppid` rows from a process-table dump. Both the POSIX `ps -axo
  1425. * pid=,ppid=` output and the Windows PowerShell `Get-CimInstance Win32_Process`
  1426. * projection emit one `pid ppid` pair per line.
  1427. * @param output - the raw dump text.
  1428. * @returns the parsed pid/ppid rows in line order; blank and malformed lines
  1429. * are dropped.
  1430. */
  1431. export function parsePidPpidLines(output: string): Array<[number, number]> {
  1432. const rows: Array<[number, number]> = []
  1433. for (const line of output.split('\n')) {
  1434. const match = line.trim().match(/^(\d+)\s+(\d+)$/)
  1435. if (match !== null) rows.push([Number(match[1]), Number(match[2])])
  1436. }
  1437. return rows
  1438. }
  1439. /**
  1440. * The taskkill invocations that terminate one Windows gate tree. The direct
  1441. * child leads, because a live `taskkill /T` walks its whole subtree in one
  1442. * call; each captured descendant follows individually, because when the root
  1443. * already exited (a descendant holding the stdio write ends keeps `close`
  1444. * pending) `taskkill /T` rooted at the dead pid finds nothing — Windows never
  1445. * reparents, so the ppid chain captured at terminate still reaches the whole
  1446. * tree, and `/T` lets a surviving intermediate carry its own subtree. A pid
  1447. * that exited between capture and termination is as tolerable as ESRCH on
  1448. * POSIX: taskkill reports a nonzero status that is deliberately unchecked.
  1449. * @param rootPid - the direct child's pid.
  1450. * @param descendants - the captured descendant pids.
  1451. * @returns one `taskkill` argument list per pid, in termination order.
  1452. */
  1453. export function taskkillArgs(rootPid: number, descendants: number[]): string[][] {
  1454. return [rootPid, ...descendants].map(pid => ['/PID', String(pid), '/T', '/F'])
  1455. }
  1456. /**
  1457. * Walk a process-table snapshot without revisiting duplicate or cyclic PID links.
  1458. * @param root - process whose descendants are collected; excluded from the result.
  1459. * @param rows - observed PID and parent PID pairs.
  1460. * @returns distinct reachable descendants in breadth-first order.
  1461. */
  1462. export function collectDescendants(root: number, rows: Array<[number, number]>): number[] {
  1463. const byParent = new Map<number, number[]>()
  1464. for (const [pid, ppid] of rows) {
  1465. const children = byParent.get(ppid) ?? []
  1466. children.push(pid)
  1467. byParent.set(ppid, children)
  1468. }
  1469. const seen = new Set([root])
  1470. const queue = [root]
  1471. for (const parent of queue) {
  1472. for (const pid of byParent.get(parent) ?? []) {
  1473. if (seen.has(pid)) continue
  1474. seen.add(pid)
  1475. queue.push(pid)
  1476. }
  1477. }
  1478. return queue.slice(1)
  1479. }
  1480. /**
  1481. * Format every independently observed failure fact for the aggregate summary.
  1482. * @param result - unsuccessful gate result.
  1483. * @returns error, exit, and signal facts without allowing one to hide another.
  1484. */
  1485. export function formatGateResultReason(result: GateResult): string {
  1486. const facts: string[] = []
  1487. if (result.error !== undefined) facts.push(result.error)
  1488. if (result.exitCode !== null) facts.push(`exit ${result.exitCode}`)
  1489. if (result.signalCode !== null) facts.push(`signal ${result.signalCode}`)
  1490. return facts.length === 0 ? 'no exit code or signal' : facts.join(', ')
  1491. }
  1492. function printResult(result: GateResult): void {
  1493. const verbose = process.env.DSH_GATE_VERBOSE === '1'
  1494. const seconds = (result.durationMs / 1000).toFixed(2)
  1495. if (result.status === 'passed' && !verbose) {
  1496. console.log(`run-gates: PASS ${result.gate.label} (${seconds}s)`)
  1497. return
  1498. }
  1499. const heading = `${result.status.toUpperCase()} ${result.gate.label} (${seconds}s)`
  1500. const writeHeading = result.status === 'passed' ? console.log : console.error
  1501. writeHeading(`\n== ${heading} ==`)
  1502. if (result.status !== 'passed') {
  1503. console.error(`command: ${result.gate.displayCommand}`)
  1504. console.error(`outcome: ${formatGateResultReason(result)}`)
  1505. }
  1506. if (result.gate.streamOutput !== true) printOutput(result.output)
  1507. }
  1508. function printSummary(results: GateResult[], durationMs: number): void {
  1509. const passed = results.filter(result => result.status === 'passed').length
  1510. const failed = results.filter(result => result.status === 'failed').length
  1511. const skipped = results.filter(result => result.status === 'skipped').length
  1512. const seconds = (durationMs / 1000).toFixed(2)
  1513. console.log(`\nrun-gates: ${passed} passed, ${failed} failed, ${skipped} skipped in ${seconds}s.`)
  1514. const unsuccessful = results.filter(result => result.status === 'failed' || result.status === 'skipped')
  1515. if (unsuccessful.length === 0) return
  1516. console.error('run-gates: unsuccessful gates:')
  1517. for (const result of unsuccessful) {
  1518. const duration = (result.durationMs / 1000).toFixed(2)
  1519. const reason = formatGateResultReason(result)
  1520. const disposition = result.gate.allowFailure === true ? 'NON-BLOCKING ' : ''
  1521. console.error(` - ${disposition}${result.status.toUpperCase()} ${result.gate.label} (${duration}s, ${reason})`)
  1522. console.error(` ${result.gate.displayCommand}`)
  1523. }
  1524. }
  1525. function printOutput(output: GateOutputChunk[]): void {
  1526. for (const chunk of output) {
  1527. if (chunk.stream === 'stdout') process.stdout.write(chunk.text)
  1528. else process.stderr.write(chunk.text)
  1529. }
  1530. }