diff --git a/.mise/tasks/lint/bash-empty-argv-forwarding b/.mise/tasks/lint/bash-empty-argv-forwarding new file mode 100755 index 0000000..87e3fb1 --- /dev/null +++ b/.mise/tasks/lint/bash-empty-argv-forwarding @@ -0,0 +1,170 @@ +#!/usr/bin/env bash +#MISE description="Flag direct empty-argv forwarding under nounset (macOS Bash 3.2 compat)" +#USAGE arg "…" help="Paths to codebases to check (one or more)" +#USAGE example "codebase lint:bash-empty-argv-forwarding ." +#USAGE example "codebase lint:bash-empty-argv-forwarding /path/to/repo" + +set -euo pipefail + +# shellcheck source=../../../lib/shell-files.sh +source "$MISE_CONFIG_ROOT/lib/shell-files.sh" + +# Rationale: 'cmd "$@"' and 'cmd "${@}"' under nounset (set -u) fail on +# macOS Bash 3.2 when the argument list is empty. Bash 5+ and Homebrew +# Bash handle it gracefully, creating a silent cross-platform gotcha. +# ShellCheck does not catch this. +# +# Safe form on all Bash versions: +# cmd ${@+"$@"} +# +# Contexts that are safe and NOT flagged: +# - 'for arg in "$@"' — Bash handles empty $@ in for loops gracefully +# - 'local arr=("$@")' — array assignment handles empty $@ +# - Files without nounset (set -u / set -eu / set -euo pipefail) — no risk +# - Already-safe forms using alternate-value: ${@+"$@"} +# - Lines with inline 'codebase:ignore bash-empty-argv-forwarding' + +IFS=' ' read -ra TARGETS <<< "${usage_targets}" + +if [[ ${#TARGETS[@]} -eq 0 ]]; then + echo "ERROR: at least one target is required" >&2 + exit 1 +fi + +# Resolve relative paths against CALLER_PWD (see lib/shell-files.sh). +for i in "${!TARGETS[@]}"; do + TARGETS[i]=$(resolve_target "${TARGETS[i]}") +done + +# Helpers + +# has_nounset +# Returns 0 if the file enables nounset via any form: +# set -u, set -eu, set -euo pipefail, set -o nounset, etc. +has_nounset() { + local file="$1" + rg -q '^[^#]*set\s+(-[a-z]*u[a-z]*|-o\s+nounset\b)' "$file" 2>/dev/null +} + +# is_safe_context +# Returns 0 if the line uses "$@" in a context that is safe under nounset. +# Safe contexts: for arg in "$@", local arr=("$@"), readonly arr=("$@") +is_safe_context() { + local line="$1" + # for arg in "$@" + [[ "$line" =~ ^[[:space:]]*for\ [a-zA-Z_][a-zA-Z0-9_]*\ in\ \"\$ ]] && return 0 + # local arr=("$@"), readonly arr=("$@"), declare arr=("$@"), typeset arr=("$@") + [[ "$line" =~ ^[[:space:]]*(local|readonly|declare|typeset)[[:space:]]+[a-zA-Z_][a-zA-Z0-9_]*=\(\"\$ ]] && return 0 + return 1 +} + +# has_safe_form +# Returns 0 if the line already uses the alternate-value safe form. +has_safe_form() { + local line="$1" + # shellcheck disable=SC2016 # intentional: match literal '${@+"$@"}' + [[ "$line" == *'${@+"$@"}'* ]] && return 0 + # shellcheck disable=SC2016 # intentional: match literal '${@+"${@}"}' + [[ "$line" == *'${@+"${@}"}'* ]] && return 0 + return 1 +} + +# Pattern: "$@" or "${@}" in double quotes +ARGV_FORWARD_RE='"\$\{?@\}?"' + +# has_line_ignore +# Returns 0 if the line has a rule-specific inline ignore. +has_line_ignore() { + local line="$1" + [[ "$line" =~ codebase:ignore[[:space:]]+bash-empty-argv-forwarding ]] +} + +# scan_file +# Emit flagged line numbers and trimmed content for lines matching the +# empty-argv forwarding pattern in a nounset file. +scan_file() { + local file="$1" + local lineno=0 + local line + + while IFS= read -r line || [[ -n "$line" ]]; do + lineno=$((lineno + 1)) + + # Skip full-line comments. + [[ "$line" =~ ^[[:space:]]*# ]] && continue + + # Rule-specific inline ignore with reason is accepted. + has_line_ignore "$line" && continue + + # Safe contexts (for loops, array assignments) are accepted. + is_safe_context "$line" && continue + + # Already-safe forms are accepted. + has_safe_form "$line" && continue + + # Flag matching lines. + if [[ "$line" =~ $ARGV_FORWARD_RE ]]; then + local trimmed="${line#"${line%%[![:space:]]*}"}" + echo "$lineno: $trimmed" + fi + done < "$file" +} + +# Main + +failures=0 + +for target in "${TARGETS[@]}"; do + if [[ ! -e "$target" ]]; then + echo "ERROR: target does not exist: $target" >&2 + exit 1 + fi + + name=$(basename "$target") + + # File-level ignore via mise.toml + toml="$target/mise.toml" + if [[ -f "$toml" ]] && grep -m1 -q 'codebase:ignore bash-empty-argv-forwarding' "$toml"; then + echo "SKIP $name (codebase:ignore)" + continue + fi + + # Collect shell files + files=() + while IFS= read -r f; do + [[ -n "$f" ]] && files+=("$f") + done < <(discover_shell_files "$target") + + if [[ ${#files[@]} -eq 0 ]]; then + echo "OK $name (no shell files found)" + continue + fi + + # Scan each file that has nounset enabled; collect hits + hit_count=0 + target_output="" + for file in "${files[@]}"; do + # Skip files without nounset — no risk of unbound variable + has_nounset "$file" || continue + + rel="${file#"$target"/}" + while IFS= read -r hit; do + [[ -z "$hit" ]] && continue + target_output+=" $rel:$hit"$'\n' + hit_count=$((hit_count + 1)) + done < <(scan_file "$file") + done + + if [[ "$hit_count" -gt 0 ]]; then + echo "FAIL $name: $hit_count empty-argv forwarding under nounset" + printf '%s' "$target_output" + cat <<'HINT' + hint: Use ${@+"$@"} instead of "$@" for Bash-3-safe empty-argv forwarding +HINT + failures=$((failures + 1)) + else + echo "OK $name (${#files[@]} file(s) clean)" + fi +done + +exit "$failures" diff --git a/test/lib/shell-files.bats b/test/lib/shell-files.bats index a462482..5d6ed6e 100644 --- a/test/lib/shell-files.bats +++ b/test/lib/shell-files.bats @@ -7,9 +7,7 @@ setup() { source "$REPO_DIR/lib/shell-files.sh" } -# ============================================================================ # resolve_target -# ============================================================================ @test "resolve_target: absolute path passes through unchanged" { result=$(resolve_target "/some/absolute/path") diff --git a/test/lint/bash-empty-argv-forwarding/bash-empty-argv-forwarding.bats b/test/lint/bash-empty-argv-forwarding/bash-empty-argv-forwarding.bats new file mode 100644 index 0000000..571038e --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/bash-empty-argv-forwarding.bats @@ -0,0 +1,265 @@ +#!/usr/bin/env bats +# Tests for lint:bash-empty-argv-forwarding rule + +load ../../test_helper + +setup() { + FIXTURES="$BATS_TEST_DIRNAME/fixtures" +} + +# Detection + +@test "bash-empty-argv-forwarding: passes on a clean codebase" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/clean" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"*"clean"* ]] +} + +@test "bash-empty-argv-forwarding: flags '\"$@\"' under nounset" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/dirty" + [ "$status" -ne 0 ] + [[ "$output" == *"FAIL"*"dirty"* ]] + [[ "$output" == *'"$@"'* ]] +} + +@test "bash-empty-argv-forwarding: does not flag '\"$@\"' in files without nounset" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/no-nounset" + [ "$status" -eq 0 ] +} + +@test "bash-empty-argv-forwarding: does not flag 'for arg in \"$@\"' (safe context)" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/safe-context" + [ "$status" -eq 0 ] +} + +@test "bash-empty-argv-forwarding: does not flag already-safe '${@+\"$@\"}'" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/already-safe" + [ "$status" -eq 0 ] +} + +@test "bash-empty-argv-forwarding: flags across exec, mise run, and piped forms" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/exec-wrapper" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +exec other "$@" +EOF + cat > "$tmp/.mise/tasks/mise-wrapper" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +mise run child "$@" +EOF + + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -ne 0 ] + [[ "$output" == *"exec other"* ]] + [[ "$output" == *"mise run child"* ]] + rm -rf "$tmp" +} + +@test "bash-empty-argv-forwarding: fail output includes the hint" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/dirty" + [ "$status" -ne 0 ] + [[ "$output" == *'Use ${@+"$@"}'* ]] +} + +@test "bash-empty-argv-forwarding: fail output names the violating file" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/dirty" + [ "$status" -ne 0 ] + [[ "$output" == *"delegate"* ]] +} + +# Ignore directives + +@test "bash-empty-argv-forwarding: inline '# codebase:ignore — reason' skips the line" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/ignored-inline" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"*"ignored-inline"* ]] +} + +@test "bash-empty-argv-forwarding: 'codebase:ignore' in mise.toml skips the whole target" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/ignored-file" + [ "$status" -eq 0 ] + [[ "$output" == *"SKIP"*"ignored-file"* ]] +} + +# Scope / discovery + +@test "bash-empty-argv-forwarding: walks the whole target — finds hits outside .mise/tasks" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/broad-walk" + [ "$status" -ne 0 ] + [[ "$output" == *"scripts/deploy.sh"* ]] + [[ "$output" == *"bin/tool"* ]] +} + +@test "bash-empty-argv-forwarding: works on a codebase with no mise.toml" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/no-toml" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"*"no-toml"* ]] +} + +@test "bash-empty-argv-forwarding: passes on a codebase with no shell files" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/no-shell-files" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"*"no-shell-files"* ]] + [[ "$output" == *"no shell files"* ]] +} + +@test "bash-empty-argv-forwarding: discovery skips non-bash shebangs (fish, zsh)" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/installer" <<'EOF' +#!/usr/bin/env fish +set -u +some_command "$@" +EOF + # fish is not a bash/sh shebang, so discover_shell_files should skip it. + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"* ]] + rm -rf "$tmp" +} + +@test "bash-empty-argv-forwarding: discovery prunes .git/ (hooks are ignored)" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.git/hooks" "$tmp/.mise/tasks" + cat > "$tmp/.git/hooks/pre-commit" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +exec hook "$@" +EOF + cat > "$tmp/.mise/tasks/greet" <<'EOF' +#!/usr/bin/env bash +echo hi +EOF + + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"* ]] + # One shell file scanned (the greet task), zero from .git + [[ "$output" == *"1 file(s) clean"* ]] + rm -rf "$tmp" +} + +# Comment handling + +@test "bash-empty-argv-forwarding: does not flag '\"$@\"' inside a full-line comment" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/t" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +# Note: some_command "$@" — not really executed +echo ok +EOF + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"* ]] + rm -rf "$tmp" +} + +# Multi-target + +@test "bash-empty-argv-forwarding: checks multiple targets and reports each" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/clean" "$FIXTURES/dirty" + [ "$status" -ne 0 ] + [[ "$output" == *"OK"*"clean"* ]] + [[ "$output" == *"FAIL"*"dirty"* ]] +} + +@test "bash-empty-argv-forwarding: exit code is the number of failing targets" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/dirty" "$FIXTURES/broad-walk" + [ "$status" -eq 2 ] +} + +# Error paths + +@test "bash-empty-argv-forwarding: fails when target does not exist" { + run codebase lint:bash-empty-argv-forwarding "$FIXTURES/does-not-exist" + [ "$status" -ne 0 ] + [[ "$output" == *"does not exist"* ]] +} + +@test "bash-empty-argv-forwarding: fails when no targets given" { + run codebase lint:bash-empty-argv-forwarding + [ "$status" -ne 0 ] + [[ "$output" == *"Missing required arg"* ]] + [[ "$output" == *""* ]] +} + +# Relative path resolution + +@test "bash-empty-argv-forwarding: relative path resolves against CODEBASE_CALLER_PWD" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/t" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +some_command "$@" +EOF + + CODEBASE_CALLER_PWD="$tmp" run codebase lint:bash-empty-argv-forwarding .mise/tasks + [ "$status" -ne 0 ] + [[ "$output" == *"FAIL"* ]] + [[ "$output" == *'"$@"'* ]] + rm -rf "$tmp" +} + +# Explicit braces detection + +@test "bash-empty-argv-forwarding: flags '\"\${@}\"' (explicit braces) under nounset" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/t" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +some_command "${@}" +EOF + + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -ne 0 ] + [[ "$output" == *'"${@}"'* ]] + rm -rf "$tmp" +} + +@test "bash-empty-argv-forwarding: flags '\"\${@}\"' in redirect context" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/t" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +some_command "${@}" > /tmp/output +EOF + + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -ne 0 ] + [[ "$output" == *'"${@}"'* ]] + rm -rf "$tmp" +} + +@test "bash-empty-argv-forwarding: does not flag local array assignment from '\"$@\"'" { + local tmp + tmp=$(mktemp -d) + mkdir -p "$tmp/.mise/tasks" + cat > "$tmp/.mise/tasks/t" <<'EOF' +#!/usr/bin/env bash +set -euo pipefail +local args=("$@") +for arg in "${args[@]}"; do + echo "$arg" +done +EOF + + run codebase lint:bash-empty-argv-forwarding "$tmp" + [ "$status" -eq 0 ] + [[ "$output" == *"OK"* ]] + rm -rf "$tmp" +} diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/already-safe/.mise/tasks/task b/test/lint/bash-empty-argv-forwarding/fixtures/already-safe/.mise/tasks/task new file mode 100644 index 0000000..275732c --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/already-safe/.mise/tasks/task @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +some_command ${@+"$@"} diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/already-safe/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/already-safe/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/already-safe/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/bin/tool b/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/bin/tool new file mode 100644 index 0000000..c2b2759 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/bin/tool @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +command "$@" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/scripts/deploy.sh b/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/scripts/deploy.sh new file mode 100644 index 0000000..076a2b5 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/broad-walk/scripts/deploy.sh @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +rsync "$@" deploy@example.com:/srv/app/ diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/clean/.mise/tasks/greet b/test/lint/bash-empty-argv-forwarding/fixtures/clean/.mise/tasks/greet new file mode 100644 index 0000000..ec8a236 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/clean/.mise/tasks/greet @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +echo "hello $USER" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/clean/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/clean/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/clean/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/dirty/.mise/tasks/delegate b/test/lint/bash-empty-argv-forwarding/fixtures/dirty/.mise/tasks/delegate new file mode 100644 index 0000000..2a429fc --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/dirty/.mise/tasks/delegate @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +mise run child "$@" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/dirty/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/dirty/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/dirty/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/ignored-file/.mise/tasks/broken b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-file/.mise/tasks/broken new file mode 100644 index 0000000..258bc84 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-file/.mise/tasks/broken @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +some_command "$@" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/ignored-file/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-file/mise.toml new file mode 100644 index 0000000..c663d19 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-file/mise.toml @@ -0,0 +1,2 @@ +[_.codebase] +# codebase:ignore bash-empty-argv-forwarding diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/ignored-inline/.mise/tasks/task b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-inline/.mise/tasks/task new file mode 100644 index 0000000..de98463 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-inline/.mise/tasks/task @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +set -euo pipefail +some_command "$@" # codebase:ignore bash-empty-argv-forwarding — intentional: always called with args diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/ignored-inline/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-inline/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/ignored-inline/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/no-nounset/.mise/tasks/delegate b/test/lint/bash-empty-argv-forwarding/fixtures/no-nounset/.mise/tasks/delegate new file mode 100644 index 0000000..f19e98c --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/no-nounset/.mise/tasks/delegate @@ -0,0 +1,3 @@ +#!/usr/bin/env bash +# No set -u here — this is safe on all platforms +mise run child "$@" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/no-nounset/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/no-nounset/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/no-nounset/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/no-shell-files/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/no-shell-files/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/no-shell-files/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/no-toml/.mise/tasks/greet b/test/lint/bash-empty-argv-forwarding/fixtures/no-toml/.mise/tasks/greet new file mode 100644 index 0000000..f90f3e8 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/no-toml/.mise/tasks/greet @@ -0,0 +1,2 @@ +#!/usr/bin/env bash +echo "greetings" diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/safe-context/.mise/tasks/loop b/test/lint/bash-empty-argv-forwarding/fixtures/safe-context/.mise/tasks/loop new file mode 100644 index 0000000..aafd136 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/safe-context/.mise/tasks/loop @@ -0,0 +1,5 @@ +#!/usr/bin/env bash +set -euo pipefail +for arg in "$@"; do + echo "$arg" +done diff --git a/test/lint/bash-empty-argv-forwarding/fixtures/safe-context/mise.toml b/test/lint/bash-empty-argv-forwarding/fixtures/safe-context/mise.toml new file mode 100644 index 0000000..26bb173 --- /dev/null +++ b/test/lint/bash-empty-argv-forwarding/fixtures/safe-context/mise.toml @@ -0,0 +1,2 @@ +[tools] +bats = "1.13.0" diff --git a/test/lint/bats-test-helper/bats-test-helper.bats b/test/lint/bats-test-helper/bats-test-helper.bats index 27ebba4..f4b0e76 100644 --- a/test/lint/bats-test-helper/bats-test-helper.bats +++ b/test/lint/bats-test-helper/bats-test-helper.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # Pass paths -# ============================================================================ @test "bats-test-helper: passes on clean wrapper-based tests" { run codebase lint:bats-test-helper "$FIXTURES/clean" @@ -24,9 +22,7 @@ setup() { [[ "$output" == *"no test/ files found"* ]] } -# ============================================================================ # Invocation signatures — each form fails -# ============================================================================ @test "bats-test-helper: flags 'bash \$TASK' (var whose name contains TASK)" { run codebase lint:bats-test-helper "$FIXTURES/dirty-task-var" @@ -84,9 +80,7 @@ setup() { [[ "$output" == *"bash \$REPO_DIR/.mise/tasks/lint/check"* ]] } -# ============================================================================ # False positives — none of these are actual invocations -# ============================================================================ @test "bats-test-helper: does NOT flag reading a task file as data (grep/cat)" { # Regression guard: 'grep "$MCR/.mise/tasks/foo"' reads the script, doesn't @@ -97,9 +91,7 @@ setup() { [[ "$output" == *"OK"* ]] } -# ============================================================================ # Ignore directives -# ============================================================================ @test "bats-test-helper: inline '# codebase:ignore' suppresses a single line" { run codebase lint:bats-test-helper "$FIXTURES/ignored-inline" @@ -113,9 +105,7 @@ setup() { [[ "$output" == *"SKIP"*"ignored-file"* ]] } -# ============================================================================ # Output details -# ============================================================================ @test "bats-test-helper: fail output includes file:line citations" { run codebase lint:bats-test-helper "$FIXTURES/dirty-task-var" @@ -130,9 +120,7 @@ setup() { [[ "$output" == *"Call the Tool"* ]] } -# ============================================================================ # Error handling -# ============================================================================ @test "bats-test-helper: fails when no targets given" { run codebase lint:bats-test-helper @@ -146,9 +134,7 @@ setup() { [[ "$output" == *"does not exist"* ]] } -# ============================================================================ # Multi-target -# ============================================================================ @test "bats-test-helper: accepts multiple targets and reports each" { run codebase lint:bats-test-helper "$FIXTURES/clean" "$FIXTURES/dirty-task-var" diff --git a/test/lint/bats-test-task/bats-test-task.bats b/test/lint/bats-test-task/bats-test-task.bats index 295d92f..f761f2b 100644 --- a/test/lint/bats-test-task/bats-test-task.bats +++ b/test/lint/bats-test-task/bats-test-task.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # Pass paths -# ============================================================================ @test "bats-test-task: passes on the canonical pattern" { run codebase lint:bats-test-task "$FIXTURES/clean" @@ -33,9 +31,7 @@ setup() { [[ "$output" == *"OK"*"shimmer-variant"* ]] } -# ============================================================================ # Failure modes -# ============================================================================ @test "bats-test-task: flags missing USAGE arg spec" { run codebase lint:bats-test-task "$FIXTURES/missing-usage-arg" @@ -80,9 +76,7 @@ setup() { [[ "$output" != *"invocations found"* ]] } -# ============================================================================ # Ignore directive -# ============================================================================ @test "bats-test-task: 'codebase:ignore bats-test-task' in mise.toml skips the target" { run codebase lint:bats-test-task "$FIXTURES/ignored-file" @@ -90,9 +84,7 @@ setup() { [[ "$output" == *"SKIP"*"ignored-file"* ]] } -# ============================================================================ # Output details -# ============================================================================ @test "bats-test-task: fail output includes the remediation hint" { run codebase lint:bats-test-task "$FIXTURES/missing-usage-arg" @@ -109,9 +101,7 @@ setup() { [[ "$output" == *"invocations"* ]] } -# ============================================================================ # Error handling -# ============================================================================ @test "bats-test-task: fails when no targets given" { run codebase lint:bats-test-task @@ -125,9 +115,7 @@ setup() { [[ "$output" == *"does not exist"* ]] } -# ============================================================================ # Multi-target -# ============================================================================ @test "bats-test-task: accepts multiple targets and reports each" { run codebase lint:bats-test-task "$FIXTURES/clean" "$FIXTURES/missing-examples" diff --git a/test/lint/gum-table/gum-table.bats b/test/lint/gum-table/gum-table.bats index 2dfddaa..809b670 100644 --- a/test/lint/gum-table/gum-table.bats +++ b/test/lint/gum-table/gum-table.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # High confidence: column -t (always a true positive) -# ============================================================================ @test "column-t: detects piping to column -t" { run codebase lint:gum-table "$FIXTURES/manual-padding/task-c" @@ -18,9 +16,7 @@ setup() { [[ "$output" == *"WARN"* ]] } -# ============================================================================ # High confidence: printf padding inside a loop -# ============================================================================ @test "loop-table: detects printf %-Ns inside while-read" { run codebase lint:gum-table "$FIXTURES/manual-padding/task-b" @@ -45,9 +41,7 @@ setup() { echo "$output" | grep "padding" | grep -q "INFO" } -# ============================================================================ # Low confidence: printf padding outside loops (INFO only, not a failure) -# ============================================================================ @test "padding: printf %-Ns outside loop is INFO, not a failure" { run codebase lint:gum-table "$FIXTURES/manual-padding/task-a" @@ -69,9 +63,7 @@ setup() { [[ "$output" == *"INFO"* ]] } -# ============================================================================ # True negatives — no output at all -# ============================================================================ @test "clean: already using gum table" { run codebase lint:gum-table "$FIXTURES/clean/task-gum" @@ -103,9 +95,7 @@ setup() { [[ "$output" == *"OK"* ]] } -# ============================================================================ # Multi-file scanning -# ============================================================================ @test "directory scan finds high-confidence hits" { run codebase lint:gum-table "$FIXTURES/manual-padding" @@ -121,9 +111,7 @@ setup() { [ "$status" -eq 0 ] } -# ============================================================================ # Output format -# ============================================================================ @test "WARN output includes file path, category, and line number" { run codebase lint:gum-table "$FIXTURES/manual-padding/task-b" @@ -136,9 +124,7 @@ setup() { [[ "$output" =~ INFO.*task-a:\[padding\].*[0-9]+: ]] } -# ============================================================================ # Error handling -# ============================================================================ @test "fails when target does not exist" { run codebase lint:gum-table /nonexistent @@ -146,9 +132,7 @@ setup() { [[ "$output" == *"ERROR"* ]] } -# ============================================================================ # Relative path resolution (regression: codebase#24) -# ============================================================================ @test "relative path resolves against CODEBASE_CALLER_PWD (dirty fixture)" { # Regression: relative targets resolved against codebase's install diff --git a/test/lint/mcr-scope/mcr-scope.bats b/test/lint/mcr-scope/mcr-scope.bats index 3ae6215..49869b4 100644 --- a/test/lint/mcr-scope/mcr-scope.bats +++ b/test/lint/mcr-scope/mcr-scope.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # Detection -# ============================================================================ @test "mcr-scope: passes on a clean codebase" { run codebase lint:mcr-scope "$FIXTURES/clean" @@ -102,9 +100,7 @@ setup() { [[ "$output" == *"no test/ or lib/ files found"* ]] } -# ============================================================================ # Ignore directives -# ============================================================================ @test "mcr-scope: inline '# codebase:ignore' suppresses a single line" { run codebase lint:mcr-scope "$FIXTURES/ignored-inline" @@ -118,9 +114,7 @@ setup() { [[ "$output" == *"SKIP"*"ignored-file"* ]] } -# ============================================================================ # Output details -# ============================================================================ @test "mcr-scope: fail output includes file:line citations" { run codebase lint:mcr-scope "$FIXTURES/dirty-lib" @@ -136,9 +130,7 @@ setup() { [[ "$output" == *"BASH_SOURCE"* ]] } -# ============================================================================ # Error handling -# ============================================================================ @test "mcr-scope: fails when no targets given" { run codebase lint:mcr-scope @@ -153,9 +145,7 @@ setup() { [[ "$output" == *"does not exist"* ]] } -# ============================================================================ # Multi-target -# ============================================================================ @test "mcr-scope: accepts multiple targets and reports each" { run codebase lint:mcr-scope "$FIXTURES/clean" "$FIXTURES/dirty-test" diff --git a/test/lint/mise-settings/mise-settings.bats b/test/lint/mise-settings/mise-settings.bats index 565be0a..d925495 100644 --- a/test/lint/mise-settings/mise-settings.bats +++ b/test/lint/mise-settings/mise-settings.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # Detection -# ============================================================================ @test "lint: passes when all settings present" { run codebase lint:mise-settings "$FIXTURES/complete" @@ -54,9 +52,7 @@ setup() { [[ "$output" == *"FAIL"*"missing-both"* ]] } -# ============================================================================ # Fix mode -# ============================================================================ @test "fix: adds missing settings" { WORK_DIR="$BATS_TEST_TMPDIR/fix-test" @@ -96,9 +92,7 @@ setup() { [[ "$output" == *"OK"* ]] } -# ============================================================================ # Error handling -# ============================================================================ @test "lint: fails when target does not exist" { run codebase lint:mise-settings /nonexistent diff --git a/test/lint/or-true/or-true.bats b/test/lint/or-true/or-true.bats index 31d7776..68cfaca 100644 --- a/test/lint/or-true/or-true.bats +++ b/test/lint/or-true/or-true.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # Detection -# ============================================================================ @test "or-true: passes on a clean codebase" { run codebase lint:or-true "$FIXTURES/clean" @@ -76,9 +74,7 @@ setup() { [[ "$output" == *"if !"* ]] } -# ============================================================================ # Corpus-calibrated diagnostics -# ============================================================================ @test "or-true: arithmetic increments get a safer arithmetic suggestion" { local tmp @@ -173,9 +169,7 @@ EOF [[ "$output" == *"Intentional cases need a rule-specific reason"* ]] } -# ============================================================================ # Ignore directives -# ============================================================================ @test "or-true: inline '# codebase:ignore or-true — reason' skips the line" { run codebase lint:or-true "$FIXTURES/ignored-inline" @@ -189,9 +183,7 @@ EOF [[ "$output" == *"SKIP"*"ignored-file"* ]] } -# ============================================================================ # Scope / discovery -# ============================================================================ @test "or-true: walks the whole target — finds hits outside .mise/tasks and lib/" { run codebase lint:or-true "$FIXTURES/broad-walk" @@ -213,9 +205,7 @@ EOF [[ "$output" == *"no shell files"* ]] } -# ============================================================================ # Discovery correctness -# ============================================================================ @test "or-true: discovery skips non-bash/sh shebangs (fish, zsh, …)" { # Regression: the shebang regex '^#!.*(bash|sh)\b' matched 'sh' as @@ -255,9 +245,7 @@ EOF rm -rf "$tmp" } -# ============================================================================ # Comment handling -# ============================================================================ @test "or-true: does not flag '|| true' inside a single-quoted string" { # Accidental protection: the closing quote ''' is not in the @@ -293,9 +281,7 @@ EOF rm -rf "$tmp" } -# ============================================================================ # Multi-target -# ============================================================================ @test "or-true: checks multiple targets and reports each" { run codebase lint:or-true "$FIXTURES/clean" "$FIXTURES/dirty" @@ -309,9 +295,7 @@ EOF [ "$status" -eq 2 ] } -# ============================================================================ # Error paths -# ============================================================================ @test "or-true: fails when target does not exist" { run codebase lint:or-true "$FIXTURES/does-not-exist" @@ -328,9 +312,7 @@ EOF [[ "$output" == *""* ]] } -# ============================================================================ # Relative path resolution (regression: codebase#24) -# ============================================================================ @test "or-true: relative path resolves against CODEBASE_CALLER_PWD, not codebase install dir" { # Regression: when invoked via the shiv shim, relative paths resolved diff --git a/test/lint/shellcheck/shellcheck.bats b/test/lint/shellcheck/shellcheck.bats index 370c7d6..f0ac032 100644 --- a/test/lint/shellcheck/shellcheck.bats +++ b/test/lint/shellcheck/shellcheck.bats @@ -7,9 +7,7 @@ setup() { FIXTURES="$BATS_TEST_DIRNAME/fixtures" } -# ============================================================================ # Detection -# ============================================================================ @test "lint: passes on a clean codebase" { run codebase lint:shellcheck "$FIXTURES/clean" @@ -37,9 +35,7 @@ setup() { [[ "$output" == *"SC"* ]] } -# ============================================================================ # Ignore directive -# ============================================================================ @test "lint: skips when codebase:ignore shellcheck is set in mise.toml" { run codebase lint:shellcheck "$FIXTURES/ignored" @@ -76,9 +72,7 @@ setup() { [[ "$output" == *"SC2154"* ]] } -# ============================================================================ # Scope -# ============================================================================ @test "lint: works on a codebase with no mise.toml" { run codebase lint:shellcheck "$FIXTURES/no-toml" @@ -100,9 +94,7 @@ setup() { [[ "$output" == *"bad.sh"* ]] } -# ============================================================================ # Multi-target -# ============================================================================ @test "lint: checks multiple targets and reports each" { run codebase lint:shellcheck "$FIXTURES/clean" "$FIXTURES/dirty" @@ -116,9 +108,7 @@ setup() { [ "$status" -eq 2 ] } -# ============================================================================ # Error paths -# ============================================================================ @test "lint: fails when target does not exist" { run codebase lint:shellcheck "$FIXTURES/does-not-exist" diff --git a/test/migrations/task-pattern/task-pattern.bats b/test/migrations/task-pattern/task-pattern.bats index d86c33e..5f8a90d 100644 --- a/test/migrations/task-pattern/task-pattern.bats +++ b/test/migrations/task-pattern/task-pattern.bats @@ -23,9 +23,7 @@ assert_matches_before() { diff -u "$FIXTURES/before/$file" "$WORK_DIR/$file" } -# ============================================================================ # Individual variant tests -# ============================================================================ @test "migrate: simple mise run → _task" { codebase migrate:task-pattern "$WORK_DIR" @@ -57,9 +55,7 @@ assert_matches_before() { assert_matches_after ".mise/tasks/error-strings" } -# ============================================================================ # Full migration test -# ============================================================================ @test "migrate: all files match expected after state" { codebase migrate:task-pattern "$WORK_DIR" @@ -68,9 +64,7 @@ assert_matches_before() { [ "$status" -eq 0 ] } -# ============================================================================ # Reverse migration tests -# ============================================================================ @test "reverse: _task → mise run" { # Start from the after state @@ -101,9 +95,7 @@ assert_matches_before() { ! grep -q '_task' "$WORK_DIR/.mise/tasks/in-subshell" } -# ============================================================================ # Round-trip tests -# ============================================================================ @test "round-trip: forward then reverse restores lossless fixtures" { # Only test fixtures where forward is lossless (no -q flag) @@ -114,9 +106,7 @@ assert_matches_before() { assert_matches_before ".mise/tasks/error-strings" } -# ============================================================================ # Error handling -# ============================================================================ @test "migrate: fails when target does not exist" { run codebase migrate:task-pattern /nonexistent diff --git a/test/pre-commit/pre-commit.bats b/test/pre-commit/pre-commit.bats index 96bd4f2..c0fbddc 100644 --- a/test/pre-commit/pre-commit.bats +++ b/test/pre-commit/pre-commit.bats @@ -24,9 +24,7 @@ EOF export CODEBASE_CALLER_PWD="$REPO" } -# ============================================================================ # Install — fresh repo -# ============================================================================ @test "install: creates dispatcher" { codebase pre-commit @@ -97,9 +95,7 @@ EOF [ -x "$REPO/.git/hooks/pre-commit" ] } -# ============================================================================ # Install — existing dispatcher -# ============================================================================ @test "install: preserves existing dispatcher and other hooks" { mkdir -p "$REPO/.git/hooks/pre-commit.d" @@ -121,9 +117,7 @@ EOF [ -f "$REPO/.git/hooks/pre-commit.d/codebase" ] } -# ============================================================================ # Install — existing plain hook (not a dispatcher) -# ============================================================================ @test "install: errors when existing plain hook is not a dispatcher" { cat > "$REPO/.git/hooks/pre-commit" <<'EOF' @@ -137,9 +131,7 @@ EOF [[ "$output" == *"not a dispatcher"* ]] } -# ============================================================================ # Idempotent -# ============================================================================ @test "install: running twice is safe" { codebase pre-commit @@ -149,9 +141,7 @@ EOF [ -f "$REPO/.git/hooks/pre-commit.d/codebase" ] } -# ============================================================================ # --check -# ============================================================================ @test "check: exits 0 when hook is current" { codebase pre-commit @@ -189,9 +179,7 @@ EOF [ "$status" -ne 0 ] } -# ============================================================================ # --revert -# ============================================================================ @test "revert: removes codebase hook" { codebase pre-commit @@ -225,9 +213,7 @@ EOF [[ "$output" == *"No codebase hook"* ]] } -# ============================================================================ # Scope -# ============================================================================ @test "scope: default scopes are delegated to aggregate lint" { cat > "$REPO/mise.toml" <<'EOF' @@ -258,9 +244,7 @@ EOF ! grep -q 'src/scripts' "$REPO/.git/hooks/pre-commit.d/codebase" } -# ============================================================================ # Error handling -# ============================================================================ @test "error: fails outside git repo" { export CODEBASE_CALLER_PWD="$BATS_TEST_TMPDIR" diff --git a/test/scan/scan.bats b/test/scan/scan.bats index 9552433..e52a500 100644 --- a/test/scan/scan.bats +++ b/test/scan/scan.bats @@ -8,9 +8,7 @@ setup() { FIXTURES_B="$BATS_TEST_DIRNAME/fixtures-b" } -# ============================================================================ # Single target (basic matching) -# ============================================================================ @test "scan: finds mise run calls in extension-less task files" { run codebase scan -p 'mise run $$$ARGS' "$FIXTURES_A" @@ -39,9 +37,7 @@ setup() { [[ -z "$output" ]] } -# ============================================================================ # Different patterns -# ============================================================================ @test "scan: finds _task calls with custom pattern" { run codebase scan -p '_task $$$ARGS' "$FIXTURES_A" @@ -56,9 +52,7 @@ setup() { [ "$count" -eq 4 ] } -# ============================================================================ # Multiple targets -# ============================================================================ @test "multi: finds matches across multiple codebases" { run codebase scan -p 'mise run $$$ARGS' "$FIXTURES_A" "$FIXTURES_B" @@ -84,9 +78,7 @@ setup() { [[ "$output" != *"fixtures-b:"* ]] } -# ============================================================================ # Exclude filter -# ============================================================================ @test "exclude: filters out files matching glob" { run codebase scan -p 'mise run $$$ARGS' -e '.mise/tasks/ci/*' "$FIXTURES_A" @@ -110,9 +102,7 @@ setup() { [[ "$output" != *"ci/deploy"* ]] } -# ============================================================================ # Error handling -# ============================================================================ @test "error: fails when no pattern provided" { run codebase scan "$FIXTURES_A"