From 9c37af90a9cb9abc47181abfdc2bd4acd099dfdc Mon Sep 17 00:00:00 2001 From: "MUH. IQRAM BAHRING" Date: Sat, 19 Sep 2026 12:37:57 +0800 Subject: [PATCH] test(harness): isolate DATA_DIR so tests never write to the real DB MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Root cause of fake connections in Usage (zed-live-*@example.com, guard-*@example.com, zed "Account N", kimchi-nope): route-level tests (zed-live-models, zed-native-auth) call createProviderConnection, which persists to $DATA_DIR/db/data.sqlite. With DATA_DIR unset — the default for `npx vitest run` — that resolved to the user's real ~/.9router DB, appending test rows on every run. Both files documented "RUN WITH AN ISOLATED DB" but never enforced it. Add tests/setup/isolateDataDir.js (wired via vitest setupFiles) that points DATA_DIR at a throwaway temp dir before src/lib/dataDir.js is imported. Opt out with RUN_REAL=1 or an explicit DATA_DIR (used by the *.real.test.js suites that read live credentials). Verified: a full suite run now leaves the real DB byte-count unchanged; new guard test tests/unit/test-data-dir-isolation.test.js locks it in. --- tests/setup/isolateDataDir.js | 26 +++++++++++++++++++++ tests/unit/test-data-dir-isolation.test.js | 27 ++++++++++++++++++++++ tests/vitest.config.js | 4 ++++ 3 files changed, 57 insertions(+) create mode 100644 tests/setup/isolateDataDir.js create mode 100644 tests/unit/test-data-dir-isolation.test.js diff --git a/tests/setup/isolateDataDir.js b/tests/setup/isolateDataDir.js new file mode 100644 index 00000000..06e11bbd --- /dev/null +++ b/tests/setup/isolateDataDir.js @@ -0,0 +1,26 @@ +// Global test isolation: never let the unit/translator suite write to the user's +// real database (~/.9router). Some tests (e.g. zed-live-models, zed-native-auth) +// exercise real route handlers that call createProviderConnection — without this +// they append test rows ("zed-live-*@example.com", "guard-*@example.com", +// "Account N") straight into the live DB. +// +// DATA_DIR must be set before src/lib/dataDir.js is imported (it reads the env +// at module-eval time), which is exactly what a vitest setupFile guarantees. +// +// Escape hatches: +// - RUN_REAL=1 → keep the real DATA_DIR so *.real.test.js can read it. +// - DATA_DIR= → respect an explicit override (CI / manual isolation). +import fs from "node:fs"; +import os from "node:os"; +import path from "node:path"; + +const RUN_REAL = process.env.RUN_REAL === "1"; +const explicit = process.env.DATA_DIR; + +if (!RUN_REAL && !explicit) { + const dir = fs.mkdtempSync(path.join(os.tmpdir(), "9router-test-")); + process.env.DATA_DIR = dir; + process.on("exit", () => { + try { fs.rmSync(dir, { recursive: true, force: true }); } catch { /* best effort */ } + }); +} diff --git a/tests/unit/test-data-dir-isolation.test.js b/tests/unit/test-data-dir-isolation.test.js new file mode 100644 index 00000000..7b0dbeda --- /dev/null +++ b/tests/unit/test-data-dir-isolation.test.js @@ -0,0 +1,27 @@ +// Guard: the test harness must never write into the user's real DB. +// +// Root cause this locks down: route-level tests (zed-live-models, +// zed-native-auth) call createProviderConnection, which persists to +// $DATA_DIR/db/data.sqlite. With no DATA_DIR set, that resolved to ~/.9router — +// polluting the live DB with "zed-live-*@example.com", "guard-*@example.com" +// and "Account N" rows on every `npx vitest run`. +// +// tests/setup/isolateDataDir.js redirects DATA_DIR to a temp dir unless the +// caller opts out via RUN_REAL=1 or an explicit DATA_DIR. +import { describe, it, expect } from "vitest"; +import os from "node:os"; +import path from "node:path"; + +// When the caller opts into the real DB (RUN_REAL=1) or supplies DATA_DIR, +// isolation is intentionally disabled — this guard only applies to the default. +const ISOLATED = !process.env.RUN_REAL && !process.env.EXPECT_REAL_DATA_DIR; + +describe.skipIf(!ISOLATED)("test DATA_DIR isolation", () => { + it("points DATA_DIR at a temp dir, not ~/.9router", () => { + const dir = process.env.DATA_DIR; + expect(dir).toBeTruthy(); + const home = path.join(os.homedir(), ".9router"); + expect(path.resolve(dir)).not.toBe(path.resolve(home)); + expect(dir.startsWith(os.tmpdir())).toBe(true); + }); +}); diff --git a/tests/vitest.config.js b/tests/vitest.config.js index d53d85e0..3db8a4ea 100644 --- a/tests/vitest.config.js +++ b/tests/vitest.config.js @@ -9,6 +9,10 @@ export default defineConfig({ environment: "node", globals: true, include: ["**/*.test.js"], + // Redirect DATA_DIR to a throwaway temp dir so route-level tests that call + // createProviderConnection never touch the user's real ~/.9router DB. + // RUN_REAL=1 or an explicit DATA_DIR opts out (see setup/isolateDataDir.js). + setupFiles: ["./setup/isolateDataDir.js"], // Don't scan into git worktrees nested under .claude/ — they carry their // own copies of the test files but lack an installed node_modules (open-sse, // etc.), which makes provider imports fail during collection.