Files
adolf/test/scripts/verify-plugin-npm-published-runtime.test.ts
alvis bedb527145
Some checks failed
ClawSweeper Dispatch / dispatch (push) Has been cancelled
CodeQL / Security High (actions) (push) Has been cancelled
CodeQL / Security High (channel-runtime-boundary) (push) Has been cancelled
CodeQL / Security High (core-auth-secrets) (push) Has been cancelled
CodeQL / Security High (mcp-process-tool-boundary) (push) Has been cancelled
CodeQL / Security High (network-ssrf-boundary) (push) Has been cancelled
CodeQL / Security High (plugin-trust-boundary) (push) Has been cancelled
CodeQL / Security High (process-exec-boundary) (push) Has been cancelled
Docs Sync Publish Repo / sync-publish-repo (push) Has been cancelled
Docs / docs (push) Has been cancelled
OpenClaw Stable Main Closeout / Resolve stable release closeout inputs (push) Has been cancelled
OpenClaw Stable Main Closeout / Verify stable main closeout (push) Has been cancelled
Workflow Sanity / no-tabs (push) Has been cancelled
Workflow Sanity / actionlint (push) Has been cancelled
Workflow Sanity / generated-doc-baselines (push) Has been cancelled
CI / runner-admission (push) Has been cancelled
CI / preflight (push) Has been cancelled
CI / security-fast (push) Has been cancelled
CI / pnpm-store-warmup (push) Has been cancelled
CI / build-artifacts (push) Has been cancelled
CI / native-i18n (push) Has been cancelled
CI / ${{ matrix.check_name }} (push) Has been cancelled
CI / ${{ matrix.checkName }} (push) Has been cancelled
CI / checks-node-compat-node22 (push) Has been cancelled
CI / check-bundled-channel-config-metadata (push) Has been cancelled
CI / check-dependencies (push) Has been cancelled
CI / check-guards (push) Has been cancelled
CI / check-lint (push) Has been cancelled
CI / check-prod-types (push) Has been cancelled
CI / check-shrinkwrap (push) Has been cancelled
CI / check-test-types (push) Has been cancelled
CI / check-additional-boundaries-a (push) Has been cancelled
CI / check-additional-boundaries-bcd (push) Has been cancelled
CI / check-additional-extension-bundled (push) Has been cancelled
CI / check-additional-extension-channels (push) Has been cancelled
CI / check-additional-extension-package-boundary (push) Has been cancelled
CI / check-additional-runtime-topology-architecture (push) Has been cancelled
CI / check-session-accessor-boundary (push) Has been cancelled
CI / check-session-transcript-reader-boundary (push) Has been cancelled
CI / check-docs (push) Has been cancelled
CI / skills-python (push) Has been cancelled
CI / macos-swift (push) Has been cancelled
CI / ios-build (push) Has been cancelled
CI / ci-timings-summary (push) Has been cancelled
Native App Locale Refresh / Refresh native fa (push) Has been cancelled
Native App Locale Refresh / Refresh native fr (push) Has been cancelled
Native App Locale Refresh / Refresh native hi (push) Has been cancelled
Native App Locale Refresh / Refresh native id (push) Has been cancelled
Native App Locale Refresh / Refresh native it (push) Has been cancelled
Native App Locale Refresh / Refresh native ja-JP (push) Has been cancelled
Control UI Locale Refresh / plan (push) Has been cancelled
Control UI Locale Refresh / Refresh ${{ matrix.locale }} (push) Has been cancelled
Control UI Locale Refresh / Commit control UI locale refresh (push) Has been cancelled
Live Media Runner Image / Build live media runner image (push) Has been cancelled
Native App Locale Refresh / Refresh native ar (push) Has been cancelled
Native App Locale Refresh / Refresh native de (push) Has been cancelled
Native App Locale Refresh / Refresh native es (push) Has been cancelled
Native App Locale Refresh / Refresh native ko (push) Has been cancelled
Native App Locale Refresh / Refresh native nl (push) Has been cancelled
Native App Locale Refresh / Refresh native pl (push) Has been cancelled
Native App Locale Refresh / Refresh native pt-BR (push) Has been cancelled
Native App Locale Refresh / Refresh native ru (push) Has been cancelled
Native App Locale Refresh / Refresh native sv (push) Has been cancelled
Native App Locale Refresh / Refresh native th (push) Has been cancelled
Native App Locale Refresh / Refresh native tr (push) Has been cancelled
Native App Locale Refresh / Refresh native uk (push) Has been cancelled
Native App Locale Refresh / Refresh native vi (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-CN (push) Has been cancelled
Native App Locale Refresh / Refresh native zh-TW (push) Has been cancelled
Native App Locale Refresh / Commit native locale refresh (push) Has been cancelled
Plugin Init Scaffold Validation / Validate provider scaffold (push) Has been cancelled
Plugin NPM Release / preview_plugins_npm (push) Has been cancelled
Plugin NPM Release / Validate release publish approval (push) Has been cancelled
Plugin NPM Release / preview_plugin_pack (push) Has been cancelled
Plugin NPM Release / publish_plugins_npm (push) Has been cancelled
Sandbox Common Smoke / sandbox-common-smoke (push) Has been cancelled
Website Installer Sync / static (push) Has been cancelled
Website Installer Sync / linux-docker (push) Has been cancelled
Website Installer Sync / macos-installer (push) Has been cancelled
Website Installer Sync / windows-installer (push) Has been cancelled
Website Installer Sync / sync-website (push) Has been cancelled
Vendor OpenClaw source as Adolf fork baseline
Adolf is a fork/vendored clone of github.com/openclaw/openclaw (v2026.6.11),
free to diverge. Tree copied sans upstream .git; upstream remote added for
future syncs. Node pinned to 24 (.nvmrc); engines already require >=22.19.
Preserves docs/ARCHITECTURE.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LeqyaxJF2nbRXJtae2kNB2
2026-07-05 09:36:54 +00:00

344 lines
12 KiB
TypeScript

// Verify Plugin Npm Published Runtime tests cover verify plugin npm published runtime script behavior.
import { describe, expect, it } from "vitest";
import {
collectPluginNpmPublishedRuntimeErrors,
findPackedPackageReadmePath,
parseVerifyPublishedPluginRuntimeArgs,
parseNpmReadmeMetadata,
readPluginNpmCommandOptions,
readPositiveIntEnv,
resolveNpmPackFilename,
runPluginNpmCommand,
usage,
} from "../../scripts/verify-plugin-npm-published-runtime.mjs";
describe("plugin npm publish verifier args", () => {
it("parses help and package specs before npm calls", () => {
expect(parseVerifyPublishedPluginRuntimeArgs(["--help"])).toEqual({ help: true, spec: "" });
expect(parseVerifyPublishedPluginRuntimeArgs(["--", "@openclaw/discord@2026.5.2"])).toEqual({
help: false,
spec: "@openclaw/discord@2026.5.2",
});
});
it("rejects unknown and extra args before npm calls", () => {
expect(() => parseVerifyPublishedPluginRuntimeArgs([])).toThrow(usage());
expect(() => parseVerifyPublishedPluginRuntimeArgs(["--wat"])).toThrow(
"Unknown plugin npm verifier option: --wat",
);
expect(() =>
parseVerifyPublishedPluginRuntimeArgs(["@openclaw/discord@2026.5.2", "extra"]),
).toThrow("Unexpected plugin npm verifier argument: extra");
});
});
describe("plugin npm publish verifier retry limits", () => {
it("rejects loose numeric retry env values instead of parsing prefixes", () => {
expect(() =>
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS", 90, {
OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS: "2tries",
}),
).toThrow("invalid OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS: 2tries");
expect(() =>
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS", 10000, {
OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS: "1e3",
}),
).toThrow("invalid OPENCLAW_PLUGIN_NPM_VERIFY_DELAY_MS: 1e3");
expect(() =>
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS", 6, {
OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS: "0",
}),
).toThrow("invalid OPENCLAW_PLUGIN_NPM_README_VERIFY_ATTEMPTS: 0");
});
it("accepts strict positive retry env values and defaults", () => {
expect(readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_VERIFY_ATTEMPTS", 90, {})).toBe(90);
expect(
readPositiveIntEnv("OPENCLAW_PLUGIN_NPM_README_VERIFY_DELAY_MS", 10000, {
OPENCLAW_PLUGIN_NPM_README_VERIFY_DELAY_MS: "2500",
}),
).toBe(2500);
});
});
describe("plugin npm publish verifier command limits", () => {
it("bounds npm command runtime and captured output by default", () => {
expect(readPluginNpmCommandOptions({})).toStrictEqual({
encoding: "utf8",
killSignal: "SIGKILL",
maxBuffer: 16 * 1024 * 1024,
stdio: ["ignore", "pipe", "pipe"],
timeout: 5 * 60 * 1000,
});
});
it("accepts strict npm command timeout and buffer overrides", () => {
expect(
readPluginNpmCommandOptions({
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "33554432",
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "120000",
}),
).toMatchObject({
maxBuffer: 32 * 1024 * 1024,
timeout: 120000,
});
});
it("rejects loose npm command timeout and buffer overrides", () => {
expect(() =>
readPluginNpmCommandOptions({
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "60s",
}),
).toThrow("invalid OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: 60s");
expect(() =>
readPluginNpmCommandOptions({
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "16mb",
}),
).toThrow("invalid OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: 16mb");
});
it("runs npm metadata commands with bounded exec options", () => {
const calls: unknown[] = [];
const output = runPluginNpmCommand(["view", "@openclaw/discord", "readme"], {
env: {
OPENCLAW_PLUGIN_NPM_COMMAND_MAX_BUFFER_BYTES: "1024",
OPENCLAW_PLUGIN_NPM_COMMAND_TIMEOUT_MS: "2500",
},
execFileSyncImpl(command: string, args: string[], options: unknown) {
calls.push({ args, command, options });
return JSON.stringify("# Discord");
},
});
expect(output).toBe(JSON.stringify("# Discord"));
expect(calls).toStrictEqual([
{
args: ["view", "@openclaw/discord", "readme"],
command: "npm",
options: {
encoding: "utf8",
killSignal: "SIGKILL",
maxBuffer: 1024,
stdio: ["ignore", "pipe", "pipe"],
timeout: 2500,
},
},
]);
});
});
describe("collectPluginNpmPublishedRuntimeErrors", () => {
it("flags published plugin packages with TypeScript entries and no compiled runtime output", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
spec: "@openclaw/discord@2026.5.2",
packageJson: {
name: "@openclaw/discord",
version: "2026.5.2",
openclaw: {
extensions: ["./index.ts"],
},
},
files: ["package.json", "index.ts"],
}),
).toEqual([
"@openclaw/discord@2026.5.2 requires compiled runtime output for TypeScript entry ./index.ts: expected ./dist/index.js, ./dist/index.mjs, ./dist/index.cjs, ./index.js, ./index.mjs, ./index.cjs",
]);
});
it("accepts published plugin packages with explicit runtimeExtensions", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/zalo",
version: "2026.5.3",
openclaw: {
extensions: ["./index.ts"],
runtimeExtensions: ["./dist/index.js"],
},
},
files: ["package.json", "index.ts", "dist/index.js"],
}),
).toStrictEqual([]);
});
it("flags missing explicit runtimeExtensions outputs", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/line",
version: "2026.5.3",
openclaw: {
extensions: ["./src/index.ts"],
runtimeExtensions: ["./dist/index.js"],
},
},
files: ["package.json", "src/index.ts"],
}),
).toEqual(["@openclaw/line@2026.5.3 runtime extension entry not found: ./dist/index.js"]);
});
it("flags runtimeExtensions length mismatches", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/acpx",
version: "2026.5.3",
openclaw: {
extensions: ["./index.ts", "./tools.ts"],
runtimeExtensions: ["./dist/index.js"],
},
},
files: ["package.json", "dist/index.js"],
}),
).toEqual([
"@openclaw/acpx@2026.5.3 package.json openclaw.runtimeExtensions length (1) must match openclaw.extensions length (2)",
]);
});
it("flags blank runtimeExtensions entries instead of falling back to inferred outputs", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/whatsapp",
version: "2026.5.3",
openclaw: {
extensions: ["./src/index.ts"],
runtimeExtensions: [" "],
},
},
files: ["package.json", "src/index.ts", "dist/index.js"],
}),
).toEqual([
"@openclaw/whatsapp@2026.5.3 package.json openclaw.runtimeExtensions[0] must be a non-empty string",
]);
});
it("flags published plugin packages with TypeScript setup entries and no compiled setup runtime", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/line",
version: "2026.5.3",
openclaw: {
extensions: ["./index.ts"],
runtimeExtensions: ["./dist/index.js"],
setupEntry: "./setup-entry.ts",
},
},
files: ["package.json", "index.ts", "dist/index.js", "setup-entry.ts"],
}),
).toEqual([
"@openclaw/line@2026.5.3 requires compiled runtime output for TypeScript entry ./setup-entry.ts: expected ./dist/setup-entry.js, ./dist/setup-entry.mjs, ./dist/setup-entry.cjs, ./setup-entry.js, ./setup-entry.mjs, ./setup-entry.cjs",
]);
});
it("accepts published plugin packages with explicit runtimeSetupEntry", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/qqbot",
version: "2026.5.3",
openclaw: {
extensions: ["./index.ts"],
runtimeExtensions: ["./dist/index.js"],
setupEntry: "./setup-entry.ts",
runtimeSetupEntry: "./dist/setup-entry.js",
},
},
files: ["package.json", "dist/index.js", "dist/setup-entry.js"],
}),
).toStrictEqual([]);
});
it("flags missing explicit runtimeSetupEntry outputs", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/matrix",
version: "2026.5.3",
openclaw: {
extensions: ["./index.ts"],
runtimeExtensions: ["./dist/index.js"],
setupEntry: "./setup-entry.ts",
runtimeSetupEntry: "./dist/setup-entry.js",
},
},
files: ["package.json", "dist/index.js"],
}),
).toEqual(["@openclaw/matrix@2026.5.3 runtime setup entry not found: ./dist/setup-entry.js"]);
});
it("flags runtimeSetupEntry without setupEntry", () => {
expect(
collectPluginNpmPublishedRuntimeErrors({
packageJson: {
name: "@openclaw/twitch",
version: "2026.5.3",
openclaw: {
extensions: ["./index.ts"],
runtimeExtensions: ["./dist/index.js"],
runtimeSetupEntry: "./dist/setup-entry.js",
},
},
files: ["package.json", "dist/index.js", "dist/setup-entry.js"],
}),
).toEqual([
"@openclaw/twitch@2026.5.3 package.json openclaw.runtimeSetupEntry requires openclaw.setupEntry",
]);
});
});
describe("resolveNpmPackFilename", () => {
it("uses the final tarball filename from plain npm pack output", () => {
const noisyOutput = [
"npm notice",
"npm notice package: @openclaw/msteams@2026.5.24-beta.1",
"openclaw-msteams-2026.5.24-beta.1.tgz",
"",
].join("\n");
expect(resolveNpmPackFilename(noisyOutput)).toBe("openclaw-msteams-2026.5.24-beta.1.tgz");
});
it("rejects path-like tarball output instead of reading outside the pack directory", () => {
const unsafeOutputs = [
"../openclaw-msteams.tgz",
"nested/openclaw-msteams.tgz",
"nested\\openclaw-msteams.tgz",
"/tmp/openclaw-msteams.tgz",
"C:\\temp\\openclaw-msteams.tgz",
"openclaw-msteams\u0000.tgz",
];
for (const output of unsafeOutputs) {
expect(() => resolveNpmPackFilename(output)).toThrow(
"npm pack did not report a tarball filename",
);
}
});
});
describe("findPackedPackageReadmePath", () => {
it("finds a root package README without accepting nested documentation files", () => {
expect(
findPackedPackageReadmePath(["package.json", "docs/README.md", "README.md", "dist/index.js"]),
).toBe("README.md");
expect(findPackedPackageReadmePath(["package.json", "docs/README.md"])).toBe("");
});
});
describe("parseNpmReadmeMetadata", () => {
it("accepts non-empty npm readme metadata", () => {
expect(parseNpmReadmeMetadata(JSON.stringify("# Plugin\n\nInstall it."))).toBe(
"# Plugin\n\nInstall it.",
);
});
it("rejects empty or unsupported npm readme metadata", () => {
expect(parseNpmReadmeMetadata(JSON.stringify(""))).toBe("");
expect(parseNpmReadmeMetadata(JSON.stringify(null))).toBe("");
expect(parseNpmReadmeMetadata("{")).toBe("");
});
});