refactor(ai-judge): split remaining hotspots and cover CRAP branches

- stage-ify judgeAuthorize into auditEnrollment, runPreflightGates, prepareModelCall, and enforceAndEmit
- extract tallyJoinedRows and tallyAttributable from computeMetrics, removing three dead locals
- extract validateVerdictResponse from requestStructuredVerdict
- extract collectUserTexts and charBudgetStart from buildConversationEvidence
- table-drive corpus-replay parseArgs and split main into resolveReplayModel, selectCorpusCases, and replayCorpus
- split analyzer cli main into loadReviewEvents, withinWindow, loadAuditEnrolled, and printReport with a run-as-script guard
- add 81 tests covering parseEntry, extractBashCommandEvidence, validateVerdictResponse, forcedToolChoice, classifyGit dry-run paths, CLI arg/window/report rendering, and the infra-failure result path
- add @vitest/coverage-istanbul for exact per-function CRAP scoring via fallow health --coverage
This commit is contained in:
2026-08-22 01:24:50 +08:00
parent 0903119a46
commit c479f51469
18 changed files with 2756 additions and 455 deletions
@@ -444,6 +444,140 @@ describe("authorizeInnerCommand — fail-closed deferrals", () => {
expect(check).toEqual([]);
});
// -- extractBashCommandEvidence guard branches: every malformed shape
// of the structured payload must defer silently (fail-closed) without
// reaching the deterministic query.
it("defers silently when payload.evidence is not an array", async () => {
const details = bashDetails("call_1", null, "timeout 30s pnpm test");
const { verdict, log, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: {
payload: {
...details.payload,
evidence: "not-an-array" as unknown as [],
},
},
});
expect(verdict.kind).toBe("defer");
expect(log).toEqual([]);
expect(check).toEqual([]);
});
it("defers silently when payload.request is missing", async () => {
const details = bashDetails("call_1", null, "timeout 30s pnpm test");
const { verdict, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: {
payload: {
...details.payload,
request: undefined as unknown as (typeof details.payload)["request"],
},
},
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently when the requester was forwarded", async () => {
const details = bashDetails("call_1", null, "timeout 30s pnpm test");
const { verdict, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: {
payload: {
...details.payload,
request: {
...details.payload.request,
requester: { agentName: null, forwarded: true, sessionId: "s-child" },
},
},
},
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently when the ask came through an invoking tool", async () => {
const details = bashDetails("call_1", null, "timeout 30s pnpm test");
const { verdict, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: {
payload: {
...details.payload,
request: {
...details.payload.request,
invokedToolName: "custom_tool",
},
},
},
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently when the request surface is not Bash", async () => {
const details = bashDetails("call_1", null, "timeout 30s pnpm test");
const { verdict, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: {
payload: {
...details.payload,
request: { ...details.payload.request, surface: "edit" },
},
},
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently on a blank request value", async () => {
const details = bashDetails("call_1", null, "timeout 30s pnpm test");
const { verdict, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: {
payload: {
...details.payload,
request: { ...details.payload.request, value: " " },
},
},
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently when the legacy command projection disagrees with the structured value", async () => {
const { verdict, check } = await run({
recoveredCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: { command: "echo different" },
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently on a blank full-command evidence text", async () => {
const details = bashDetails(
"call_1",
null,
"timeout 30s pnpm test",
" ",
);
const { verdict, check } = await run({
recoveredCommand: " ",
unitCommand: "timeout 30s pnpm test",
states: { "pnpm test": "allow" },
details: { payload: details.payload },
});
expect(verdict.kind).toBe("defer");
expect(check).toEqual([]);
});
it("defers silently for a shell alias that re-exposes Bash", async () => {
const details = bashDetails(
"call_1",