Skip to content

test(sections): drop the thin secret-family suites the scenarios already pin - #396

Merged
Vivswan merged 1 commit into
mainfrom
wt/r2s-secret-family
Sep 22, 2026
Merged

Vivswan merged 1 commit into
mainfrom
wt/r2s-secret-family

Conversation

@Vivswan

@Vivswan Vivswan commented Sep 21, 2026 •

Copy link
Copy Markdown
Owner

Before / After

file cases before cases after
src/sections/agents_secrets/agents_secrets.test.ts 0 (3 through the shared helper) deleted
src/sections/codespaces_secrets/codespaces_secrets.test.ts 0 (3 through the shared helper) deleted
src/sections/dependabot_secrets/dependabot_secrets.test.ts 0 (3 through the shared helper) deleted
test/sections/secret-family.ts 3 deleted

The count is test( and test.each( lines; the three thin files ran the helper's three cases each, nine in all.

How

Each thin file pinned three facts for its family: the label, noun, and route of the plan, the seal against the family's public key, and the keep default with the delete under the knob.
Five mutants of the shared factory and engine redden those cases and the family scenarios alike, with the source restored after each.
The scenarios are bun run test:e2e --sections agents_secrets,codespaces_secrets,dependabot_secrets.

mutant (source, edit) thin suites scenarios red
src/sections/shared/repo-secrets.ts, undeclaredDefault: "keep" becomes "delete" 6 of 9 fail 12 of 19 (apply-converges, check-drift, snapshot-roundtrip, undeclared-keep-note per family)
repo-secrets.ts, the path segment becomes "actions" for every family 9 of 9 fail 16 of 19 (every family scenario but name-rejected)
repo-secrets.ts, the scope noun becomes "secret" 3 of 9 fail 6 of 19 (apply-converges and check-drift per family)
repo-secrets.ts, the scope label becomes "secrets" 3 of 9 fail 3 of 19 (check-drift per family)
src/sections/shared/secrets-engine.ts, the sealed body's key_id becomes a constant 3 of 9 fail 9 of 19 (apply-converges, undeclared-delete, undeclared-keep-note per family)
  • The shared helper leaves too. With the three importers gone, bun run knip names test/sections/secret-family.ts as an unused file.
  • The thin files' stated reason no longer holds. The shared helper's header said the thin files kept the diff-aware CI selector mapped to the section.
    .github/scripts/changed-sections.ts maps any file under a section directory to its key, test or not.

Proof

  • Unit: the full bun test is 4217 pass, 0 fail (nine cases fewer).
  • Gates: bun run check (lint, arch lint, compat, typecheck, build:check) green; bun run knip green after the helper's deletion.
  • Scenarios: bun run test:e2e --sections agents_secrets,codespaces_secrets,dependabot_secrets 19/19 passed on the unmutated source.

Kept

  • src/sections/actions_secrets/actions_secrets.test.ts still pins the shared factory and engine through the actions family; nothing in it changes here.
  • The family scenarios stay the owners of each family's route, noun, label, key, and default.
Technical details
  • Line accounting: git diff --numstat origin/main...HEAD is 0 added, 144 deleted across four files: 13, 12, and 12 for the thin suites, 107 for the helper.
  • Reviewer note: the five mutants are source edits that were never committed; each was reverted with git checkout -- src before the next.
  • Reviewer note: test/e2e/mock/server.ts mentions "secret-family" in a comment about the PUT handlers unsealing synchronously; it does not import the deleted helper.
  • Reviewer note: no fixture here is derived from real data.
  • Reviewer note: the unseal-to-plaintext assertion is pinned by src/sections/actions_secrets/actions_secrets.test.ts and test/sections/secrets-engine.test.ts, not by scenarios.
    The e2e mock stores a digest and no scenario compares unsealed values for any family.

BEGIN_COMMIT_OVERRIDE
test(sections): drop the thin secret-family suites the scenarios already pin
END_COMMIT_OVERRIDE

…ady pin

The agents, codespaces, and dependabot secrets suites pinned three facts per family through one shared helper: the label, noun, and route of the plan, the seal against the family's key, and the keep default with the delete under the knob.
Five mutants of the shared factory and engine that redden those suites also fail the scenarios of all three families, so the scenarios own every fact.

The shared helper in test/sections had no importer left, so it leaves in the same change.
The thin files' stated reason, keeping the diff-aware CI selector mapped to the section, no longer holds: any file under a section directory selects it.
@Vivswan Vivswan added the merge-when-green Owner approved: merge once every gate is green label Sep 21, 2026
Copilot AI balanced review requested due to automatic review settings September 21, 2026 23:46
@Vivswan Vivswan added the merge-when-green Owner approved: merge once every gate is green label Sep 21, 2026
@github-actions

Copy link
Copy Markdown
Contributor

File size check

0 over a hard cap (fails), 31 warning(s).

File Size Tier Cap
.github/scripts/release-pipeline.ts:6 156 chars warn 150
.github/scripts/release-pipeline.ts:468 151 chars warn 150
.github/scripts/release-pipeline.ts:1417 153 chars warn 150
.github/scripts/release-pipeline.ts:1 30 comment lines (header) warn 25
.github/scripts/release-pipeline.ts:464 14 comment lines warn 10
.github/workflows/post-green.yml:27 153 chars warn 150
.github/workflows/post-green.yml:140 16 comment lines warn 10
docs/upgrading/v2-to-v3.md 1257 lines warn 1040
src/engine/layers.ts:217 157 chars warn 150
src/flows/settings-write.ts:142 159 chars warn 150
src/flows/settings-write.ts:30 11 comment lines warn 10
src/flows/snapshot.ts:189 13 comment lines warn 10
src/github/secret-scan.ts:42 11 comment lines warn 10
src/schema.ts:186 153 chars warn 150
src/schema.ts:197 176 chars warn 150
src/sections/contract/errors.ts:14 14 comment lines warn 10
src/sections/contract/module.ts:963 185 chars warn 150
src/sections/contract/module.ts:627 12 comment lines warn 10
src/sections/contract/module.ts:897 12 comment lines warn 10
src/sections/secret_scanning_custom_patterns/compilable-form.ts:382 161 chars warn 150
src/sections/shared/roles.ts:43 13 comment lines warn 10
src/types.ts:16 156 chars warn 150
test/docs/guides.test.ts:451 155 chars warn 150
test/e2e/generators.ts 2639 lines warn 2560
test/e2e/generators.ts:1709 166 chars warn 150
test/e2e/generators.ts:1863 161 chars warn 150
test/e2e/generators.ts:1672 12 comment lines warn 10
test/engine/execute.test.ts:617 152 chars warn 150
test/flows/merge-parity.test.ts:63 164 chars warn 150
test/scripts/auto-fix-allowlist.test.ts:8 12 comment lines warn 10
test/scripts/gen-docs.test.ts:588 155 chars warn 150

Split the file, wrap the line, shorten or exempt the comment, or list the path in .file-size-allow.local with a # reason.

5 managed file(s) skipped; repo-platform owns them.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Existing unit and end-to-end scenarios retain coverage of the deleted assertions.

Review effort: Balanced
Findings: None

What changed in this PR

Removes redundant secret-family unit suites whose behavior is already covered by section-specific end-to-end scenarios and the shared Actions secrets suite.

Changes:

  • Deletes three thin section test wrappers.
  • Deletes their now-unused shared test helper.
File Description
src/​sections/​agents_secrets/​agents_secrets.test.ts Removes redundant Agents secrets tests.
src/​sections/​codespaces_secrets/​codespaces_secrets.test.ts Removes redundant Codespaces secrets tests.
src/​sections/​dependabot_secrets/​dependabot_secrets.test.ts Removes redundant Dependabot secrets tests.
test/​sections/​secret-family.ts Removes the unused shared test helper.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@Vivswan
Vivswan marked this pull request as ready for review September 22, 2026 00:26
@Vivswan
Vivswan merged commit 76d911e into main Sep 22, 2026
39 checks passed
@Vivswan
Vivswan deleted the wt/r2s-secret-family branch September 22, 2026 00:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

merge-when-green Owner approved: merge once every gate is green

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants