fix(sdk): scan CommonJS imports

This commit is contained in:
2026-09-05 08:38:04 +08:00
parent 2570dd7b97
commit 4cc83ea713
2 changed files with 154 additions and 13 deletions
@@ -91,6 +91,7 @@ test('every existing modern runtime entry is transitively isolated from the lega
test('compatibility graph catches static imports, re-exports, and import types through barrels', async () => {
const cases = [
"import '../platform/session.ts'\n",
"import Legacy = require('../platform/session.ts')\n",
"export * from '../platform/session.ts'\n",
"export type { LegacySession } from '../platform/session.ts'\n",
"type Legacy = import('../platform/session.ts').LegacySession\n",
@@ -138,6 +139,25 @@ test('compatibility graph catches string and no-substitution-template dynamic im
}
});
test('compatibility graph treats literal require calls as static dependencies', async () => {
for (const source of [
"require('../platform/session.ts')\n",
'require(`../platform/session.ts`)\n',
]) {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/platform/session.ts', 'export const legacy = true\n');
await writeFixture(root, 'framework/protocol/router.ts', source);
const found = scanCompatibilityFixture(root);
assert.equal(found?.kind, 'forbidden', source);
assert.deepEqual(
found?.path.map((file) => file.replaceAll('\\', '/').split('/framework/')[1]),
['protocol/router.ts', 'platform/session.ts'],
source,
);
}
});
test('compatibility graph resolves tsconfig path aliases to canonical files', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/platform/session.ts', 'export const legacy = true\n');
@@ -171,6 +191,24 @@ test('compatibility graph fails closed on a reachable non-static dynamic import'
assert.ok(found?.path[0]?.replaceAll('\\', '/').endsWith('/framework/protocol/router.ts'));
});
test('compatibility graph fails closed on reachable non-static require calls', async () => {
for (const source of [
"const target = '../platform/session.ts'; require(target)\n",
"const name = 'session'; require(`../platform/${name}.ts`)\n",
]) {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/platform/session.ts', 'export const legacy = true\n');
await writeFixture(root, 'framework/protocol/router.ts', source);
const found = scanCompatibilityFixture(root);
assert.equal(found?.kind, 'dynamic', source);
assert.ok(
found?.path[0]?.replaceAll('\\', '/').endsWith('/framework/protocol/router.ts'),
source,
);
}
});
test('compatibility graph applies the same isolation to a future platform/runtime.ts entry', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/platform/session.ts', 'export const legacy = true\n');
@@ -242,6 +280,54 @@ test('scanner resolves and rejects an sdk runtime path alias into framework impl
assert.match(violations[0].message, /sdk.*framework implementation.*framework\/core/);
});
test('scanner resolves and rejects a nested sdk CommonJS path alias into framework implementation', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/core/internal.ts', 'export const value = true\n');
await writeFixture(
root,
'framework/sdk/runtime/nested/bad.ts',
"const value = require('@framework/core/internal'); void value\n",
);
await writeFixture(root, 'tsconfig.json', JSON.stringify({
compilerOptions: {
baseUrl: '.',
paths: { '@framework/*': ['framework/*'] },
module: 'ESNext',
moduleResolution: 'Bundler',
allowImportingTsExtensions: true,
},
}));
const violations = scan(root, 'tsconfig.json');
assert.equal(violations.length, 1);
assert.equal(violations[0].specifier, '@framework/core/internal');
assert.match(violations[0].message, /sdk.*framework implementation.*framework\/core/);
});
test('scanner resolves and rejects a TypeScript import-equals sdk path alias', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/core/internal.ts', 'export const value = true\n');
await writeFixture(
root,
'framework/sdk/runtime/nested/bad.ts',
"import alias = require('@framework/core/internal'); void alias\n",
);
await writeFixture(root, 'tsconfig.json', JSON.stringify({
compilerOptions: {
baseUrl: '.',
paths: { '@framework/*': ['framework/*'] },
module: 'ESNext',
moduleResolution: 'Bundler',
allowImportingTsExtensions: true,
},
}));
const violations = scan(root, 'tsconfig.json');
assert.equal(violations.length, 1);
assert.equal(violations[0].specifier, '@framework/core/internal');
assert.match(violations[0].message, /sdk.*framework implementation.*framework\/core/);
});
test('scanner resolves and rejects a no-substitution-template dynamic sdk path alias', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/core/internal.ts', 'export const value = true\n');
@@ -296,6 +382,20 @@ test('scanner rejects a no-substitution-template dynamic Cocos import in nested
assert.match(violations[0].message, /sdk.*Cocos/);
});
test('scanner rejects a CommonJS Cocos import in nested sdk code', async () => {
const root = await createFixtureRoot();
await writeFixture(
root,
'framework/sdk/testing/nested/bad.ts',
"const env = require('cc/env'); void env\n",
);
const violations = scan(root);
assert.equal(violations.length, 1);
assert.equal(violations[0].specifier, 'cc/env');
assert.match(violations[0].message, /sdk.*Cocos/);
});
test('sdk migration barrel exception permits only its four retained legacy dependencies', async () => {
const root = await createFixtureRoot();
for (const file of [
@@ -329,6 +429,7 @@ test('scanner permits sdk-internal relatives and ordinary external pure dependen
"import type { Contract } from '../contracts/index.ts'; void (0 as unknown as Contract);",
"import { helper } from './helper.ts'; void helper;",
"import type { PureValue } from 'pure-external'; void (0 as unknown as PureValue);",
"const pure = require('pure-commonjs-external'); void pure;",
].join('\n'));
assert.deepEqual(scan(root), []);
@@ -442,6 +543,20 @@ test('scanner rejects new production imports of a quarantined legacy runtime', a
assert.match(violations[0].message, /new production code.*legacy runtime/);
});
test('scanner rejects CommonJS imports of a quarantined legacy runtime', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'framework/net/net-client.ts', 'export const legacy = true\n');
await writeFixture(
root,
'framework/application/nested/bad.ts',
"const legacy = require('../../net/net-client.ts'); void legacy\n",
);
const violations = scan(root);
assert.equal(violations.length, 1);
assert.equal(violations[0].specifier, '../../net/net-client.ts');
assert.match(violations[0].message, /new production code.*legacy runtime/);
});
test('scanner rejects string-literal dynamic imports that cross a boundary', async () => {
const root = await createFixtureRoot();
await writeFixture(root, 'games/a/assets/game/bad.ts', "await import('../../../framework/net/net-client.ts')\n");