Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

test(mcp): os.homedir spy in lifecycle.test.ts leaks across test files → 6 permission tests fail on CI

オープン 初心者向け
#1,042 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
2/5
見積もり時間
1〜3時間
初心者へのやさしさ
84/100
issue の種類
バグ
明瞭さ
明確に書かれている
活発さ
静か
技術スタック
bun, typescript
領域
ci-cd, testing

調査の方向性

packages/opencode/test/mcp/lifecycle.test.ts:250 から始めて beforeEach の spy 設定を確認し、次に lifecycle スイートと packages/opencode/test/permission/next.test.ts を実行します。テスト間で spy がクリーンアップされ、6 つの permission ケースがパスし、完全な bun test スイートで順序依存の失敗が発生しなくなったら作業完了です。リグレッションカバレッジのために、提案されている smoke test を検討してください。

索引モデルが issue の本文から書いたものです。

説明

Symptom

The CI / TypeScript job (which runs the full bun test suite) fails intermittently on 6 tests in packages/opencode/test/permission/next.test.ts:

  • fromConfig - expands tilde to home directory
  • fromConfig - expands \$HOME to home directory
  • fromConfig - expands \$HOME without trailing slash
  • fromConfig - expands exact tilde to home directory
  • evaluate - matches expanded tilde pattern
  • evaluate - matches expanded \$HOME pattern

Failure output shows two DIFFERENT os.homedir() return values in the same test — one at test-execution time, one at expect().toEqual() time:

error: expect(received).toEqual(expected)
[
  {
    "action": "allow",
-   "pattern": "/tmp/mcp-lifecycle-home-Zz7Y0f/projects/*",
+   "pattern": "/tmp/mcp-lifecycle-home-VvysFV/projects/*",
    "permission": "external_directory",
  }
]

The mcp-lifecycle-home- prefix is the smoking gun — the two paths come from mkdtempSync(path.join(tmpdir(), "mcp-lifecycle-home-")).

Root cause

packages/opencode/test/mcp/lifecycle.test.ts:250 installs a spy on os.homedir in beforeEach but never restores it:

beforeEach(() => {
  spyOn(os, "homedir").mockImplementation(() => mkdtempSync(path.join(tmpdir(), "mcp-lifecycle-home-")))
  // …
})

There is no matching afterEach that calls .mockRestore() (per-spy) or mock.restore() (all mocks). When bun runs test files in the same worker process, the spy persists past lifecycle.test.ts and pollutes any downstream test that calls os.homedir(). Each new call inside the spy hits mkdtempSync again, so two calls in the same downstream test return two different random temp dirs — which is exactly what test/permission/next.test.ts observes.

Reproducibility
  • Passes locally in isolation (bun test test/permission/next.test.ts → 80/80). Local HOME is stable, no spy is installed.
  • Passes locally in isolation (bun test test/mcp/lifecycle.test.ts → clean).
  • Fails on CI when the full suite runs, because file order in the worker exposes the leak.
Impact
  • release.yml is unaffected — the release workflow runs test/branding/ + test/install/ only (see .github/workflows/release.yml:47), not the full suite, so tag builds ship green.
  • PR checks are affected — the required CI/TypeScript job fails on any PR whose test-run order exposes the leak, forcing an admin bypass or a re-run gamble. This bit PR #1041 (v0.9.3 release PR).
Fix

Two clean options — pick whichever fits the file's style:

Option A — per-spy restore (explicit, mirrors the beforeEach setup):

import { afterEach, beforeEach, spyOn } from "bun:test"

let homedirSpy: ReturnType<typeof spyOn>

beforeEach(() => {
  homedirSpy = spyOn(os, "homedir").mockImplementation(() =>
    mkdtempSync(path.join(tmpdir(), "mcp-lifecycle-home-")),
  )
  // …
})

afterEach(() => {
  homedirSpy.mockRestore()
})

Option B — blanket restore (also cleans up any other spy installed during a test):

import { afterEach, mock } from "bun:test"

afterEach(() => {
  mock.restore()
})
Regression test

Add a smoke test that asserts os.homedir() returns the process's real home immediately after the lifecycle.test.ts suite completes:

// packages/opencode/test/mcp/lifecycle-spy-leak.test.ts
import { test, expect } from "bun:test"
import os from "os"

test("os.homedir spy from lifecycle.test.ts must not leak", () => {
  expect(os.homedir()).not.toMatch(/mcp-lifecycle-home-/)
})

Or, less surgical but more general — a bun:test hook in a top-level preload that runs mock.restore() at file boundaries.

Priority

Low-medium — no production impact, no data risk. Purely a CI/DX problem: it forces PR authors to either re-run the check hoping for a favourable file order or ask for an admin bypass on unrelated PRs. Fix is small and self-contained; regression test would prevent recurrence.

主要言語
TypeScript
スター
813
フォーク
134
平均マージ
1日 19時間
マージ済み PR(30日)
64

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

AltimateAI/altimate-code のほかの issue

AltimateAI/altimate-code の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。