Repository navigation
test(shared): mutation-gate MusicControlService + GuildAutomationOrchestrator - #1454
Conversation
50 tests; scoped mutation total 17.29% -> 79.84% (covered 90.35%).
Add music/MusicControlService and guildAutomation/GuildAutomationOrchestrator to the Stryker mutate set. Combined All-files score 83.23% -> 83.67% (17 modules). break stays 82 (headroom for CI timing variance).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
📝 WalkthroughWalkthroughTwo spec files are substantially expanded with new test helpers and broad method-level coverage: ChangesGuildAutomationOrchestrator Test Expansion
MusicControlService Test Expansion and Stryker Config
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~25 minutes Possibly related PRs
Suggested labels
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Failed to generate code suggestions for PR |
There was a problem hiding this comment.
Actionable comments posted: 4
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In
`@packages/shared/src/services/guildAutomation/GuildAutomationOrchestrator.spec.ts`:
- Around line 1046-1080: The test for "uses provided actualState over
lastCapturedState" has a descriptive title but the assertion does not verify
that the provided state is actually being used. The current assertion only
checks that call[4] (operations array) has a length property, which does not
confirm that the providedState (with version 99 and guild.discordId
'provided-guild-id') took precedence over storedManifest or lastCapturedState.
Add assertions that examine the createPlanRecord mock call arguments to verify
that the provided state's unique properties were actually used in the plan
creation, such as checking that the plan diagnostics or arguments reflect the
version 99 and discordId 'provided-guild-id' from providedState, not the values
from storedManifest.
- Around line 1200-1231: The severity-mapping tests are only asserting that
upsertDrift was called, but not verifying the actual severity argument passed.
In
packages/shared/src/services/guildAutomation/GuildAutomationOrchestrator.spec.ts
at lines 1200-1231, 1233-1253, 1255-1286, and 1288-1318, replace the
non-assertive expect(mocks.upsertDrift).toHaveBeenCalled() with an actual
assertion that checks the severity values collected in the severities array
match the expected severity for each test: 'low' for the 1-2 operations test,
'medium' for the corresponding mid-range operations test, and 'high' for the
high operations test. This ensures the tests will catch severity-mapping
regressions rather than just verifying the mock was invoked.
- Around line 220-238: The test uses jest.useFakeTimers() but restoration with
jest.useRealTimers() is not protected, so if any assertion fails before
restoration, fake timers will leak to subsequent tests. Restructure the test by
moving jest.useFakeTimers() before a try block, keeping all the test logic
(including all await calls and expect statements in the 'releases lock in
finally block when plan succeeds' test and the other affected tests) inside the
try block, and placing jest.useRealTimers() in a finally block to ensure timer
restoration always occurs regardless of whether assertions pass or fail.
In `@packages/shared/src/services/music/MusicControlService.spec.ts`:
- Around line 334-349: The test "uses default timeout of 10000ms" currently
waits on a real 10,000ms timeout when calling sendCommand, making the test slow.
Replace the real timeout with fake timers by calling jest.useFakeTimers() before
the test or within the test setup, then use jest.runAllTimers() or
jest.advanceTimersByTime() to simulate the timeout passage without actually
waiting. This will make the test run quickly while still verifying the 10-second
timeout behavior. Remember to restore real timers after the test completes using
jest.useRealTimers() if using fake timers at the test level.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Organization UI
Review profile: CHILL
Plan: Pro
Run ID: f5ae7412-c6b4-46cf-8ab1-a23ec4e8af8a
📒 Files selected for processing (3)
packages/shared/src/services/guildAutomation/GuildAutomationOrchestrator.spec.tspackages/shared/src/services/music/MusicControlService.spec.tspackages/shared/stryker.conf.json
📜 Review details
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (12)
- GitHub Check: Test — bot
- GitHub Check: Test — frontend
- GitHub Check: Checks
- GitHub Check: Test — backend
- GitHub Check: Test — shared
- GitHub Check: cubic · AI code reviewer
- GitHub Check: quality / Lint (lint)
- GitHub Check: quality / SAST (CodeQL) (javascript-typescript)
- GitHub Check: Build — bot
- GitHub Check: Build — backend
- GitHub Check: Build — frontend
- GitHub Check: Mutation — shared
🔇 Additional comments (1)
packages/shared/stryker.conf.json (1)
25-27: LGTM!
There was a problem hiding this comment.
5 issues found across 3 files
Tip: cubic can generate docs of your entire codebase and keep them up to date. Try it here.
Re-trigger cubic
- orchestrator: drive createAutomationPlan via mock to assert real severity values (none/low/medium/high boundaries) instead of toHaveBeenCalled; raises module mutation 79.84% -> 90.70%. - orchestrator: assert provided actualState precedence; protect fake timers with try/finally to prevent leakage. - music: use fake timers for the 10s default-timeout test (no real wait).
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
|
@coderabbitai addressed all 4 findings in 16ccc29:
|
|
Tip For best results, initiate chat on the files or code changes.
Combined 84.36% with (๑˃ᴗ˂)ﻭ If you found this review helpful, would you consider giving us a shout-out on X? Thank you for using CodeRabbit! |
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Requires human review: Auto-approving this large, test-only expansion is risky. A human review is needed to verify coverage quality and test correctness.
Re-trigger cubic
…#1457) Closes #1456. ## Problem The `Security` CI check (`npm audit --audit-level=high`) fails on **every open PR** (e.g. #1454, #1455) — the lockfile pins two transitive deps with high-severity advisories, surfaced by an advisory-DB update. This blocks the merge queue (priority #3). ## Fix | package | before | after | advisory | |---|---|---|---| | `vite` | 8.0.14 | 8.0.16 | GHSA-fx2h-pf6j-xcff (`server.fs.deny` bypass), GHSA-v6wh-96g9-6wx3 (launch-editor NTLMv2) | | `form-data` | 4.0.5 | 4.0.6 | CRLF injection via unescaped multipart field names | - `packages/frontend/package.json`: vite devDependency floor `^8.0.14` → `^8.0.16`. vite 8.0.16 requires rolldown 1.0.3, which accounts for the bulk of the lockfile churn. - `package.json`: root `overrides` pin `form-data: ">=4.0.6"` (transitive, no workspace owner). - `package-lock.json`: regenerated; `npm audit --audit-level=high` → **0 high** (verified locally). Both are dev/build-tool deps not shipped to the bot runtime. All four workspace `type:check`s pass locally with vite 8.0.16. Moderate advisories remain below the gate and are out of scope. ## Verification - [x] `npm audit --audit-level=high` exits 0 - [x] `npm run type:check` (shared, bot, backend, frontend) passes - [ ] CI: Build/Test (all packages), Security <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Updated build tool dependency to latest compatible version. * Extended dependency override configurations for enhanced compatibility. <!-- end of auto-generated comment: release notes by coderabbit.ai --> <!-- This is an auto-generated description by cubic. --> --- ## Summary by cubic Bump `vite` to 8.0.16 and enforce `form-data` >= 4.0.6 to clear high-severity advisories and unblock the Security CI gate. Also pin `vite` at the repo root so `@vitejs/plugin-react` resolves it correctly during builds. - **Dependencies** - Root dev + frontend: `vite` ^8.0.16 (was ^8.0.14); pulls `rolldown` 1.0.3 and `tinyglobby` ^0.2.17. - Root overrides: `form-data` >= 4.0.6 to fix CRLF injection in transitive deps. - Regenerated lockfile; `npm audit --audit-level=high` now reports 0 high. - **Bug Fixes** - Fixed hoisting so `@vitejs/plugin-react` resolves the updated `vite`; `npm run build:frontend` succeeds. <sup>Written for commit dba6347. Summary will update on new commits.</sup> <a href="https://cubic.dev/pr/LucasSantana-Dev/Lucky/pull/1457?utm_source=github" target="_blank" rel="noopener noreferrer" data-no-image-dialog="true"><picture><source media="(prefers-color-scheme: dark)" srcset="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"><source media="(prefers-color-scheme: light)" srcset="https://www.cubic.dev/buttons/review-in-cubic-light.svg"><img alt="Review in cubic" src="https://www.cubic.dev/buttons/review-in-cubic-dark.svg"></picture></a> <!-- End of auto-generated description by cubic. -->
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
Clears 4 CodeQL findings blocking #1454: unused afterEach import in MusicControlService.spec, unused makeRepository destructuring and unused result binding in GuildAutomationOrchestrator.spec. Specs still pass (95 tests).
There was a problem hiding this comment.
Your free trial has ended. If you'd like to continue receiving code reviews, you can add a payment method here.
There was a problem hiding this comment.
0 issues found across 2 files (changes from recent commits).
Auto-approved: Test-only and config changes adding mutation testing for two services. No source logic modified; low risk of breakage.
Re-trigger cubic
|



Second gate-expansion batch for sub-issues of #1426. Adds 2 services to the Stryker
mutateset (now 17 modules gated).Modules gated (scoped mutation total before → after)
Combined
All filesmutation score 83.23% → 83.67% (17 modules).breakstays at 82 — kept ~1.7pt below combined for CI timing-variance headroom (orchestrator has a few timeout/errored mutants on the lock/cleanup paths). Full gate green locally.Test-only + config change; no source touched. MusicControlService reaches 93.70%; the orchestrator jumps from 17%→79.84% total (90.35% of covered code killed) — remaining gap is a handful of timeout-prone lock-cleanup mutants, acceptable above the 82 gate.
Closes #1447
Closes #1448
Relates to #1426
Summary by cubic
Adds
music/MusicControlServiceandguildAutomation/GuildAutomationOrchestratorto the Stryker mutate set and expands tests to gate mutants, raising scores to 93.70% and 90.70%. Hardens specs (locks/TTL, severity mapping, actualState precedence) and clears 4 CodeQL findings; test-only + config; gate stays 82 — completes #1447 and #1448 (part of #1426) and unblocks #1454.Dependencies
src/services/music/MusicControlService.tsandsrc/services/guildAutomation/GuildAutomationOrchestrator.tstopackages/shared/stryker.conf.jsonmutate list.Bug Fixes
Written for commit bd67c19. Summary will update on new commits.
Summary by CodeRabbit
Tests
Chores