fix(verifier): don't crash on throwing JS predicates (#21)

* fix(verifier): don't crash on throwing JS predicates

formulaThunk used to panic whenever goja returned an error from a
predicate callable, and nothing on the LTL -> runner path recovered, so
a malformed spec (e.g. a property whose body throws or touches an
undefined field) would kill the verifier process.

Latch the first error on formulaState, return false so LTL marks the
property violated, and expose PredicateError(name) that walks the
property's formula-spec tree and surfaces the latched cause.

* fix(runner): log predicate errors alongside violations

For each violated property, surface the verifier's latched predicate
error via logger.Warn so operators can distinguish a genuine false
verdict from a malformed spec. Add a runner-level test asserting that a
throwing predicate no longer crashes the run and that the error message
appears in the log.
This commit is contained in:
pj authored and GitHub committed 2026-04-20 16:55:10 +07:00
1 parent a2e96af1af
commit 323878c34a
5 files changed
+113 -2

No files matched your search

+27
View File
@@ -219,6 +219,33 @@ func TestLoad_PropagatesSyntaxError(t *testing.T) {
}
}
func TestEvaluateProperties_ThrowingPredicateDoesNotPanic(t *testing.T) {
const spec = `
globalThis.properties = {
broken: __uatu__.always(() => { throw new Error("bad predicate"); }),
};
`
verifier := newVerifier(t)
mustLoad(t, verifier, spec)
if err := verifier.PushSnapshot(SnapshotInput{Snapshots: Snapshots{}}); err != nil {
t.Fatal(err)
}
verdicts := verifier.EvaluateProperties()
if got := verdicts["broken"]; got != ltl.VerdictViolated {
t.Errorf("verdict: got %v, want %v", got, ltl.VerdictViolated)
}
predicateErr := verifier.PredicateError("broken")
if predicateErr == nil {
t.Fatal("PredicateError: got nil, want non-nil")
}
if !strings.Contains(predicateErr.Error(), "bad predicate") {
t.Errorf("PredicateError message: got %q, want to contain %q", predicateErr.Error(), "bad predicate")
}
}
func TestLoad_AcceptsSpecWithoutPropertiesOrActions(t *testing.T) {
verifier := newVerifier(t)
if err := verifier.Load(`const noop = 1;`); err != nil {