feat(#1740): require-fs-op-fallback production AST rule + Windows transient-lock retry (Phase 6) (#1742)
* feat(#1740): require-fs-op-fallback production AST rule + Windows transient-lock retry (Phase 6) ADR-1703 Phase 6 of the cross-platform portability epic (#1702). Adds the second production-code portability AST rule + the ADR-mandated glob expansion to bin/install.js and scripts/build-hooks.js. - eslint-rules/require-fs-op-fallback.cjs: flags an unguarded fs.rename / fs.renameSync (the atomic-publish primitive named first in DEFECT.WINDOWS-FS-OPS.symptom) that is NOT inside a try/catch whose handler references a transient errno ('EPERM'/'EBUSY'/'EACCES' or a *RETRY_ERRNOS set) AND NOT behind a Windows platform guard. A catch that silently swallows or cleans-up-and-rethrows without an errno check does NOT satisfy the defect's 'never silently swallow' clause. copyFile/unlink are deliberately not flagged (they are the fallback primitives per the defect's own fix-forward). Scope narrowed to rename per Phase 5's precision discipline; documented on #1740. - src/shell-command-projection.cts: export retryRenameSync(from, to) — the drop-in bounded-retry helper over the existing atomicRenameWithRetry. - 27 bare fs.renameSync sites across 11 modules routed through retryRenameSync (capability-lifecycle/lock/source, installer-migrations, milestone, phase, planning-workspace, roadmap-upgrade, runtime-hooks-surface, state, workstream). Idempotent on POSIX; resilient to AV/indexer transient locks on Windows. - eslint.config.mjs: register rule at error on src/**/*.cts; new focused portability-rules block covering bin/install.js + scripts/build-hooks.js (ADR-1703 L124-126 glob expansion — both files are compliant: zero rename violations). - tests: 15-case RuleTester suite; portability-rule-disable-ban extended (PROTECTED_RULES + scans bin/install.js/build-hooks.js with shebang handling); ci-test-scope portability-lint selection rule. - CONTEXT.md DEFECT.WINDOWS-FS-OPS predicate rewritten to point at the rule; docs/contributing/cross-platform-portability-rules.md reference + how-to. Closes #1740 * chore(#1740): backfill changeset pr:1742 * fix(#1740): tighten require-fs-op-fallback precision (codex review HIGH-1/HIGH-2) Addresses two false-negative findings from the codex (gpt-5.5/high) adversarial review of PR #1742: HIGH-1 — a catch that REFERENCES a transient errno but only rethrows (no retry/fallback) was marked compliant. The DEFECT.WINDOWS-FS-OPS fix-forward requires retry, not just recognition. Fix: catchHandlerHasRetrySignal now requires a loop `continue` backedge OR a `return <call>` delegation; a bare rethrow is flagged. The misleading `/* retry logic */` valid test is replaced with a real retry loop, and the rethrow-only shape is added as invalid. HIGH-2 — the nested-try ancestor walk treated an OUTER errno-catch as protecting the rename even when an INNER catch intercepted/swallowed the error (the outer catch is unreachable). Fix: isInsideTransientErrnoTryCatch now stops at the NEAREST enclosing TryStatement WITH A CATCH HANDLER whose block contains the rename (try-finally is skipped — it doesn't catch); outer catches are no longer consulted. The unsound nested-try valid test is converted to invalid, and a try-finally-skipped valid case is added. Verified: 17 RuleTester cases pass; zero new production violations (the 27 fixed sites use retryRenameSync; the real retry loops — atomicRenameWithRetry, capability-ledger/consent, build-hooks — remain compliant via continue/errno); lint:ci green; disable-ban + vocab-drift green. --------- Co-authored-by: review-bot <review-bot@gsd>
This commit is contained in:
@@ -214,17 +214,35 @@ const RULES = [
|
||||
],
|
||||
},
|
||||
{
|
||||
name: 'configuration',
|
||||
match: path => ['config', 'configuration', 'model-catalog', 'model-profile'].some(k => path.includes(k)),
|
||||
name: 'configuration',
|
||||
match: path => ['config', 'configuration', 'model-catalog', 'model-profile'].some(k => path.includes(k)),
|
||||
tests: [
|
||||
'tests/config.test.cjs',
|
||||
'tests/config-get-default.test.cjs',
|
||||
'tests/configuration-migrate-config.test.cjs',
|
||||
'tests/model-catalog-runtime-defaults.test.cjs',
|
||||
'tests/model-profiles.test.cjs',
|
||||
],
|
||||
},
|
||||
{
|
||||
// ADR-1703 portability lint surface. Editing a rule, the shared vocab/guard
|
||||
// helpers, or the eslint config that wires them must re-run the rule suites
|
||||
// + the disable-ban. The disable-ban also scans bin/install.js and
|
||||
// scripts/build-hooks.js (the Phase 6 glob-expansion surface), so changes
|
||||
// to those files re-run it too.
|
||||
name: 'portability lint rules (ADR-1703)',
|
||||
match: path => path.startsWith('eslint-rules/') ||
|
||||
path === 'eslint.config.mjs' ||
|
||||
path === 'bin/install.js' ||
|
||||
path === 'scripts/build-hooks.js',
|
||||
tests: [
|
||||
'tests/config.test.cjs',
|
||||
'tests/config-get-default.test.cjs',
|
||||
'tests/configuration-migrate-config.test.cjs',
|
||||
'tests/model-catalog-runtime-defaults.test.cjs',
|
||||
'tests/model-profiles.test.cjs',
|
||||
'tests/portability-rule-disable-ban.test.cjs',
|
||||
'tests/portability-vocab-drift.test.cjs',
|
||||
'tests/require-fs-op-fallback.rule.test.cjs',
|
||||
'tests/normalize-path-in-content.rule.test.cjs',
|
||||
],
|
||||
},
|
||||
];
|
||||
];
|
||||
|
||||
function usage() {
|
||||
return [
|
||||
|
||||
Reference in New Issue
Block a user