feat(#1733): normalize-path-in-content production AST rule + fix Windows agent-skills content leak (Phase 5) (#1736)
* feat(#1733): normalize-path-in-content production AST rule (Phase 5) ADR-1703 Phase 5 — the first production-code rule. local/normalize-path-in-content (src/**/*.cts, @typescript-eslint/parser): flags a path-returning fn result (path.basename excluded — returns a separator-less filename) interpolated into an @-reference / config-dir markdown body without .replace(/\\/g,'/') normalization, per RULESET.CONTENT-PATH-NORMALIZATION / DEFECT.WINDOWS-PATH-LEAK-IN-MARKDOWN-CONTENT. Build-and-assess found the canonical defect site (computePathPrefix) already compliant and only 1 src/ hit — a false positive (path.basename in a status message) — eliminated by narrowing (exclude basename; require a real @-ref/ config-dir marker, not bare .md). 0 src/ violations: clean forward-prevention. The out-of-band disable-ban now scans src/**/*.cts too (typescript-estree) so the production rule also cannot be eslint-disabled. Registered (error) + PROTECTED_RULES; CONTEXT.md predicates + how-to doc updated. - RuleTester suite (26 cases) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * docs(#1733): add changeset for Windows agent-skills path-leak fix Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * fix: harden mutation-matrix.cjs stdin read against EAGAIN on non-blocking pipe scripts/mutation-matrix.cjs read piped stdin via readFileSync(process.stdin.fd). On macOS libuv marks the stdin pipe fd non-blocking, so a synchronous read can throw EAGAIN before the writer fills the pipe — intermittently, under heavy CI shard load — aborting the script (status 2) and flaking mutation-matrix-ratchet. Replace with readStdinSync(): an fs.readSync loop that retries on EAGAIN (1ms synchronous Atomics.wait yield), stops on 0-byte/EOF, and rethrows other errors. Deterministic regression test injects EAGAIN via an fs.readSync monkeypatch. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> * ci: re-run golden-install-parity on src/lib + installer changes (close drift guard) golden-install-parity hashes every installed bin/lib/*.cjs per runtime, so it must re-run whenever the built lib could change. ci-test-scope selected it for neither src/** nor installer changes, so a source-only edit (e.g. #1691's milestone.cts/roadmap.cts) recompiled bin/lib and silently drifted the golden fixtures past the scoped lane. Add golden-install-parity.test.cjs to both the 'TS runtime sources' and 'installer and package layout' selection rules, with behavioral regression tests for each. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com> Co-authored-by: review-bot <review-bot@gsd>
This commit is contained in:
@@ -22,6 +22,7 @@ import noCrlfFragileSplit from './eslint-rules/no-crlf-fragile-split.cjs';
|
||||
import noHardcodedTmp from './eslint-rules/no-hardcoded-tmp.cjs';
|
||||
import noBareNpmExec from './eslint-rules/no-bare-npm-exec.cjs';
|
||||
import requireUserprofileWithHome from './eslint-rules/require-userprofile-with-home.cjs';
|
||||
import normalizePathInContent from './eslint-rules/normalize-path-in-content.cjs';
|
||||
|
||||
const localPlugin = {
|
||||
rules: {
|
||||
@@ -38,6 +39,7 @@ const localPlugin = {
|
||||
'no-hardcoded-tmp': noHardcodedTmp,
|
||||
'no-bare-npm-exec': noBareNpmExec,
|
||||
'require-userprofile-with-home': requireUserprofileWithHome,
|
||||
'normalize-path-in-content': normalizePathInContent,
|
||||
},
|
||||
};
|
||||
|
||||
@@ -216,6 +218,12 @@ export default tseslint.config(
|
||||
// ADR-1372 T7: enforce use of the markdown-sectionizer seam; grandfather
|
||||
// pre-migration sites with // allow-adhoc-markdown: <reason>
|
||||
'local/no-adhoc-markdown-parsing': 'error',
|
||||
// ADR-1703 Phase 5: flag path-returning calls interpolated into content
|
||||
// (markdown @-references, workflow files, generated docs) without POSIX
|
||||
// normalization. Promoted to 'error' after precision review (path.basename
|
||||
// excluded; content heuristic tightened to genuine reference/config-dir
|
||||
// markers). See RULESET.CONTENT-PATH-NORMALIZATION in CONTEXT.md.
|
||||
'local/normalize-path-in-content': 'error',
|
||||
},
|
||||
},
|
||||
|
||||
|
||||
Reference in New Issue
Block a user