fix(#2086): AC2 source-guard must ignore comments/backtick prose, not just code

The #338 fail-safe commit added a comment containing the literal `runtime === 'claude'`
(explaining what the data lookup is NOT), which the AC2 source-grep test matched as a
false positive (the test read the whole file, prose included). Strip block/line comments
+ backtick spans before matching so the guard flags only LIVE code, and reword the
comment. CRLF-safe line-comment strip.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-07-08 15:26:19 -04:00
parent 102ffa0f9e
commit eeec6b512e
2 changed files with 9 additions and 2 deletions

View File

@@ -321,7 +321,7 @@ try {
// {} and silently route a claude LOCAL install to the repo-shared, committed
// `settings.json` instead of the gitignored `settings.local.json` (#338) — leaking
// engineer-specific absolute paths. Keyed by runtime id (a DATA lookup, not a
// `runtime === 'claude'` branch) so behavior degrades CLOSED (safe), never open.
// hardcoded string-equality branch) so behavior degrades CLOSED (safe), never open.
// The live descriptor (capabilities/claude/capability.json) remains the source of
// truth; this mirrors only the privacy-load-bearing subset. (ADR-1239 / #2086)
const FALLBACK_HOST_BEHAVIORS = Object.freeze({

View File

@@ -134,7 +134,14 @@ test('claude descriptor declares runtime.hostBehaviors (the folded-in host behav
test('bin/install.js contains no `runtime === "claude"` / `runtime !== "claude"` string-equality branches (AC2)', () => {
const src = fs.readFileSync(path.join(__dirname, '..', 'bin', 'install.js'), 'utf8');
const offenders = src.match(/runtime\s*[!=]==\s*'claude'/g) || [];
// Strip comments + backtick/inline-code spans so PROSE mentions of the old
// pattern (a comment explaining "not a string-equality branch") do not
// false-positive — only LIVE code counts.
const codeOnly = src
.replace(/\/\*[\s\S]*?\*\//g, '') // block comments
.replace(/\/\/[^\r\n]*/g, '') // line comments (CRLF-safe)
.replace(/`[^`]*`/g, ''); // backtick / inline-code spans
const offenders = codeOnly.match(/runtime\s*[!=]==\s*'claude'/g) || [];
assert.deepEqual(
offenders,
[],