enhance(#3545): widen no-source-grep with fold+hooks, migrate 76 sites (#4161)

* feat(#3545): widen no-source-grep with one-hop path-fold and hooks dir

Resolve a readFileSync() path argument that is a bare Identifier one hop
back to its VariableDeclarator initializer before classification, and
recognize `hooks` as a source directory alongside bin/lib/gsd-core/src.

Measured (epic #3464 phase 7): fold+hooks together newly flag 76
unsuppressed sites across 18 files that were previously invisible to
identifier-indirected or hooks/-rooted source reads. Neither widening
alone is sufficient — hooks-only surfaces 0 new sites, confirming #3520's
prior finding that the identifier-indirection gap must close first.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(#3545): migrate 76 sites newly flagged by the fold+hooks widening

Per-site classification: rewrite behaviorally (require() the real module,
assert on its actual exported behavior) wherever the read was a proxy for
code behavior; add a site-scoped `// allow-test-rule: <reason> (#3545)`
marker only where the raw source text genuinely is the product under test
(codex-config.test.cjs's adapter-header-contract checks, install.js
structural-wiring guards with no exported symbol, AST-parse fixture
inputs, etc.) — each marker cites an existing repo-sanctioned category
from CONTRIBUTING.md's allow-test-rule exception table.

Also converts two try/finally test bodies (introduced during this same
migration) to the required t.after() cleanup pattern per CONTRIBUTING.md.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#3545): re-baseline effective-exemption ceiling to 81

The fold+hooks widening's own newly-detected sites are now suppressed by
site-scoped markers, moving them from invisible into the tightly-ratcheted
effective-exemption count. Ceiling rises from 10 to 81 (the exact measured
high-water mark, grace unchanged at 2) — a deliberate, measured re-baseline
per the widening working as intended, not an ordinary ceiling bump.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3545): use canonical allow-test-rule category tokens

4 markers added during migration cited an issue ref correctly but didn't
use one of CONTRIBUTING.md's seven recognized category tokens, unlike
every other marker in this change. Cosmetic only — same suppression
lines, same effective/live counts (81/81, 0 live).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3545): correct stale phase-artifact path in test comment

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
Tom Boucher
2026-09-01 21:40:38 -04:00
committed by GitHub
parent ff0361071d
commit f16ff7d1b3
21 changed files with 360 additions and 83 deletions

View File

@@ -182,6 +182,9 @@ test('no `isAugment` occurrence gates a call to an Augment converter function (t
const converterCallPattern = new RegExp(`(${converterNames.join('|')})\\s*\\(`);
const file = path.join(__dirname, '..', 'bin', 'install.js');
// allow-test-rule: structural-regression-guard (#3545) — absence of an
// isAugment-gated converter call is a source-text property (see file
// header, #2097).
const lines = fs.readFileSync(file, 'utf8').split(/\r?\n/);
const offenders = [];
for (let i = 0; i < lines.length; i++) {
@@ -200,6 +203,9 @@ test('no `isAugment` occurrence gates a call to an Augment converter function (t
test('legitimate isAugment destructure/enumeration sites survive (not eliminated, unlike isAntigravity)', () => {
const file = path.join(__dirname, '..', 'bin', 'install.js');
// allow-test-rule: structural-regression-guard (#3545) — presence of the
// isAugment identifier itself is a source-text property (see file header,
// #2097).
const src = fs.readFileSync(file, 'utf8');
assert.ok(/isAugment/.test(src), 'isAugment must still be destructured from runtimeFlags() for non-conversion uses');
});
@@ -234,6 +240,9 @@ test('augment capability.json declares a real, converter-bearing agents kind for
test('_DESCRIPTOR_AGENTS_RUNTIMES no longer exists as a live declaration — the descriptor is authoritative for every runtime, not an allow-listed subset', () => {
const file = path.join(__dirname, '..', 'bin', 'install.js');
// allow-test-rule: structural-regression-guard (#3545) — absence of a live
// _DESCRIPTOR_AGENTS_RUNTIMES declaration is a source-text property (see
// file header, #2097).
const src = fs.readFileSync(file, 'utf8');
// A residual mention in a historical // comment (documenting the #2875
// deletion itself) is fine; a live `const _DESCRIPTOR_AGENTS_RUNTIMES =`