Files
Jakub Zych a9a7a328e6 refactor: hard-fork GSD -> MSD (Make Software Done)
Mechanical rename produced by scripts/msd-rename.cjs: gsd/Gsd/GSD -> msd/Msd/MSD
across contents and paths, upstream package/repo coordinates -> @golem15/msd-core
and golem15com/msd-core. Deep links into upstream history, sibling upstream
packages, the GSD-2 import feature, CHANGELOG.md and .changeset/ are kept as-is.

Hand edits on top: MSD block-letter banner and logos, LICENSE copyright line,
package/plugin identity, regenerated lockfile, install-tree fixtures, derived
registries and benchmark baseline; migration checksum baseline re-locked
(MSD keeps its own install state, so no install had applied the old sums);
sort-order and regex-escaped expectations in tests adjusted.
2026-10-06 01:47:40 +02:00
..

Adversarial Frontmatter Fixtures (#3594)

Reusable hostile inputs for msd-core/bin/lib/frontmatter.cjs extractFrontmatter() and downstream consumers.

Each fixture is a single markdown file whose name encodes the abuse category. Tests load them by relative path so the corpus can grow without test code changes. Adding a new fixture means: drop the file in here, add an entry to the matrix in tests/feat-3594-parser-adversarial-frontmatter.test.cjs, decide what invariant the parser must satisfy (typically "does not throw, does not return half-parsed garbage, does not silently lose data").

Categories present:

  • duplicate-keys.md — same key appears twice. Parser must produce a deterministic result; tests document which value wins (last-wins is the current behavior).
  • crlf-mixed.md — CRLF endings throughout the frontmatter block. Parser must handle the \r consistently and not bleed it into values.
  • unclosed-block.md — opening --- with no closing ---. Parser must return empty frontmatter (or a clean error), never partial.
  • unicode-keys-and-values.md — non-ASCII keys/values. Parser must round-trip them as-is.
  • null-byte-value.md — value contains a U+0000 null. Parser must preserve or normalize it; must not crash and must not truncate silently.
  • huge-bounded.md — a deliberately-large but bounded frontmatter block (~64KB of array items). Parser must complete in reasonable time with a typed result, not OOM or hang.
  • anchor-alias-bomb.md — a 7-line "billion laughs" frontmatter of nested YAML anchors/aliases. Parser must refuse it (zero keys, FRONTMATTER_UNPARSEABLE set) rather than expand it — ADR-3473 §8.1 consequence 6.
  • anchor-alias-bomb-quoted.md — the same "billion laughs" bomb, spelled with quoted keys ("a": &a [...]) instead of bare keys. Added after #3881 review found the original raw-text anchor/alias refusal regex matched only the bare-key line shape and was bypassable by this (and other) spellings. Must refuse identically to anchor-alias-bomb.md.