Files
msd-core/scripts/lint-shell-command-projection-drift.cjs
Tom Boucher f729101eec refactor(scripts): replace process.exit() with ExitError + runMain handler (#739) (#740)
Part 1 of 2 of the n/no-process-exit cleanup (umbrella #738): convert every
process.exit() call in standalone scripts/** CLIs to the rule-compliant pattern.

- New shared helper scripts/lib/cli-exit.cjs: ExitError(code,message) + runMain()
  which translates a thrown ExitError / returned number into process.exitCode
  (never process.exit()), flushing output and still firing process.on('exit').
- main()-based entrypoints: throw new ExitError(code) for errors, return <code>
  for verdicts; invoked via runMain(main). Child exit codes preserved via return.
- top-level-only scripts: imperative body extracted into main() so mid-flow
  aborts (throw ExitError) actually halt; pure consts/helpers stay at module scope.
- diff-touches-shipped-paths.cjs: stdin event handling restructured to an async
  read so the whole flow runs under runMain; uncaughtException/unhandledRejection
  nets replaced by an in-band catch that preserves EXIT_ERROR=2.

Exit codes verified unchanged for every converted script (success/error/help and
the 0/1/2 semantic codes in diff-touches). Rule stays warn here; flipped to error
in part 2 (#738) once gsd-core/bin/** is also clean.

Refs #739

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-06 16:13:13 -04:00

63 lines
1.9 KiB
JavaScript

#!/usr/bin/env node
'use strict';
/**
* Focused drift guard for issue #3442:
* prevent installer-owned inline shim/wrapper text builders from bypassing the
* Shell Command Projection Module seam.
*
* Scope intentionally excludes subprocess execution helpers (spawnSync /
* execFileSync) because those are safe internal execution primitives, not
* serialized shell-command rendering.
*/
const fs = require('fs');
const path = require('path');
const { ExitError, runMain } = require('./lib/cli-exit.cjs');
const ROOT = path.resolve(__dirname, '..');
const forbidden = [
{
label: 'inline cmd shim builder',
pattern: /@ECHO OFF\\r\\n@SETLOCAL\\r\\n@node /,
},
{
label: 'inline pwsh shim builder',
pattern: /#!\/usr\/bin\/env pwsh\\n& node /,
},
{
label: 'inline sh shim builder',
pattern: /#!\/usr\/bin\/env sh\\nexec node /,
},
];
function main() {
const targetArg = process.argv[2] || path.join(ROOT, 'bin', 'install.js');
const target = path.resolve(targetArg);
const rel = path.relative(ROOT, target);
let content;
try {
content = fs.readFileSync(target, 'utf8');
} catch (error) {
throw new ExitError(1, `lint-shell-command-projection-drift: failed to read ${target}: ${error.message}`);
}
const matches = forbidden.filter((rule) => rule.pattern.test(content));
if (matches.length === 0) {
process.stdout.write(`ok shell-projection-drift: ${rel}\n`);
return 0;
}
process.stderr.write(`ERROR shell-projection-drift: inline serialized shim builders found in ${rel}\n`);
for (const match of matches) {
process.stderr.write(` - ${match.label}\n`);
}
process.stderr.write('Route shim/wrapper rendering through gsd-core/bin/lib/shell-command-projection.cjs\n');
process.stderr.write('Safe subprocess execution via spawnSync/execFileSync is intentionally allowed.\n');
return 1;
}
runMain(main);