The previous commit widened the guard's watch set and claimed the enumeration
was complete. Re-running the pre-push adversarial gate on that commit -- which I
should have done before pushing it, and did not -- refuted the claim on four
counts. All four were real.
1. FALSE POSITIVES, which is the worse polarity. `hooks/lib`,
`hooks/package.json`, `scripts/lib` and `scripts/changeset` were watched
WHOLESALE. The installer preserves foreign files in every one of them -- it
removes the CommonJS marker only on an exact content match, because "a
user-authored package.json is never deleted" -- so a user editing their own
helper mid-suite tripped the guard. A driven probe produced four violations
from touching only user-owned files. Watching shared ground is exactly what
the module's SCOPE note refuses: a guard that cries wolf gets switched off,
and then catches nothing at all. Now only exact GSD filenames inside those
dirs are watched, and a test asserts foreign edits stay silent.
2. THE PREFIX WAS HARDCODED, which is this PR's own defect one level down. Each
artifactLayout declares its OWN prefix, and kimi's `kimi-agents` layout
declares `gsd` with no hyphen, writing `agents/gsd.yaml` and `agents/gsd.md`.
A fixed `gsd-` scan is structurally blind to both, as it is to pi's
`extensions/gsd.js`. The prefix is now derived per parent, as a SET -- the
same destSubpath carries different prefixes across runtimes (`agents` appears
with both `gsd` and `gsd-`). `extensions` joins the non-registry parents; pi
declares no artifactLayout at all, so no registry walk could find it.
3. THE ENTRY BOUND FAILED OPEN on a non-finite limit: `Math.max(0, NaN)` is NaN,
and every budget comparison against NaN is false, so the walk was unbounded --
the single thing the constant exists to prevent. Clamped with Number.isFinite.
The walk also kept invoking itself for every remaining sibling after the
budget was gone; it now returns.
4. THE RESIDUAL LIST WAS WRONG AGAIN. `agents/subagents/**` (kimi stages under an
unprefixed intermediate dir), the loose capability generators, and the
`extensions`/`plugins` CommonJS markers are all unwatched and were unnamed.
They are named now, and the four shared dirs are recorded as DELIBERATELY not
watched -- a different thing from missed.
Each fix is negative-controlled and each control fires. The NaN control did not
fire on its first form: the test asserted `truncated: false`, which the broken
code also produces on a small tree, so it discriminated nothing. Repaired with a
NaN perTarget against a small finite ceiling, where the two behaviours differ.