Files
msd-core/scripts/lint-canary-version-leak.cjs
Tom Boucher bcf7b04864 chore(#2896): convert CONTEXT.md prose defect registry into enforced gates (#3325)
* chore(#2896): convert CONTEXT.md prose defect registry into enforced gates

Squashes the prior 4-commit sequence and fixes defects found while
resuming this branch: 5 orphaned/corrupted DEFECT fragment lines left
by an earlier botched edit, 17 "Source of truth: Memtrace `find_symbol`"
placeholders that had destroyed real file-path citations, and 3
DEFECT.GENERATIVE-* entries merged into one RULESET.GENERATIVE-FIX
predicate (policy, not an unenforced defect) to satisfy the zero
DEFECT.<NAME>.<field>= acceptance criterion.

Six mechanizable defects get real gates: DEFECT.UNBOUNDED-SUBPROCESS
(eslint-rules/require-subprocess-timeout.cjs), DEFECT.CANARY-VERSION-LEAK
(scripts/lint-canary-version-leak.cjs + version-gate.yml),
DEFECT.CHANGESET-PR-FIELD-DRIFT (findPrFieldDrift in changeset/lint.cjs),
DEFECT.FRONTMATTER-SCALAR-BROAD-GREP, DEFECT.REMOVED-BUT-NEEDED, and
DEFECT.DEFAULT-FLIP-DOCUMENTATION (new lint scripts, wired into lint:ci).
Already-enforced and unenforceable prose entries are deleted; the gate
is the record.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#2896): route the new lint tests' subprocess calls through the bounded process-seam helper

The 4 new test files for this PR's lint checks called cp.spawnSync/
execFileSync directly with no timeout, tripping this repo's own
existing local/no-unbounded-spawn ESLint rule. Route every one through
runNode/gitOrThrow (tests/helpers/process-seam.cjs,
tests/helpers/git-fixture.cjs) instead, matching the pattern already
used elsewhere in the suite (e.g. tests/changeset-lint.test.cjs).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix: register claude-orchestration.cjs and regenerate stale generated indexes

Pre-existing drift on next, unrelated to this PR's own change, surfaced
by running lint:ci as part of verifying #2896: two cli_modules
(claude-orchestration.cjs, write-set.cjs) landed without a manifest
regen, and CONTEXT.md's own edits in this PR staled its two generated
indexes. Adds the missing docs/INVENTORY.md row for
claude-orchestration.cjs (write-set.cjs already had one — only its
manifest entry was stale) and regenerates
docs/INVENTORY-MANIFEST.json, docs/CONTEXT-INDEX.json, and
examples/dynamic-context-management/CONTEXT-INDEX.json.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#2896): default-flip-documentation lint's local fallback base was main, not next

Found in review: every other base-ref fallback in this repo (see
scripts/changeset/lint.cjs's DEFAULT_BASE, #2988) defaults to `next`,
the integration branch every PR actually targets — `main` is the
release branch. This script's local fallback (used only when
GITHUB_BASE_REF is unset, i.e. never in CI, but potentially on a local
or direct invocation) diffed against the wrong ref. No test exercised
the unset-env-var path, so it shipped unnoticed; every e2e test sets
GITHUB_BASE_REF explicitly and is unaffected by this fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#2896): stale eslint comment, overclaiming CONTEXT.md wording, and an incompletely-regenerated manifest

Found by the isolated Standards code-review pass:
- eslint.config.mjs's require-subprocess-timeout comment said "'warn'
  for now... flip to 'error' once migrated" while the rule already
  shipped as 'error' with all 8 sites migrated in the same commit —
  described a state that never existed.
- The CONTEXT.md pointer block claimed the rule's bounded call sites
  "never throw", but roadmap-upgrade.cts's pre-mutation clean-tree
  check correctly still throws on failure (it gates a destructive
  real-run migration; degrading to "assume clean" would risk clobbering
  uncommitted work) — softened the claim to describe both shapes
  accurately instead of overclaiming one.
- docs/INVENTORY-MANIFEST.json's claude-orchestration.cjs/write-set.cjs
  entries from the prior "fix: register claude-orchestration.cjs..."
  commit didn't actually land — re-running the generator now includes
  them; lint:generated-sync is green.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#2896): backfill changeset pr field with the real PR number

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#2896): normalize buildCorpus file paths to POSIX in lint-removed-but-needed

Windows CI caught it: path.relative(root, abs) returns backslash-
separated paths on Windows, but findSurvivingReferences's package-lock
special case does file.startsWith('.github/workflows') — a forward-
slash literal. On Windows the check silently never matched, so
tests/removed-but-needed-lint.test.cjs's real-defect-shape fixture got
exit 0 instead of the expected exit 1. Normalize at the production
source (RULESET.CONTENT-PATH-NORMALIZATION) rather than the test side.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-10 12:55:52 -04:00

74 lines
2.6 KiB
JavaScript

#!/usr/bin/env node
'use strict';
/**
* Canary-version-leak lint (DEFECT.CANARY-VERSION-LEAK, CONTEXT.md).
*
* `package.json` `.version` on `main` must never carry a `-canary.<N>`
* suffix — that suffix is a dev-branch/prerelease marker. Nothing published
* depends on the string at runtime, but every consumer of the version
* metadata (release flow, install banners, statusline) surfaces the
* dev-channel label as if it were the shipped release. The 2026-05-16 audit
* found `origin/main` at `"version": "1.50.0-canary.0"`, landed by a fix PR
* that accidentally carried a version bump from a dev-branch base (commit
* 2d32ad82, #3206).
*
* Modeled on scripts/lint-package-identity-drift.cjs / scripts/lint-table-schema-drift.cjs:
* a standalone node script (not a node:test), exit 0 clean / exit 1 + message
* on a leaked canary version. Wired to run only for PRs targeting `main`
* (.github/workflows/version-gate.yml) — a canary version is expected and
* harmless on every other branch.
*/
const fs = require('node:fs');
const path = require('node:path');
const CANARY_RE = /-canary\.\d+/;
/**
* Pure: does this version string carry a `-canary.<N>` suffix?
* @param {string} version
* @returns {boolean}
*/
function isCanaryVersion(version) {
return typeof version === 'string' && CANARY_RE.test(version);
}
/**
* Read `<root>/package.json` and return its `.version`, or null if the file
* is missing/unreadable/unparsable.
* @param {string} root
* @returns {string|null}
*/
function readPackageVersion(root) {
try {
const raw = fs.readFileSync(path.join(root, 'package.json'), 'utf8');
const pkg = JSON.parse(raw);
return typeof pkg.version === 'string' ? pkg.version : null;
} catch {
return null;
}
}
function main() {
const root = path.join(__dirname, '..');
const version = readPackageVersion(root);
if (version == null) {
process.stderr.write('canary-version-leak: could not read/parse package.json .version\n');
process.exitCode = 1;
return;
}
if (!isCanaryVersion(version)) {
process.stdout.write(`ok canary-version-leak: package.json version '${version}' carries no -canary.<N> suffix\n`);
return;
}
process.stderr.write(`canary-version-leak: package.json version '${version}' carries a -canary.<N> suffix (DEFECT.CANARY-VERSION-LEAK).\n`);
process.stderr.write('A -canary.<N> version must never land on main. Reset .version to the canonical\n');
process.stderr.write('pre-canary stable before merging — see CONTEXT.md DEFECT.CANARY-VERSION-LEAK.\n');
process.exitCode = 1;
}
if (require.main === module) main();
module.exports = { isCanaryVersion, readPackageVersion, CANARY_RE };