Files
msd-core/bin
Tom Boucher 19efcddfc7 fix(#941): track managed-hooks-registry.cjs in file manifest (#953)
* test(#941): regression test for managed-hooks-registry.cjs manifest omission

Adds bug-941-managed-hooks-registry-manifest.test.cjs which verifies:
- managed-hooks-registry.cjs appears in gsd-file-manifest.json after install
- manifest covers the full HOOKS_TO_COPY set (forward-proof)
- detect-custom-files reports 0 custom files after a clean install
- manifest hook keys use forward slashes (cross-platform)

All four assertions fail before the fix, confirming the bug is reproducible.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* fix(#941): track managed-hooks-registry.cjs in file manifest

The writeManifest() hooks loop in bin/install.js filtered hook filenames
with `file.startsWith('gsd-') && (file.endsWith('.js') || file.endsWith('.sh'))`.
managed-hooks-registry.cjs fails both predicates (wrong prefix, .cjs extension),
so it was never recorded in gsd-file-manifest.json even though it is shipped to
users as part of HOOKS_TO_COPY.

detect-custom-files scans the installed hooks/ dir and reports any file with no
manifest entry as a custom file, producing a perpetual false-positive
"Found 1 custom file(s)" warning on every /gsd-update for all users.

Fix: import HOOKS_TO_COPY from scripts/build-hooks.js and drive the manifest
hooks loop from that set (as a Set for O(1) lookup), so the manifest set is
structurally identical to the build set. Any future hook of any prefix or
extension added to HOOKS_TO_COPY is automatically covered. The new regression
test asserts full HOOKS_TO_COPY coverage and zero detect-custom-files
false-positives after a clean install.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* chore(#941): add changeset for managed-hooks-registry.cjs manifest fix

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

* test(#941): assert manifest hash matches installed hook contents (adversarial review)

Strengthen the regression test to not only verify that the manifest KEY
`hooks/managed-hooks-registry.cjs` is present after install, but also that
the stored hash equals the SHA256 of the actual installed file bytes — the
same algorithm used by the installer's fileHash() function.  A future
refactor that records the right key from the wrong path or content would
now fail this assertion immediately.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-09 23:28:02 -04:00
..