* chore(#2896): convert CONTEXT.md prose defect registry into enforced gates Squashes the prior 4-commit sequence and fixes defects found while resuming this branch: 5 orphaned/corrupted DEFECT fragment lines left by an earlier botched edit, 17 "Source of truth: Memtrace `find_symbol`" placeholders that had destroyed real file-path citations, and 3 DEFECT.GENERATIVE-* entries merged into one RULESET.GENERATIVE-FIX predicate (policy, not an unenforced defect) to satisfy the zero DEFECT.<NAME>.<field>= acceptance criterion. Six mechanizable defects get real gates: DEFECT.UNBOUNDED-SUBPROCESS (eslint-rules/require-subprocess-timeout.cjs), DEFECT.CANARY-VERSION-LEAK (scripts/lint-canary-version-leak.cjs + version-gate.yml), DEFECT.CHANGESET-PR-FIELD-DRIFT (findPrFieldDrift in changeset/lint.cjs), DEFECT.FRONTMATTER-SCALAR-BROAD-GREP, DEFECT.REMOVED-BUT-NEEDED, and DEFECT.DEFAULT-FLIP-DOCUMENTATION (new lint scripts, wired into lint:ci). Already-enforced and unenforceable prose entries are deleted; the gate is the record. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore(#2896): route the new lint tests' subprocess calls through the bounded process-seam helper The 4 new test files for this PR's lint checks called cp.spawnSync/ execFileSync directly with no timeout, tripping this repo's own existing local/no-unbounded-spawn ESLint rule. Route every one through runNode/gitOrThrow (tests/helpers/process-seam.cjs, tests/helpers/git-fixture.cjs) instead, matching the pattern already used elsewhere in the suite (e.g. tests/changeset-lint.test.cjs). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix: register claude-orchestration.cjs and regenerate stale generated indexes Pre-existing drift on next, unrelated to this PR's own change, surfaced by running lint:ci as part of verifying #2896: two cli_modules (claude-orchestration.cjs, write-set.cjs) landed without a manifest regen, and CONTEXT.md's own edits in this PR staled its two generated indexes. Adds the missing docs/INVENTORY.md row for claude-orchestration.cjs (write-set.cjs already had one — only its manifest entry was stale) and regenerates docs/INVENTORY-MANIFEST.json, docs/CONTEXT-INDEX.json, and examples/dynamic-context-management/CONTEXT-INDEX.json. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#2896): default-flip-documentation lint's local fallback base was main, not next Found in review: every other base-ref fallback in this repo (see scripts/changeset/lint.cjs's DEFAULT_BASE, #2988) defaults to `next`, the integration branch every PR actually targets — `main` is the release branch. This script's local fallback (used only when GITHUB_BASE_REF is unset, i.e. never in CI, but potentially on a local or direct invocation) diffed against the wrong ref. No test exercised the unset-env-var path, so it shipped unnoticed; every e2e test sets GITHUB_BASE_REF explicitly and is unaffected by this fix. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#2896): stale eslint comment, overclaiming CONTEXT.md wording, and an incompletely-regenerated manifest Found by the isolated Standards code-review pass: - eslint.config.mjs's require-subprocess-timeout comment said "'warn' for now... flip to 'error' once migrated" while the rule already shipped as 'error' with all 8 sites migrated in the same commit — described a state that never existed. - The CONTEXT.md pointer block claimed the rule's bounded call sites "never throw", but roadmap-upgrade.cts's pre-mutation clean-tree check correctly still throws on failure (it gates a destructive real-run migration; degrading to "assume clean" would risk clobbering uncommitted work) — softened the claim to describe both shapes accurately instead of overclaiming one. - docs/INVENTORY-MANIFEST.json's claude-orchestration.cjs/write-set.cjs entries from the prior "fix: register claude-orchestration.cjs..." commit didn't actually land — re-running the generator now includes them; lint:generated-sync is green. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * chore(#2896): backfill changeset pr field with the real PR number Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * fix(#2896): normalize buildCorpus file paths to POSIX in lint-removed-but-needed Windows CI caught it: path.relative(root, abs) returns backslash- separated paths on Windows, but findSurvivingReferences's package-lock special case does file.startsWith('.github/workflows') — a forward- slash literal. On Windows the check silently never matched, so tests/removed-but-needed-lint.test.cjs's real-defect-shape fixture got exit 0 instead of the expected exit 1. Normalize at the production source (RULESET.CONTENT-PATH-NORMALIZATION) rather than the test side. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> --------- Co-authored-by: sim <sim@local> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
110 lines
4.1 KiB
JavaScript
110 lines
4.1 KiB
JavaScript
'use strict';
|
|
process.env.GSD_TEST_MODE = '1';
|
|
|
|
/**
|
|
* Canary-version-leak lint (DEFECT.CANARY-VERSION-LEAK, CONTEXT.md).
|
|
*
|
|
* scripts/lint-canary-version-leak.cjs fails a run whose package.json
|
|
* .version carries a -canary.<N> suffix — that suffix belongs to a dev
|
|
* branch only and must never land on main (2026-05-16 audit: origin/main at
|
|
* "1.50.0-canary.0", commit 2d32ad82, #3206). Wired into
|
|
* .github/workflows/version-gate.yml, gated to PRs targeting main.
|
|
*/
|
|
|
|
const { test, describe } = require('node:test');
|
|
const assert = require('node:assert/strict');
|
|
const fs = require('node:fs');
|
|
const os = require('node:os');
|
|
const path = require('node:path');
|
|
const fc = require('fast-check');
|
|
|
|
const ROOT = path.join(__dirname, '..');
|
|
const LINT_SCRIPT = path.join(ROOT, 'scripts', 'lint-canary-version-leak.cjs');
|
|
const { isCanaryVersion, readPackageVersion } = require(LINT_SCRIPT);
|
|
const { cleanup } = require('./helpers.cjs');
|
|
const { runNode } = require('./helpers/process-seam.cjs');
|
|
|
|
describe('canary-version-leak lint: isCanaryVersion (pure)', () => {
|
|
test('a plain release version is not canary', () => {
|
|
assert.equal(isCanaryVersion('1.8.0'), false);
|
|
});
|
|
|
|
test('a -canary.<N> version IS flagged', () => {
|
|
assert.equal(isCanaryVersion('1.8.0-canary.3'), true);
|
|
});
|
|
|
|
test('boundary: -canary.0 (N=0) is flagged', () => {
|
|
assert.equal(isCanaryVersion('1.50.0-canary.0'), true);
|
|
});
|
|
|
|
test('a non-canary prerelease suffix (e.g. -rc.1) is not flagged', () => {
|
|
assert.equal(isCanaryVersion('1.8.0-rc.1'), false);
|
|
});
|
|
|
|
test('non-string input is not flagged (fails closed to false, main() handles missing version separately)', () => {
|
|
assert.equal(isCanaryVersion(undefined), false);
|
|
assert.equal(isCanaryVersion(null), false);
|
|
});
|
|
|
|
test('property: appending -canary.<N> to any base string always flags it', () => {
|
|
fc.assert(
|
|
fc.property(
|
|
fc.string().filter((s) => !/-canary\.\d+/.test(s)),
|
|
fc.nat(),
|
|
(base, n) => {
|
|
assert.equal(isCanaryVersion(`${base}-canary.${n}`), true);
|
|
},
|
|
),
|
|
);
|
|
});
|
|
|
|
test('property: a version with no "-canary." substring is never flagged', () => {
|
|
fc.assert(
|
|
fc.property(
|
|
fc.string().filter((s) => !s.includes('-canary.')),
|
|
(version) => {
|
|
assert.equal(isCanaryVersion(version), false);
|
|
},
|
|
),
|
|
);
|
|
});
|
|
});
|
|
|
|
describe('canary-version-leak lint: the live repo package.json is clean', () => {
|
|
test('readPackageVersion + isCanaryVersion pass against the real package.json', () => {
|
|
const version = readPackageVersion(ROOT);
|
|
assert.equal(typeof version, 'string');
|
|
assert.equal(isCanaryVersion(version), false, `package.json version '${version}' must not carry -canary.<N>`);
|
|
});
|
|
});
|
|
|
|
describe('canary-version-leak lint: main() end-to-end wiring', () => {
|
|
function writeFixtureRoot(version) {
|
|
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'gsd-canary-lint-e2e-'));
|
|
fs.writeFileSync(path.join(tmpDir, 'package.json'), JSON.stringify({ name: 'fixture', version }), 'utf8');
|
|
return tmpDir;
|
|
}
|
|
|
|
test('exit 0 on a clean version (real package.json, 1.8.0)', () => {
|
|
const result = runNode([LINT_SCRIPT], { cwd: ROOT });
|
|
assert.equal(result.exitCode, 0, `expected exit 0, got ${result.exitCode}: ${result.stderr}`);
|
|
});
|
|
|
|
test('exit 1 on a fixture package.json carrying a -canary.<N> suffix (never touches the real package.json)', (t) => {
|
|
const tmpDir = writeFixtureRoot('1.8.0-canary.3');
|
|
t.after(() => cleanup(tmpDir));
|
|
|
|
// The script resolves its target as `<script-dir>/../package.json`, so
|
|
// run a throwaway copy of the script from inside the fixture root
|
|
// rather than mutating the real repo's package.json.
|
|
const scriptCopyDir = path.join(tmpDir, 'scripts');
|
|
fs.mkdirSync(scriptCopyDir, { recursive: true });
|
|
const scriptCopy = path.join(scriptCopyDir, 'lint-canary-version-leak.cjs');
|
|
fs.copyFileSync(LINT_SCRIPT, scriptCopy);
|
|
|
|
const result = runNode([scriptCopy]);
|
|
assert.equal(result.exitCode, 1, `expected exit 1, got ${result.exitCode}`);
|
|
assert.match(result.stderr, /canary-version-leak/);
|
|
});
|
|
});
|