Files
msd-core/scripts/lint-allow-test-rule-refs.allowlist.json
Tom Boucher 2131fe13f3 enhance(#3464): exec() detection widening, citation-debt cleanup — Phase 8 (#4171)
* feat(#3464): widen no-source-grep to detect regex.exec() on tracked text

Adds an execCall kind alongside the existing regexTest detection --
regex.exec(tracked) was invisible to the rule while regex.test(tracked)
was already caught, despite both reading a source-derived string through
a regex. Measured: 4 previously-invisible sites across 2 files.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* test(#3464): migrate 4 sites newly flagged by the exec() widening

docs-hooks-table-parity.test.cjs's three regex-extraction loops are
site-scoped marked (source-text-is-the-product) -- the dynamic
preToolEvent/postToolEvent dialect branching they mirror is explicitly
documented as not statically parseable, so a literal-pattern mirror is
the practical minimum-cost check.

no-bare-gsd-tools-command-position.test.cjs's readRouterVerbs() now
requires HOST_COMMAND_ROUTERS directly instead of regex-walking
gsd-tools.cjs's source text -- the same accessor three other suites
already use.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3464): pay down 6 grandfathered uncited allow-test-rule markers

Two were genuinely load-bearing (suppressing a real detected violation)
and just needed a citation added -- phase6-capstone-conformance.test.cjs,
runtime-name-policy.test.cjs, both now (#3464).

Four were dead-weight file-header markers suppressing nothing -- each
file's real effective sites are covered by separate, already-cited
markers elsewhere in the same file. Deleted outright rather than cited,
per Phase 1's own precedent (remove non-load-bearing markers instead of
grandfathering them forever) -- codex-config.test.cjs (two copies),
gsd-check-update-worker-platform-gate.test.cjs, orphaned-hooks.test.cjs,
settings-jsonc.test.cjs.

allowlist.json: 134 -> 128 entries.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* chore(#3464): re-baseline effective-exemption ceiling to 84

The exec() widening's 3 newly-marked sites are now suppressed and
counted; ceiling rises 81 -> 84, the exact measured high-water mark.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(#3464): correct citation and restore a wrongly-deleted marker

Two review corrections, both found by the orthogonal review pass:

- docs-hooks-table-parity.test.cjs's 3 new exec() markers cited #3464
  (mechanically "the phase that widened the rule") when the file's own
  established, correct reference is #3839 (the issue this whole test
  exists to enforce, already cited in its file header) -- fixed to match.

- gsd-check-update-worker-platform-gate.test.cjs's deleted file-header
  marker was NOT dead weight: its codeOnly() helper wraps readFileSync
  and is called inline as an assert argument, a genuine source-grep
  pattern on real .cjs/.js source that the rule cannot currently see
  (helper-function indirection is a distinct blind spot from anything
  Phase 7/8 measured) -- CONTRIBUTING.md is explicit that "unverified"
  is not the same as "vestigial." Restored, site-scoped this time
  (directly above codeOnly(), not as an inert file-header comment) and
  cited (#3103, the issue the file's own docstring already references).

codex-config.test.cjs's two deletions and orphaned-hooks.test.cjs's /
settings-jsonc.test.cjs's deletions were independently re-verified and
stand: their flagged lines read generated .toml/.json OUTPUT, not
source, or have no residual pattern at all.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: sim <sim@local>
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-02 08:11:23 -04:00

131 lines
8.8 KiB
JSON

[
"tests/agent-classification-parity.test.cjs :: source-text-is-the-product",
"tests/agent-frontmatter.test.cjs :: source-text-is-the-product",
"tests/agent-required-reading-consistency.test.cjs :: source-text-is-the-product",
"tests/agent-skills-awareness.test.cjs :: source-text-is-the-product",
"tests/ai-evals.test.cjs :: source-text-is-the-product",
"tests/analyze-dependencies.test.cjs :: source-text-is-the-product",
"tests/anti-pattern-enforcement.test.cjs :: source-text-is-the-product",
"tests/ask-user-questions-fallback.test.cjs :: source-text-is-the-product",
"tests/audit-fix-command.test.cjs :: source-text-is-the-product",
"tests/autonomous-allowed-tools.test.cjs :: source-text-is-the-product",
"tests/autonomous-converge.test.cjs :: source-text-is-the-product",
"tests/autonomous-decomposition.test.cjs :: source-text-is-the-product",
"tests/autonomous-interactive.test.cjs :: source-text-is-the-product",
"tests/autonomous-to-flag.test.cjs :: source-text-is-the-product",
"tests/chain-flag-plan-phase.test.cjs :: source-text-is-the-product",
"tests/changeset-cli.test.cjs :: source-text-is-the-product",
"tests/claude-md.test.cjs :: source-text-is-the-product",
"tests/cleanup-branch-pruning.test.cjs :: source-text-is-the-product",
"tests/cline-install.test.cjs :: source-text-is-the-product",
"tests/cline-support.test.cjs :: source-text-is-the-product",
"tests/code-review-agent-skills.test.cjs :: source-text-is-the-product",
"tests/code-review-command.test.cjs :: source-text-is-the-product",
"tests/code-review-pipeline-regression.test.cjs :: source-text-is-the-product",
"tests/code-review.test.cjs :: source-text-is-the-product",
"tests/codebuddy-install.test.cjs :: source-text-is-the-product",
"tests/command-contract.test.cjs :: source-text-is-the-product",
"tests/commands.test.cjs :: source-text-is-the-product",
"tests/config-field-docs.test.cjs :: docs-parity",
"tests/context-enrichment.test.cjs :: source-text-is-the-product",
"tests/contributor-standards.test.cjs :: source-text-is-the-product",
"tests/copilot-install.test.cjs :: integration-test-input",
"tests/cursor-hooks.test.cjs :: source-text-is-the-product",
"tests/cursor-reviewer.test.cjs :: source-text-is-the-product",
"tests/debug-session-management.test.cjs :: source-text-is-the-product",
"tests/discuss-checkpoint.test.cjs :: source-text-is-the-product",
"tests/discuss-phase-power.test.cjs :: source-text-is-the-product",
"tests/docs-parity-live-registry.test.cjs :: source-text-is-the-product",
"tests/drift-detection.test.cjs :: source-text-is-the-product",
"tests/edge-probe-docs-fixtures.test.cjs :: source-text-is-the-product",
"tests/edge-probe-planner-contract.test.cjs :: source-text-is-the-product",
"tests/edge-probe-spec-phase-contract.test.cjs :: source-text-is-the-product",
"tests/edit-phase.test.cjs :: source-text-is-the-product",
"tests/execute-phase-active-flags.test.cjs :: source-text-is-the-product",
"tests/execute-phase-step-5-5-deviation-doc.test.cjs :: source-text-is-the-product",
"tests/execute-phase-wave.test.cjs :: source-text-is-the-product",
"tests/execute-phase-worktree-artifacts.test.cjs :: source-text-is-the-product",
"tests/explore-command.test.cjs :: source-text-is-the-product",
"tests/extract-learnings.test.cjs :: source-text-is-the-product",
"tests/forensics.test.cjs :: source-text-is-the-product",
"tests/frontmatter-cli.test.cjs :: source-text-is-the-product",
"tests/gates-taxonomy.test.cjs :: source-text-is-the-product",
"tests/git-base-branch.test.cjs :: source-text-is-the-product",
"tests/gsd-researcher-app-aware.test.cjs :: source-text-is-the-product",
"tests/gsd-researcher-flow-diagram.test.cjs :: source-text-is-the-product",
"tests/gsd-settings-advanced.test.cjs :: source-text-is-the-product",
"tests/helpers/live-command-registry.cjs :: source-text-is-the-product",
"tests/hermes-skills-migration.test.cjs :: source-text-is-the-product",
"tests/import-command.test.cjs :: source-text-is-the-product",
"tests/ingest-docs.test.cjs :: source-text-is-the-product",
"tests/inline-plan-threshold.test.cjs :: source-text-is-the-product",
"tests/install-nested-layout.test.cjs :: source-text-is-the-product",
"tests/install-runtime-artifacts.test.cjs :: source-text-is-the-product",
"tests/intel.test.cjs :: source-text-is-the-product",
"tests/inventory-headings-countfree.test.cjs :: source-text-is-the-product",
"tests/ios-scaffold-safety.test.cjs :: source-text-is-the-product",
"tests/locking-bugs-1909-1916-1925-1927.test.cjs :: architectural-invariant",
"tests/mcp-tool-inheritance.test.cjs :: source-text-is-the-product",
"tests/milestone-summary.test.cjs :: source-text-is-the-product",
"tests/milestone.test.cjs :: source-text-is-the-product",
"tests/model-catalog-runtime-defaults.test.cjs :: source-text-is-the-product",
"tests/next-safety-gates.test.cjs :: source-text-is-the-product",
"tests/next-up-clear-order.test.cjs :: source-text-is-the-product",
"tests/no-hardcoded-home-gsd-tools.test.cjs :: source-text-is-the-product",
"tests/package-legitimacy-gate.test.cjs :: source-text-is-the-product",
"tests/parallel-dependent-plans.test.cjs :: source-text-is-the-product",
"tests/path-replacement.test.cjs :: source-text-is-the-product",
"tests/phase.test.cjs :: source-text-is-the-product",
"tests/phase6-capability-docs.test.cjs :: source-text-is-the-product",
"tests/phase6-planning-capabilities.test.cjs :: source-text-is-the-product",
"tests/plan-bounce.test.cjs :: source-text-is-the-product",
"tests/plan-phase-drift-guard.test.cjs :: source-text-is-the-product",
"tests/plan-phase-ui-redirect.test.cjs :: source-text-is-the-product",
"tests/plan-review-convergence.test.cjs :: source-text-is-the-product",
"tests/planner-decomposition.test.cjs :: source-text-is-the-product",
"tests/planner-language-regression.test.cjs :: source-text-is-the-product",
"tests/playwright-ui-verify.test.cjs :: source-text-is-the-product",
"tests/policy-160-route0-resume.test.cjs :: source-text-is-the-product",
"tests/policy-release-no-npm-self-upgrade.test.cjs :: source-text-is-the-product",
"tests/product-name-purity.test.cjs :: source-text-is-the-product",
"tests/profile-output.test.cjs :: source-text-is-the-product",
"tests/progress-forensic.test.cjs :: source-text-is-the-product",
"tests/prompt-thinning.test.cjs :: source-text-is-the-product",
"tests/qwen-skills-migration.test.cjs :: source-text-is-the-product",
"tests/read-guard.test.cjs :: source-text-is-the-product",
"tests/reapply-patches.test.cjs :: source-text-is-the-product",
"tests/reapply-verify-hunks.test.cjs :: source-text-is-the-product",
"tests/release-coverage-scope.test.cjs :: source-text-is-the-product",
"tests/release-tarball-smoke-workflow.test.cjs :: source-text-is-the-product",
"tests/release-tarball-smoke.install.test.cjs :: integration-test-input",
"tests/research-agent-profiles.test.cjs :: source-text-is-the-product",
"tests/roadmap.test.cjs :: source-text-is-the-product",
"tests/runtime-launcher-parity.test.cjs :: structural-regression-guard",
"tests/scan-command.test.cjs :: source-text-is-the-product",
"tests/secret-scan-lint.security.test.cjs :: source-text-is-the-product",
"tests/secure-phase.test.cjs :: source-text-is-the-product",
"tests/security-prompt-injection.security.test.cjs :: structural-regression-guard",
"tests/security-scan.security.test.cjs :: source-text-is-the-product",
"tests/seed-scan-new-milestone.test.cjs :: source-text-is-the-product",
"tests/settings-integrations.test.cjs :: source-text-is-the-product",
"tests/skill-frontmatter-contract.test.cjs :: source-text-is-the-product",
"tests/spawn-liveness-banner.test.cjs :: source-text-is-the-product",
"tests/state.test.cjs :: source-text-is-the-product",
"tests/subagent-timeout.test.cjs :: source-text-is-the-product",
"tests/template.test.cjs :: source-text-is-the-product",
"tests/thinking-partner.test.cjs :: source-text-is-the-product",
"tests/ultraplan-phase.test.cjs :: source-text-is-the-product",
"tests/verify-health.test.cjs :: source-text-is-the-product",
"tests/verify-test-quality.test.cjs :: source-text-is-the-product",
"tests/verify-work-auto-transition.test.cjs :: source-text-is-the-product",
"tests/windows-robustness.test.cjs :: source-text-is-the-product",
"tests/workflow-compat.test.cjs :: source-text-is-the-product",
"tests/workflow-guard-registration.test.cjs :: structural-regression-guard",
"tests/workflow-maintainer-skip.test.cjs :: source-text-is-the-product",
"tests/workflow-shell-pinning.test.cjs :: source-text-is-the-product",
"tests/workflow-size-budget.test.cjs :: source-text-is-the-product",
"tests/workspace.test.cjs :: source-text-is-the-product",
"tests/worktree-cleanup.test.cjs :: source-text-is-the-product",
"tests/worktree.test.cjs :: source-text-is-the-product"
]