Files
msd-core/gsd-core
Dennis Alexis Valin Dittrich c9bff8d2b9 fix(#3899): resolve REVIEWS.md by quoted assignment, not an unquoted ls (#3928)
* fix(#3899): resolve REVIEWS.md by quoted assignment, not an unquoted ls

The convergence loop resolved the phase REVIEWS.md through
`$(ls ${phase_dir}/... 2>/dev/null)`. The unquoted ${phase_dir} word-splits,
so a project path containing a space handed `ls` arguments that do not exist,
the discarded stderr hid the error, and the empty result was reported as
"review agent did not produce REVIEWS.md" — blaming the agent for a quoting
defect. A glob metacharacter fails worse: the pattern expands to whatever
sibling directory matches, so the loop silently reads a different phase's
REVIEWS.md and `ls` still exits 0.

Assign the path directly, quoted, and fail closed with an error that names the
expected location. The regression block extracts the bash fence from the
shipped workflow and RUNS it against space-, glob- and missing-file fixtures,
because every text assertion in that suite passed against the broken line.

* chore(#3899): add the changelog fragment

* fix(#3899): reject a non-file reviews path and anchor the gate harness

Adversarial review (codex, gemini) on the first cut, three findings taken:

- `[ -r ]` alone is true for a readable DIRECTORY, so a directory standing
  where the reviews file belongs passed the gate and reached the consumers
  that read it. Require a regular file as well.
- the harness picked its fence by scanning the WHOLE document for a bash
  block assigning REVIEWS_FILE. If the real fence ever stopped assigning it
  and an unrelated one started, the harness would execute the wrong block and
  report green. Anchor the span to the verification step, between its opening
  sentence and the next heading.
- the no-subshell assertion matched only `$(`; a backtick rewrite would
  reintroduce identical word-splitting unseen. The discarded-stderr assertion
  is scoped to lines naming REVIEWS_FILE rather than banning the redirect
  across the whole fence.

Four findings declined: `return 1 || exit 1` (the document's own idiom is a
bare `exit 1`, including the guard immediately below), `${phase_dir:-}` for
`set -u` (unchanged exposure from the old line, and an unset phase_dir is a
bug worth surfacing), an explicit empty-phase_dir branch (the guard already
fails closed and prints the truncated path), and a downstream
`[ -n "$REVIEWS_FILE" ]` hazard (no such consumer exists — the guard exits
before any of them run).

* chore(#3899): backfill the changeset PR number

* fix(#3899): address required review feedback

Use the fragment-aware workflow reader, remove the inert exemption marker, document the unreadable-arm coverage limit, align errors with the workflow convention, and name an empty phase_dir directly. Migrate the obsolete emitted-drift fragment to the current commit-trailer contract.

Emitted-Drift-Ack-Growth: plan-review-convergence.md — #3899: replace unquoted $(ls ... 2>/dev/null) resolution with a quoted direct path, fail-closed file/readability checks, and an explicit phase_dir diagnostic; surrounding prose records why quoting is load-bearing.

---------

Co-authored-by: davdittrich <davdittrich@gmail.com>
Co-authored-by: CI Rebase Check <ci@gsd-redux>
Co-authored-by: Tom Boucher <trekkie@nomorestars.com>
2026-09-01 20:25:27 -04:00
..