Files
msd-core/tests
Tom Boucher d3305fc3a5 fix(#2858): exclude gen-emitted-baseline.cjs from npm tarball + class-extinction guard (#2968)
* test(#2858): add class-extinction guard for shipped-script require boundary

Every shipped scripts/**/*.cjs must be require-able using only shipped paths.
The guard resolves the tarball file list via npm pack --dry-run --json (not a
hardcoded list) and statically checks each require() call against the shipped
set. A script requiring ../tests/** (which does not ship) is a violation.

* fix(#2858): exclude gen-emitted-baseline.cjs from the npm tarball

scripts/gen-emitted-baseline.cjs is repo-only CI tooling (CI workflows +
test fixtures spawn it from a checkout). It requires three modules from
tests/, which does not ship — so in a published install it is
MODULE_NOT_FOUND at load time.

Add a targeted files[] negation (!scripts/gen-emitted-baseline.cjs) so the
script stays in the repo for CI use but does not ship. Other scripts that
ship and are required by bin/install.js (build-hooks.js,
fix-slash-commands.cjs, gen-capability-registry.cjs) are unaffected.

The class-extinction guard test in
tests/packaging-shipped-scripts-require-only-shipped.test.cjs ensures no
shipped script can require outside the shipped tree going forward.

* test(#2858): widen guard to .js + strip block comments (review fixes)

Two findings from isolated adversarial review:
1. MAJOR: the guard only checked .cjs files, but scripts/build-hooks.js
   ships and is required by bin/install.js — a .js file with a broken
   require would bypass the guard. Widened filter to /\.(cjs|js)$/.
2. MODERATE: the static parser could false-positive on require() calls
   inside /* */ block comments or inline // comments. Now strips both
   before matching.

* chore(#2858): add changeset fragment

* chore(#2858): backfill changeset PR number 2968

* fix(#2858): add issue ref to allow-test-rule exemption (ADR-456)

CI lint-tests caught: the allow-test-rule comment needs a 'see #NNN' ref
per ADR-456. Added '(see #2858)' to the integration-test-input exemption.

---------

Co-authored-by: sim <sim@local>
2026-08-01 09:29:15 -04:00
..