Skip to content

fix(resource-shipping): close LOW follow-ups - #2543

Merged
namastex888 merged 1 commit into
devfrom
fix/resource-shipping-low-followups
Jul 10, 2026
Merged

namastex888 merged 1 commit into
devfrom
fix/resource-shipping-low-followups

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

Closes the three LOW follow-ups recorded at ship time of wish plugin-resource-shipping (merged to dev via PR #2540, commits ecbb67fc/203c97df/bbd6439e). Each was verified against the actual code before fixing; all three were real.

1. scripts/fresh-install-smoke.ts — temp-dir cleanup bypassed on phase-b failure

fail() called process.exit(1), which does not run finally blocks, so the try/finally tmp-dir removal in runWishScaffoldSmoke was skipped on any phase-b failure — orphaning a genie-fresh-install-* dir despite the header comment claiming cleanup on failure.

Fix: fail() now throws a SmokeFailure; main() catches it and translates to the same exit-1 + fresh-install-smoke: FAIL — … stderr contract CI depends on. The existing finally now runs on every exit path. Any non-SmokeFailure error still propagates untouched. Guarded main() behind import.meta.main so the module is importable/testable.

Verified: ran the pre-fix script vs the fixed script against an induced phase-b failure in an isolated TMPDIR — original left 1 orphaned temp dir, fixed left 0, both exit 1 with identical stderr. Colocated test (phase-b failure cleanup) asserts non-zero exit + no surviving scaffold temp dir.

2. scripts/skills-lint.ts — substring-based same-line guard

The unguarded-repo-lint rule exempted a repo-only bun run wishes:lint/skills:lint whenever the literal package.json appeared anywhere on the line (!line.includes('package.json')) — a trailing comment, an echo arg, or a mention after the command all falsely exempted it.

Fix: the exemption now requires a package.json probe that short-circuits (&&) into the command (/\bpackage\.json\b[^&|;]*&&/ over the segment before the invocation). Existing positive/negative fixtures still pass; added fixtures for the false-exemption cases (trailing comment, ref-after-command, ;-joined prose) and for broader probe shapes (test -f package.json &&, [ -f package.json ] &&).

3. plugin-resource-shipping WISH.md G1 validation sweep — not replay-safe post-G2

Note: there is no validate/ dir for this wish; the G1 sweep lives inline in WISH.md (Group 1 → Validation). The recursive grep -rn 'templates/wish-template.md' . tripped on the lint rule's own negative fixtures in scripts/skills-lint.test.ts (bare cp templates/wish-template.md strings), which are intentional test data.

Fix: switched that sweep line to git grep -In (tracked-only; auto-skips node_modules/.git and the .docs-vendor submodule) with :(exclude) pathspecs for .genie/ history docs and the fixture file. Still catches real regressions.

Verified: on the current tree the sweep passes clean (exit 0); injecting a stale templates/wish-template.md ref into a tracked decoy file fires it (exit 1); the full G1 validation block runs green end-to-end.

Gates (all green)

Run from scratchpad/gates.sh (script file — inline multi-line bash false-PASSES in this env):

  • bun run check — exit 0 (typecheck + lint + dead-code + skills:lint + wishes:lint + council-workflow lint + full suite, 810 pass / 1 skip / 0 fail)
  • bun run skills:lint — exit 0 (31 files, 0 violations)
  • bun run lint:complexity-budget — exit 0
  • bun test scripts/fresh-install-smoke.test.ts scripts/skills-lint.test.ts — 21 pass / 0 fail

No items skipped — all three follow-ups were real and are fixed.

…on, replay-safe sweep

Three ship-time LOW follow-ups from wish plugin-resource-shipping (PR #2540):

1. fresh-install-smoke.ts: fail() called process.exit(1), which skips finally
   blocks, so a phase-b failure orphaned its mkdtemp work dir despite the
   try/finally in runWishScaffoldSmoke. fail() now throws a SmokeFailure that
   main() catches and translates to the same exit-1 + stderr contract, so the
   existing finally runs on every exit path. Colocated test induces a phase-b
   failure and asserts no genie-fresh-install-* temp dir survives.

2. skills-lint.ts unguarded-repo-lint rule: the same-line guard was
   line.includes('package.json'), so any incidental mention (trailing comment,
   echo arg, reference after the command) exempted a repo-only lint invocation.
   Tightened to require a package.json probe that short-circuits (&&) into the
   command. Added fixtures for the false-exemption cases and broader probe shapes.

3. plugin-resource-shipping WISH.md G1 validation sweep (inline, not a validate/
   dir): the recursive grep tripped on the lint rule's own negative fixtures in
   skills-lint.test.ts on replay. Switched to git grep -In with :(exclude)
   pathspecs (.genie history + the fixture file); still catches real stale refs.
@coderabbitai

coderabbitai Bot commented Jul 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: e2e4de82-e2b1-47ab-80c6-2ee1383b697c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/resource-shipping-low-followups

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: eb3b840db7

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread scripts/skills-lint.ts
const lintMatch = /\bbun run (?:wishes|skills):lint\b/.exec(line);
if (lintMatch) {
const guard = line.slice(0, lintMatch.index);
const guarded = /\bpackage\.json\b[^&|;]*&&/.test(guard);

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Require a real package.json probe before exempting lint

When a skill command line mentions package.json before the lint invocation without testing it, for example echo package.json && bun run skills:lint, this regex still sets guarded to true because it only requires the token before an &&. That lets an incidental pre-command mention evade the unguarded-repo-lint rule, so shipped skill docs can still contain repo-only lint commands that run outside the genie repo; please restrict this to recognized probe forms such as grep ... package.json, test -f package.json, or [ -f package.json ].

Useful? React with 👍 / 👎.

@namastex888
namastex888 merged commit 65759f5 into dev Jul 10, 2026
11 checks passed

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request improves cleanup reliability in the smoke tests by throwing a custom error instead of calling process.exit(1) directly, ensuring temporary directories are deleted even on failures. It also refactors the skills-lint script to more accurately detect when a lint command is properly guarded by a package.json check on the same line. The review feedback points out a potential bypass in the guard detection regex where a broken short-circuit chain (e.g., with an intervening semicolon) could falsely exempt a command, and suggests a more robust regex along with an additional test case to cover this scenario.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread scripts/skills-lint.ts
const lintMatch = /\bbun run (?:wishes|skills):lint\b/.exec(line);
if (lintMatch) {
const guard = line.slice(0, lintMatch.index);
const guarded = /\bpackage\.json\b[^&|;]*&&/.test(guard);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

high

The current regex /\bpackage\.json\b[^&|;]*&&/ only checks if package.json is followed by && with no operators in between. However, it does not verify that this && short-circuit chain actually extends all the way to the command itself.

For example, if a line contains:
test -f package.json && echo "hello"; bun run wishes:lint

The guard segment extracted is test -f package.json && echo "hello"; . The regex matches package.json && at the beginning, but the trailing semicolon ; breaks the short-circuit chain, executing bun run wishes:lint unconditionally.

To prevent such false exemptions, we should ensure that the && short-circuit chain continues to the end of the guard segment (just before the command) without any intervening command separators like ;, |, or single &.

Suggested change
const guarded = /\bpackage\.json\b[^&|;]*&&/.test(guard);
const guarded = /\bpackage\.json\b(?:[^&|;]|&&)*&&\s*$/.test(guard);

Comment on lines +51 to +54
// Mention in a `;`-joined prose segment is not a short-circuit guard.
expect(checkResourceLine('echo "see package.json"; bun run skills:lint').map((v) => v.rule)).toEqual([
'unguarded-repo-lint',
]);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

To ensure that broken short-circuit chains (e.g., due to trailing semicolons or other command separators) are correctly flagged as unguarded, we should add a test case covering this scenario.

Suggested change
// Mention in a `;`-joined prose segment is not a short-circuit guard.
expect(checkResourceLine('echo "see package.json"; bun run skills:lint').map((v) => v.rule)).toEqual([
'unguarded-repo-lint',
]);
// Mention in a `;`-joined prose segment is not a short-circuit guard.
expect(checkResourceLine('echo "see package.json"; bun run skills:lint').map((v) => v.rule)).toEqual([
'unguarded-repo-lint',
]);
// Broken short-circuit chain due to a trailing semicolon.
expect(checkResourceLine('test -f package.json && echo "hello"; bun run wishes:lint').map((v) => v.rule)).toEqual([
'unguarded-repo-lint',
]);

@automagik-genie
automagik-genie deleted the fix/resource-shipping-low-followups branch September 25, 2026 04:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant