Skip to content

Commit a36af67

Browse files
committed
tooling(pm): record 14 unrecorded REFUSE-WIDE gate families, fold in the sandbox-filename fix
12 of #14695's 14 unrecorded REFUSE-WIDE members are recorded in a new CENSUS_REFUSE_WIDE table in scripts/pm/bare-root-worklist.mjs, each with its own measured share and the base commit (2aa8456, the base #14325's own census used) it was measured at. A new table rather than new TRIAGE rows: TRIAGE is coupled to sweep(), which can only discover a bare-word population literal assigned to a POPULATION_CONSTANT-shaped name, and none of these families hold that shape (confirmed empirically: adding one to TRIAGE makes --self-test fail STALE immediately). Two of the fourteen ("the two packages/spec-filtered ones") are not recorded -- PR #14692's body, read in full, does not name them, and guessing would fabricate a measurement no one took. Also folds in the small second half: scripts/check-whole-set-label-write.mjs's three self-test sandbox filenames (scripts/w.mjs, scripts/writer.sh, .github/workflows/w.yml) existed in no tracked tree and, spelled as bare literals in a top-level export outside any selfTest()-shaped function, entered the gate's own declared-population hint set as dead leads. Renamed to three real, unrelated, already-tracked paths; no behaviour change to the gate's verdict. Fixes #14695 Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01WLJQhde67SeTccsmnBVarV
1 parent fc648a2 commit a36af67

2 files changed

Lines changed: 321 additions & 28 deletions

File tree

‎scripts/check-whole-set-label-write.mjs‎

Lines changed: 45 additions & 27 deletions
Original file line numberDiff line numberDiff line change
@@ -762,85 +762,103 @@ function baseFiles() {
762762
};
763763
}
764764

765+
// RED_CASES/GREEN_CASES below reuse three REAL tracked paths as their sandbox
766+
// keys (`scripts/check-nul-bytes.mjs`, `scripts/build-console.sh`,
767+
// `.github/workflows/ci.yml`) rather than invented names (`scripts/w.mjs`,
768+
// `scripts/writer.sh`, `.github/workflows/w.yml`, pre-#14695). The fixture's
769+
// own content is written into an isolated temp directory (`writeTree`) either
770+
// way, so which real path stands in for "a script" or "a workflow" makes no
771+
// difference to what any RED/GREEN case here asserts — but the KEY is a
772+
// string literal in THIS module's own source, and `RED_CASES`/`GREEN_CASES`
773+
// are top-level exports, not bodies inside a `selfTest()`-shaped function, so
774+
// `maskSelfTests` never hides them from `extractWatchHints`: every key here
775+
// already entered this gate's own declared-population hint set. An invented
776+
// name that exists in no tracked tree is therefore a DEAD lead — exactly the
777+
// shape `check:declared-population-live` exists to refuse — and it read as
778+
// live only because that gate's liveness bar is per-FAMILY (at least one hint
779+
// live) rather than per-hint; a real path clears the same bar honestly at
780+
// full precision instead of by accident (#14695). The two paths chosen for
781+
// the `.mjs`/`.sh` cases are deliberately UNRELATED scripts, picked only to be
782+
// tracked and short — not files this gate has any real interest in reading.
765783
/** Every spelling that MUST be refused. */
766784
export const RED_CASES = {
767785
'curl -X PUT, one line': {
768-
'scripts/writer.sh': 'curl -X PUT -H "auth" "https://api.github.com/repos/o/r/issues/1/labels" -d "{}"\n'
786+
'scripts/build-console.sh': 'curl -X PUT -H "auth" "https://api.github.com/repos/o/r/issues/1/labels" -d "{}"\n'
769787
},
770788
'curl -X PUT, backslash-continued onto the path line': {
771-
'scripts/writer.sh': 'curl -X PUT \\\n -H "auth" \\\n "https://api.github.com/repos/o/r/issues/1/labels"\n'
789+
'scripts/build-console.sh': 'curl -X PUT \\\n -H "auth" \\\n "https://api.github.com/repos/o/r/issues/1/labels"\n'
772790
},
773791
'gh api -X PUT': {
774-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - run: gh api -X PUT "repos/$R/issues/$N/labels" -f labels[]=a\n'
792+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - run: gh api -X PUT "repos/$R/issues/$N/labels" -f labels[]=a\n'
775793
},
776794
'gh api --method PUT': {
777-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - run: gh api --method PUT repos/o/r/issues/1/labels\n'
795+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - run: gh api --method PUT repos/o/r/issues/1/labels\n'
778796
},
779797
'github-script issues.setLabels': {
780-
'.github/workflows/w.yml':
798+
'.github/workflows/ci.yml':
781799
'jobs:\n j:\n steps:\n - uses: actions/github-script@v9\n with:\n script: |\n' +
782800
' await github.rest.issues.setLabels({ owner, repo, issue_number: 1, labels });\n'
783801
},
784802
'octokit.request route string': {
785-
'scripts/w.mjs': "await octokit.request('PUT /repos/{owner}/{repo}/issues/{issue_number}/labels', { labels });\n"
803+
'scripts/check-nul-bytes.mjs': "await octokit.request('PUT /repos/{owner}/{repo}/issues/{issue_number}/labels', { labels });\n"
786804
},
787805
'fetch with a multi-line options object': {
788-
'scripts/w.mjs': 'await fetch(`${api}/repos/${repo}/issues/${n}/labels`, {\n headers,\n method: "PUT",\n body\n});\n'
806+
'scripts/check-nul-bytes.mjs': 'await fetch(`${api}/repos/${repo}/issues/${n}/labels`, {\n headers,\n method: "PUT",\n body\n});\n'
789807
},
790808
'a bare .put( onto the endpoint': {
791-
'scripts/w.mjs': "await client.put(`/issues/${n}/labels`, { labels });\n"
809+
'scripts/check-nul-bytes.mjs': "await client.put(`/issues/${n}/labels`, { labels });\n"
792810
},
793811
'uses: actions/labeler at the version #10703 read': {
794-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - uses: actions/labeler@v7.0.0\n'
812+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - uses: actions/labeler@v7.0.0\n'
795813
},
796814
'uses: actions/labeler at ANY other version': {
797-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - uses: actions/labeler@a1b2c3d4\n'
815+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - uses: actions/labeler@a1b2c3d4\n'
798816
},
799817
'uses: codelytv/pr-size-labeler': {
800-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - uses: codelytv/pr-size-labeler@v1.10.4\n'
818+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - uses: codelytv/pr-size-labeler@v1.10.4\n'
801819
},
802820
'the method slot WINDOW_LINES-1 lines from the path': {
803-
'scripts/w.mjs': `const url = '/issues/1/labels';\n${'// filler\n'.repeat(WINDOW_LINES - 2)}await go({ method: 'PUT', url });\n`
821+
'scripts/check-nul-bytes.mjs': `const url = '/issues/1/labels';\n${'// filler\n'.repeat(WINDOW_LINES - 2)}await go({ method: 'PUT', url });\n`
804822
}
805823
};
806824

807825
/** Forms that MUST stay clean. Every one is correct as written. */
808826
export const GREEN_CASES = {
809827
'the additive POST': {
810-
'scripts/w.mjs': "await gh('POST', `/issues/${n}/labels`, { labels: ['size/l'] });\n"
828+
'scripts/check-nul-bytes.mjs': "await gh('POST', `/issues/${n}/labels`, { labels: ['size/l'] });\n"
811829
},
812830
'the targeted DELETE': {
813-
'scripts/w.mjs': "await gh('DELETE', `/issues/${n}/labels/${encodeURIComponent(name)}`);\n"
831+
'scripts/check-nul-bytes.mjs': "await gh('DELETE', `/issues/${n}/labels/${encodeURIComponent(name)}`);\n"
814832
},
815833
'the ban documented in a YAML comment': {
816-
'.github/workflows/w.yml': '# never `curl -X PUT .../issues/1/labels`, and never issues.setLabels\njobs:\n j:\n steps:\n - run: true\n'
834+
'.github/workflows/ci.yml': '# never `curl -X PUT .../issues/1/labels`, and never issues.setLabels\njobs:\n j:\n steps:\n - run: true\n'
817835
},
818836
'the ban documented in a JS block comment': {
819-
'scripts/w.mjs': '/**\n * `PUT /issues/{n}/labels` and `issues.setLabels` are both banned.\n * Not `curl -X PUT .../issues/1/labels` either.\n */\nexport const ok = 1;\n'
837+
'scripts/check-nul-bytes.mjs': '/**\n * `PUT /issues/{n}/labels` and `issues.setLabels` are both banned.\n * Not `curl -X PUT .../issues/1/labels` either.\n */\nexport const ok = 1;\n'
820838
},
821839
'the ban documented in a JS line comment': {
822-
'scripts/w.mjs': "// await octokit.request('PUT /repos/o/r/issues/1/labels') -- BANNED\nexport const ok = 1;\n"
840+
'scripts/check-nul-bytes.mjs': "// await octokit.request('PUT /repos/o/r/issues/1/labels') -- BANNED\nexport const ok = 1;\n"
823841
},
824842
'a comparison REFUSING the verb': {
825-
'scripts/w.mjs': "if (step.method === 'PUT') throw new Error(`refused for /issues/${n}/labels`);\n"
843+
'scripts/check-nul-bytes.mjs': "if (step.method === 'PUT') throw new Error(`refused for /issues/${n}/labels`);\n"
826844
},
827845
'the verb named in a test name next to a labels path': {
828-
'scripts/w.mjs': "const plan = { path: '/issues/10698/labels' };\ncheck('the retired whole-set PUT destroys the label', plan);\n"
846+
'scripts/check-nul-bytes.mjs': "const plan = { path: '/issues/10698/labels' };\ncheck('the retired whole-set PUT destroys the label', plan);\n"
829847
},
830848
'an unrelated action pin': {
831-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - uses: actions/checkout@v7\n - uses: actions/stale@v11.0.0\n'
849+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - uses: actions/checkout@v7\n - uses: actions/stale@v11.0.0\n'
832850
},
833851
'a PUT to a different endpoint entirely': {
834-
'scripts/w.mjs': "await gh('PUT', `/repos/${repo}/actions/variables/${name}`);\n"
852+
'scripts/check-nul-bytes.mjs': "await gh('PUT', `/repos/${repo}/actions/variables/${name}`);\n"
835853
},
836854
'a label READ, no write': {
837-
'.github/workflows/w.yml': 'jobs:\n j:\n steps:\n - run: gh api "repos/$R/issues/$N/labels" --jq ".[].name"\n'
855+
'.github/workflows/ci.yml': 'jobs:\n j:\n steps:\n - run: gh api "repos/$R/issues/$N/labels" --jq ".[].name"\n'
838856
},
839857
'steps.labels output references': {
840-
'.github/workflows/w.yml': "jobs:\n j:\n steps:\n - if: steps.labels.outputs.skip != 'true'\n run: true\n"
858+
'.github/workflows/ci.yml': "jobs:\n j:\n steps:\n - if: steps.labels.outputs.skip != 'true'\n run: true\n"
841859
},
842860
'the method slot WINDOW_LINES lines from the path (a STATED miss)': {
843-
'scripts/w.mjs': `const url = '/issues/1/labels';\n${'// filler\n'.repeat(WINDOW_LINES - 1)}await go({ method: 'PUT', url });\n`
861+
'scripts/check-nul-bytes.mjs': `const url = '/issues/1/labels';\n${'// filler\n'.repeat(WINDOW_LINES - 1)}await go({ method: 'PUT', url });\n`
844862
}
845863
};
846864

@@ -899,9 +917,9 @@ export function selfTest() {
899917

900918
// Refusal 3 -- an allowlist entry with no stated reason. Assertion 3.
901919
withTree(RED_CASES['gh api -X PUT'], (dir) => {
902-
const noReason = [{ path: '.github/workflows/w.yml', rule: 'endpoint', reason: 'too short' }];
920+
const noReason = [{ path: '.github/workflows/ci.yml', rule: 'endpoint', reason: 'too short' }];
903921
expect('REFUSE allowlist entry without a reason', run(dir, { allowlist: noReason }, silent), EXIT_REFUSED);
904-
const noRule = [{ path: '.github/workflows/w.yml', rule: 'whatever', reason: 'a'.repeat(MIN_REASON_LENGTH) }];
922+
const noRule = [{ path: '.github/workflows/ci.yml', rule: 'whatever', reason: 'a'.repeat(MIN_REASON_LENGTH) }];
905923
expect('REFUSE allowlist entry with no valid rule', run(dir, { allowlist: noRule }, silent), EXIT_REFUSED);
906924
});
907925

@@ -916,7 +934,7 @@ export function selfTest() {
916934
withTree(RED_CASES['gh api -X PUT'], (dir) => {
917935
const reasoned = [
918936
{
919-
path: '.github/workflows/w.yml',
937+
path: '.github/workflows/ci.yml',
920938
rule: /** @type {'endpoint'} */ ('endpoint'),
921939
reason: 'fixture: a deliberate exception recorded with a real sentence explaining itself.'
922940
}

0 commit comments

Comments
 (0)