fix(scanners): close the CLI argument class across all fourteen CLIs
`KNOWN_OPEN` in cli-unknown-flag-rejection.test.mjs named two CLIs as still carrying the argument-swallow defect. That number was the previous session's field of view, not a measurement. Measuring all fourteen found **7** open on the unknown-flag arm and **10** on a second arm the deferral note never described. Arm 1 — unknown flag: with no `else` branch, `--zzz` leaves no trace. exit 0, full payload, a confident answer to a question the caller did not ask. Arm 2 — the sharper one: `a === '--output-file' && args[i + 1]` asks only whether a next token EXISTS, never whether it is a value. `manifest`, `campaign-cli` and `knowledge-refresh-cli` each wrote a file literally named `--json` into the caller's working directory when handed `--output-file --json`, exit 0, with `--json` mode silently dropped. A wrong answer is bad; an unintended file on disk is worse. Two of the CLIs this catches were already in GUARDED and green on arm 1 while arm 2 stood open a few lines away — the guard asserted one relation instead of the invariant. Fixed with a shared gate (`lib/cli-args.mjs`) that runs BEFORE each CLI's own parse loop rather than replacing it: valid argv reaches the existing parser byte-for-byte unchanged, so the byte-stability argument is structural rather than empirical. `drift-cli`, `fix-cli` and `plugin-health-scanner` were already correct on both arms and were moved into GUARDED instead of rewritten. The three CLIs with a bespoke unknown-flag branch had it removed once the gate made it unreachable. Suite 1488 → 1531. Frozen v5.0.0 snapshots untouched; `self-audit --check-readme` passed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014P6Rh59Mtj4uYrdYMCYZJE
This commit is contained in:
parent
3d6ddb273c
commit
182a37c1af
14 changed files with 337 additions and 45 deletions
|
|
@ -27,6 +27,7 @@ import { resolve } from 'node:path';
|
|||
import { writeOutputFile } from './lib/write-output.mjs';
|
||||
import { loadRegister, REGISTER_PATH } from './lib/best-practices-register.mjs';
|
||||
import { assessFreshness, STALE_AFTER_DAYS_DEFAULT } from './lib/knowledge-refresh.mjs';
|
||||
import { findArgError } from './lib/cli-args.mjs';
|
||||
|
||||
const DATE_RE = /^\d{4}-\d{2}-\d{2}$/;
|
||||
|
||||
|
|
@ -41,8 +42,14 @@ function fail(message) {
|
|||
throw new CliUsageError(message);
|
||||
}
|
||||
|
||||
/** Flag surface, measured 2026-08-09. The gate runs BEFORE the loop below, so the
|
||||
* loop no longer needs to re-check that a value followed its flag. */
|
||||
const ARG_SPEC = { boolean: ['--dry-run'], value: ['--output-file', '--stale-after', '--reference-date'] };
|
||||
|
||||
async function main() {
|
||||
const args = process.argv.slice(2);
|
||||
const argError = findArgError(args, ARG_SPEC);
|
||||
if (argError) fail(argError);
|
||||
let outputFile = null;
|
||||
let staleAfterDays = STALE_AFTER_DAYS_DEFAULT;
|
||||
let referenceDate = null; // null → today
|
||||
|
|
@ -51,20 +58,15 @@ async function main() {
|
|||
for (let i = 0; i < args.length; i++) {
|
||||
const a = args[i];
|
||||
if (a === '--dry-run') dryRun = true;
|
||||
else if (a === '--output-file' && args[i + 1]) outputFile = args[++i];
|
||||
else if (a === '--stale-after' && args[i + 1] !== undefined) {
|
||||
else if (a === '--output-file') outputFile = args[++i];
|
||||
else if (a === '--stale-after') {
|
||||
const n = Number.parseInt(args[++i], 10);
|
||||
if (!Number.isInteger(n) || n < 0) fail('--stale-after must be a non-negative integer (days)');
|
||||
staleAfterDays = n;
|
||||
} else if (a === '--reference-date' && args[i + 1]) {
|
||||
} else if (a === '--reference-date') {
|
||||
referenceDate = args[++i];
|
||||
if (!DATE_RE.test(referenceDate)) fail('--reference-date must be YYYY-MM-DD');
|
||||
}
|
||||
// A flag we do not understand must fail loudly. Silently dropping it is how
|
||||
// `--stale-after 30` — arriving as ONE argv entry from a shell that does not
|
||||
// word-split — became "all 14 entries are fresh within 90 days": a confident
|
||||
// answer to a question the caller did not ask.
|
||||
else if (a.startsWith('--')) fail(`unknown flag "${a}"`);
|
||||
}
|
||||
|
||||
// The clock is read here ONLY — the core takes an injected date and stays pure.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue