fix(scanners): close the CLI argument class across all fourteen CLIs

`KNOWN_OPEN` in cli-unknown-flag-rejection.test.mjs named two CLIs as still
carrying the argument-swallow defect. That number was the previous session's
field of view, not a measurement. Measuring all fourteen found **7** open on
the unknown-flag arm and **10** on a second arm the deferral note never
described.

Arm 1 — unknown flag: with no `else` branch, `--zzz` leaves no trace. exit 0,
full payload, a confident answer to a question the caller did not ask.

Arm 2 — the sharper one: `a === '--output-file' && args[i + 1]` asks only
whether a next token EXISTS, never whether it is a value. `manifest`,
`campaign-cli` and `knowledge-refresh-cli` each wrote a file literally named
`--json` into the caller's working directory when handed `--output-file
--json`, exit 0, with `--json` mode silently dropped. A wrong answer is bad;
an unintended file on disk is worse.

Two of the CLIs this catches were already in GUARDED and green on arm 1 while
arm 2 stood open a few lines away — the guard asserted one relation instead of
the invariant.

Fixed with a shared gate (`lib/cli-args.mjs`) that runs BEFORE each CLI's own
parse loop rather than replacing it: valid argv reaches the existing parser
byte-for-byte unchanged, so the byte-stability argument is structural rather
than empirical. `drift-cli`, `fix-cli` and `plugin-health-scanner` were
already correct on both arms and were moved into GUARDED instead of rewritten.
The three CLIs with a bespoke unknown-flag branch had it removed once the gate
made it unreachable.

Suite 1488 → 1531. Frozen v5.0.0 snapshots untouched; `self-audit
--check-readme` passed.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014P6Rh59Mtj4uYrdYMCYZJE
This commit is contained in:
Kjell Tore Guttormsen 2026-08-09 21:42:00 +02:00
commit 182a37c1af
14 changed files with 337 additions and 45 deletions

View file

@ -0,0 +1,52 @@
/**
* Unit-level companion to `tests/scanners/cli-unknown-flag-rejection.test.mjs`.
* That file measures the real CLIs end-to-end; this one pins the decision table
* itself, including the cases no CLI happens to exercise today.
*/
import { test } from 'node:test';
import { strict as assert } from 'node:assert';
import { findArgError } from '../../scanners/lib/cli-args.mjs';
const SPEC = { boolean: ['--json', '--raw'], value: ['--output-file', '--context-window'] };
test('well-formed argv passes', () => {
assert.equal(findArgError([], SPEC), null);
assert.equal(findArgError(['--json'], SPEC), null);
assert.equal(findArgError(['--output-file', 'out.json', '--raw'], SPEC), null);
assert.equal(findArgError(['/some/target', '--json'], SPEC), null);
});
test('an unknown flag is named in the diagnostic', () => {
const err = findArgError(['--zzz'], SPEC);
assert.match(err, /unknown flag "--zzz"/, 'the caller must be able to find the offending token');
});
test('a value flag followed by another flag is rejected', () => {
const err = findArgError(['--output-file', '--json'], SPEC);
assert.match(err, /--output-file/);
assert.match(err, /--json/, 'both the flag and the thing mistaken for its value must appear');
});
test('a value flag with nothing after it is rejected', () => {
assert.match(findArgError(['--output-file'], SPEC), /nothing followed it/);
});
test('a value is never re-read as a flag', () => {
// Without the consume step, a value that looks like a positional is harmless,
// but a spec change could make this the difference between pass and reject.
assert.equal(findArgError(['--output-file', 'report.json'], SPEC), null);
});
test('positionals and subcommands pass through untouched', () => {
assert.equal(findArgError(['init', '/target'], SPEC), null);
});
test('the FIRST error is reported, not the last', () => {
// A caller fixing errors one at a time should see them in argv order.
assert.match(findArgError(['--zzz', '--output-file'], SPEC), /--zzz/);
});
test('a spec with no value flags still rejects unknown flags', () => {
assert.match(findArgError(['--nope'], { boolean: ['--json'] }), /unknown flag "--nope"/);
});