feat(cps): scan @imported files for volatile cached-prefix content (v5.10 B6) [skip-docs]
CPS originally inspected only files discovery classifies as claude-md, but a CLAUDE.md can pull arbitrary files into the cached prefix via @import — and those targets (e.g. @shared/conventions.md) are usually not claude-md in discovery, so their inlined content was never scanned. Neither TOK Pattern A (top-30 of cascade files) nor the in-file CPS scan reaches past the importing file, so volatility inside an imported file was invisible. B6 closes the gap: for each @import whose import site sits within the cached-prefix window (imp.line <= CACHED_PREFIX_LINES), CPS resolves the path (resolveImportPath, mirroring import-resolver/token-hotspots semantics), reads the target, and runs findVolatileLines over its first 150 lines. A hit emits a distinct medium finding — "Volatile content in @imported file breaks cached prefix" — keyed on the resolved file, evidence naming the importer. Scope boundaries (deliberate): - One hop only; imports-of-imports stay with IMP (deep-chain owner). - No lines-1-30 skip for imported content — that exclusion is root-file-specific to avoid Pattern A overlap, which never reaches imported files. - No double-reporting: an import resolving to a discovered claude-md is skipped (own iteration); a reportedImports set dedupes a target imported by several CLAUDE.md files. Dropped from B6 (per plan verdict): confident behavioral cache-buster detection (opusplan/model-switch is runtime, not static config) and jq-transcript automation. "No overstated behavioral finding ships" — even the permitted opusplan info-advisory was left out; the @import extension is the whole of B6. Byte-stability: the in-file finding keeps the same condition + byte-identical evidence/description (continue-skip refactored to if-emit, behaviour-preserving); new findings fire only on a volatile import, which no frozen v5.0.0 fixture has. docs: README + scanner-internals CPS rows + full B6 note; CLAUDE.md kept lean ([skip-docs]). Suite 1254 -> 1257 green; snapshots + SC-5 untouched. Version/badges/CHANGELOG wait for the v5.10 release cut. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
d2c45a3bb8
commit
fa1ddd963a
8 changed files with 183 additions and 26 deletions
|
|
@ -61,6 +61,31 @@ describe('CPS scanner — does not duplicate TOK Pattern A territory', () => {
|
|||
});
|
||||
});
|
||||
|
||||
describe('CPS scanner — volatile content in @imported files (v5.10 B6)', () => {
|
||||
it('flags volatile content inside an @imported file even when the root file is stable', async () => {
|
||||
const result = await runScanner('import-volatile/positive');
|
||||
const f = result.findings.find(x => /volatile content in @imported file/i.test(x.title || ''));
|
||||
assert.ok(f, `expected @import-volatile finding; got: ${result.findings.map(x => x.title).join(' | ')}`);
|
||||
assert.equal(f.severity, 'medium', `expected medium, got ${f.severity}`);
|
||||
assert.match(String(f.evidence || ''), /imported by/i);
|
||||
assert.match(String(f.evidence || ''), /BUILD_TIMESTAMP|git log|VAR substitution|shell-exec/i);
|
||||
assert.equal(f.category, 'token-efficiency');
|
||||
});
|
||||
|
||||
it('does NOT emit the in-file CPS finding when the importing file itself is stable', async () => {
|
||||
// Root CLAUDE.md carries no volatile lines; only the @imported file does.
|
||||
const result = await runScanner('import-volatile/positive');
|
||||
const inFile = result.findings.find(x => /volatile content inside cached prefix/i.test(x.title || ''));
|
||||
assert.equal(inFile, undefined, 'a byte-stable importing file must not trip the in-file finding');
|
||||
});
|
||||
|
||||
it('does NOT flag a clean @imported file', async () => {
|
||||
const result = await runScanner('import-volatile/clean');
|
||||
const f = result.findings.find(x => /volatile content in @imported file/i.test(x.title || ''));
|
||||
assert.equal(f, undefined, `expected no finding for a clean import; got: ${f?.title}`);
|
||||
});
|
||||
});
|
||||
|
||||
describe('CPS scanner — orchestrator wiring', () => {
|
||||
it('CPS appears in scan-orchestrator scanner list', async () => {
|
||||
const orch = await import('../../scanners/scan-orchestrator.mjs');
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue