`KNOWN_OPEN` in cli-unknown-flag-rejection.test.mjs named two CLIs as still carrying the argument-swallow defect. That number was the previous session's field of view, not a measurement. Measuring all fourteen found **7** open on the unknown-flag arm and **10** on a second arm the deferral note never described. Arm 1 — unknown flag: with no `else` branch, `--zzz` leaves no trace. exit 0, full payload, a confident answer to a question the caller did not ask. Arm 2 — the sharper one: `a === '--output-file' && args[i + 1]` asks only whether a next token EXISTS, never whether it is a value. `manifest`, `campaign-cli` and `knowledge-refresh-cli` each wrote a file literally named `--json` into the caller's working directory when handed `--output-file --json`, exit 0, with `--json` mode silently dropped. A wrong answer is bad; an unintended file on disk is worse. Two of the CLIs this catches were already in GUARDED and green on arm 1 while arm 2 stood open a few lines away — the guard asserted one relation instead of the invariant. Fixed with a shared gate (`lib/cli-args.mjs`) that runs BEFORE each CLI's own parse loop rather than replacing it: valid argv reaches the existing parser byte-for-byte unchanged, so the byte-stability argument is structural rather than empirical. `drift-cli`, `fix-cli` and `plugin-health-scanner` were already correct on both arms and were moved into GUARDED instead of rewritten. The three CLIs with a bespoke unknown-flag branch had it removed once the gate made it unreachable. Suite 1488 → 1531. Frozen v5.0.0 snapshots untouched; `self-audit --check-readme` passed. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014P6Rh59Mtj4uYrdYMCYZJE
126 lines
4.1 KiB
JavaScript
126 lines
4.1 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
/**
|
|
* campaign-cli — read-only reporter for the durable machine-wide campaign ledger
|
|
* (v5.7 Fase 2, Block 3b).
|
|
*
|
|
* Mirrors the knowledge-refresh-cli precedent: it is the DETERMINISTIC, READ-ONLY half
|
|
* of the hybrid motor. It loads the campaign ledger (the durable file that sits ABOVE
|
|
* individual config-audit sessions), validates it, and emits the repo list + a
|
|
* machine-wide roll-up as JSON. It NEVER writes the ledger — initialization and every
|
|
* status transition belong to the command layer (Block 3c `/config-audit campaign`),
|
|
* which calls the lib's pure transforms + saveLedger only on explicit, human-approved
|
|
* action. A missing ledger file is reported gracefully (initialized:false), NEVER created.
|
|
*
|
|
* Naming: `-cli` suffix → NOT an orchestrated scanner (the scan-orchestrator only loads
|
|
* scanner modules), so the scanner count is unchanged and the snapshot suite stays
|
|
* byte-stable.
|
|
*
|
|
* Usage:
|
|
* node campaign-cli.mjs [--ledger-file <path>] [--output-file <path>]
|
|
*
|
|
* Exit codes: 0 = initialized & valid, 1 = not initialized yet (advisory), 3 = error.
|
|
*/
|
|
|
|
import { resolve } from 'node:path';
|
|
import { writeOutputFile } from './lib/write-output.mjs';
|
|
import { findArgError } from './lib/cli-args.mjs';
|
|
import {
|
|
loadLedger,
|
|
validateLedger,
|
|
rollUp,
|
|
buildBacklog,
|
|
defaultLedgerPath,
|
|
} from './lib/campaign-ledger.mjs';
|
|
|
|
/**
|
|
* Usage error. Throws rather than calling process.exit(): exit() discards
|
|
* unflushed stdout when stdout is a pipe. The top-level catch prints the same
|
|
* `Error: ` text and sets the same exit code 3, so callers see no difference.
|
|
*/
|
|
class CliUsageError extends Error {}
|
|
|
|
function fail(message) {
|
|
throw new CliUsageError(message);
|
|
}
|
|
|
|
/** Flag surface, measured 2026-08-09. The gate runs BEFORE the loop below, so the
|
|
* loop no longer needs to re-check that a value followed its flag. */
|
|
const ARG_SPEC = { value: ['--ledger-file', '--output-file'] };
|
|
|
|
async function main() {
|
|
const args = process.argv.slice(2);
|
|
const argError = findArgError(args, ARG_SPEC);
|
|
if (argError) fail(argError);
|
|
let ledgerFile = null;
|
|
let outputFile = null;
|
|
|
|
for (let i = 0; i < args.length; i++) {
|
|
const a = args[i];
|
|
if (a === '--ledger-file') ledgerFile = args[++i];
|
|
else if (a === '--output-file') outputFile = args[++i];
|
|
}
|
|
|
|
const ledgerPath = resolve(ledgerFile || defaultLedgerPath());
|
|
|
|
let ledger;
|
|
try {
|
|
// loadLedger returns null on ENOENT (graceful first run) and throws on parse error.
|
|
ledger = await loadLedger(ledgerPath);
|
|
} catch (err) {
|
|
fail(`could not read ledger at ${ledgerPath}: ${err.message}`);
|
|
}
|
|
|
|
let payload;
|
|
let exitCode;
|
|
|
|
if (ledger === null) {
|
|
// Graceful first run — the ledger does not exist yet. We DO NOT create it; that is
|
|
// the command layer's job (Block 3c), on explicit human-approved action.
|
|
payload = {
|
|
status: 'ok',
|
|
initialized: false,
|
|
ledgerPath,
|
|
schemaVersion: null,
|
|
createdDate: null,
|
|
updatedDate: null,
|
|
repos: [],
|
|
rollUp: rollUp({ repos: [] }),
|
|
backlog: buildBacklog({ repos: [] }),
|
|
};
|
|
exitCode = 1; // advisory: there is no campaign to report yet
|
|
} else {
|
|
const { valid, errors } = validateLedger(ledger);
|
|
if (!valid) {
|
|
fail(`ledger at ${ledgerPath} is invalid:\n - ${errors.join('\n - ')}`);
|
|
}
|
|
payload = {
|
|
status: 'ok',
|
|
initialized: true,
|
|
ledgerPath,
|
|
schemaVersion: ledger.schemaVersion,
|
|
createdDate: ledger.createdDate,
|
|
updatedDate: ledger.updatedDate,
|
|
repos: ledger.repos,
|
|
rollUp: rollUp(ledger),
|
|
backlog: buildBacklog(ledger),
|
|
};
|
|
exitCode = 0;
|
|
}
|
|
|
|
const json = JSON.stringify(payload, null, 2);
|
|
if (outputFile) await writeOutputFile(outputFile, json, 'utf-8');
|
|
else process.stdout.write(json + '\n');
|
|
|
|
process.exitCode = exitCode;
|
|
}
|
|
|
|
const isDirectRun =
|
|
process.argv[1] && resolve(process.argv[1]) === resolve(new URL(import.meta.url).pathname);
|
|
if (isDirectRun) {
|
|
main().catch((err) => {
|
|
const prefix = err instanceof CliUsageError ? 'Error' : 'Fatal';
|
|
process.stderr.write(`${prefix}: ${err.message}\n`);
|
|
process.exitCode = 3;
|
|
});
|
|
}
|