config-audit/scanners/campaign-write-cli.mjs
Kjell Tore Guttormsen de8a7b5d51 fix(scanners): stop discarding our own stdout when it is a pipe
process.exit() terminates immediately, but Node writes stdout asynchronously
when stdout is a pipe — everything still buffered is dropped. scan-orchestrator
measured 246 854 bytes to a file against 65 536 to a pipe (131 072 on another
run; the cut point is a flush race), so every machine consumer that pipes the
envelope got truncated, unparseable JSON. The failure reads like a corrupt file,
not like a cut-off, which is what made it survive this long. Reported by
org-ops, whose census pipes our output.

Closes the class rather than the one CLI where it was visible. campaign-cli,
campaign-export-cli, campaign-write-cli, knowledge-refresh-cli, drift-cli and
fix-cli all exited the same way on their success paths and were green only
because their payloads fit the pipe buffer today; size is not correctness. All
38 sites across 14 files now set process.exitCode and return, which is the
pattern self-audit.mjs already used.

Two contracts needed care rather than substitution: fail() is a never-returns
guard at ~25 call sites, so it throws a CliUsageError the top-level catch
renders with the identical "Error: " prefix and exit code 3; the path guards
needed an explicit return so main() stops instead of running on. Exit codes and
stderr text are unchanged, and the frozen v5.0.0 snapshots are untouched.

The class sweep is landed as a test, not as fourteen edits — it caught one site
this commit had missed. Suite 1443/0.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01B8sS1DuDV6bUJcyumLwbvj
2026-07-31 21:40:15 +02:00

259 lines
10 KiB
JavaScript

#!/usr/bin/env node
/**
* campaign-write-cli — the human-approved WRITE half of the durable campaign ledger
* (v5.7 Fase 2, Block 3c).
*
* Sibling of the read-only `campaign-cli`: where that one only reports, this one mutates.
* Every mutation is routed through the pure, invariant-enforcing lib transforms
* (`createLedger`/`addRepo`/`setRepoStatus`) + `saveLedger` — so path normalization/dedup,
* idempotent add, the status-lifecycle guard, and the `updatedDate` bump are never
* re-implemented by hand. The `/config-audit campaign` command is a thin opus orchestrator:
* it reports (via campaign-cli), proposes a change, and only on explicit human approval
* invokes a single subcommand here (Verifiseringsplikt). It NEVER auto-writes.
*
* Determinism mirrors the lib + the knowledge-refresh CLI: `--reference-date` is the only
* place the clock is read (defaulting to today), and it is passed to the transforms as the
* injected `now`, so the persisted stamps are fully testable.
*
* Naming: `-cli` suffix → NOT an orchestrated scanner (the scan-orchestrator only loads
* scanner modules), so the scanner count is unchanged and the snapshot suite stays
* byte-stable.
*
* Usage:
* node campaign-write-cli.mjs init [--ledger-file <p>] [--reference-date <YYYY-MM-DD>]
* node campaign-write-cli.mjs add <path>... [--name <n>] [--ledger-file <p>] [--reference-date <d>]
* node campaign-write-cli.mjs set-status <path> <status>
* [--findings '<json>'] [--session <id>]
* [--ledger-file <p>] [--reference-date <d>]
* node campaign-write-cli.mjs refresh-tokens [--ledger-file <p>] [--reference-date <d>]
* (all accept [--output-file <p>] to write the result payload to a file instead of stdout)
*
* `refresh-tokens` is the live cross-repo token sweep (v5.9 B2b): for every tracked
* repo it runs the manifest's always-loaded accounting (readActiveConfig → buildManifest)
* and splits each source into the shared global layer vs the repo's per-repo delta
* (splitManifestByOwnership). The shared layer is HOME-derived and identical across
* repos, so it is captured ONCE (from the first successful read) and stored at the
* ledger root; each repo gets only its delta. This is the IO half of the machine-wide
* token roll-up whose pure data model shipped in B2a.
*
* Exit codes: 0 = write performed (or no repos to sweep, a benign no-op), 1 = advisory
* no-op (init when already initialized), 3 = error (unknown subcommand, bad args,
* invalid status, untracked repo, no/corrupt ledger).
*/
import { resolve } from 'node:path';
import { writeFile } from 'node:fs/promises';
import {
createLedger,
addRepo,
setRepoStatus,
setSharedGlobal,
setRepoTokens,
rollUp,
loadLedger,
saveLedger,
defaultLedgerPath,
} from './lib/campaign-ledger.mjs';
import { readActiveConfig } from './lib/active-config-reader.mjs';
import { buildManifest, splitManifestByOwnership } from './manifest.mjs';
const DATE_RE = /^\d{4}-\d{2}-\d{2}$/;
/**
* Usage error. Throws rather than calling process.exit(): exit() discards
* unflushed stdout when stdout is a pipe. The top-level catch prints the same
* `Error: ` text and sets the same exit code 3, so callers see no difference.
*/
class CliUsageError extends Error {}
function fail(message) {
throw new CliUsageError(message);
}
/** Parse argv into a subcommand, positional args, and the flag map. */
function parseArgs(argv) {
const positionals = [];
const flags = { ledgerFile: null, referenceDate: null, outputFile: null, name: null, findings: null, session: null };
for (let i = 0; i < argv.length; i++) {
const a = argv[i];
if (a === '--ledger-file' && argv[i + 1] !== undefined) flags.ledgerFile = argv[++i];
else if (a === '--reference-date' && argv[i + 1] !== undefined) flags.referenceDate = argv[++i];
else if (a === '--output-file' && argv[i + 1] !== undefined) flags.outputFile = argv[++i];
else if (a === '--name' && argv[i + 1] !== undefined) flags.name = argv[++i];
else if (a === '--findings' && argv[i + 1] !== undefined) flags.findings = argv[++i];
else if (a === '--session' && argv[i + 1] !== undefined) flags.session = argv[++i];
else if (a.startsWith('--')) fail(`unknown flag "${a}"`);
else positionals.push(a);
}
return { subcommand: positionals[0], rest: positionals.slice(1), flags };
}
/** Load an existing ledger, treating a parse error as a hard failure (never clobber corrupt data). */
async function loadOrFail(path) {
try {
return await loadLedger(path); // null on ENOENT (no ledger yet)
} catch (err) {
fail(`could not read ledger at ${path}: ${err.message}`);
}
}
async function emit(payload, outputFile, exitCode) {
const json = JSON.stringify(payload, null, 2);
if (outputFile) await writeFile(outputFile, json, 'utf-8');
else process.stdout.write(json + '\n');
process.exitCode = exitCode;
}
async function main() {
const { subcommand, rest, flags } = parseArgs(process.argv.slice(2));
if (!subcommand) fail('a subcommand is required: init | add | set-status | refresh-tokens');
const ledgerPath = resolve(flags.ledgerFile || defaultLedgerPath());
if (flags.referenceDate && !DATE_RE.test(flags.referenceDate)) fail('--reference-date must be YYYY-MM-DD');
// The clock is read here ONLY — the transforms take this injected `now` and stay pure.
const now = flags.referenceDate || new Date().toISOString().slice(0, 10);
if (subcommand === 'init') {
const existing = await loadOrFail(ledgerPath);
if (existing !== null) {
// Advisory no-op: never wipe an existing campaign.
return emit(
{ status: 'ok', action: 'init', written: false, alreadyInitialized: true, ledgerPath },
flags.outputFile,
1,
);
}
const ledger = createLedger({ now });
await saveLedger(ledgerPath, ledger);
return emit(
{
status: 'ok', action: 'init', written: true, alreadyInitialized: false, ledgerPath,
schemaVersion: ledger.schemaVersion, createdDate: ledger.createdDate, updatedDate: ledger.updatedDate,
repos: ledger.repos, rollUp: rollUp(ledger),
},
flags.outputFile,
0,
);
}
if (subcommand === 'add') {
const paths = rest;
if (paths.length === 0) fail('add requires at least one repo path');
const loaded = await loadOrFail(ledgerPath);
const autoInitialized = loaded === null;
let ledger = loaded === null ? createLedger({ now }) : loaded;
const added = [];
const skipped = [];
for (const p of paths) {
const resolved = resolve(p);
const present = ledger.repos.some((r) => r.path === resolved);
// --name applies only to a lone path; multi-add lets the lib derive each basename.
const name = paths.length === 1 ? flags.name || undefined : undefined;
ledger = addRepo(ledger, { path: p, name }, { now });
(present ? skipped : added).push(resolved);
}
await saveLedger(ledgerPath, ledger);
return emit(
{
status: 'ok', action: 'add', written: true, autoInitialized, ledgerPath,
added, skipped, repos: ledger.repos, rollUp: rollUp(ledger),
},
flags.outputFile,
0,
);
}
if (subcommand === 'set-status') {
const [path, status] = rest;
if (!path || !status) fail('set-status requires <path> <status>');
const ledger = await loadOrFail(ledgerPath);
if (ledger === null) fail(`no ledger at ${ledgerPath} — run "init" or "add" first`);
let findingsBySeverity;
if (flags.findings !== null) {
try {
findingsBySeverity = JSON.parse(flags.findings);
} catch (err) {
fail(`--findings must be valid JSON: ${err.message}`);
}
}
const opts = { now };
if (findingsBySeverity !== undefined) opts.findingsBySeverity = findingsBySeverity;
if (flags.session !== null) opts.sessionId = flags.session;
let next;
try {
next = setRepoStatus(ledger, path, status, opts);
} catch (err) {
// RangeError (bad status) or Error (untracked repo) → caller error.
fail(err.message);
}
await saveLedger(ledgerPath, next);
const resolved = resolve(path);
return emit(
{
status: 'ok', action: 'set-status', written: true, ledgerPath,
repo: next.repos.find((r) => r.path === resolved), repos: next.repos, rollUp: rollUp(next),
},
flags.outputFile,
0,
);
}
if (subcommand === 'refresh-tokens') {
const ledger0 = await loadOrFail(ledgerPath);
if (ledger0 === null) fail(`no ledger at ${ledgerPath} — run "init" or "add" first`);
let ledger = ledger0;
const swept = [];
const skipped = [];
// The shared global layer is HOME-derived and identical across every repo, so it
// is captured ONCE (from the first repo that reads cleanly) and stored at the
// ledger root — the structural guard against the historic shared-layer double-count.
let sharedSummary = null;
for (const repo of ledger0.repos) {
let split;
try {
const activeConfig = await readActiveConfig(repo.path, { verbose: false });
const { sources } = buildManifest(activeConfig);
split = splitManifestByOwnership(sources);
} catch (err) {
skipped.push({ path: repo.path, reason: err.message });
continue;
}
if (sharedSummary === null) sharedSummary = split.shared;
ledger = setRepoTokens(ledger, repo.path, split.delta, { now });
swept.push(repo.path);
}
if (sharedSummary !== null) ledger = setSharedGlobal(ledger, sharedSummary, { now });
const written = swept.length > 0;
if (written) await saveLedger(ledgerPath, ledger);
return emit(
{
status: 'ok', action: 'refresh-tokens', written, ledgerPath,
swept, skipped, sharedGlobal: ledger.sharedGlobal ?? null, rollUp: rollUp(ledger),
},
flags.outputFile,
0,
);
}
fail(`unknown subcommand "${subcommand}" — expected init | add | set-status | refresh-tokens`);
}
const isDirectRun =
process.argv[1] && resolve(process.argv[1]) === resolve(new URL(import.meta.url).pathname);
if (isDirectRun) {
main().catch((err) => {
const prefix = err instanceof CliUsageError ? 'Error' : 'Fatal';
process.stderr.write(`${prefix}: ${err.message}\n`);
process.exitCode = 3;
});
}