process.exit() terminates immediately, but Node writes stdout asynchronously when stdout is a pipe — everything still buffered is dropped. scan-orchestrator measured 246 854 bytes to a file against 65 536 to a pipe (131 072 on another run; the cut point is a flush race), so every machine consumer that pipes the envelope got truncated, unparseable JSON. The failure reads like a corrupt file, not like a cut-off, which is what made it survive this long. Reported by org-ops, whose census pipes our output. Closes the class rather than the one CLI where it was visible. campaign-cli, campaign-export-cli, campaign-write-cli, knowledge-refresh-cli, drift-cli and fix-cli all exited the same way on their success paths and were green only because their payloads fit the pipe buffer today; size is not correctness. All 38 sites across 14 files now set process.exitCode and return, which is the pattern self-audit.mjs already used. Two contracts needed care rather than substitution: fail() is a never-returns guard at ~25 call sites, so it throws a CliUsageError the top-level catch renders with the identical "Error: " prefix and exit code 3; the path guards needed an explicit return so main() stops instead of running on. Exit codes and stderr text are unchanged, and the frozen v5.0.0 snapshots are untouched. The class sweep is landed as a test, not as fourteen edits — it caught one site this commit had missed. Suite 1443/0. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01B8sS1DuDV6bUJcyumLwbvj
138 lines
4.4 KiB
JavaScript
138 lines
4.4 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
/**
|
|
* Config-Audit Posture Assessment CLI
|
|
* Runs all scanners + scoring in a single Node.js process.
|
|
* Usage: node posture.mjs <target-path> [--json] [--global] [--output-file path]
|
|
* Zero external dependencies.
|
|
*/
|
|
|
|
import { resolve } from 'node:path';
|
|
import { writeFile } from 'node:fs/promises';
|
|
import { runAllScanners } from './scan-orchestrator.mjs';
|
|
import { humanizeEnvelope } from './lib/humanizer.mjs';
|
|
import {
|
|
calculateUtilization,
|
|
determineMaturityLevel,
|
|
determineSegment,
|
|
scoreByArea,
|
|
topActions,
|
|
generateScorecard,
|
|
generateHealthScorecard,
|
|
} from './lib/scoring.mjs';
|
|
|
|
/**
|
|
* Run posture assessment and return structured result.
|
|
* @param {string} targetPath
|
|
* @param {object} [opts]
|
|
* @param {boolean} [opts.includeGlobal=false]
|
|
* @param {boolean} [opts.fullMachine=false] - Scan all known locations across the machine
|
|
* @returns {Promise<object>}
|
|
*/
|
|
export async function runPosture(targetPath, opts = {}) {
|
|
const envelope = await runAllScanners(targetPath, opts);
|
|
|
|
// Extract GAP scanner results
|
|
const gapScanner = envelope.scanners.find(s => s.scanner === 'GAP');
|
|
const gapFindings = gapScanner ? gapScanner.findings : [];
|
|
|
|
// Calculate scores
|
|
const utilization = calculateUtilization(gapFindings);
|
|
const maturity = determineMaturityLevel(gapFindings, { files: [] });
|
|
const segment = determineSegment(utilization.score);
|
|
const areaScores = scoreByArea(envelope.scanners);
|
|
const actions = topActions(gapFindings);
|
|
|
|
return {
|
|
utilization,
|
|
maturity,
|
|
segment,
|
|
areas: areaScores.areas,
|
|
overallGrade: areaScores.overallGrade,
|
|
topActions: actions,
|
|
opportunityCount: gapFindings.length,
|
|
scannerEnvelope: envelope,
|
|
};
|
|
}
|
|
|
|
// --- CLI entry point ---
|
|
async function main() {
|
|
const args = process.argv.slice(2);
|
|
let targetPath = '.';
|
|
let outputFile = null;
|
|
let jsonMode = false;
|
|
let rawMode = false;
|
|
let includeGlobal = false;
|
|
let fullMachine = false;
|
|
let contextWindow = null;
|
|
|
|
for (let i = 0; i < args.length; i++) {
|
|
if (args[i] === '--output-file' && args[i + 1]) {
|
|
outputFile = args[++i];
|
|
} else if (args[i] === '--context-window' && args[i + 1]) {
|
|
contextWindow = args[++i];
|
|
} else if (args[i] === '--json') {
|
|
jsonMode = true;
|
|
} else if (args[i] === '--raw') {
|
|
rawMode = true;
|
|
} else if (args[i] === '--global') {
|
|
includeGlobal = true;
|
|
} else if (args[i] === '--full-machine') {
|
|
fullMachine = true;
|
|
} else if (args[i] === '--include-fixtures') {
|
|
// handled below
|
|
} else if (!args[i].startsWith('-')) {
|
|
targetPath = args[i];
|
|
}
|
|
}
|
|
|
|
const filterFixtures = !args.includes('--include-fixtures');
|
|
const humanizedProgress = !jsonMode && !rawMode;
|
|
const result = await runPosture(targetPath, {
|
|
includeGlobal,
|
|
fullMachine,
|
|
filterFixtures,
|
|
humanizedProgress,
|
|
contextWindow,
|
|
});
|
|
|
|
// stdout JSON path: --json and --raw both write the v5.0.0-shape result
|
|
// (byte-identical). Default mode writes nothing to stdout.
|
|
if (jsonMode || rawMode) {
|
|
const json = JSON.stringify(result, null, 2);
|
|
process.stdout.write(json + '\n');
|
|
}
|
|
|
|
// stderr scorecard path: --json suppresses; --raw renders v5.0.0 verbatim
|
|
// (humanized=false); default renders humanized scorecard.
|
|
if (!jsonMode) {
|
|
const scorecard = generateHealthScorecard(
|
|
{ areas: result.areas, overallGrade: result.overallGrade },
|
|
result.opportunityCount,
|
|
{ humanized: !rawMode },
|
|
);
|
|
process.stderr.write('\n' + scorecard + '\n');
|
|
}
|
|
|
|
if (outputFile) {
|
|
// Consumers (feature-gap.md, posture.md) read scannerEnvelope.scanners[].findings
|
|
// and group on humanizer fields. posture's result nests the envelope under
|
|
// `scannerEnvelope`, so humanize THAT (not `result`, which has no top-level
|
|
// `scanners` array — humanizeEnvelope would no-op). --json/--raw stay raw.
|
|
const fileEnv = (jsonMode || rawMode)
|
|
? result
|
|
: { ...result, scannerEnvelope: humanizeEnvelope(result.scannerEnvelope) };
|
|
const json = JSON.stringify(fileEnv, null, 2);
|
|
await writeFile(outputFile, json, 'utf-8');
|
|
process.stderr.write(`\nResults written to ${outputFile}\n`);
|
|
}
|
|
}
|
|
|
|
// Only run CLI if invoked directly
|
|
const isDirectRun = process.argv[1] && resolve(process.argv[1]) === resolve(new URL(import.meta.url).pathname);
|
|
if (isDirectRun) {
|
|
main().catch(err => {
|
|
process.stderr.write(`Fatal: ${err.message}\n`);
|
|
process.exitCode = 1;
|
|
});
|
|
}
|