fix(engine): TAG-ANNOTATED never consulted the register for the newest tag
Reported by catalog (coord, 2026-08-17): register/repos.json has listed ktg-plugin-marketplace v7.7.2 under tags_lightweight_accepted since the 0.11.2 release (2026-08-14), but `accepted` was only ever applied to tags.slice(0, -1) — the newest tag is excluded from that slice by construction, so the entry was dead weight from the day it was written. checkTagIntegrity now checks the newest tag against `accepted` too, emitting a distinct TAG-ANNOTATED-ACCEPTED-NEWEST OK instead of silently doing nothing when the register names it exactly. Acceptance is per-tag-name, not a standing exemption: a new lightweight tag that becomes newest afterwards is still judged (tested). TDD: two new tests written failing first (an existing test's title claimed "cannot be accepted away" but never actually passed a matching `name`, so it was accidentally still green either way — reworded to test what it actually covers). Verified against a fresh clone of ktg-plugin-marketplace: the full finding set now reads OK TAG-ANNOTATED-ACCEPTED-NEWEST + OK TAG-ANNOTATED-ACCEPTED(7 older) instead of ERROR, with no knock-on effect on TAG-SIGNED (all 9 tags predate the signing policy). Register comment updated to record the three-day dead-weight window rather than silently correcting it — a decision that turns out wrong is worse than no record. 247 tests pass (245 + 2 new).
This commit is contained in:
parent
4714f13959
commit
aee0f28539
3 changed files with 72 additions and 12 deletions
|
|
@ -708,15 +708,27 @@ export function checkTagIntegrity({ tagObjects, name }, register) {
|
|||
|
||||
const findings = [];
|
||||
const newest = tags[tags.length - 1];
|
||||
if (!newest.annotated) {
|
||||
findings.push({
|
||||
level: 'ERROR',
|
||||
code: 'TAG-ANNOTATED',
|
||||
bucket: 'broken',
|
||||
msg: `newest tag \`${newest.name}\` is lightweight — it can be moved to another commit with no record that it ever pointed elsewhere, and the catalog pins releases by tag. Re-cut it annotated: \`git tag -a -f ${newest.name} ${newest.name}^{}\`.`,
|
||||
});
|
||||
}
|
||||
const accepted = new Set(register?.tags_lightweight_accepted?.[name] ?? []);
|
||||
if (!newest.annotated) {
|
||||
if (accepted.has(newest.name)) {
|
||||
// Named acceptance, not a standing exemption: only THIS exact tag is
|
||||
// excused, so a later real release still fires ERROR the moment it
|
||||
// becomes newest and isn't itself on the list (proven by the sibling
|
||||
// test below).
|
||||
findings.push({
|
||||
level: 'OK',
|
||||
code: 'TAG-ANNOTATED-ACCEPTED-NEWEST',
|
||||
msg: `newest tag \`${newest.name}\` is lightweight, but the register accepts it by name as an exception to the newest-tag rule — a safe remedy exists (\`git tag -a -f\`) but costs more than the finding for this specific tag. Any OTHER tag that becomes newest is still judged.`,
|
||||
});
|
||||
} else {
|
||||
findings.push({
|
||||
level: 'ERROR',
|
||||
code: 'TAG-ANNOTATED',
|
||||
bucket: 'broken',
|
||||
msg: `newest tag \`${newest.name}\` is lightweight — it can be moved to another commit with no record that it ever pointed elsewhere, and the catalog pins releases by tag. Re-cut it annotated: \`git tag -a -f ${newest.name} ${newest.name}^{}\`.`,
|
||||
});
|
||||
}
|
||||
}
|
||||
const olderLightweight = tags.slice(0, -1).filter((t) => !t.annotated);
|
||||
const older = olderLightweight.filter((t) => !accepted.has(t.name));
|
||||
const excused = olderLightweight.filter((t) => accepted.has(t.name));
|
||||
|
|
@ -842,7 +854,7 @@ export function checkTagSigned({ tagObjects }, register) {
|
|||
level: 'SKIP',
|
||||
skip: 'byDesign',
|
||||
code: 'TAG-SIGNED-LIGHTWEIGHT',
|
||||
msg: `${lightweight.length} tag(s) cut under the policy are lightweight (${lightweight.map((t) => t.name).join(', ')}) — a lightweight tag has no tag object to carry a signature, so signing is not a remedy it has. TAG-ANNOTATED owns that finding; this check declines rather than report one defect twice.`,
|
||||
msg: `${lightweight.length} tag(s) cut under the policy are lightweight (${lightweight.map((t) => t.name).join(', ')}) — a lightweight tag has no tag object to carry a signature, so signing is not a remedy it has. TAG-ANNOTATED owns the verdict on these — an ERROR, or an OK if the register names one as an accepted exception; this check declines rather than report one defect twice.`,
|
||||
});
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue