fix(shell): remove runtime early-exit pipe hazards (#1105)
ci/woodpecker/push/publish Pipeline failed
ci/woodpecker/push/ci Pipeline was successful

Co-authored-by: f10-coder <[email protected]>
This commit was merged in pull request #1105.
This commit is contained in:
2026-08-07 09:38:37 +00:00
committed by Mos
parent df4c591ab4
commit 3a1203b2f8
20 changed files with 308 additions and 32 deletions
+3 -2
View File
@@ -72,8 +72,9 @@ elif [[ -n "$DATA_DIR" ]]; then
while IFS= read -r file; do
[[ -z "$file" ]] && continue
done_total=$((done_total + 1))
if git -C "$DATA_DIR" log --since="${WINDOW_DAYS} days ago" --pretty='%s' -- "$file" 2>/dev/null \
| grep -qiE 'reopen|revert|fix|regression|wrong|incorrect|redo'; then
history_rc=0
history="$(git -C "$DATA_DIR" log --since="${WINDOW_DAYS} days ago" --pretty='%s' -- "$file" 2>/dev/null)" || history_rc=$?
if [[ "$history_rc" -eq 0 ]] && grep -qiE 'reopen|revert|fix|regression|wrong|incorrect|redo' <<<"$history"; then
detectable=$((detectable + 1))
fi
done < <(find "$DATA_DIR" -type f -name '*.json' 2>/dev/null)
+2 -2
View File
@@ -64,9 +64,9 @@ for line in "${LINES[@]}"; do
# - build/test/lint/type/ci signals → CI would have caught it
# - security/auth/permission/data/migration → human review would flag it
# - everything else (logic/UX/assumption/edge) → only-self-reflection bucket
if printf '%s' "$subj" | grep -qiE 'test|lint|type|build|ci|compile|typo'; then
if grep -qiE 'test|lint|type|build|ci|compile|typo' <<<"$subj"; then
ci=$((ci + 1))
elif printf '%s' "$subj" | grep -qiE 'security|auth|permission|rbac|secret|migration|data|sql|injection'; then
elif grep -qiE 'security|auth|permission|rbac|secret|migration|data|sql|injection' <<<"$subj"; then
human=$((human + 1))
else
selfonly=$((selfonly + 1))
@@ -0,0 +1,28 @@
[
"tools/matrix-presence-harness/run.sh:TSX_CLI=\"$(ls -d \"${REPO}\"/node_modules/.pnpm/tsx@*/node_modules/tsx/dist/cli.mjs 2>/dev/null | head -1)\"",
"tools/e2e-install-test.sh:if ! mosaic gateway --help 2>&1 | grep -q 'verify'; then",
"tools/install.sh:EXTRACTED_DIR=\"$(find \"$WORK_DIR\" -maxdepth 1 -mindepth 1 -type d | head -1)\"",
"scripts/analysis/reflect-board-history.sh:if git -C \"$DATA_DIR\" log --since=\"${WINDOW_DAYS} days ago\" --pretty='%s' -- \"$file\" 2>/dev/null | grep -qiE 'reopen|revert|fix|regression|wrong|incorrect|redo'; then",
"scripts/analysis/reflect-git-history.sh:if printf '%s' \"$subj\" | grep -qiE 'test|lint|type|build|ci|compile|typo'; then",
"scripts/analysis/reflect-git-history.sh:elif printf '%s' \"$subj\" | grep -qiE 'security|auth|permission|rbac|secret|migration|data|sql|injection'; then",
"packages/mosaic/framework/tools/authentik/user-create.sh:group_pk=$(echo \"$group_response\" | jq -r \".results[] | select(.name == \\\"$GROUP\\\") | .pk\" | head -1)",
"packages/mosaic/framework/tools/git/mutate-push-guard.sh:PROSE_LO=\"$(grep -n '^usage() {' \"$BAK\" | head -1 | cut -d: -f1)\"",
"packages/mosaic/framework/tools/orchestrator/session-resume.sh:echo \"$dirty_files\" | head -20 | while IFS= read -r line; do",
"packages/mosaic/framework/tools/prdy/prdy-status.sh:if echo \"$PRD_CONTENT\" | grep -qiE \"$pattern\"; then",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'auth|login|session|token|permission|rbac|credential|secret'; then echo auth; return; fi",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'migration|prisma|schema|\\.sql|entity|repository|seed'; then echo data; return; fi",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'docker|\\.woodpecker|compose|traefik|deploy|helm|k8s|terraform'; then echo infra; return; fi",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qiE 'package\\.json|tsconfig|turbo\\.json|pnpm-|\\.config\\.|eslint|vite'; then echo build; return; fi",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qE '\\.tsx|\\.css|components/|apps/web/'; then echo ui; return; fi",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qE '\\.spec\\.|\\.test\\.|__tests__/'; then echo test; return; fi",
"packages/mosaic/framework/tools/qa/reflect-stop-hook.sh:if printf '%s' \"$p\" | grep -qE '\\.md$|docs/'; then echo docs; return; fi",
"packages/mosaic/framework/tools/qa/typecheck-hook.sh:FILE_PATH=$(echo \"$JSON_INPUT\" | grep -o '\"file_path\"[[:space:]]*:[[:space:]]*\"[^\"]*\"' | sed 's/.*\"\\([^\"]*\\)\"$/\\1/' | head -1)",
"packages/mosaic/framework/tools/qa/typecheck-hook.sh:RELEVANT=$(echo \"$OUTPUT\" | grep -A2 \"$BASENAME\" 2>/dev/null || echo \"$OUTPUT\" | head -20)",
"packages/mosaic/framework/tools/tmux/send-message.sh:if printf '%s' \"$pane\" | grep -qF \"$QUEUED_RE\"; then",
"packages/mosaic/framework/tools/tmux/send-message.sh:if [ -n \"$snippet\" ] && printf '%s' \"$promptline\" | grep -qF \"$snippet\"; then",
"packages/mosaic/framework/tools/wake/detector.sh:sed -n \"s/^${key}=//p\" \"$MANIFEST\" | head -n1 | tr -d '[:space:]'",
"packages/mosaic/framework/tools/wake/detector.sh:if [ -n \"$snap_sha\" ] && ! printf '%s' \"$snap_sha\" | grep -Eq '^[0-9a-f]{7,64}$'; then",
"packages/mosaic/framework/tools/wake/detector.sh:if [ -n \"$snap_ts\" ] && ! printf '%s' \"$snap_ts\" | grep -Eq '^[0-9]{1,12}$'; then",
"packages/mosaic/framework/tools/wake/digest.sh:olabel=\"$(_locator_line \"$oloc\" | head -n1)\"",
"packages/mosaic/framework/tools/wake/reconcile.sh:sed -n \"s/^${key}=//p\" \"$MANIFEST\" | head -n1 | tr -d '[:space:]'"
]
+135
View File
@@ -0,0 +1,135 @@
import assert from 'node:assert/strict';
import { spawnSync } from 'node:child_process';
import { chmod, mkdtemp, readFile, rm, writeFile } from 'node:fs/promises';
import { tmpdir } from 'node:os';
import path from 'node:path';
import test from 'node:test';
const ROOT = new URL('../', import.meta.url);
const EXPECTED_BASELINE_SITES = 26;
const TARGETS = [
'tools/matrix-presence-harness/run.sh',
'tools/e2e-install-test.sh',
'tools/install.sh',
'scripts/agent/session-start.sh',
'scripts/analysis/reflect-board-history.sh',
'scripts/analysis/reflect-git-history.sh',
'packages/mosaic/framework/templates/repo/scripts/agent/session-start.sh',
'packages/mosaic/framework/tools/authentik/user-create.sh',
'packages/mosaic/framework/tools/git/mutate-push-guard.sh',
'packages/mosaic/framework/tools/orchestrator/session-resume.sh',
'packages/mosaic/framework/tools/prdy/prdy-status.sh',
'packages/mosaic/framework/tools/qa/reflect-stop-hook.sh',
'packages/mosaic/framework/tools/qa/typecheck-hook.sh',
'packages/mosaic/framework/tools/tmux/send-message.sh',
'packages/mosaic/framework/tools/wake/detector.sh',
'packages/mosaic/framework/tools/wake/digest.sh',
'packages/mosaic/framework/tools/wake/reconcile.sh',
];
// These statuses are explicitly non-load-bearing or unreachable at designed input.
// They remain inventoried until the final #1099 tranche records every verdict.
const ACCEPTED = [
['tools/install.sh', 'mosaic-bak-', '|| true'],
['tools/install.sh', 'mosaicstack-mosaic-*.tgz', 'head -1'],
['tools/install.sh', 'mosaicstack-gateway-*.tgz', 'head -1'],
['scripts/agent/session-start.sh', 'docs/scratchpads/*.md', '|| true'],
[
'packages/mosaic/framework/templates/repo/scripts/agent/session-start.sh',
'docs/scratchpads/*.md',
'|| true',
],
];
const earlyExit =
/(?<!\|)\|(?!\|)[^;\n]*(?:grep\b[^;\n]*(?:-[A-Za-z]*q|--quiet|-m\s*1)|head\b(?:\s|$))/;
function scan(sources) {
const found = [];
for (const [file, rawSource] of sources) {
const source = rawSource.replace(/\\\n\s*/g, ' ');
for (const rawLine of source.split('\n')) {
const line = rawLine.trim();
if (!earlyExit.test(line)) continue;
const accepted = ACCEPTED.some(
([acceptedFile, ...fragments]) =>
acceptedFile === file && fragments.every((item) => line.includes(item)),
);
if (!accepted) found.push(`${file}:${line}`);
}
}
return found;
}
async function currentSources() {
return Promise.all(
TARGETS.map(async (file) => [file, await readFile(new URL(file, ROOT), 'utf8')]),
);
}
test('the registered baseline denominator is exactly 26 unsafe sites', async () => {
const baseline = JSON.parse(
await readFile(new URL('scripts/fixtures/pipefail-early-exit-baseline.json', ROOT), 'utf8'),
);
assert.equal(baseline.length, EXPECTED_BASELINE_SITES);
assert.equal(new Set(baseline).size, EXPECTED_BASELINE_SITES);
const fixtureSources = baseline.map((site) => {
const separator = site.indexOf(':');
assert.ok(separator > 0, `invalid baseline site: ${site}`);
return [site.slice(0, separator), site.slice(separator + 1)];
});
assert.deepEqual(scan(fixtureSources), baseline);
});
test('load-bearing pipefail paths do not pipe into early-exiting consumers', async () => {
assert.deepEqual(scan(await currentSources()), []);
});
test('gateway verify capability preserves the complete help-probe truth table', async () => {
const directory = await mkdtemp(path.join(tmpdir(), 'gateway-help-probe-'));
const mosaic = path.join(directory, 'mosaic');
const probe = new URL('tools/e2e-gateway-verify-supported.sh', ROOT).pathname;
try {
await writeFile(
mosaic,
'#!/usr/bin/env bash\nprintf \'%s\\n\' "${MOCK_HELP_OUTPUT:-}"\nexit "${MOCK_HELP_RC:-0}"\n',
);
await chmod(mosaic, 0o755);
const run = (rc, output) =>
spawnSync('bash', [probe], {
env: {
...process.env,
PATH: `${directory}:${process.env.PATH}`,
MOCK_HELP_RC: String(rc),
MOCK_HELP_OUTPUT: output,
},
}).status;
assert.equal(run(0, 'commands: verify'), 0);
assert.equal(run(0, 'commands: install'), 1);
assert.equal(run(1, 'commands: verify'), 1);
} finally {
await rm(directory, { recursive: true, force: true });
}
});
test('board-history preserves non-git data-dir as a non-detectable result', async () => {
const directory = await mkdtemp(path.join(tmpdir(), 'reflect-board-non-git-'));
try {
await writeFile(path.join(directory, 'task.json'), '{}\n');
const result = spawnSync(
'bash',
[
new URL('scripts/analysis/reflect-board-history.sh', ROOT).pathname,
'--data-dir',
directory,
],
{ encoding: 'utf8' },
);
assert.equal(result.status, 0, result.stderr);
assert.match(result.stdout, /"done_tasks": 1/);
assert.match(result.stdout, /"detectable_outcomes": 0/);
} finally {
await rm(directory, { recursive: true, force: true });
}
});