chore(guards): add durable markers so fixes aren't silently dropped

Introduce AGENTS.md (root, primary agent instruction file) documenting six
hard-won fixes with explicit DO NOT / WHY, plus executable enforcement so a
future AI cannot delete or reintroduce them:

1. package-lock.json must be generated with npm 10 (Docker's npm 10.9.8).
   npm 11 drops the top-level @emnapi/core + @emnapi/runtime entries npm 10
   needs, breaking the tag-triggered Docker build at `npm ci` (happened on
   v1.0.14). Add scripts/verify-lockfile-npm10.mjs + .npmrc + a Dockerfile
   fail-fast check + a CI step + tests/unit/lockfile-npm10-guard.test.js.
   Also re-fix the lockfile itself (regenerated with npm 10.9.8).
2. Tests must never write to the real ~/.9router DB (isolateDataDir).
3. Hidden providers must not leak into Usage (usageProviders !p.hidden).
4. codebuddy-intl connection test + OAuth identity.
5. Fork-only features that must survive upstream syncs.
6. Upstream sync procedure.

Each marker cross-references AGENTS.md and the covering test. CLAUDE.md now
points to AGENTS.md at the top. Verified: build ok, guard script passes,
full suite leaves the real DB count unchanged (38), 0 new regressions.
This commit is contained in:
MUH. IQRAM BAHRING
2026-09-19 12:52:19 +08:00
parent 9c37af90a9
commit 25df5e6a9d
13 changed files with 365 additions and 28 deletions
+6
View File
@@ -24,6 +24,12 @@ jobs:
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
# Guard: the committed package-lock.json must be npm-10-compatible (the
# Docker image ships npm 10.9.8). Fails fast with a fix hint instead of a
# cryptic `npm ci` EUSAGE error. See AGENTS.md §1.
- name: Verify lockfile is npm-10-compatible
run: node scripts/verify-lockfile-npm10.mjs
- uses: docker/setup-buildx-action@f7ce87c1d6bead3e36075b2ce75da1f6cc28aaca # v3.9.0
- name: Log in to GHCR