chore(guards): add durable markers so fixes aren't silently dropped
Introduce AGENTS.md (root, primary agent instruction file) documenting six hard-won fixes with explicit DO NOT / WHY, plus executable enforcement so a future AI cannot delete or reintroduce them: 1. package-lock.json must be generated with npm 10 (Docker's npm 10.9.8). npm 11 drops the top-level @emnapi/core + @emnapi/runtime entries npm 10 needs, breaking the tag-triggered Docker build at `npm ci` (happened on v1.0.14). Add scripts/verify-lockfile-npm10.mjs + .npmrc + a Dockerfile fail-fast check + a CI step + tests/unit/lockfile-npm10-guard.test.js. Also re-fix the lockfile itself (regenerated with npm 10.9.8). 2. Tests must never write to the real ~/.9router DB (isolateDataDir). 3. Hidden providers must not leak into Usage (usageProviders !p.hidden). 4. codebuddy-intl connection test + OAuth identity. 5. Fork-only features that must survive upstream syncs. 6. Upstream sync procedure. Each marker cross-references AGENTS.md and the covering test. CLAUDE.md now points to AGENTS.md at the top. Verified: build ok, guard script passes, full suite leaves the real DB count unchanged (38), 0 new regressions.
This commit is contained in:
@@ -4,6 +4,9 @@
|
||||
// they append test rows ("zed-live-*@example.com", "guard-*@example.com",
|
||||
// "Account N") straight into the live DB.
|
||||
//
|
||||
// GUARD — DO NOT DELETE this file or remove it from vitest.config.js setupFiles.
|
||||
// See AGENTS.md §2. Covered by tests/unit/test-data-dir-isolation.test.js.
|
||||
//
|
||||
// DATA_DIR must be set before src/lib/dataDir.js is imported (it reads the env
|
||||
// at module-eval time), which is exactly what a vitest setupFile guarantees.
|
||||
//
|
||||
|
||||
@@ -0,0 +1,31 @@
|
||||
// GUARD — DO NOT DELETE. See AGENTS.md §1.
|
||||
//
|
||||
// The Docker image (node:22-alpine, pinned by digest) ships npm 10.9.8 and runs
|
||||
// `npm ci` against the committed package-lock.json. Regenerating the lockfile
|
||||
// with npm 11+ drops the top-level @emnapi/core + @emnapi/runtime entries npm 10
|
||||
// requires, breaking the tag-triggered Docker build at `npm ci` (already
|
||||
// happened on tag v1.0.14).
|
||||
//
|
||||
// Regenerate the lockfile with npm 10 only:
|
||||
// npx -y npm@10.9.8 install --package-lock-only
|
||||
import { describe, it, expect } from "vitest";
|
||||
import { readFileSync } from "node:fs";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { dirname, join } from "node:path";
|
||||
|
||||
const here = dirname(fileURLToPath(import.meta.url));
|
||||
const lock = JSON.parse(readFileSync(join(here, "..", "..", "package-lock.json"), "utf8"));
|
||||
|
||||
describe("package-lock.json is npm-10-compatible (Docker npm ci)", () => {
|
||||
it("keeps the top-level @emnapi/core entry npm 10 requires", () => {
|
||||
expect(lock.packages?.["node_modules/@emnapi/core"]).toBeTruthy();
|
||||
});
|
||||
|
||||
it("keeps the top-level @emnapi/runtime entry npm 10 requires", () => {
|
||||
expect(lock.packages?.["node_modules/@emnapi/runtime"]).toBeTruthy();
|
||||
});
|
||||
|
||||
it("stays on lockfileVersion 3", () => {
|
||||
expect(lock.lockfileVersion).toBe(3);
|
||||
});
|
||||
});
|
||||
Reference in New Issue
Block a user